Status: draft pending review by a Dutch IT/privacy lawyer. The DPA in this form is auto-accepted on signup; replace with the lawyer-reviewed version by 2026-08-02.
1. Scope and definitions
This DPA applies to all personal data we (the “Processor”) process on behalf of you (the “Controller”) in connection with Warden. Defined terms used here have the meaning given in the GDPR (Regulation (EU) 2016/679) unless explicitly redefined.
2. Subject matter and duration
Subject matter. Storage, indexing, retrieval, signing, and presentation of your AI agent register, audit log entries, intake answers, and EU AI Act dossier exports.
Duration. For as long as your Warden account is active, plus the deletion windows defined in section 9 below.
Nature and purpose. To deliver the Warden Service as described in the Terms of Service and to enable your compliance with the EU AI Act.
3. Categories of data and data subjects
The personal data processed under this DPA consists of:
- Email addresses — yours and those of any “owner of record” you assign per agent.
- Names — of accountable persons and agents.
- Audit-log content — the “summary” field of each logged action. May contain personal data if you write it there.
- Intake answers — structured answers to the EU AI Act classification questionnaire, including any free-text the user provides.
- Webhook delivery records — URL, request payload, response status.
Data subjects are typically your employees, your service providers’ employees, or the natural persons your AI agents interact with.
4. Our obligations as processor
4.1 Instructions
We process personal data only on your documented instructions, including with regard to transfers, unless required by EU or Dutch law. If we are required to act outside your instructions by law, we inform you before processing, unless that law prohibits us.
4.2 Confidentiality
We ensure that everyone authorised to process personal data has committed to confidentiality or is under a statutory obligation of confidentiality.
4.3 Security
We implement appropriate technical and organisational measures:
- Data encrypted at rest (Supabase default) and in transit (TLS 1.2+).
- Per-tenant logical isolation; row-level scoping on every read and write.
- Bearer-token authentication on every API call.
- HMAC-SHA256 signatures on outbound webhooks.
- Access to production limited to FlowVolt personnel with a documented need.
- Server-side access logs retained for fourteen days.
- Regular dependency upgrades and security advisories monitored.
4.4 Sub-processors
You authorise the sub-processors listed in section 8 below. We give you at least thirty days’ notice before adding or replacing a sub-processor, by updating this page and emailing the notice to your billing email. You may object on reasonable grounds, in which case we work with you to find an alternative or you may terminate without penalty for the remaining prepaid period.
4.5 Data subject rights
We help you respond to data subject requests (access, rectification, erasure, portability, objection, restriction) by providing the technical means via the API and dashboard. We forward any request we receive directly from a data subject about your data to you within five business days.
4.6 Breach notification
If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any event within forty-eight hours of becoming aware. The notification includes the nature of the breach, approximate categories and numbers of data subjects and records, the likely consequences, and the measures taken or proposed.
4.7 Audit
Once per twelve-month period, on at least thirty days’ notice and at your cost, you may commission an independent third-party audit to verify our compliance with this DPA. We cooperate in good faith and provide reasonable access. The auditor signs an NDA before any access is granted.
5. International transfers
Personal data is processed inside the European Union, primarily in Frankfurt, Germany. Where a sub-processor (Stripe; AI vendors via the integrations feature) transfers data outside the EU, the transfer is governed by Standard Contractual Clauses (Commission Decision 2021/914) and supplementary measures as required by the EDPB.
6. Your obligations as controller
- You ensure you have a lawful basis to process the personal data you put into Warden.
- You inform your data subjects about your use of Warden where required by GDPR Articles 13 and 14.
- You do not record personal data of categories prohibited by GDPR Article 9 unless you have a specific Article 9(2) basis and have informed us in writing.
7. Liability and indemnity
Each party’s liability under this DPA is governed by the Terms of Service, including the liability cap set out there. Nothing in this DPA limits liability for breach of GDPR for which the law does not allow limitation.
8. Sub-processors
The following sub-processors are authorised as of the last-updated date:
- Supabase (Inc., USA, EU region) — database and storage.
- Vercel (Inc., USA, EU region) — hosting and edge.
- Stripe (Payments Europe, IE) — payments.
- Resend (Inc., USA) — transactional email.
- Anthropic (PBC, USA) — only if you enable the OpenAI/Anthropic usage import.
Each sub-processor is bound by a written contract containing data protection obligations no less protective than this DPA.
9. Deletion and return of data
On termination of your Warden account, we delete your personal data within thirty days, except for data we are required to retain by law (notably AI Act Article 26 audit logs, with a six-month minimum). On written request before deletion, we provide you a full export of your agent register, audit log, intake records, and dossier exports in machine-readable form.
10. Effective date and changes
This DPA takes effect on the day you sign up to Warden. Material changes are announced at least thirty days in advance by email to your billing email. The current version is always available at warden.flowvolt.io/dpa.
11. Contact
For DPA-related questions: privacy@flowvolt.nl.