Data Processing Agreement

Last updated: August 26, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer," "Data Controller") and Cyphrex, Inc. ("Cyphrex," "Data Processor") and governs the processing of personal data under GDPR, CCPA, and other applicable data protection laws.

This DPA applies to Scale and Enterprise customers and is available upon request for Core, Scale and Enterprise plans.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person processed by Cyphrex on behalf of Customer
  • "Processing" means any operation performed on Personal Data, including collection, storage, analysis, and deletion
  • "Data Subject" means the individual to whom Personal Data relates
  • "Sub-processor" means any third party engaged by Cyphrex to process Personal Data
  • "Data Protection Laws" means GDPR, CCPA/CPRA, and other applicable privacy regulations
  • "Security Incident" means any breach of security leading to unauthorized access, loss, or disclosure of Personal Data

3. Scope and Nature of Processing

Subject Matter

Cyphrex processes Personal Data to provide AI agent security and identity infrastructure services, including monitoring, logging, and alerting.

Duration

Processing continues for the duration of the service agreement and data retention period as specified in the Customer's plan.

Nature and Purpose

  • Agent identity verification and registration
  • Real-time action monitoring and audit logging
  • Behavior profile enforcement
  • Detection of known injection patterns, including encoded and obfuscated variants
  • Alert generation and delivery
  • Compliance reporting and analytics

Types of Personal Data

  • Customer account information (email, name, company)
  • Agent identifiers and configuration data
  • Audit logs (timestamps, action types, API endpoints)
  • Usage analytics and system metadata
  • IP addresses and device information

Categories of Data Subjects

  • Customer employees and contractors
  • Customer's end users (if monitoring customer-facing agents)
  • System administrators

3.5 Blockchain processing

Blockchain SSN registration involves writing data to the public Solana blockchain. Customer acknowledges that:

  • Blockchain data is public and permanent once confirmed on-chain
  • Data may include agent type, registration timestamp, and status fields (not personal data about end users by default)
  • Cyphrex cannot delete or modify immutable on-chain records
  • Self-custody users' wallet addresses may become publicly linked to agent identities on-chain
  • This processing is necessary for the cryptographic verification and audit-trail services Customer requests

Customer consents to public blockchain processing by enabling Blockchain SSN features.

4. Customer's Responsibilities

As Data Controller, Customer shall:

  • Ensure it has a lawful basis for processing Personal Data
  • Provide necessary notices to Data Subjects
  • Obtain required consents from Data Subjects
  • Comply with all applicable Data Protection Laws
  • Only instruct Cyphrex to process data in accordance with laws
  • Implement appropriate security measures for data sent to Cyphrex
  • Not send sensitive personal data (health, biometric, financial) without prior agreement

5. Cyphrex's Responsibilities

As Data Processor, Cyphrex shall:

  • Process Personal Data only on documented instructions from Customer
  • Ensure confidentiality of persons authorized to process Personal Data
  • Implement appropriate technical and organizational security measures
  • Provide 30 days notice before engaging new Sub-processors, with Customer's right to object
  • Assist Customer in responding to Data Subject requests
  • Assist Customer with data protection impact assessments
  • Notify Customer of Security Incidents without undue delay
  • Delete or return Personal Data upon termination
  • Make available information to demonstrate compliance

6. Security Measures

Cyphrex implements industry-standard security measures including:

Technical Measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Encrypted backups with separate encryption keys
  • API keys stored with per-user encryption
  • Multi-factor authentication for access control
  • Regular security patching and updates
  • Intrusion detection and prevention systems
  • Database access logging and monitoring

Organizational Measures

  • Role-based access control (RBAC)
  • Employee confidentiality agreements
  • Security awareness training
  • Incident response procedures
  • Regular security audits and penetration testing
  • SOC 2 Type II certification (in progress)
  • Data minimization and pseudonymization where possible

7. Sub-processors

Cyphrex engages the following Sub-processors. Customer authorizes the use of these Sub-processors by accepting this DPA:

The current list of Sub-processors is published at cyphrex.io/legal/subprocessors.

NamePurposeData locationWebsite
Supabase Inc.Database and authenticationUSA (AWS us-east-1)supabase.com
Railway Corp.Application hostingUSA (us-west-2)railway.app
Resend Inc.Transactional email deliveryUSAresend.com
Sentry (Functional Software, Inc.)Error monitoring and performance trackingUSAsentry.io
BetterStackUptime monitoringEUbetterstack.com
Solana FoundationPublic blockchain anchoring of audit Merkle rootsDecentralized (global validators)solana.org

Only Merkle root hashes are written on chain. No customer content, payload data, or personal data is published to the blockchain.

Cyphrex will notify Customer at least 30 days in advance of adding or replacing Sub-processors. Customer may object on reasonable grounds within 15 days of notification.

