Data Processing Agreement
Applies where Agily processes personal data contained in your Customer Data on your behalf.
Last updated: 2026-09-12 · Effective: 2026-09-12
We are finalizing our legal documentation ahead of general availability. These pages describe our current practices; contact legal@agily.app with any questions.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service or other agreement (the “Agreement”) between [Legal entity name] (“Processor”, “Agily”) and the customer identified in the Agreement (“Controller”, “Customer”). It governs Processor’s Processing of Personal Data on Controller’s behalf. Capitalized terms not defined here have the meaning in the Agreement.
1. Definitions
“Data Protection Laws” means all laws applicable to the Processing of Personal Data under the Agreement, including, as applicable: the EU General Data Protection Regulation 2016/679 (“EU GDPR”); the UK GDPR and Data Protection Act 2018 (“UK GDPR”); India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”); and the California Consumer Privacy Act as amended by the CPRA (“CCPA”).
“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, and “Supervisory Authority” have the meanings in the EU GDPR (and the corresponding meanings under other Data Protection Laws, e.g. “Data Fiduciary” / “Data Processor” / “Data Principal” under the DPDP Act; “Business” / “Service Provider” / “Consumer” under the CCPA).
“Customer Personal Data” means Personal Data contained in Customer Data (as defined in the Agreement) that Processor Processes on Controller’s behalf. “Sub-processor” means a third party engaged by Processor to Process Customer Personal Data. “SCCs” means the Standard Contractual Clauses approved by the European Commission on 4 June 2021, and “UK Addendum” means the ICO’s International Data Transfer Addendum.
2. Roles and scope
2.1 As between the parties, Controller is the controller (and, under the CCPA, “business”; under the DPDP Act, “Data Fiduciary”) of Customer Personal Data, and Processor is the processor (and “service provider” / “Data Processor”). For Processor’s own Account Data, Billing Data, and security/usage data, Processor is an independent controller and the Privacy Policy applies, not this DPA.
2.2 This DPA applies for the duration of the Agreement. Details of the Processing are in Annex II.
3. Processing instructions
3.1 Processor will Process Customer Personal Data only: (a) to provide, secure, support, and maintain the Service in accordance with the Agreement and this DPA; (b) as further instructed by Controller in writing (including via the Service’s configuration and features), where consistent with the Agreement; and (c) as required by applicable law, in which case Processor will inform Controller of that legal requirement before Processing unless the law prohibits it.
3.2 Processor will promptly inform Controller if, in its opinion, an instruction infringes Data Protection Laws (without obligation to give legal advice).
3.3 CCPA. Processor will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship, except as permitted by the CCPA; (c) combine it with Personal Data received from or on behalf of another person, except as the CCPA permits a service provider to do; or (d) retain, use, or disclose it outside Processor’s role as a service provider. Processor certifies it understands and will comply with these restrictions.
4. Confidentiality
Processor will ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate data-protection training, and will limit access to those who need it to provide the Service.
5. Security
5.1 Processor will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against a Personal Data Breach, as described in Annex III and the Security Overview, taking into account the state of the art, costs, and the nature, scope, context, and purposes of Processing, and the risks to Data Subjects.
5.2 Processor may update the measures over time provided the overall level of protection is not materially reduced.
6. Sub-processors
6.1 General authorization. Controller authorizes Processor to engage Sub-processors. The current Sub-processors are listed on the Sub-processors page (the “Sub-processor List”), as updated from time to time.
6.2 Notice of changes. Processor will update the Sub-processor List and give Controller at least 30 days’ prior notice before a new Sub-processor begins Processing Customer Personal Data.
6.3 Objection. Controller may object in writing on reasonable data-protection grounds within the notice period. The parties will work in good faith to resolve the objection. If they cannot, Controller may terminate the affected part of the Service, as its sole remedy, and receive a pro-rata refund of pre-paid, unused fees for the terminated part.
6.4 Flow-down and responsibility. Processor will impose on each Sub-processor data-protection obligations no less protective than those in this DPA, and remains responsible to Controller for each Sub-processor’s performance.
7. Assistance to Controller
7.1 Data Subject requests. Taking into account the nature of the Processing, Processor will assist Controller by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests. Export and deletion of account-level data is available on request (not yet a self-service control in the interface); for Customer Personal Data inside Customer Data, Processor will provide reasonable assistance to Controller. If Processor receives a request directly from a Data Subject, it will not respond substantively (except to acknowledge and direct the Data Subject to Controller) and will promptly notify Controller.
7.2 DPIAs and consultation. Processor will provide Controller with reasonable information and assistance for data protection impact assessments and prior consultations with a Supervisory Authority, to the extent they relate to Processor’s Processing.
7.3 Compliance information and audits. Processor will make available information reasonably necessary to demonstrate compliance with this DPA. Where available, Processor will provide its most recent third-party audit report or certification (e.g. SOC 2, ISO 27001) as the primary means of demonstrating compliance. If that is insufficient to meet a mandatory audit right under Data Protection Laws, Processor will permit and contribute to an audit, on at least 30 days’ notice, during business hours, no more than once per 12 months (unless required by a Supervisory Authority or following a Personal Data Breach), subject to confidentiality and to not compromising other customers’ data or Processor’s security.
