Data Processing Agreement
Data Processing Agreement (DPA)
Pursuant to Article 28 of the General Data Protection Regulation (GDPR)
DPA: pending legal finalization. Version
2026-09-13-draft.Requires review and approval by qualified EU/Spanish legal counsel before being presented as final contractual/legal documentation.
This draft is filled in from how the AgentLane platform actually works (see the Compliance Center), so counsel reviews facts rather than a blank template. It is not a signable agreement. Do not send it to a partner as final. Items marked
[ ]are open questions for counsel. The platform refuses to record any partner DPA as executed until this template is approved.
This DPA is entered into between the agency partner identified in an AgentLane order or signup flow ("Agency", "you") and AgentLane Ltd ("AgentLane", "we"), and forms part of the agreement governing the Agency's use of the AgentLane platform (the "Agreement"). Where the Agreement and this DPA conflict on data-protection matters, this DPA controls.
0. Roles
The platform is resold white-label: an Agency serves many businesses ("End Clients"), each of whose customers ("End Customers") call or text that business.
| Party | Role for End Customer data (as designed) | Status |
|---|---|---|
| End Client (the business) | Controller | [ ] Confirm |
| Agency | Processor acting for the End Client | [ ] Confirm. The Agency may instead be a controller or joint controller for its own purposes. |
| AgentLane | Sub-processor acting for the Agency (processor where an End Client contracts with AgentLane directly) | [ ] Confirm |
| AgentLane | Controller for Agency account, billing and website-visitor data | [ ] Confirm |
The platform records the confirmed roles per End Client in the Compliance Center (processing.agencyRole, processing.agentlaneRole). Until they are confirmed, the client is shown as not ready for an EU pilot.
[ ] Decide whether a single back-to-back structure (End Client ↔ Agency DPA, Agency ↔ AgentLane sub-processing DPA) is used, and provide the Agency's End Client DPA template.
1. Subject matter, term, personal data processed, and categories of data subjects
(1) Subject matter. AgentLane processes personal data only to provide the platform: agency and client account administration, missed-call detection and SMS conversations run by automations, AI-generated replies, appointment booking integrations, support chat, billing, data export and deletion.
(2) Term. For the term of the Agreement, then subject to §11.
(3) Categories of personal data.
- Agency and End Client users: name, email, role, login and audit events.
- End Customers: phone number, SMS message content, missed-call metadata (calling number, called number, call status, timestamps), name and appointment details where given, and outbound-contact consent and do-not-contact records.
- Support chat messages written by Agency and End Client users.
- Billing contact data for Agencies (card data is handled by Stripe, not stored by AgentLane).
AgentLane does not run live AI voice calls and stores no call audio and no call transcripts. If a voice runtime is added, this section and §12 must be updated first.
(4) Categories of data subjects. Agency users; End Client users; End Customers who call or text an End Client; website visitors who submit forms.
(5) Special categories. The platform is not designed for special-category data, but End Customers of clinics may volunteer health information in messages. [ ] Counsel to advise on Article 9 handling for dental/aesthetics End Clients.
2. Sub-processors and international transfers
AgentLane's platform runs on one server in Frankfurt am Main, Germany. This comes from the production host's IP registration and geolocation, not the hosting contract. [ ] Confirm the provider (IP registered to xTom GmbH), the data-centre location and whether provider support staff access the server from outside the EEA.
| Sub-processor | Purpose | Data | Location / transfer | Transfer mechanism |
|---|---|---|---|---|
| VPS hosting provider (xTom GmbH per IP registration) | Hosts the application, PostgreSQL, Redis, MinIO object storage, Activepieces and Keycloak | All platform data, including backups | Germany (Frankfurt) — to confirm | [ ] Confirm |
| Twilio | Phone numbers, missed-call callbacks, SMS | Phone numbers, SMS content, call metadata | US-headquartered; no regional option configured | [ ] Confirm. Usually contracted by the Agency or End Client directly. |
| Anthropic | AI replies (automations, support chat) | Message content, business context | US-headquartered | [ ] Confirm. Zero data retention is not confirmed. |
| OpenAI | AI replies (alternate provider) | Message content, business context | US-headquartered | [ ] Confirm. Zero data retention is not confirmed. |
| Cal.com | Booking integration | Name, contact, appointment time | Depends on the End Client's account | Contracted by the End Client |
| Resend | Transactional and automation email | Name, email, email content | US-headquartered | [ ] Confirm |
| Stripe | Agency billing | Agency billing contacts | US-headquartered | [ ] Confirm |
| Slack | Internal operational alerts | Agency names in alerts (no conversation content) | US-headquartered | [ ] Confirm |
Activepieces, PostgreSQL, Redis, MinIO and Keycloak are self-hosted software on the server above, not separate sub-processors. The Activepieces engine runs one shared deployment with a project per Agency. n8n is no longer used, and neither Retell nor Vapi receives any data.
Where the Agency or End Client supplies its own provider credentials (BYOK), that provider acts under the Agency's or End Client's own contract.
[ ] For each US provider: the SCC module (2021/914), DPF certification, or other Article 46 mechanism; a transfer impact assessment (docs/tia-us-ai-transfers.md currently asserts SCCs and DPF without evidence and must be re-verified).
