Data processing agreement
In short
- Control Tower runs on your servers. The personal data passing through it never reaches us, so most of what a DPA usually covers doesn't arise.
- This agreement covers what you choose to share with us: support emails, attachments, logs and support bundles.
- We use it only to help you, keep it safe, delete it within 90 days of your request being resolved, and tell you within 48 hours if something goes wrong.
- It forms part of your Enterprise subscription. There's nothing to sign unless you want a countersigned copy.
1. Parties and scope
This data processing agreement ("DPA") is between Agent Control Tower ("we", the processor; privacy@agentcontroltower.app), and the organisation that holds a Control Tower Enterprise subscription or trial ("you", the controller). It forms part of our Enterprise subscription terms ("Agreement"). Where they disagree about personal data, this DPA wins.
What it covers. You run Control Tower on your own infrastructure. We don't host it or have access to it, and the prompts, responses, call records, credentials and users it handles stay with you. This DPA covers the personal data you choose to send us when you ask for support, described in Annex 1 ("Support Data").
What it doesn't cover. Your account, billing and license details (who bought, their email, the license renewal), which we handle as a controller under our privacy policy.
Terms such as personal data, processing, controller, processor, data subject and personal data breach have the meanings given in the GDPR (Regulation (EU) 2016/679) and the UK GDPR. "Data Protection Law" means those laws, and any other privacy law that applies to the Support Data.
2. Processing on your instructions
We process Support Data only to provide support under the Agreement, and otherwise only on your documented instructions. The Agreement, this DPA and your support requests are those instructions. If we believe an instruction breaks Data Protection Law, we'll tell you. If the law requires us to process Support Data otherwise, we'll tell you first, unless the law forbids it.
Please send us only what we need. The support bundle Control Tower produces leaves out keys, credentials, prompts, answers, hostnames and the names of agents and people. Read it before you send it.
3. Confidentiality
Only people who need Support Data to help you have access to it, and each of them is bound by confidentiality.
4. Security
We protect Support Data with the measures in Annex 2, appropriate to the risk. We may improve them, but we won't lower the overall level of protection.
5. Sub-processors
You authorise the sub-processors in Annex 3. We'll tell you at least 30 days before adding or replacing one. If you object on reasonable data protection grounds and we can't resolve it, you may end the affected subscription and we'll refund the fees prepaid for the rest of its term. Each sub-processor is bound by written terms that protect Support Data at least as well as this DPA does. We remain responsible for them.
6. Helping you
- Requests from data subjects: we help you answer them. If a data subject asks us directly, we'll pass the request to you rather than answer it ourselves.
- Your other obligations: where it concerns Support Data, we help with data protection impact assessments, prior consultations and security.
7. Personal data breaches
We'll tell you without undue delay, and within 48 hours, of becoming aware of a personal data breach affecting Support Data. We'll say what we know (what happened, the data and people affected, the likely consequences, and what we're doing about it) and update you as we learn more.
8. Deletion
We delete Support Data within 90 days of the support request it came with being resolved, and all of it within 30 days of the Agreement ending, unless the law requires us to keep it. You can ask us to delete Support Data sooner at any time.
9. Information and audits
We'll give you the information you reasonably need to show that we meet this DPA. That includes:
- answering a reasonable security questionnaire once a year;
- our security documentation.
If that isn't enough, or a supervisory authority requires it, we'll allow an audit by you or an independent auditor bound by confidentiality, on 30 days' notice, during business hours, at your cost, and at most once a year.
10. International transfers
Where Support Data is transferred out of the EEA, the UK or Switzerland to a country without an adequacy decision, the following are incorporated into this DPA and govern the transfer:
- the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), with you as data exporter and us as data importer;
- for the UK, the International Data Transfer Addendum;
- for Switzerland, the clauses as adapted for the Swiss Federal Act on Data Protection.
How the clauses' options are taken:
- Clause 7 (docking) applies.
- Under Clause 9, option 2 applies, with 30 days' notice.
- Clause 11's optional wording doesn't apply.
- Clauses 17 and 18 refer to the law and courts of Ireland.
- Annexes 1 to 3 of this DPA complete Annexes I to III of the clauses.
11. Liability and term
Each party's liability under this DPA is subject to the limits in the Agreement, except where Data Protection Law doesn't allow them. This DPA lasts as long as we process Support Data.
Annex 1 — The processing
| Subject matter | Support for your use of Control Tower |
|---|---|
| Nature and purpose | Receiving, reading and storing what you send us to answer support requests; diagnosing and fixing problems |
| Duration | For the Agreement, and until the deletion in section 8 |
| Data subjects | Your staff and contractors who contact support; any other people named in what you choose to send |
| Personal data | Names, work email addresses and roles; the content of support requests, and of attachments, logs, screenshots and support bundles you send |
| Special categories | None intended. Please don't send them. |
| Frequency | Whenever you ask for support |
Annex 2 — Security measures
- Support Data is reached only through accounts that require multi-factor authentication, by the people helping you.
- It's stored only in our email and support systems and on encrypted devices. It's never placed in public repositories or issue trackers.
- Email is sent and received over TLS.
- Devices that hold Support Data have full-disk encryption, screen lock and current security updates.
- It's deleted on the schedule in section 8.
- We handle incidents as in section 7.
- Control Tower's own measures are described on our security page.
Annex 3 — Sub-processors
| Sub-processor | What for | Where |
|---|---|---|
| ImprovMX | Forwarding support email to our inbox | France (EU); onward delivery from the United States |
| Google (Gmail) | Our support inbox | United States |
If you open a shared Slack or Teams channel with us, it's hosted in your own workspace, under your own agreement with that provider.