8. Personal Data Breach
8.1 Processor will notify Controller without undue delay, and in any case within the timeframe required by applicable Data Protection Laws, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; and the measures taken or proposed. Processor will provide further information as it becomes available.
8.3 Processor will take reasonable steps to mitigate and remediate the breach. Processor’s notification is not an acknowledgment of fault or liability.
9. Return and deletion
On termination or expiry of the Agreement, Processor will, at Controller’s choice, delete or return all Customer Personal Data, and delete existing copies, within [30 days], unless applicable law requires storage. Customer Personal Data in routine backups is deleted in accordance with Processor’s backup retention cycle and is protected from further Processing until deleted. Controller may export Customer Data through the Service’s export features before the effective date of termination.
10. International transfers
10.1 Processor and its Sub-processors may Process Customer Personal Data in [AWS region — to confirm] and other countries, including the United States. Details are in the Sub-processor List.
10.2 EEA/UK transfers. Where Processor Processes Customer Personal Data originating in the EEA or the UK in a country without an adequacy decision, the SCCs (and, for UK transfers, the UK Addendum) are incorporated into this DPA by reference: Module Two (controller-to-processor) applies between Controller (data exporter) and Processor (data importer); Module Three (processor-to-processor) applies to onward transfers to Sub-processors. Clause 9 uses Option 2 (general written authorization), with the notice period in Section 6.2. Annexes I, II, and III of the SCCs are populated by Annexes I, II, and III of this DPA.
10.3 India transfers. Processor will not transfer Customer Personal Data originating in India to any country the Central Government has restricted by notification under the DPDP Act.
11. Liability
Each party’s liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement. This DPA does not limit any right a Data Subject has under Data Protection Laws.
12. Term; conflict; general
12.1 This DPA is effective for as long as Processor Processes Customer Personal Data.
12.2 In the event of a conflict between this DPA and the rest of the Agreement on the subject of Personal Data protection, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
Annex I — Parties
Data exporter / Controller: the Customer identified in the Agreement. Role: Controller. Activities: use of the Service for internal project and work management.
Data importer / Processor: [Legal entity name], [Registered office address]. Contact: privacy@agily.app. Role: Processor. Activities: providing the Service described in the Agreement.
Annex II — Description of the Processing
| Subject matter | Processing of Customer Personal Data to provide the Agily project/work-management Service. |
|---|---|
| Duration | For the term of the Agreement, plus the deletion/return window in Section 9. |
| Nature and purpose | Hosting, storage, transmission, display, indexing, backup, and access-controlled retrieval of Customer Data; delivering notifications; generating AI summaries where enabled; providing analytics/reporting features over Customer’s own data; providing support. |
| Types of Personal Data | Identification and contact data (names, emails, usernames, avatars); employment/profile data (job title, department, employee ID, phone, location, time zone); user-generated content that may contain Personal Data (work item and comment text, document and whiteboard content, standup/retrospective answers, timesheet notes and hours, goal check-ins, @mentions); technical identifiers from enabled Integrations (Slack/Teams/Telegram/Discord user IDs and usernames); file attachments; audit and activity metadata (actor, action, timestamp, IP, user-agent). |
| Special-category data | Not intended. Controller instructs its users not to submit special-category / sensitive Personal Data to free-text fields or attachments (see the Acceptable Use Policy). Any such data submitted is Processed only as generic Customer Data. |
| Categories of Data Subjects | Controller’s Authorized Users (employees, contractors, agents); individuals named or referenced within Customer Data; participants in connected chat channels. |
| Frequency | Continuous, for the duration of the Agreement. |
Annex III — Technical and Organizational Measures
Processor implements measures including, as applicable: role-based access control with least privilege; application-enforced tenant isolation; unique user IDs; support for multi-factor authentication; session management with token rotation, reuse detection, and remote revocation; TLS for data in transit; hashing of passwords and authentication tokens; AES-256-GCM encryption at rest for designated sensitive fields; account deletion that anonymizes the user record; an append-only, database-immutable audit log with automatic redaction of credential-like values; structured application logging with request correlation; version-controlled, peer-reviewed changes with automated linting, testing, dependency-vulnerability scanning, secret scanning, and container-image scanning in CI; parameterized database queries; security response headers; configurable CORS; hardened, non-root container images; upload type allow-listing and content-signature verification with malware scanning; per-entity authorization on every file operation; short-lived signed URLs; Sub-processor selection with data-protection diligence and contractual flow-down. Additional measures — automated encrypted backups with tested restore, centralized monitoring and alerting, and a documented incident-response process — are being implemented; the current status is described on the Security Overview page.
Annex IV — Sub-processors
The list of Sub-processors, their function, and processing locations is maintained on the Sub-processors page and is incorporated by reference. Changes are notified per Section 6.2.
Questions? Email legal@agily.app. Privacy requests: privacy@agily.app. Report a security issue: security@agily.app.