Data Processing Agreement
Last updated 2026-07-21
Launch draft pending counsel review. Questions: legal@pagerox.com.
1. Introduction and applicability
This Data Processing Agreement (the "DPA") forms part of the agreement between Pagerox ("we", "us", the "processor") and the customer (the "controller") under which Pagerox operates AI employees for the customer's workspace (the "Agreement"). It governs Pagerox's processing of personal data contained in customer workspace content, as processor on the customer's documented instructions.
This DPA applies to the extent the processing of personal data in customer content is subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or similar data protection laws that distinguish between controllers and processors. Where such laws do not apply to a given processing activity, the operational commitments in this DPA still describe how the service handles customer content.
Contact support@pagerox.com for a countersigned copy.
2. Definitions and roles
"Personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the GDPR or, for processing subject to the UK GDPR, the meanings given there.
"Customer content" means the workspace content the customer routes through or stores in the service: messages and files transiting connected channels, content submitted on Pagerox surfaces, and the persisted records described in Section 4.
For customer content, the customer is the controller (or, where the customer is itself a processor for a third party, Pagerox acts as its subprocessor and this DPA applies with the necessary changes) and Pagerox is the processor. Pagerox acts as an independent controller only for the limited account, billing, and usage records it needs to run its own business, which are covered by the Privacy Policy rather than this DPA.
3. Subject matter, duration, nature and purpose
Subject matter: operating AI employees for the customer workspace, including reading and responding to messages the customer connects, carrying out approved tasks, and maintaining the workspace's working knowledge.
Duration: the subscription term plus the deletion window in Section 12.
Nature and purpose: in-flight processing of messages from connected channels (Slack and email content is processed in flight and dropped, and nothing raw persists outside the in-flight pipeline); storage of the distilled knowledge the workspace keeps; model inference via configured providers; and generation of responses and actions inside the permission model the customer configures. Processing is automated and includes the use of large language models. No processing produces legal or similarly significant automated decisions about data subjects; the customer's approval model keeps consequential actions under human control.
4. Data subjects and categories of personal data
Data subjects: workspace members; authors and recipients of messages whose content transits the service in flight; and the customer's own end customers or other individuals who appear in customer content.
Categories of personal data: business communications and documents, and whatever personal data the customer's own content happens to contain (typically names, contact details, and the substance of workplace conversations). The service does not require special categories of personal data, and the customer should not route them through the service.
Persisted data is limited to: distilled knowledge the workspace keeps, attributed memories, Pagerox-surface conversation history and uploaded chat images (held in private workspace-scoped storage), the audit trail (12-month standard retention), and usage metadata. Everything else is process-and-drop.
5. Documented instructions
Pagerox processes customer content only on the customer's documented instructions, including with regard to transfers to third countries, unless required otherwise by law that applies to Pagerox; in that case Pagerox informs the customer before processing unless the law prohibits it on important grounds of public interest.
The Agreement, this DPA, and the customer's configuration of the service are the documented instructions. In practice the instruction mechanics are the workspace's own controls: which channels are connected, each employee's role configuration and tool grants, and the permission ladder under which consequential actions require an explicit approval record before they execute. Changing those settings changes the instructions; Pagerox does not act outside them.
If Pagerox believes an instruction infringes applicable data protection law, it informs the customer and may suspend the instruction until it is confirmed or changed.
6. Confidentiality of personnel
Pagerox ensures that persons authorized to process customer content are bound by confidentiality obligations, whether contractual or statutory, and access customer content only on a least-privilege basis for operating, securing, and supporting the service.
7. Security measures
Taking into account the state of the art and the risks of the processing, Pagerox implements appropriate technical and organizational measures, including: encryption in transit and at rest (the application is hosted on Vercel and data is stored on Supabase); tenancy isolation enforced through row-level security so each workspace's data is segregated at the database layer; server-side credential vaulting; append-only audit logging; least-privilege internal access; and the process-and-drop ingestion boundary described in the Privacy Policy, under which Slack and email content is processed in flight and dropped.
Analytics receive scrubbed event metadata only, never customer content.
