Last updated: August 26, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer," "Data Controller") and Cyphrex, Inc. ("Cyphrex," "Data Processor") and governs the processing of personal data under GDPR, CCPA, and other applicable data protection laws.
This DPA applies to Scale and Enterprise customers and is available upon request for Core, Scale and Enterprise plans.
Cyphrex processes Personal Data to provide AI agent security and identity infrastructure services, including monitoring, logging, and alerting.
Processing continues for the duration of the service agreement and data retention period as specified in the Customer's plan.
Blockchain SSN registration involves writing data to the public Solana blockchain. Customer acknowledges that:
Customer consents to public blockchain processing by enabling Blockchain SSN features.
As Data Controller, Customer shall:
As Data Processor, Cyphrex shall:
Cyphrex implements industry-standard security measures including:
Cyphrex engages the following Sub-processors. Customer authorizes the use of these Sub-processors by accepting this DPA:
The current list of Sub-processors is published at cyphrex.io/legal/subprocessors.
| Name | Purpose | Data location | Website |
|---|---|---|---|
| Supabase Inc. | Database and authentication | USA (AWS us-east-1) | supabase.com |
| Railway Corp. | Application hosting | USA (us-west-2) | railway.app |
| Resend Inc. | Transactional email delivery | USA | resend.com |
| Sentry (Functional Software, Inc.) | Error monitoring and performance tracking | USA | sentry.io |
| BetterStack | Uptime monitoring | EU | betterstack.com |
| Solana Foundation | Public blockchain anchoring of audit Merkle roots | Decentralized (global validators) | solana.org |
Only Merkle root hashes are written on chain. No customer content, payload data, or personal data is published to the blockchain.
Cyphrex will notify Customer at least 30 days in advance of adding or replacing Sub-processors. Customer may object on reasonable grounds within 15 days of notification.
All Sub-processors are bound by data protection obligations equivalent to those in this DPA.
Customer acknowledges that Personal Data may be transferred to and processed in the United States and other jurisdictions where Cyphrex or its Sub-processors operate.
For transfers from the EU/EEA, Cyphrex relies on:
Enterprise customers may request a copy of applicable SCCs.
Cyphrex will assist Customer in responding to Data Subject requests, including:
Customer shall forward Data Subject requests to Cyphrex at hello@cyphrex.io. Cyphrex will respond within 10 business days with available data or assistance.
In the event of a Security Incident affecting Customer's Personal Data, Cyphrex shall:
Notification does not constitute acknowledgement of fault or liability.
Customer has the right to audit Cyphrex's compliance with this DPA:
During the service term, Cyphrex deletes event log rows older than the Customer's configured retention window. Windows are taken from plan configuration (Sandbox 30 days, Core 1 year, Scale 3 years, Enterprise as contracted) and may be overridden per account. Those values live in configuration; they are not compiled into the deletion job.
Merkle roots and on-chain records are not deleted. They are permanent by design and do not contain event payloads, URLs, or account identifiers from the event table. Events beneath a root may be deleted; the root stays.
An evidence package the Customer already holds continues to verify after those event rows are deleted. The package embeds its own event records and is Ed25519-signed over RFC 8785 JSON Canonicalization Scheme bytes. Verification uses the file (or the stored signed JSON), not a live read of Cyphrex's event table. Cyphrex cannot re-issue an evidence package for a window whose events have already been deleted.
Public verification at /verify loads the stored signed JSON for a published report. It does not re-query the event table. After event deletion, a still-published report continues to verify until that stored copy is itself removed.
Upon termination or expiration of the service agreement:
Public blockchain records (including Blockchain SSN-related data on Solana) are outside Cyphrex's control and are not deleted by Cyphrex when Personal Data is removed from Cyphrex systems. Cyphrex may remove or update only its internal records linking Customer to on-chain identifiers.
Each party's liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.
Cyphrex shall indemnify Customer against claims arising from Cyphrex's breach of this DPA or Data Protection Laws, provided Customer:
This DPA takes effect when Customer accepts the Terms of Service and remains in effect for the duration of the service agreement. It survives termination to the extent necessary to complete data deletion obligations.
Cyphrex may amend this DPA to reflect changes in Data Protection Laws or security practices. Material changes require 60 days' notice to Enterprise customers.
All Blockchain SSN registrations use self-custody. You own and control your agent's private keys and wallet. Cyphrex never holds, accesses, or manages private keys. Cyphrex may cover Solana gas fees on paid plans as a convenience. Blockchain transactions are irreversible. Cyphrex is not responsible for lost wallet access, network failures, or irreversible transactions.
For DPA-related matters, contact:
Data Protection Officer: hello@cyphrex.io
Legal: hello@cyphrex.io
Mailing address: Available upon request from hello@cyphrex.io.