Delagents

Data Processing Addendum

How Delagents processes personal data on your behalf: roles, scope, instructions, confidentiality, security measures, subprocessors, transfers, deletion and audits.

Effective 17 September 2026

This page summarizes the addendum that will apply to customer workspaces when the app launches. A signed copy is available to customers on request at hello@delagents.com. Where this summary and the signed addendum differ, the signed addendum applies.

1. Roles

For personal data contained in briefs, attachments, connected accounts, transcripts and deliverables ('customer data'), the customer is the controller and Delagents is the processor. Where the customer is itself a processor for its own clients, for example an agency running delegations on client accounts, Delagents acts as a subprocessor, and the customer remains responsible for having the authority to engage us.

For account and billing data, and for data collected on the website, Delagents is the controller and the Privacy Policy applies.

2. Scope

Description
Subject matterProviding the Delagents service: running delegations, filing approvals, delivering results and keeping the activity log
DurationThe term of the customer's agreement, plus the deletion period in section 9
Nature of processingStorage, retrieval, analysis by language models, drafting, transmission to connected tools on approval, and logging
Categories of dataContact details, correspondence, business records, support tickets, financial records, candidate applications and other data the customer chooses to process
Data subjectsThe customer's staff, customers, prospects, suppliers, candidates and other people whose data appears in connected tools or briefs

3. Instructions

We process customer data only on the customer's documented instructions. The instructions are: the agreement and this addendum; the briefs, checkpoint settings and approval policies set in the workspace; each sign-off made on an approval card; and the scopes granted when connecting a tool. We do not process customer data for our own purposes, and we do not use it to train models.

If we believe an instruction breaches data protection law, we tell the customer before acting on it, and we may pause the affected processing until the matter is resolved.

4. Confidentiality

People working for Delagents who may access customer data are bound by written confidentiality obligations and are trained on them. Access is limited to what a task requires. We do not read customer content except to provide support at the customer's request, to investigate a security incident or abuse, or where the law requires it, and each such access is logged.

5. Security measures

We maintain technical and organizational measures appropriate to the risk. The measures in place at the effective date include:

  • Encryption in transit (TLS) for all connections, and encryption at rest for databases, files and backups.
  • Per-agent scopes: access to a connected tool is granted per agent as a subset of what an administrator approved, and fails closed outside that subset.
  • An envelope-encrypted token vault: each integration token is encrypted with its own data key, which is in turn wrapped by a key-encryption key that is rotated; plaintext exists only inside the tool call and never in logs, prompts or the model's context.
  • An append-only activity log: tool calls, approvals and policy changes are recorded in a log that the application cannot update or delete, with each entry chained to the previous one so that tampering can be detected.
  • Workspace isolation at the data layer, tested by attempting to cross the boundary.
  • The approval floor: eight categories of action always require a human sign-off and cannot be disabled by any role.
  • Treatment of tool output as untrusted data, so that content read from the web or from a connected account cannot instruct an agent to change policy, widen scopes or approve itself.
  • Least privilege for our own staff, secrets held in a managed store, rate limiting, and redaction of known secret patterns before any output is stored.

We may improve these measures over time and will not reduce the overall level of protection during the term.

6. Subprocessors

The customer authorizes the subprocessors below. We impose data protection obligations on each that are no less protective than this addendum, and we remain responsible for their performance.

SubprocessorPurposeStatus
CloudflareHosting, content delivery, security and edge servicesIn use now
AnthropicModel inference for delegations; API data retained up to 30 days; not used for trainingWhen the app launches
ClerkSign-in, sessions and identityPlanned
StripeBilling and payment processingPlanned
NeonManaged Postgres databasePlanned

We publish this list and give customers at least 30 days notice by email before a new subprocessor begins processing customer data. A customer may object on reasonable data protection grounds within that period. If we cannot address the objection, the customer may terminate the affected part of the service and receive a pro rata refund of prepaid fees for it.

7. International transfers

Customer data may be processed outside the customer's country, including in the United States. For transfers out of the EU, EEA, UK or Switzerland we rely on the European Commission's standard contractual clauses, the UK addendum to them, or an equivalent lawful mechanism, supported by the measures in section 5. Regional hosting is planned and is not available in the preview.

8. Assistance to the customer

  • Data subject requests: if a request reaches us directly we forward it to the customer without undue delay, and we provide the tools and assistance needed to answer it, including export and deletion of a person's data on request.
  • Security incidents: we notify the customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting customer data, with the information we have and updates as we learn more.
  • Assessments: we provide the information reasonably needed for data protection impact assessments and for consultations with supervisory authorities.

9. Deletion at termination

When the agreement ends, we stop all processing, expire open approvals and, at the customer's choice, return customer data in a common machine-readable format before deletion. We delete customer data, including backups on their normal cycle, within 30 days of termination, and confirm deletion in writing on request. Where the law requires us to keep a record, we keep only what it requires, for as long as it requires, and continue to protect it under this addendum. Data sent to our model provider is deleted on their side within 30 days under their retention terms.

10. Audits

On request, no more than once a year unless a supervisory authority requires it or a breach has occurred, we provide the information necessary to demonstrate compliance with this addendum, including summaries of independent assessments when available and exports from the activity log. Where that information is not sufficient, the customer or an independent auditor bound by confidentiality may audit our relevant processing on reasonable notice, at the customer's cost, during business hours and without disrupting the service.

11. Precedence and contact

This addendum forms part of the agreement between the customer and Delagents. Where it conflicts with the Terms of Service on a data protection matter, this addendum applies. Questions and requests go to hello@delagents.com.