Subtile Icon
Protecting Your Data

Data Processing Agreement (DPA)

Processor:BuildingAgentic

version:
1.0 — July 2026

This  Data Processing Agreement applies when BuildingAgentic processes personal  data on behalf of a client ("Controller") as part of custom AI  development services. This DPA supplements the main engagement agreement or  Statement of Work.

 

4.1 Definitions

"Controller" means the client who determines the purposes and meansof processing personal data.

"Processor" means BuildingAgentic, who processes personal data onbehalf of the Controller.

"PersonalData" has the meaning given in GDPRArticle 4(1) and applicable national or state laws.

"Processing" means any operation or set of operations performed onpersonal data.

"DataSubject" means any identified oridentifiable natural person whose personal data is processed.

"GDPR" means Regulation (EU) 2016/679 of the EuropeanParliament and of the Council.

"Sub-processor" means any third party engaged by BuildingAgentic toprocess personal data.

 

4.2 Nature and Purpose of Processing

BuildingAgenticprocesses personal data solely for the purpose of delivering the AI developmentservices described in the engagement agreement, including but not limited to:

•     Training and fine-tuning AImodels on client-provided datasets

•     Processing operational data(procurement records, ERP data, logistics data, customer records) to build andtest AI systems

•     Analyzing return data,customer behavior, and business metrics for AI model development

•     Integrating AI systems withclient's existing enterprise software (ERP, CRM, TMS, etc.)

 

4.3 Categories of Personal Data and Data Subjects

Thespecific categories of personal data and data subjects processed are defined inSchedule A (Appendix) of each engagement agreement. Typical examples include:

Right

What it means

Employees / Staff

Name, email, role, system access logs, HR records(for internal AI tools)

Customers / End Users

Purchase history, return behavior, session data,behavioral analytics

Suppliers / Vendors

Contact information, transaction history,performance data

Prospects / Leads

Contact details, CRM records (for sales automationprojects)

4.4 Processor Obligations

BuildingAgenticagrees to:

1.  Process personal data onlyon documented instructions from the Controller (including those in theengagement agreement)

2.  Ensure persons authorizedto process personal data are bound by confidentiality obligations

3.  Implement appropriatetechnical and organizational security measures per Article 32 GDPR

4.  Assist the Controller inresponding to Data Subject rights requests (access, deletion, portability,etc.)

5.  Assist the Controller withdata breach notification obligations (notify within 36 hours of becoming awareof a breach affecting Controller's data)

6.  Delete or return allpersonal data upon termination of services, at the Controller's choice

7.  Provide all informationnecessary to demonstrate compliance and cooperate with audits conducted by theController or its designee (with reasonable notice)

8.  Not engage sub-processorswithout the Controller's prior written consent

 

4.5 Sub-processors

BuildingAgenticmay engage the following sub-processors to deliver services. Controller isdeemed to have provided general written authorization for these sub-processors:

Right

What it means

Microsoft Azure / Azure OpenAI

Microsoft Azure / Azure OpenAI

Anthropic (Claude API)

AI model inference

Meta AI (Llama — self-hosted)

On-premise AI model deployment on clientinfrastructure

GitHub

Source code repository

Linear / Notion / Slack

Project management and communication

BuildingAgenticwill notify the Controller of any intended changes to sub-processors with atleast 14 days notice, allowing the Controller to object.

 

4.6 Technical and Organizational Security Measures (TOMS)

BuildingAgenticimplements the following measures:

Access Control

•     Least-privilege access:team members access only data required for their specific project tasks

•     Multi-factor authenticationrequired for all systems containing client data

•     Access revoked immediatelyupon project completion or team member departure

 

Data Security

•     All data in transitencrypted using TLS 1.2 or higher

•     All data at rest encryptedusing AES-256 or equivalent

•     No training of public AImodels on client proprietary data (contractually enforced with AI providers)

•     Client data processed onlywithin private cloud environments or on-premise as specified in the engagementagreement

 

Incident Response

•     Security incident responseprocedure maintained and tested

•     Controller notified within36 hours of a confirmed personal data breach

 

4.7 International Data Transfers

Ifpersonal data is transferred outside the EEA or UK, BuildingAgentic will ensurean appropriate transfer mechanism is in place, including:

•     Standard ContractualClauses (SCCs) under GDPR Article 46(2)(c) or Article 46(2)(d)

•     Binding Corporate Rules(where applicable)

•     EU-US Data PrivacyFramework (for US-based processors)

•     Adequacy decisions (whereapplicable)

 

4.8 Governing Law

ThisDPA is governed by the laws of [the European Union (GDPR)] for EU/UK datasubjects and by the laws of [the State of Delaware, USA] for US data subjects.In case of conflict, the law providing greater protection to Data Subjectsshall prevail.

 

4.9 Term and Termination

ThisDPA remains in effect for the duration of the engagement agreement. Upontermination, BuildingAgentic shall, within 30 days of termination date, at theController's option: (a) return all personal data in a portable format, or (b)securely delete all personal data. Certification of deletion shall be providedupon request.