Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement between Smart Sky for Advanced Systems and Computer Software (السماء الذكية للأنظمة المتطورة والبرمجيات الحاسوبية), a company registered in the Hashemite Kingdom of Jordan (company ID 200214341) (“ACP”, “Processor”) and the customer that accepted it (“Customer”) for Agent Control Panel (the “Agreement”). It applies when ACP processes Customer Personal Data on Customer’s behalf. It is effective automatically when the Agreement is accepted; a countersigned copy is available from Founders@skaigroup.tech.
On this page
- 1. Definitions
- 2. Roles and scope
- 3. Processing on documented instructions
- 4. Confidentiality of personnel
- 5. Security measures
- 6. Subprocessors
- 7. Data subject requests and assistance
- 8. Personal data breach notification
- 9. Deletion or return at the end of processing
- 10. Information and audits
- 11. Location of processing
- 12. International transfers
- 13. Liability
- 14. US state privacy laws
- 15. Order of precedence and term
- 16. Annex I: Details of processing
- 17. Annex II: Technical and organizational measures
- 18. Annex III: Subprocessors
1. Definitions
“Data Protection Laws” means all laws applicable to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable US state privacy laws. “Customer Personal Data” means personal data contained in Customer Data (as defined in the Agreement) that ACP processes on Customer’s behalf. “Controller”, “processor”, “data subject”, “personal data”, “personal data breach”, “processing”, and “supervisory authority” have the meanings given in the GDPR. “Subprocessor” means a third party engaged by ACP to process Customer Personal Data. “SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
2. Roles and scope
Customer is the controller (or a processor acting on behalf of its own controller) and ACP is the processor (or subprocessor) of Customer Personal Data. The subject matter, duration, nature and purpose of processing, and the types of personal data and categories of data subjects, are described in Annex I. ACP processes account and security data about Customer’s users as an independent controller, as described in its Privacy Policy; this DPA does not apply to that processing.
Customer is responsible for the lawfulness of the processing instructions it gives and for having provided any notices and obtained any consents Data Protection Laws require for ACP to process Customer Personal Data.
3. Processing on documented instructions
ACP will process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers, unless required to do otherwise by law, in which case ACP will inform Customer before processing unless the law prohibits it. The Agreement, this DPA, and Customer’s configuration and use of the Service (including enabling AI Features and configuring webhooks) are Customer’s complete instructions. ACP will inform Customer promptly if, in its opinion, an instruction infringes Data Protection Laws.
ACP will not sell or share Customer Personal Data, retain, use, or disclose it for any purpose other than providing the Service, or combine it with personal data it receives from other sources except as permitted by Data Protection Laws. ACP does not use Customer Personal Data to train machine-learning models.
4. Confidentiality of personnel
ACP will ensure that everyone it authorizes to process Customer Personal Data is bound by confidentiality obligations or an appropriate statutory duty of confidentiality, and has access only as needed to provide, secure, and support the Service.
5. Security measures
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, ACP will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, including the measures in Annex II. ACP may update these measures provided that the overall level of protection is not materially reduced. The current status of each control is published on the Security & Trust page.
6. Subprocessors
Customer gives ACP general authorization to engage Subprocessors. The current list is in Annex III and on the Security & Trust page. ACP will:
- impose on each Subprocessor data protection obligations that offer at least the same level of protection as this DPA, by written contract;
- give Customer at least 30 days’ prior notice of any intended addition or replacement of a Subprocessor, by updating the Security & Trust page and notifying the account owner by email or in the Service (or on a shorter period if necessary to address an urgent security or continuity risk, with notice as soon as practicable);
- remain responsible to Customer for each Subprocessor’s performance of its obligations.
Customer may object to a new Subprocessor on reasonable data-protection grounds by notifying ACP within the notice period. The parties will discuss the objection in good faith. If ACP cannot offer a reasonable alternative, such as not using that Subprocessor for Customer’s data or disabling the affected feature, Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the unused period.
Destinations that Customer configures, such as alert webhooks, are not ACP Subprocessors.
7. Data subject requests and assistance
Taking into account the nature of the processing, ACP will assist Customer by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights. The Service provides tools for this, including run retention settings, organization export and deletion, and per-run deletion. If ACP receives a request directly from a data subject about Customer Personal Data, it will not respond other than to direct the data subject to Customer, unless required by law, and will forward the request to Customer without undue delay.
ACP will also provide reasonable assistance with Customer’s data protection impact assessments and prior consultations with supervisory authorities, to the extent the information is available to ACP.
8. Personal data breach notification
ACP will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where information is not available at once, ACP will provide it in phases without undue further delay. ACP will take reasonable steps to contain and remediate the breach and will cooperate with Customer’s reasonable requests. Notification is not an acknowledgment of fault or liability.
9. Deletion or return at the end of processing
During the term, Customer can delete Customer Personal Data through the Service’s retention settings and deletion tools, or by request. On termination of the Agreement, Customer may request an export of Customer Personal Data within 30 days. After that period, ACP will delete Customer Personal Data from its production systems within 30 days, unless retention is required by law, in which case ACP will keep it confidential and process it only for that purpose. Any copies in backups managed by ACP’s database provider are deleted or overwritten according to that provider’s backup retention and are not restored except for disaster recovery.
