GDPR Article 28 · template version 1.1
Data processing addendum.
If your agents receive mail from people in the EU, you probably need a data processing agreement with us. Ours is a standard template you can read now; we complete it with your company’s details and both sign it.
hello@agentboxd.com
Getting a signed copy
- Write to hello@agentboxd.com from an address at your company, with your company’s legal name, registered address, the workspace it covers and who will sign.
- We send back the completed addendum. If your counsel wants changes, send them with the request or in reply.
- Both sides sign, and you keep the countersigned copy. Ask for sub-processor change notices by email at the same time if you want them.
It’s a template. The text is our standard starting point, not an offer on its own; both sides should have it reviewed by counsel before signing. Prefer your own DPA? Send it and we will review it.
- Roles
- You are the controller of the mail and other data in your workspace; Agentboxd is your processor and acts only on your instructions.
- AI processing
- Your workspace’s AI processing setting is part of your instructions: Off sends nothing to AI providers, Categorize uses JEV, Full adds DeepSeek reply drafts on request.
- Security measures
- Annex 2 lists the technical and organisational measures in place today, and marks the ones still planned as planned.
- Sub-processors
- Listed in Annex 3 and on our sub-processor page. We give 30 days’ notice of a new one, and you can object.
- Breach notice
- We tell you without undue delay, and within 48 hours at most, so you can meet the 72-hour deadline to notify your authority.
- Transfers
- Data stays in the EU unless your AI setting sends part of it to JEV (US) or DeepSeek (China), under Standard Contractual Clauses.
- Deletion
- At the end of the contract we delete or return your data. Backups age out within 14 days of deletion from the live system.
- Audits
- Mainly through documentation: our security policies, controls mapping and a yearly questionnaire. On-site audits in the cases the DPA sets out.
Related
Read with it
- Sub-processors: who processes your data, where, and when.
- Privacy and data flow: what we store and what leaves the server at each AI processing level.
- Security: how the service is protected, and what is still on our roadmap.