A fuller description of the security program is published on the Security page at /security and is updated as the measures evolve. Pagerox may update the measures over time provided the overall level of protection does not decrease.
8. Subprocessing
The customer grants Pagerox general authorization to engage subprocessors for the categories published on the Subprocessors page: hosting (Vercel), database, auth, and storage (Supabase), payments (Stripe), model providers (OpenAI, Anthropic) engaged under no-training terms, email delivery (Resend), analytics (PostHog, EU), rate limiting (Upstash), and the tool-integration platform for tools the customer itself authorizes.
The customer authorizes the subprocessors listed at /legal/subprocessors. We give 30 days notice before adding one; the customer may object on reasonable data-protection grounds. If an objection cannot be resolved, the customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
Pagerox imposes data protection obligations on each subprocessor that are materially no less protective than this DPA, and remains responsible to the customer for its subprocessors' performance.
9. International transfers
Where processing under this DPA involves a transfer of personal data from the EEA, the UK, or Switzerland to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (controller-to-processor module), which are incorporated into this DPA by reference, together with the UK Addendum or the applicable Swiss adaptations where those regimes apply. Pagerox enters equivalent transfer terms with its subprocessors where required.
For model calls made under the customer's own provider keys, see the BYOK carve-out in Section 14.
10. Assistance with data-subject rights and DPIAs
Taking into account the nature of the processing, Pagerox assists the customer with appropriate technical and organizational measures in fulfilling its obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). Because raw channel content is process-and-drop, most requests concern the persisted records in Section 4, which the customer can inspect, export, and delete through the workspace itself; Pagerox assists where the tools do not suffice.
If a data subject contacts Pagerox directly about customer content, Pagerox refers them to the customer and does not respond on the merits except on the customer's instruction or where legally required.
Pagerox provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent the required information is available to Pagerox and the customer cannot obtain it otherwise, starting from the documentation on the Security page and this DPA.
11. Personal data breach notification
Pagerox notifies the customer without undue delay after becoming aware of a personal data breach affecting customer content, and in time to support the customer's own notification deadlines. The notification describes, to the extent known, the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences, and the measures taken or proposed. Pagerox does not notify authorities or data subjects on the customer's behalf unless instructed or legally required.
Security incidents can be reported to support@pagerox.com.
12. Deletion and return on termination
Customers can export all persisted content and delete the workspace at any time; on termination the customer should export first, because deletion is not reversible. On termination, customer content is deleted within 30 days; audit records survive in anonymized form. Copies in encrypted backups are overwritten on the backup rotation schedule, and Pagerox does not restore deleted customer content from backups except as required to meet a legal obligation.
Pagerox may retain data it is legally required to keep, protected under this DPA and processed for no other purpose.
13. Audits and information
Pagerox makes available to the customer the information reasonably necessary to demonstrate compliance with this DPA, starting with this DPA, the Security page, and the Subprocessors page, and answers reasonable written security questionnaires. As third-party audit reports or certifications are obtained, Pagerox provides them under confidentiality in place of individual audits to the extent they cover the customer's questions.
Where those materials are insufficient and applicable law grants the customer an audit right, the customer (or an independent auditor that is not a competitor of Pagerox) may audit Pagerox's compliance with this DPA on reasonable prior notice, no more than once per year absent a supervisory authority requirement or a personal data breach, during business hours, without access to other customers' data, and at the customer's expense.
14. BYOK carve-out
When the customer brings its own model provider keys, model calls made with those keys run directly under the customer's own agreement and data processing terms with that provider. For those calls Pagerox is not the exporter of the data sent to the provider, the provider is not a Pagerox subprocessor, and Sections 8 and 9 do not apply to that leg of the processing. Pagerox's obligations under this DPA continue to apply to everything else, including how the inputs and outputs of those calls are handled inside the service.
15. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where applicable data protection law does not permit them to be limited. This DPA does not enlarge either party's total liability under the Agreement.
If this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails. If incorporated Standard Contractual Clauses conflict with this DPA, the Clauses prevail for the transfers they govern.
16. Contact
Questions about this DPA, requests for a countersigned copy, and privacy or security notices go to support@pagerox.com.