SaaSFactory.ai Data Processing Agreement (DPA)
This DPA forms part of the SaaSFactory.ai Terms of Service. It applies where we process personal data on your behalf: the data inside your product about your end users. Words defined in the terms keep their meaning.
1. Roles. For your product’s end user data, you are the controller and we are your processor. For your own account data, we are a controller under our Privacy Policy. For verification data, Stripe processes under Stripe’s own terms.
2. What we process. Subject matter: operating your product on SaaS Factory. Duration: your subscription plus the retention windows in the terms. Nature and purpose: hosting, storage, transmission, backup, error monitoring, support and the platform features you enable. Data types: whatever your product collects from its end users, which you control. Data subjects: your end users and their contacts.
3. Your responsibilities. You are responsible for the lawfulness of the data your product collects: lawful basis, privacy notices, consents, and honouring data subject rights. You must not submit special category or similarly protected data unless we have expressly agreed in writing (clause 48.5 of the terms).
4. Our commitments. We process end user data only on your documented instructions: these terms, the DPA and your configuration of the platform are those instructions. We do not access end user data in the ordinary course of business; access happens only for troubleshooting, security, safety, abuse prevention or legal compliance. Our personnel are bound by confidentiality. We apply appropriate technical and organisational measures: encryption in transit (TLS 1.2+), encryption at rest, access controls, segregated environments, logging, and the security practices of our infrastructure providers.
5. Sub processors. You authorise our sub processors; the current list is published in your SaaS Factory account under Terms & Legals, Sub-processors. We give 30 days’ notice of additions or replacements. If you object on reasonable data protection grounds and we cannot resolve it, you may terminate the affected product and export your data.
6. International transfers. Data is stored in the region you select at setup. Where transfers occur, they are protected by the UK IDTA (or UK Addendum) and EU Standard Contractual Clauses, or adequacy decisions.
7. Data subject requests. If an end user contacts us directly, we redirect them to you. We provide the platform tools (export, deletion, access to records) for you to answer requests yourself. Further assistance is available at our then current professional services rates.
8. Breach notification. We notify you without undue delay after becoming aware of a personal data breach affecting your end user data, with the information we have, and update you as we learn more. Notifying authorities and end users is your duty as controller.
9. Assistance. We provide reasonable assistance with your data protection impact assessments and regulator consultations, limited to information about how the platform processes data, at our professional services rates where the work is material.
10. Audit. We satisfy audit rights by providing documentation: our security measures, sub processor list, and available third party attestations (including the Enterprise vendor security review pack). On site audits are not offered on standard tiers.
11. Deletion and return. On product deletion or exit, you can export your end user data as JSON. After the retention windows in the terms, data is hard deleted, except financial and compliance records retained by law.
12. Liability. Liability under this DPA is subject to the caps and carve outs in clause 57 of the terms.
agentOS Proptech Group Ltd t/a SaaSFactory.ai · 13 Lambourne Crescent, Llanishen, Cardiff, Wales, CF14 5GF · support@saas-factory.ai