10. Information and audits
ACP will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, including completed security questionnaires, the Security & Trust page, and, once available, its SOC 2 report or other third-party audit reports under confidentiality terms.
If that information is not sufficient to demonstrate compliance, or where a supervisory authority requires it, Customer may conduct an audit, including an inspection, no more than once in any 12-month period (unless following a personal data breach), on at least 30 days’ written notice, during normal business hours, in a manner that minimizes disruption, and subject to reasonable confidentiality and security obligations. Customer may use an independent auditor who is not a competitor of ACP. Each party bears its own costs, except that Customer will reimburse ACP’s reasonable costs for audits beyond the scope described here.
11. Location of processing
ACP and its Subprocessors store and process Customer Personal Data in the United States, as listed in Annex III. Cloudflare, the network in front of the Service, processes it in transit at the edge location nearest the sender and does not store it. ACP does not currently offer data residency in the EU or UK.
12. International transfers
To the extent ACP processes Customer Personal Data originating in the European Economic Area in a country that has not received an adequacy decision, the SCCs are incorporated into this DPA as follows: Module 2 (controller to processor) applies where Customer is a controller, and Module 3 (processor to processor) applies where Customer is a processor. For both modules: the optional docking clause 7 applies; under clause 9 option 2 (general written authorization) applies with the notice period in section 6; the optional language in clause 11 does not apply; under clause 13 the competent supervisory authority is the one determined by Customer’s establishment or representative; under clauses 17 and 18 the SCCs are governed by, and disputes resolved in the courts of, the EU Member State in which Customer is established or, if none, Ireland. Annexes I to III of this DPA complete the corresponding annexes of the SCCs.
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the SCCs (version B1.0) applies, with Table 1 completed with the parties’ details in Annex I, Table 2 referring to the SCC modules above, Table 3 completed by Annexes I to III, and Table 4 allowing either party to end the Addendum as set out in its section 19. For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss FADP and the competent authority being the Swiss FDPIC.
ACP will ensure that onward transfers to Subprocessors are covered by an appropriate transfer mechanism. If the SCCs conflict with this DPA, the SCCs prevail.
13. Liability
Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent that Data Protection Laws or the SCCs do not permit such limitation as regards data subjects.
14. US state privacy laws
To the extent US state privacy laws apply, ACP acts as a “service provider” or “processor” and will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship with Customer, or combine it with other personal data except as permitted by those laws. ACP will notify Customer if it can no longer meet its obligations under those laws.
15. Order of precedence and term
This DPA remains in effect for as long as ACP processes Customer Personal Data. If this DPA conflicts with the Agreement, this DPA prevails with respect to the processing of Customer Personal Data. Notices under this DPA go to the addresses in the Agreement; ACP’s privacy contact is Founders@skaigroup.tech.
16. Annex I: Details of processing
- Parties
- Data exporter: Customer, as identified in its account or order form (controller or processor). Data importer: Smart Sky for Advanced Systems and Computer Software (السماء الذكية للأنظمة المتطورة والبرمجيات الحاسوبية), a company registered in the Hashemite Kingdom of Jordan (company ID 200214341), Amman, Hashemite Kingdom of Jordan, contact Founders@skaigroup.tech (processor).
- Subject matter and duration
- Provision of the Service under the Agreement, for the term of the Agreement plus the deletion period in section 9.
- Nature and purpose
- Receiving, storing, displaying, analyzing, and deleting agent telemetry; sending signed commands to Customer’s agents on Customer’s configuration; optional AI Features (quality reviews, error explanations, Test Lab judging, integration analysis); alerts; support; and security of the Service.
- Frequency
- Continuous, as Customer’s agents report.
- Categories of data subjects
- End users of Customer’s agents and applications; Customer’s personnel and other individuals whose data appears in agent inputs, outputs, errors, or configuration.
- Types of personal data
- Whatever Customer’s integration sends, which may include names, contact details, identifiers, message contents, and other data present in prompts, outputs, and errors. Customer controls what is sent.
- Special categories
- Not intended. Customer must not send special categories of data or government identifiers unless agreed in writing with appropriate safeguards (see the Acceptable Use Policy).
- Retention
- Run records are deleted after Customer’s retention window (30 days on Free and Hobby, 90 days on Team, or as agreed); other data per the Service’s retention controls or on deletion by Customer.
- Competent supervisory authority
- As determined under clause 13 of the SCCs.
17. Annex II: Technical and organizational measures
ACP maintains the following measures, each marked “Implemented” on the Security & Trust page at the “Last updated” date above. Measures shown there as in progress or planned are not commitments under this DPA until implemented.
Infrastructure security
- Database public roles locked down. Row-level security is enabled and default grants are revoked for the database’s public API roles, so data is reachable only through the ACP server.
- Security headers on every page. Content Security Policy that only allows our own scripts, HSTS, frame protection, and MIME-sniffing protection.
