Legal

Data Processing Agreement

Last updated: August 6, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Noetic IT Services ("Ideople," "we," "us") and the customer entity that has accepted those terms ("Customer," "you"). It governs our processing of personal data on your behalf when you use the Ideople platform (the "Service").

Where you are subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or comparable data protection law, this DPA applies automatically on acceptance of the Terms of Service — no signature is required. If your procurement process requires a countersigned copy, email privacy@ideople.com.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that is contained within Customer Data.
  • "Customer Data" means data you or your end users submit to the Service — including agent instructions, prompts, conversation content, knowledge base documents, datatable rows, and data pulled in through connected integrations.
  • "Controller," "Processor," "Data Subject," "Processing," and "Supervisory Authority" have the meanings given in the GDPR.
  • "Sub-processor" means any third party engaged by us to process Personal Data on your behalf.
  • "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2. Roles of the Parties

You are the Controller of Customer Data. We are the Processor, acting on your documented instructions. Where you process Personal Data on behalf of a third party, you act as that party's Processor and we act as Sub-processor; in that case, references to "Controller" in this DPA should be read accordingly.

We are an independent Controller for a limited set of data we collect in our own right — account registration details, billing records, and platform usage telemetry. That processing is governed by our Privacy Policy, not by this DPA.

3. Scope and Purpose of Processing

ElementDetail
Subject matterProvision of the Ideople AI agent automation platform
DurationFor the term of your subscription, plus the deletion periods in Section 9
Nature and purposeHosting, storage, agent execution, LLM inference, retrieval and embedding of knowledge sources, workflow execution, integration calls, and support
Categories of Personal DataWhatever you choose to submit. Typically: names, email addresses, phone numbers, job titles, company details, CRM and support records, and free-text content in prompts, conversations, and documents
Categories of Data SubjectsYour employees, contractors, customers, prospects, and other individuals referenced in Customer Data
Special category dataNot contemplated. The Service is not designed for special category data under GDPR Article 9 or for data subject to HIPAA, PCI-DSS, or comparable sectoral regimes. Do not submit such data without a separate written agreement

4. Our Obligations as Processor

We will:

  • Process Personal Data only on your documented instructions, which comprise this DPA, the Terms of Service, and your configuration of the Service (agents, workflows, integrations, and knowledge sources you set up);
  • Notify you if, in our opinion, an instruction infringes applicable data protection law, unless legally prohibited from doing so;
  • Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations;
  • Implement the technical and organizational measures described in Section 6;
  • Not sell Personal Data, and not use Customer Data to train our own or any third party's foundation models;
  • Assist you, taking into account the nature of processing, with your obligations under GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments, and prior consultation).

5. Your Obligations as Controller

  • You are responsible for the lawfulness of the Personal Data you submit and for having a valid legal basis for its processing;
  • You must provide any notices and obtain any consents required from Data Subjects;
  • You control what data your agents can reach. Configuring an agent to read a source, or connecting an integration, is an instruction to process that data;
  • You are responsible for managing workspace access, roles, and credentials, and for promptly removing members who should no longer have access.

6. Security Measures

We maintain technical and organizational measures appropriate to the risk, including:

  • Encryption in transit: All traffic to and from the Service uses HTTPS/TLS;
  • Encryption at rest: Integration credentials, OAuth tokens, and API keys are encrypted with AES-256 at the application layer; the underlying database and object storage are encrypted at rest;
  • Tenant isolation: All data is scoped to a workspace and enforced by authorization policies on every request;
  • Access control: Role-based access within workspaces; least-privilege access for our own personnel, granted only where needed to operate or support the Service;
  • Authentication: Support for two-factor authentication (TOTP) and OAuth-based sign-in;
  • Network and infrastructure: Hosted on Amazon Web Services with managed, private database instances not exposed to the public internet;
  • Logging and retention limits: Agent execution logs are retained for 90 days and then purged.

We may update these measures over time, provided the overall level of security is not reduced.

