Data Processing Agreement (DPA)
Last updated: 2026-07-16
Standard data processing terms for customers who act as controllers and appoint Phthos as processor under GDPR and similar laws.
This summary is provided for transparency. Enterprise customers may request a signed DPA at hello@phthos.ai.
1. Roles
You (the customer) are the controller of personal data you submit to Task AI. Phthos acts as processor on your instructions, except where we act as controller for account billing, security logging, or product analytics described in our Privacy Policy.
2. Subject matter and duration
Processing covers personal data submitted to Task AI while your subscription or trial is active and for a reasonable wind-down period after termination to allow export and deletion.
3. Nature and purpose
- Hosting and storing task configuration, chat history, and workspace membership.
- Executing AI runs, schedules, and connector syncs you enable.
- Billing, metering, support, and security monitoring.
4. Categories of data subjects
Your employees, contractors, and end users whose data you choose to process through Task AI.
5. Categories of personal data
Identifiers (name, email), professional data, prompts and files you upload, connector content, usage metadata, and technical logs. Sensitive data should not be submitted unless you have a lawful basis and appropriate safeguards.
6. Subprocessors
We use the subprocessors listed below. We will provide notice of material changes (for example via this page or email to workspace owners). You may object on reasonable grounds by contacting us within 30 days of notice.
| Subprocessor | Purpose | Data categories | Location |
|---|---|---|---|
| Hetzner Cloud | Application hosting, databases, and object storage | Account data, task configuration, logs, uploaded files | European Union (Germany / Finland) |
| Stripe | Subscription billing, invoicing, and payment processing | Billing contact, payment metadata (no full card numbers stored by us) | United States / EU (Stripe entity depends on account) |
| Resend | Transactional email (verification, invites, notifications) | Email address, message content | United States |
| OAuth identity providers | Sign-in (Google, GitHub, etc. when you choose them) | Profile identifiers and email from the provider | Provider-dependent |
| LLM and embedding providers | Model inference and embeddings you route through Task AI / Phthos gateway | Prompts, completions, files, and metadata you submit | Provider-dependent (configured by workspace) |
| Connected app providers | OAuth connectors (Google Drive, Notion, Slack, etc.) | Content and metadata from sources you authorize | Provider-dependent |
See also the dedicated Subprocessors page.
7. Security measures
We implement technical and organisational measures including encryption of secrets, role-based access, rate limiting, audit logging for selected actions, and isolated production networking. Details are available on request for security reviews.
8. International transfers
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms where required by law.
9. Assistance with data subject requests
We will assist you in responding to data subject requests within reasonable scope, using tools we provide or manual support for Enterprise plans. Direct requests to Phthos as processor may be forwarded to you unless we are legally required to respond directly.
10. Deletion and return
Upon termination, you may export workspace data where product features allow. We will delete or anonymise customer personal data within 90 days of account closure unless retention is required by law or for dispute resolution.
11. Audits
Upon reasonable notice and subject to confidentiality, we will provide information necessary to demonstrate compliance, or allow audits for Enterprise customers under mutually agreed scope and frequency.
Execute or customize this DPA
Email hello@phthos.ai with your company name, billing contact, and any required addenda.