The machine-readable version of this table is packages/shared/src/compliance/subprocessors.ts.
3. Technical and organisational measures
Measures in place today:
- Tenant isolation: every Agency and End Client query is scoped server-side, and a CLIENT user is pinned to its own client.
- Provider credentials encrypted with AES-256-GCM envelope encryption at the application level.
- TLS on all public endpoints.
- Application audit log of partner, client and admin actions.
- Role-based access, including view-only agency moderators. MFA is available but optional.
- Automated retention and deletion jobs, each run logged (§11).
- Firewall exposing only SSH, HTTP and HTTPS.
Known gaps disclosed to counsel: database backups are stored on the same disk as the database, with no offsite copy and no recorded restore test; object storage (MinIO) is not backed up; disk-level encryption of the host is not confirmed; MFA is not enforced.
[ ] Agree the TOMs annex wording.
4. Data subjects' rights
(1) AgentLane assists the Agency, and through it the End Client, with data subject requests. Available tools: portal data export (ZIP of JSON/CSV), account deletion requests, a per-client do-not-contact list, and SMS STOP handling.
(2) Requests received directly from an End Customer are passed to the responsible Agency/End Client without undue delay. AgentLane does not answer them on its own authority unless instructed. Identity checks are proportionate. Government ID is not requested. Verification happens by email, not SMS.
5. Further duties of AgentLane
Establishment and representative. AgentLane Ltd is a company registered in England and Wales (No. 17400209). It is not established in the EU/EEA. [ ] Counsel to determine whether an Article 27 EU representative is required, and name it here if so.
Data protection contact. No DPO has been appointed. Contact: contact@agentlane.agency. [ ] Confirm whether Article 37 applies.
Confidentiality. Personnel with access to personal data are bound by confidentiality obligations.
Cooperation with supervisory authorities. AgentLane cooperates with authority requests and informs the Agency promptly, where permitted.
6. Sub-processor changes
AgentLane will notify the Agency of any new sub-processor before it processes the Agency's data, giving the Agency an opportunity to object. [ ] Agree the notice period (30 days proposed) and the remedy if the Agency objects.
7. Audits
On written request, AgentLane provides information showing compliance with this DPA, including evidence of the measures in §3. On-site audits are not offered at the current scale. [ ] Revisit if an Agency's obligations require third-party audit rights.
8. Assistance and personal data breaches
AgentLane assists with Articles 32–36 GDPR. It notifies the Agency of a personal data breach affecting the Agency's data without undue delay after becoming aware of it. [ ] Agree a maximum notification period and the notification content. No incident-response runbook has been formally approved yet (see docs/policies/security-incident-policy.md).
9. Instructions
AgentLane processes personal data only on documented instructions: the Agreement, this DPA, and the Agency's and End Client's configuration of the platform, including retention periods, AI disclosure wording and outbound policy. The only exception is where EU or Member State law requires otherwise; AgentLane will inform the Agency of that requirement unless the law prohibits it.
10. Liability
As set out in the Agreement, consistent with Article 82 GDPR. [ ] Counsel to align with the Agreement's liability cap.
11. Retention, deletion and return of personal data
- Export. The Agency and each End Client can export their data from the portal at any time. Export archives are deleted automatically after 7 days.
- Conversation retention. Conversations are deleted 12 months after last activity by default. The Agency or End Client can set a period of 1–3650 days, and the period cannot be unlimited.
- Closure. An approved deletion request disables the account immediately and schedules a permanent purge 30 days later. The purge deletes conversations, End Customer records in the legacy home-services tables linked to that client, provider credentials, consent and do-not-contact records, and export archives, and it anonymises user records. Billing records are kept as required by law.
- Backups. Deleted data remains in database backups until they rotate out (14 days).
- Phone numbers. Numbers stay in the Twilio account that holds them. AgentLane does not transfer or release numbers held in an Agency or End Client account.
- Known gaps. Legacy home-services data not linked to a client or agency is not purged automatically. Retention for support chat, webhook delivery logs and the audit log currently runs in dry-run mode.
The full retention register is published in the Compliance Center and packages/shared/src/compliance/retention.ts.
12. AI transparency and outbound calling (technical annex)
- AI disclosure. Every End Client's voice configuration has a localized AI-identity disclosure enabled by default. The call-start contract (
buildVoiceCallStartPlan) places it ahead of the business prompt with barge-in disabled while it plays. Only AgentLane can disable it, and only with a recorded reason. The platform can record disclosure evidence (status, locale, wording version, call id) without audio. No live voice runtime exists today, so no disclosure is played to callers yet and no call evidence exists.[ ]Counsel to confirm the wording satisfies Article 50(1) EU AI Act for each locale and use case. - Outbound calling. Disabled by default. No dialer exists. Before any outbound call is permitted, the platform requires: an admin-recorded legal approval, jurisdiction, calling entity, allowed purposes, a recorded consent (where required), no do-not-contact match, allowed calling hours in the client's timezone, and an active disclosure.
[ ]Counsel to set the Spanish rules (consumer-protection calling restrictions, Robinson list checks, marketing consent) that the policy must encode.
Requesting the current draft: email contact@agentlane.agency. A signable version will be published only after counsel approval.