This Data Processing Agreement applies when BuildingAgentic processes personal data on behalf of a client ("Controller") as part of custom AI development services. This DPA supplements the main engagement agreement or Statement of Work.
"Controller" means the client who determines the purposes and meansof processing personal data.
"Processor" means BuildingAgentic, who processes personal data onbehalf of the Controller.
"PersonalData" has the meaning given in GDPRArticle 4(1) and applicable national or state laws.
"Processing" means any operation or set of operations performed onpersonal data.
"DataSubject" means any identified oridentifiable natural person whose personal data is processed.
"GDPR" means Regulation (EU) 2016/679 of the EuropeanParliament and of the Council.
"Sub-processor" means any third party engaged by BuildingAgentic toprocess personal data.
BuildingAgenticprocesses personal data solely for the purpose of delivering the AI developmentservices described in the engagement agreement, including but not limited to:
• Training and fine-tuning AImodels on client-provided datasets
• Processing operational data(procurement records, ERP data, logistics data, customer records) to build andtest AI systems
• Analyzing return data,customer behavior, and business metrics for AI model development
• Integrating AI systems withclient's existing enterprise software (ERP, CRM, TMS, etc.)
Thespecific categories of personal data and data subjects processed are defined inSchedule A (Appendix) of each engagement agreement. Typical examples include:
Right
What it means
Employees / Staff
Name, email, role, system access logs, HR records(for internal AI tools)
Customers / End Users
Purchase history, return behavior, session data,behavioral analytics
Suppliers / Vendors
Contact information, transaction history,performance data
Prospects / Leads
Contact details, CRM records (for sales automationprojects)
BuildingAgenticagrees to:
1. Process personal data onlyon documented instructions from the Controller (including those in theengagement agreement)
2. Ensure persons authorizedto process personal data are bound by confidentiality obligations
3. Implement appropriatetechnical and organizational security measures per Article 32 GDPR
4. Assist the Controller inresponding to Data Subject rights requests (access, deletion, portability,etc.)
5. Assist the Controller withdata breach notification obligations (notify within 36 hours of becoming awareof a breach affecting Controller's data)
6. Delete or return allpersonal data upon termination of services, at the Controller's choice
7. Provide all informationnecessary to demonstrate compliance and cooperate with audits conducted by theController or its designee (with reasonable notice)
8. Not engage sub-processorswithout the Controller's prior written consent
BuildingAgenticmay engage the following sub-processors to deliver services. Controller isdeemed to have provided general written authorization for these sub-processors:
Right
What it means
Microsoft Azure / Azure OpenAI
Microsoft Azure / Azure OpenAI
Anthropic (Claude API)
AI model inference
Meta AI (Llama — self-hosted)
On-premise AI model deployment on clientinfrastructure
GitHub
Source code repository
Linear / Notion / Slack
Project management and communication
BuildingAgenticwill notify the Controller of any intended changes to sub-processors with atleast 14 days notice, allowing the Controller to object.
BuildingAgenticimplements the following measures:
• Least-privilege access:team members access only data required for their specific project tasks
• Multi-factor authenticationrequired for all systems containing client data
• Access revoked immediatelyupon project completion or team member departure
• All data in transitencrypted using TLS 1.2 or higher
• All data at rest encryptedusing AES-256 or equivalent
• No training of public AImodels on client proprietary data (contractually enforced with AI providers)
• Client data processed onlywithin private cloud environments or on-premise as specified in the engagementagreement
• Security incident responseprocedure maintained and tested
• Controller notified within36 hours of a confirmed personal data breach
Ifpersonal data is transferred outside the EEA or UK, BuildingAgentic will ensurean appropriate transfer mechanism is in place, including:
• Standard ContractualClauses (SCCs) under GDPR Article 46(2)(c) or Article 46(2)(d)
• Binding Corporate Rules(where applicable)
• EU-US Data PrivacyFramework (for US-based processors)
• Adequacy decisions (whereapplicable)
ThisDPA is governed by the laws of [the European Union (GDPR)] for EU/UK datasubjects and by the laws of [the State of Delaware, USA] for US data subjects.In case of conflict, the law providing greater protection to Data Subjectsshall prevail.
ThisDPA remains in effect for the duration of the engagement agreement. Upontermination, BuildingAgentic shall, within 30 days of termination date, at theController's option: (a) return all personal data in a portable format, or (b)securely delete all personal data. Certification of deletion shall be providedupon request.