Legal · AgentRelay MCP

Data Processing Addendum

Effective: 24 August 2026.

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and the provider identified in the applicable AgentRelay MCP order or invoice ("Provider") when Provider processes Personal Data on Customer's behalf. Capitalized privacy terms have the meanings given by applicable data-protection law, including the GDPR where applicable.

1. Roles and scope

For Customer Personal Data processed to provide the messaging gateway, Customer is the Controller (or Processor acting for another Controller) and Provider is the Processor (or Sub-processor). This DPA does not govern Provider's independent controller processing for billing, account administration, security, legal compliance or business operations, which is described in the Privacy Policy.

2. Documented instructions

Provider will process Customer Personal Data only to provide, secure and support AgentRelay MCP in accordance with the agreement, Customer's configuration and documented instructions, unless applicable law requires other processing. If Provider reasonably believes an instruction violates applicable data-protection law, it may suspend the affected processing and inform Customer where legally permitted.

3. Confidentiality and personnel

Provider will limit access to Customer Personal Data to personnel and contractors who need it to perform the service and who are bound by appropriate confidentiality obligations. Provider remains responsible for its personnel's compliance with this DPA.

4. Security

Taking into account the nature of processing and risk, Provider will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Measures may include access controls, server-side secret handling, encryption in transit where supported, environment separation, audit/security logging, backup controls, vulnerability management and incident-response procedures. Customer is responsible for configuring bots, credentials, agents, recipients and retention appropriately.

5. Sub-processors

Customer authorizes Provider to use sub-processors for infrastructure, storage, security, observability, support and other functions necessary to operate the service. Provider will impose data-protection obligations on sub-processors that are materially consistent with this DPA for the processing they perform. Provider remains responsible for sub-processor performance to the extent required by law. Material new sub-processors may be communicated through the service, documentation or account contact, and Customer may raise reasonable data-protection objections within 14 days of notice.

6. Customer-selected third parties

Telegram is a platform Customer directs Provider to use as a message destination/source and may process data as an independent third party under its own terms. Payment providers such as Dodo Payments or Lemon Squeezy may act independently for payment, tax and compliance processing. Such parties are not treated as Provider sub-processors under this DPA merely because Customer selects or uses them, except to the extent Provider expressly appoints a party as a sub-processor for Customer Personal Data.

7. Data-subject requests

Taking into account the nature of processing, Provider will provide reasonable assistance to Customer with requests to exercise data-subject rights where Customer cannot reasonably fulfill the request without Provider's assistance. Provider may direct a requester who contacts Provider about Customer-controlled data back to Customer unless law requires otherwise.

8. Security incidents

Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and will provide information reasonably available to help Customer meet applicable notification obligations. Notification is not an admission of fault or liability. Customer is responsible for notifications to data subjects and regulators unless law assigns that duty to Provider.

9. DPIAs and regulatory cooperation

Provider will provide reasonable information and assistance, taking into account the processing and information available to Provider, for Customer's data-protection impact assessments and consultations with supervisory authorities where the requested assistance relates to the service.

10. Deletion and return

At the end of the services, Provider will delete or return Customer Personal Data in accordance with Customer's available product controls and documented request, unless applicable law requires retention. Data in encrypted or immutable backups may remain until the ordinary backup cycle expires, during which it will remain protected and unavailable for routine use.

11. International transfers

Where Customer Personal Data protected by the GDPR, UK GDPR or Swiss data-protection law is transferred to a country without an applicable adequacy decision, the parties will use a lawful transfer mechanism. Where appropriate, the 2021 EU Standard Contractual Clauses are incorporated by reference using the module that matches the parties' roles, with Customer as data exporter and Provider as data importer, unless another valid mechanism applies. UK-protected data will use the applicable UK transfer addendum or replacement mechanism where required.

12. Audit information

Provider will make available information reasonably necessary to demonstrate compliance with this DPA. Where that information is insufficient, Customer may request a reasonable audit no more than once annually, or after a material incident, subject to confidentiality, security, scope and scheduling controls. Audits must avoid access to other customers' data and unnecessary disruption; Customer bears its audit costs unless applicable law requires otherwise.

13. Customer obligations

Customer is responsible for the lawfulness, accuracy and minimization of Customer Personal Data; providing required notices and obtaining required permissions; configuring retention and recipients; ensuring its instructions are lawful; and not submitting special-category, highly sensitive or regulated data unless the service and parties have expressly agreed appropriate safeguards for that use.

14. Liability and order of precedence

Liability arising from this DPA is subject to the liability provisions of the agreement except where applicable data-protection law requires otherwise. If this DPA conflicts with the agreement on processing of Customer Personal Data, this DPA controls for that processing.

Annex I — Processing details

Subject matter: operation of an AI-agent/MCP messaging gateway and associated support/security functions. Duration: the service term plus limited deletion/backup periods. Nature and purpose: receive authorized agent events; route notifications, questions and files to configured recipients; receive replies; return reply context to the originating workflow; authenticate/pair sources; meter usage; secure and troubleshoot the service.

Data subjects: Customer personnel, contractors, service users, configured recipients and other individuals whose personal data Customer lawfully routes through the service. Data categories: identifiers, usernames/display names, chat/source identifiers, message and file content, reply content, timestamps, delivery status, technical/security logs, account/contact data and Customer-selected metadata. Sensitive data: not intentionally required; Customer must avoid special-category or similarly sensitive data unless specifically agreed.

Annex II — Security measures

Measures are selected according to deployment and may include least-privilege access, server-side storage of credentials, separation of production secrets from client code, authenticated MCP/API access, TLS/network protections, signed payment webhooks, security/audit logs, dependency and vulnerability review, backup/recovery controls, incident procedures and controlled administrative access.

Annex III — Sub-processor information

Current categories may include infrastructure hosting, storage, operational support and security/observability providers. Payment providers and Telegram may process data under independent terms as explained above. An up-to-date operational sub-processor list may be requested through the support contact shown in the dashboard or purchase receipt.