Data Processing Agreement

Version 1.5 · Last updated: September 4, 2026

This Data Processing Agreement ("DPA") governs our processing of personal data on your behalf when you use AnroAgents. It forms part of the Terms of Service and applies automatically from the moment you accept them — you do not need to sign anything for it to be in force. If your procurement process requires a counter-signed copy, or your own DPA template, write to support@anroagents.com.

1. Parties and roles

Processor: Anro Technologies Limited, Nafpliou 15, 3025 Limassol, Cyprus, registration number HE 439985 ("we", "us").
Controller: the account holder accepting the Terms of Service ("you").

For the personal data your agents process — what your visitors type, the contact details they leave, the material you upload as a knowledge base — you are the controller and we are the processor acting on your instructions. This DPA covers that processing.

For your own account data — your name, your email address, your billing details, how you use the dashboard — we are the controller, and our Privacy Policy applies rather than this DPA.

2. Subject matter and instructions

We process personal data only to provide the Service as described in the Terms, and only on your documented instructions. Your instructions are: the Terms, this DPA, and the configuration you set in the dashboard and API — which agent answers, what it collects, what it is connected to, and how long conversations are kept.

We will tell you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law. If we are required by EU or member-state law to process beyond your instructions, we will inform you before doing so unless that law forbids it.

We do not use personal data processed on your behalf for our own purposes. In particular, we do not use your conversations or your knowledge base to train or fine-tune AI models. The terms we contract under with our AI model provider state that data submitted through its API is not used to train or improve its models, and we have not opted into any arrangement that would change that.

3. Confidentiality

Access to personal data processed on your behalf is limited to the people who need it to operate and support the Service. They are bound by confidentiality obligations that survive the end of their engagement.

4. Security

We implement the technical and organisational measures set out in Annex II, taking account of the state of the art, the cost of implementation, and the risk to the people whose data it is. Those measures may change as the Service evolves, but not in a way that materially reduces the level of protection.

5. Sub-processors

You give general authorisation for us to engage sub-processors. Those currently engaged are listed at anroagents.com/subprocessors.html, which forms part of this DPA.

We notify you by email at least 30 days before a new sub-processor starts processing personal data, or before an existing one is replaced — a change of AI model provider included. You may object on reasonable data-protection grounds within that period; if we cannot offer an alternative, you may terminate the affected part of the Service and receive a refund of fees paid for the unused remainder.

Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA. We remain fully liable to you for their performance.

6. International transfers

The Service is hosted in the European Union — Ireland and Frankfurt. Personal data stays there except for two things it has to leave for:

Those transfers are made under the transfer mechanism in each provider's own data processing terms — the Standard Contractual Clauses approved by the European Commission, and the EU–U.S. Data Privacy Framework where the provider is certified under it. Our agreement with Resend, for instance, incorporates Module Three of the Standard Contractual Clauses for exactly this position, in which we are your processor and they are ours. Where we act as your processor and the transfer is onward, Module Three of the Standard Contractual Clauses applies. Where you are established outside the EEA and the transfer to us is itself restricted, Module Two applies and this DPA incorporates those Clauses by reference, with Cyprus as the member state whose law governs them and the courts of Cyprus as the forum. For transfers subject to UK law, the UK International Data Transfer Addendum applies.

Our AI model provider keeps a copy of each request for a limited period — up to 30 days — for abuse monitoring, and then deletes it. It is not used to train or improve any model. That period is the provider's, and runs independently of the retention period you set here: deleting a conversation in AnroAgents does not shorten it.

If you need the Service without a transfer to the United States, say so before you subscribe: today we cannot offer it, because the model provider and the email provider are both US-based, and we would rather tell you than have you discover it in an audit.

7. Assistance with data subject rights

The dashboard is the first route, and for most requests the only one needed: conversations are visible, searchable and deletable there, the retention period can be shortened for the whole workspace at any time, and Settings has a one-click export of everything the account holds in a machine-readable form — which is the Article 20 portability right, exercisable without asking us. Where a request cannot be satisfied that way — a person asking for everything held about them across your account — write to support@anroagents.com and we will assist within 10 working days.

If a data subject contacts us directly about data we process for you, we will not answer them on the substance. We will tell them to contact you, and forward the request to you without undue delay.

8. Personal data breaches

We notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting personal data we process for you. The notification describes the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we provide it in phases as it becomes available.

Notifying your supervisory authority and the affected people is your decision as controller; we give you the information you need to make it and to meet your own 72-hour deadline.

9. Data protection impact assessments

We provide reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority, to the extent they relate to our processing and taking into account the information available to us. The description of the Service, this DPA, the sub-processor list and the security overview are written to be usable directly in such an assessment.

10. Retention, deletion and return

Conversations are deleted automatically once the retention period for your account has passed, measured from the last message in the conversation. The period is set by you in Settings, up to the maximum your plan allows — 30 days on Free, 90 on Starter, 180 on Pro, 365 on Business. Deletion covers the transcript, the messages and everything filed under the conversation.

You can delete individual conversations, agents and knowledge base documents from the dashboard at any time, and you can delete the whole account from Settings. Deleting the account takes your agents offline and out of the public registry immediately; erasure follows seven days later, and the request can be cancelled at any point in those seven days. Erasure covers agents, conversations and messages, the knowledge base in both storage and the search index, uploaded files, integrations, connected domains and the sign-in identity.