7. Sub-processors

You give general written authorization for us to engage Sub-processors. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain liable for their performance.

Our current Sub-processors are:

Sub-processorPurposePrimary location
Amazon Web ServicesCloud hosting, database, object storage, and Bedrock model inferenceIndia (ap-south-1); United States for Bedrock
OpenAILLM inference and embeddings, where selectedUnited States
AnthropicLLM inference, where selectedUnited States
GoogleLLM inference, where selected; OAuth sign-inUnited States
Mistral AILLM inference and embeddings, where selectedEuropean Union
Cohere, Jina AI, Voyage AIEmbedding generation, where selectedUnited States / European Union
Pinecone, QdrantVector storage for knowledge sources, where selectedUnited States / European Union
PayPalSubscription billing and payment processingUnited States

Model provider selection is yours. Prompts and context are sent only to the provider configured on the agent that executes. If you restrict an agent to a single provider, no other provider receives that data.

Integrations you connect are not our Sub-processors. When an agent writes to Slack, HubSpot, or another service you have authorized, that data flows to a Controller or Processor of your own choosing, under your agreement with them.

To be notified of new Sub-processors, email privacy@ideople.com with the subject "Sub-processor notifications." We will give at least 30 days' notice before a new Sub-processor begins processing Personal Data. If you reasonably object on data protection grounds within that period, we will work with you in good faith on an alternative; if none is available, you may terminate the affected part of the Service.

8. International Transfers

Personal Data may be transferred to and processed in countries other than where it was collected, including India and the United States. Where a transfer from the EEA, UK, or Switzerland is not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where applicable, which are incorporated into this DPA by reference. Module Two (Controller to Processor) applies where you are a Controller; Module Three (Processor to Processor) applies where you are a Processor.

We carry out transfer impact assessments where required and apply supplementary measures, including encryption in transit and at rest, and minimization of data sent to model providers.

9. Deletion and Return of Data

  • You can export or delete Customer Data yourself at any time through the Service;
  • On termination of your subscription, we delete Customer Data within 30 days, unless you request an export first;
  • Agent execution logs are purged on a rolling 90-day cycle;
  • Backups are overwritten on their normal rotation cycle, not exceeding 35 days after deletion;
  • We retain billing records for 7 years where required by tax and accounting law. These do not contain Customer Data.

10. Data Subject Requests

The Service gives you direct access to Customer Data so you can respond to access, correction, deletion, and portability requests yourself. Where you cannot fulfil a request through the Service, we will provide reasonable assistance at no additional cost. If a Data Subject contacts us directly about Customer Data, we will refer them to you rather than respond on your behalf, unless legally required to do otherwise.

11. Personal Data Breach Notification

We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate volume of data and Data Subjects affected, the likely consequences, and the measures taken or proposed. We will keep you updated as the investigation progresses. Notification is not an acknowledgement of fault or liability.

12. Audits and Information Rights

On written request, no more than once per year, we will provide the information reasonably necessary to demonstrate compliance with this DPA — including responses to a security questionnaire and copies of any third-party audit reports or certifications we hold. Where such documentation is insufficient to satisfy a Supervisory Authority, you may request an on-site audit on at least 30 days' notice, conducted during business hours, subject to confidentiality obligations, and at your expense.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA limits a Data Subject's rights under applicable data protection law.

14. Term, Conflicts, and Changes

This DPA takes effect when you accept the Terms of Service and continues for as long as we process Personal Data on your behalf. In the event of a conflict, this DPA prevails over the Terms of Service in respect of the processing of Personal Data, and the Standard Contractual Clauses prevail over this DPA.

We may update this DPA to reflect changes in law, our Sub-processors, or our security measures. Material changes will be posted on this page with a revised date and, where they affect your rights, notified to you by email.

15. Contact

For privacy questions, Data Subject requests, Sub-processor notifications, or a countersigned copy of this DPA:

Related documents: Privacy Policy · Terms of Service · Cookie Policy