- API responses are never cached. API responses carry no-store caching headers so browsers and intermediaries do not keep copies.
- Secure-configuration boot guards. The server refuses to start in production with a weak or missing session secret, a shared-password login left enabled, or no encryption key for stored secrets.
- Passwords handled by a managed identity provider. Sign-in and password storage are handled by Supabase Auth; ACP never stores user passwords itself.
- Encrypted database connections enforced. The server refuses to start in production unless its database connection uses TLS. Certificate verification against a pinned CA is supported and recommended.
Organizational security
- Written security and compliance policies. Information security, access control, incident response, vendor management, and data retention policies.
Product security
- Tenant isolation on every query. Every read and write is scoped to the caller’s organization, with automated tests that try to cross organization boundaries.
- Hashed, scoped API keys. API keys are stored only as SHA-256 hashes and can be scoped, given an expiry, and revoked at any time.
- Signed control commands. Commands sent to your agents are signed with HMAC-SHA256 over a timestamp and a single-use nonce, so they cannot be forged or replayed.
- Monitor-only by default. New connections can only report. Prompt edits and Test Lab results require explicit approval by an organization owner or admin, against the exact version they were proposed on, and expire after 7 days. Editing a shared skill applies to its assigned agents immediately: that is limited to owners and admins on apps with full control, versioned with one-click rollback, and recorded in the audit log.
- Role-based access for sensitive actions. Key, secret, scope, and settings changes require the owner or admin role; denied attempts are audited.
- Outbound request (SSRF) protection. Customer webhook URLs are validated so ACP cannot be pointed at private or internal network addresses.
- Rate limiting and per-organization AI quotas. Sign-in, ingest, prompt, and AI endpoints are rate limited, with a daily AI quota per organization.
- Untrusted-data isolation in AI prompts. Run content sent to AI features is fenced and marked as untrusted data to reduce prompt-injection risk.
- AI model allowlist and usage caps. ACP’s own AI features only call allow-listed models, with input-size limits and per-organization usage caps.
- MFA for platform administrators. Operators with platform-admin access must sign in with a verified second factor (TOTP) before the admin console will respond. Organization owners can also require MFA for individual members.
Internal security procedures
- Security audit trail. Changes to API keys, webhook secrets, control scopes, commands, settings, and skills are recorded with actor and time.
- Tamper-resistant audit log. Database triggers reject edits and deletions of audit entries; only the documented retention sweep may remove entries older than 365 days. Operator actions go to a separate append-only log.
- Audited operator console. A platform admin console where every operator action is written to an append-only audit log before it runs, and also appears in the affected organization’s own audit trail.
- Dependency scanning and hardened CI. Every change runs a dependency vulnerability audit; CI actions are pinned to commits and run with a least-privilege token.
- Pre-commit secret scanning. A pre-commit hook blocks credentials, keys, and connection strings from entering the repository.
- Automated dependency updates and code scanning. Dependabot updates, CodeQL static analysis, and repository secret scanning.
- No request bodies in logs, no internal errors exposed. Request bodies are never written to logs, and internal error details are never returned to clients.
- security.txt and disclosure policy. A standard /.well-known/security.txt points researchers to our contact and responsible disclosure policy.
Data & privacy
- Webhook secrets encrypted at rest. Webhook signing secrets are encrypted in the application with AES-256-GCM, with support for key rotation.
- Automatic deletion of run records. Run records are deleted automatically once they are older than the organization’s retention window (30 days on Free and Hobby, 90 days on Team).
- Retention for all telemetry and logs. Automatic deletion covers every telemetry table on the organization’s retention window, audit logs after 365 days, and early-access applications after 24 months.
- Organization data export and deletion. Self-service export of all organization data and full deletion, available to organization owners.
- Per-run deletion for erasure requests. Delete individual runs so you can honor an end user’s erasure request without deleting anything else.
- AI processing controls per organization. Owners choose whether ACP’s AI features are enabled, limited to the primary provider (no fallback), or disabled.
- No advertising or analytics cookies. The site and dashboard use only strictly necessary cookies and storage; the Content Security Policy blocks third-party scripts.
- No third-party requests from the dashboard. The dashboard and marketing site self-host their fonts, so loading them makes no requests to third-party servers.
18. Annex III: Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Postgres database and user authentication | United States (AWS us-east-1) |
| Railway | Application hosting and application logs | United States |
| Anthropic | Primary model for ACP’s AI features (quality reviews, error explanations, Test Lab judging, integration analysis and code generation); customer agents that run on Claude models | United States |
| OpenAI | Fallback model for the same AI features; customer agents that run on GPT models | United States |
| Google (Gemini) | Fallback model for the same AI features; customer agents that run on Gemini models | United States |
| xAI | Customer agents that run on Grok models; model-pricing lookups | United States |
| Perplexity | Customer agents that run on Sonar models | United States |
| OpenRouter | Routing to a model provider when a direct provider is unavailable; model-pricing catalog | United States |
| Cloudflare | Network in front of the Service: TLS, DDoS and bot protection, caching of public files, DNS; sign-in protection for ACP’s internal operator console | Global network (edge location nearest the user) |