When the Terms end, we delete the personal data we process for you within 30 days, unless EU or member-state law requires us to keep it — invoices and payment records carry a statutory retention period of their own and are kept as long as the law requires. Backups are the one lag: deleted data can persist in point-in-time backups for up to 35 days, after which it is gone. Backups are not used to restore individual records; they exist to recover the database as a whole from a failure.

A provider we send data to may hold it for a period of its own after we have deleted ours — the email provider deletes what it holds for us within 90 days of the account closing, and the AI model provider's abuse-monitoring window is described in section 6. Those periods are stated on the sub-processor page as they change.

On request made before the Terms end, we return the personal data we process for you in a machine-readable form.

11. Audits

We make available the information needed to demonstrate compliance with Article 28 GDPR: this DPA, the sub-processor list, the security overview, and written answers to your security questionnaire. We hold no third-party certification such as ISO 27001 or SOC 2 today, and we will not claim otherwise.

Where that is not enough for your obligations, you may audit us, or mandate an independent auditor bound by confidentiality to do so, once in any twelve-month period and on 30 days' written notice — more often if a supervisory authority requires it or after a personal data breach. Audits take place during business hours, must not unreasonably disrupt the Service, and must not access another customer's data. You bear the cost of the audit, and we bear our own cost of cooperating.

12. Liability and precedence

The liability provisions of the Terms of Service apply to this DPA. In the event of a conflict, this DPA prevails over the Terms in respect of the processing of personal data; the Standard Contractual Clauses, where they apply, prevail over both.

13. Term, changes and governing law

This DPA applies for as long as we process personal data on your behalf. We may update it — to reflect a change in the law, in the Service, or in our sub-processors — by posting a new version here and changing the version number. Where a change materially affects your rights, we notify you by email or in the dashboard before it takes effect.

This DPA is governed by the law of the Republic of Cyprus, and the courts of the Republic of Cyprus have jurisdiction, without prejudice to any different forum required by the Standard Contractual Clauses.

Annex I — Details of the processing

A. Categories of data subjects

B. Categories of personal data

The Service is not designed for special categories of personal data under Article 9 GDPR, and you should not configure an agent to collect them. If a visitor volunteers such data in a chat anyway, it is processed as ordinary conversation content and deleted with it.

C. Nature and purpose of the processing

Hosting and storing the data; sending conversation content to an AI model provider to generate a reply; indexing your knowledge base for retrieval; scoring leads; delivering email and calendar invitations you have configured; sending events to systems you have connected; and making all of it visible to you in the dashboard.

D. Duration

For conversations, the retention period set for your account, measured from the last message. For everything else, the term of the Terms of Service plus the deletion window in section 10.

E. Frequency

Continuous, for as long as your agents are answering.

Annex II — Technical and organisational measures

These are the measures in place today. They are described in more detail, and in plainer language, in the security overview.

MeasureWhat is in place
Location of processingHosting in the European Union — Ireland (eu-west-1) and Frankfurt (eu-central-1). Exceptions in section 6.
Encryption in transitTLS on every connection: the dashboard, the API, the widget, the WebSocket used for chat, and every call to a sub-processor.
Encryption at restDatabases, object storage and backups are encrypted at rest by the platform provider. Every credential you connect — a mailbox, a calendar, a CRM, a Telegram bot, a connected store — is additionally encrypted with a dedicated managed key and bound to the account or agent it belongs to, so a ciphertext read out of one record cannot be used as another's. Those credentials are never returned to anyone, including you, once stored.
Tenant separationEvery stored record is keyed by the account that owns it, and every read and write is checked against the identity making the request rather than against an identifier supplied by the caller. One customer's agent retrieves only that customer's knowledge base.
Access controlSign-in through a managed identity provider, with email and password or Google. Personnel access to production is limited to those who need it, uses individually issued credentials, and is granted with least privilege. Secrets are held in a managed parameter store, encrypted, and never in source control.
Workspace rolesTeam members you invite see conversations and agents; they do not see billing. Only the account owner can change the retention period.
PseudonymisationVisitors are identified by a random session identifier, not by anything they are asked to provide. The Service asks a visitor for a name or an email only where you configure it to.
Resilience and backupServerless infrastructure across multiple availability zones. The databases holding accounts, agents and conversations have continuous point-in-time backups with a 35-day window and deletion protection. The knowledge-base search index is not separately backed up — it is derived data, rebuilt by re-indexing the source documents, which we hold.
Restoring availabilityThose databases can be restored to any point within the backup window, and the search index re-derived from the stored source documents. Application infrastructure is defined as code and can be rebuilt from source.
LoggingApplication and access logs retained for 30 days for operating and securing the Service, and, for a domain you connect, 90 days.
DeletionAutomatic expiry of conversations at the end of the retention period, applied by a daily process and enforced by the database itself. Deletion on request as set out in section 10.
Model providersContracted on terms that prohibit training on data sent through the API. No customer data is used to train or fine-tune any model, ours or theirs.
Change controlChanges go through version control and an automated test suite before deployment. Production and development run as separate environments with separate data.
Vulnerability managementDependencies are monitored and updated for known vulnerabilities. Security reports are received at support@anroagents.com and acknowledged within two working days.

← Back to Anro Agents  ·  Sub-processors  ·  Security  ·  Privacy  ·  Terms