This Data Processing Addendum ("DPA") is part of the AgentOS Terms of Service and applies whenever a customer’s use of AgentOS involves personal information about the customer’s clients and contacts. It is designed to satisfy the service provider and processor contract requirements of U.S. state privacy laws.
This DPA is between the customer organization that accepts the Terms of Service ("Customer") and AgentOS, a North Carolina company ("AgentOS"). For personal information contained in Customer Content ("Customer Personal Data"), Customer is the business or controller and AgentOS is the service provider or processor. "Consumer Privacy Laws" means U.S. state comprehensive privacy laws applicable to a party, including the California Consumer Privacy Act as amended, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Texas Data Privacy and Security Act, together with their regulations.
Subject matter and duration: processing of Customer Personal Data to provide the Platform for the term of the agreement plus the deletion window. Nature and purpose: hosting, storage, transmission, display, transcription, document processing, communication delivery, analytics for the Customer’s benefit, and related support. Categories of data subjects: Customer’s clients, leads, contacts, transaction parties, and visitors to pages Customer shares. Categories of data: identifiers and contact details, transaction and property information, documents and their contents, communications, and event records. Customer instructs AgentOS to process Customer Personal Data to provide the Platform as configured by Customer.
AgentOS will: (a) process Customer Personal Data only on Customer’s documented instructions as expressed through the Terms, this DPA, and Customer’s configuration of the Platform, and not for any other purpose; (b) not sell or share Customer Personal Data as those terms are defined in Consumer Privacy Laws; (c) not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for any commercial purpose other than providing the Platform, except as permitted by Consumer Privacy Laws (including security, deidentified analytics, and legal compliance); (d) not combine Customer Personal Data with personal information from other sources except as permitted for the services; (e) ensure personnel with access are bound by confidentiality; and (f) notify Customer if AgentOS determines it can no longer meet its obligations under Consumer Privacy Laws, in which case Customer may take reasonable steps to stop and remediate unauthorized processing.
Customer authorizes AgentOS to use the subprocessors listed in Section 7 of the Privacy Policy (the current list as posted). AgentOS will bind subprocessors to data protection obligations no less protective than this DPA, remains responsible for their performance, and will update the posted list before adding a new subprocessor that processes Customer Personal Data. If Customer reasonably objects to a new subprocessor on data protection grounds and AgentOS cannot offer an alternative, Customer may terminate and receive a pro-rata refund of prepaid, unused fees.
AgentOS maintains appropriate technical and organizational measures, including encryption in transit and at rest, row-level access controls, tenant isolation, private file storage with short-lived signed URLs, hashed credentials, optional multi-factor authentication, audit logging, and access limited to personnel who need it. Customer is responsible for configuring roles, managing its users, and protecting its credentials.
AgentOS will notify Customer without undue delay after confirming a breach of security leading to unauthorized access to Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations, along with reasonable cooperation on remediation.
Taking into account the nature of processing, AgentOS provides tools that help Customer honor consumer rights requests: record editing and deletion, data export, and account-level deletion. If a consumer submits a request directly to AgentOS about Customer Personal Data, AgentOS will forward it to Customer and will not respond substantively except as required by law. AgentOS will provide reasonable assistance with Customer’s data protection assessments where required.
Upon termination or upon Customer’s instruction, AgentOS deletes Customer Personal Data on the schedule described in the Privacy Policy (30-day recovery window, plus up to 30 days for backup aging), except where retention is required by law. Export tools are available before deletion.
No more than once per 12-month period and upon reasonable written notice, AgentOS will make available information reasonably necessary to demonstrate compliance with this DPA, in the form of written responses, documentation, and summaries of assessments. Customer may take reasonable and appropriate steps to ensure AgentOS uses Customer Personal Data consistently with Customer’s obligations under Consumer Privacy Laws.
This DPA is effective while AgentOS processes Customer Personal Data and, for that processing, controls over any conflicting term of the Terms of Service. No additional fees apply to the rights and obligations in this DPA.
Questions about this DPA or need a countersigned copy for your brokerage? Reach us at support@getagentos.io. See also our Privacy Policy and Terms of Service.
Join hundreds of agents who replaced chaos with clarity. Setup takes five minutes. Results start immediately.
7-day free trial · no credit card · 5-minute setup