All Sub-processors are bound by data protection obligations equivalent to those in this DPA.

8. International Data Transfers

Customer acknowledges that Personal Data may be transferred to and processed in the United States and other jurisdictions where Cyphrex or its Sub-processors operate.

Transfer Mechanisms

For transfers from the EU/EEA, Cyphrex relies on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Supplementary measures to ensure data protection equivalent to EU standards

Enterprise customers may request a copy of applicable SCCs.

9. Data Subject Rights

Cyphrex will assist Customer in responding to Data Subject requests, including:

  • Access: Provide copies of Personal Data
  • Rectification: Correct inaccurate data
  • Erasure: Delete data ("right to be forgotten")
  • Portability: Export data in machine-readable format
  • Restriction: Limit processing under certain conditions
  • Objection: Object to processing on legitimate interest grounds

Customer shall forward Data Subject requests to Cyphrex at hello@cyphrex.io. Cyphrex will respond within 10 business days with available data or assistance.

10. Data Breach Notification

In the event of a Security Incident affecting Customer's Personal Data, Cyphrex shall:

  • Notify Customer without undue delay (target: within 72 hours of discovery)
  • Provide details of the incident, affected data, and potential impact
  • Describe measures taken to address the incident
  • Cooperate with Customer's investigation and regulatory notifications
  • Implement remediation measures to prevent recurrence

Notification does not constitute acknowledgement of fault or liability.

11. Audits and Compliance

Customer has the right to audit Cyphrex's compliance with this DPA:

  • Cyphrex will provide available security documentation and audit evidence annually, including SOC 2 reports once certification is obtained
  • Customer may request additional audits once per year with 60 days' notice
  • Audits shall be conducted during business hours with minimal disruption
  • Auditors must sign confidentiality agreements
  • Customer bears the cost of audits beyond that annual documentation provision

12. Data Retention and Deletion

During the service term, Cyphrex deletes event log rows older than the Customer's configured retention window. Windows are taken from plan configuration (Sandbox 30 days, Core 1 year, Scale 3 years, Enterprise as contracted) and may be overridden per account. Those values live in configuration; they are not compiled into the deletion job.

Merkle roots and on-chain records are not deleted. They are permanent by design and do not contain event payloads, URLs, or account identifiers from the event table. Events beneath a root may be deleted; the root stays.

An evidence package the Customer already holds continues to verify after those event rows are deleted. The package embeds its own event records and is Ed25519-signed over RFC 8785 JSON Canonicalization Scheme bytes. Verification uses the file (or the stored signed JSON), not a live read of Cyphrex's event table. Cyphrex cannot re-issue an evidence package for a window whose events have already been deleted.

Public verification at /verify loads the stored signed JSON for a published report. It does not re-query the event table. After event deletion, a still-published report continues to verify until that stored copy is itself removed.

Upon termination or expiration of the service agreement:

  • Customer may export all Personal Data within the configured post-termination export window (default 30 days)
  • Cyphrex will delete or anonymize Personal Data within the configured post-termination deletion window (default 90 days), including stored signed-report copies
  • Backup copies will be deleted according to backup retention schedules (maximum 1 year)
  • Data required for legal, tax, or regulatory purposes may be retained as required
  • Upon request, Cyphrex will provide written confirmation of deletion from the deletion-run log

Public blockchain records (including Blockchain SSN-related data on Solana) are outside Cyphrex's control and are not deleted by Cyphrex when Personal Data is removed from Cyphrex systems. Cyphrex may remove or update only its internal records linking Customer to on-chain identifiers.

13. Liability and Indemnification

Each party's liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.

Cyphrex shall indemnify Customer against claims arising from Cyphrex's breach of this DPA or Data Protection Laws, provided Customer:

  • Promptly notifies Cyphrex of the claim
  • Allows Cyphrex to control the defense
  • Provides reasonable cooperation

14. Term and Termination

This DPA takes effect when Customer accepts the Terms of Service and remains in effect for the duration of the service agreement. It survives termination to the extent necessary to complete data deletion obligations.

15. Amendments

Cyphrex may amend this DPA to reflect changes in Data Protection Laws or security practices. Material changes require 60 days' notice to Enterprise customers.

Blockchain SSN (self-custody)

All Blockchain SSN registrations use self-custody. You own and control your agent's private keys and wallet. Cyphrex never holds, accesses, or manages private keys. Cyphrex may cover Solana gas fees on paid plans as a convenience. Blockchain transactions are irreversible. Cyphrex is not responsible for lost wallet access, network failures, or irreversible transactions.

16. Contact and Data Protection Officer

For DPA-related matters, contact:

Data Protection Officer: hello@cyphrex.io
Legal: hello@cyphrex.io
Mailing address: Available upon request from hello@cyphrex.io.