Data Processing Addendum
Last updated: August 11, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service between Ruligent (the "Processor") and the customer that has accepted the Terms ("Customer", the "Controller"), and applies wherever Ruligent processes personal data on Customer's behalf. It is incorporated into the Terms by reference and takes effect when Customer uses the service.
1. Roles
For personal data contained in agent activity data (tool-call metadata and bounded payload summaries) processed through the service, Customer is the controller and Ruligent is the processor. For Customer's own account and billing data, Ruligent acts as an independent controller as described in the Privacy Policy.
2. Scope and nature of processing
- Subject matter: operation of the Ruligent governance service — policy evaluation, approvals, audit logging, spend limits, kill switches, and webhook delivery.
- Data processed: agent tool-call metadata (agent ID, tool, action, decision, reason, risk level, cost, timestamps) and bounded payload summaries. Ruligent does not store raw payloads. Customer controls what its agents place in payloads and must not submit regulated data (PHI, cardholder data) absent separate written agreement (see the Acceptable Use Policy).
- Data subjects: determined by Customer — typically Customer's personnel and any individuals referenced in agent tool calls.
- Duration: the subscription term, with audit events retained per the plan's retention window (7 days Free / 30 days Founder / 180 days Operator / 1 year Business) and then automatically purged.
3. Processor obligations
Ruligent will: (a) process personal data only on Customer's documented instructions, including as embodied in Customer's use and configuration of the service; (b) ensure persons authorized to process the data are bound by confidentiality; (c) implement the technical and organizational measures in Annex A; (d) assist Customer, taking into account the nature of processing, with data subject requests and with obligations under Articles 32–36 GDPR; (e) notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data; and (f) at termination, delete Customer personal data (retention-window purging plus account deletion on request), unless law requires retention.
4. Subprocessors
Customer provides general authorization for the subprocessors listed at /legal/subprocessors. Ruligent will update that page before adding a subprocessor; Customer may object on reasonable data-protection grounds within 15 days of the update, in which case the parties will work in good faith toward a resolution, including Customer's right to terminate affected services.
5. International transfers
Where Customer personal data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Module 2: controller-to-processor), and the UK Addendum / Swiss adaptations as applicable, with Customer as data exporter and Ruligent as data importer. Annex details (parties, description of processing, security measures) are completed by reference to this DPA and its annexes.
6. Audits
Ruligent will make available information reasonably necessary to demonstrate compliance with this DPA — including this page, the Security Policy, and the open-source core — and will allow audits by Customer or its mandated auditor as required by Article 28(3)(h) GDPR, subject to reasonable notice, frequency, and confidentiality terms. Ruligent does not currently hold SOC 2 or ISO 27001 certification and no audit report of that kind is available.
Annex A — Technical and organizational measures (summary)
- Encryption in transit (TLS) for all endpoints; strict security headers and locked-down CORS.
- Credentials stored only as hashes: SHA-256 for API keys and session tokens, scrypt for passwords.
- Tenant isolation: every query scoped to the authenticated organization.
- HMAC-SHA256 signed webhooks with per-endpoint secrets and timestamp tolerance.
- Automatic purging of audit events at the end of the plan retention window.
- Hosting on Vercel; data storage in Supabase (Postgres, region-configurable); payments via Stripe with no card data stored by Ruligent.
- Optional, configurable telemetry (Sentry errors, PostHog analytics).
- Responsible disclosure program per Security Policy.
Execution
This DPA is incorporated into the Terms of Service and applies automatically — no signature is required. Customers whose compliance program requires a countersigned copy can request one through the contact page.