Data Processing Agreement
Last updated 2026-09-18 · Terms · Privacy · Imprint · DPA
This DPA applies when your agents process personal data of other people (customers, contacts, users of your own product) through alleex. Then you are the controller and the operator is your processor under Art. 28 GDPR. It is part of the Terms; no signature is needed.
1. Parties and roles
Controller: you, the account holder. Processor: Alexander Burger, Josef-Maderspergerstraße 15, 5020 Salzburg, Austria, 5020 Salzburg, Austria (the operator).
For your own account data (e-mail, sessions, billing) the operator is a controller; that is covered by the Privacy Policy, not by this DPA.
2. Subject matter, duration, nature and purpose
Subject matter: the personal data your agents fetch, receive, transform, store as run input, output, logs, artifacts or knowledge bases, and send on to services you configured. Duration: for as long as you have an account, plus the deletion period in section 8. Nature and purpose: automated execution of the workflows you defined, on your instruction, plus storage of runs so you can inspect them. Data subjects and categories: whatever your agents handle. You decide; typical examples are contact data, messages, tickets and web content. Special categories (Art. 9) only where you have the required legal basis and have told us.
3. Instructions
The operator processes personal data only on your documented instructions. Your instructions are: the agent graphs you build, the runs you trigger, the settings you choose (visibility, retention through deletion, credentials) and the Terms. The operator tells you if it thinks an instruction breaks the law. It will not use your agents' data for its own purposes and does not train models on it.
4. Confidentiality and security (Art. 32)
Persons with access to the data are bound to confidentiality. Measures in place: encrypted transport (TLS); credentials encrypted at rest with AES-256-GCM under a server-side key; per-account isolation of agents, runs and credentials in the database; session tokens instead of shared passwords; run and storage quotas; access to the production server limited to the operator over key-based SSH; regular backups inside the EU; no analytics or tracking scripts. The operator may improve measures over time without lowering the level of protection.
5. Sub-processors
You authorise these sub-processors. Any addition or replacement is announced on this page and in the app at least 14 days before it takes effect; if you object on reasonable data-protection grounds and no solution is found, you may terminate.
- EU hosting provider (Oracle Cloud Infrastructure, region Frankfurt, Germany): servers, database and backups.
- Nebius B.V., Netherlands: platform language model (only when a run uses platform credits).
- Resend, Inc., USA (or equivalent): transactional e-mail.
- Stripe Payments Europe, Ltd., Ireland: payments (account data only, no agent data).
Not sub-processors: model vendors and services you connect with your own keys (OpenAI, Anthropic, Google and the rest, plus every API, inbox and website your nodes call). Those receive data because you instructed your agent to send it, under your own contract with them.
6. International transfers
Processing by the operator and its hosting takes place in the EU. Where a sub-processor is outside the EEA (e-mail delivery), the transfer rests on the European Commission's Standard Contractual Clauses, Decision (EU) 2021/914, module 3 (processor to processor), with supplementary measures where needed, or on an adequacy decision such as the EU-US Data Privacy Framework where the recipient is certified. Copies are available on request.
7. Assistance and audits
The operator helps you, as far as possible with the tools in the app, to answer data-subject requests (export agents as JSON, inspect and cancel runs, delete everything by deleting the account; ask for the deletion of single runs by e-mail) and to meet Art. 32 to 36 (security, breach notification, DPIA). Personal data breaches affecting your data are reported to you without undue delay after the operator becomes aware of them, with what is known at that time.
You may ask for the information needed to show compliance with Art. 28 and, once a year or after a breach, conduct an audit at your cost on reasonable notice; the operator may answer with a written description of its measures where that suffices.
8. Deletion and return
You can export agents at any time and delete all data by deleting your account; single runs are deleted on request. When your account is deleted, the operator deletes all data it processes for you within 30 days, except what it must keep by law (billing records, § 132 BAO) and backups, which are overwritten on their normal cycle of at most 30 days.
9. Precedence
If this DPA conflicts with the Terms, the DPA wins for the processing of personal data on your behalf. Where the law of your country requires additional processor terms, tell us and we will add them where reasonable.