Data Processing Agreement
Last updated: August 6, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Noetic IT Services ("Ideople," "we," "us") and the customer entity that has accepted those terms ("Customer," "you"). It governs our processing of personal data on your behalf when you use the Ideople platform (the "Service").
Where you are subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or comparable data protection law, this DPA applies automatically on acceptance of the Terms of Service — no signature is required. If your procurement process requires a countersigned copy, email privacy@ideople.com.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that is contained within Customer Data.
- "Customer Data" means data you or your end users submit to the Service — including agent instructions, prompts, conversation content, knowledge base documents, datatable rows, and data pulled in through connected integrations.
- "Controller," "Processor," "Data Subject," "Processing," and "Supervisory Authority" have the meanings given in the GDPR.
- "Sub-processor" means any third party engaged by us to process Personal Data on your behalf.
- "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
2. Roles of the Parties
You are the Controller of Customer Data. We are the Processor, acting on your documented instructions. Where you process Personal Data on behalf of a third party, you act as that party's Processor and we act as Sub-processor; in that case, references to "Controller" in this DPA should be read accordingly.
We are an independent Controller for a limited set of data we collect in our own right — account registration details, billing records, and platform usage telemetry. That processing is governed by our Privacy Policy, not by this DPA.
3. Scope and Purpose of Processing
| Element | Detail |
|---|---|
| Subject matter | Provision of the Ideople AI agent automation platform |
| Duration | For the term of your subscription, plus the deletion periods in Section 9 |
| Nature and purpose | Hosting, storage, agent execution, LLM inference, retrieval and embedding of knowledge sources, workflow execution, integration calls, and support |
| Categories of Personal Data | Whatever you choose to submit. Typically: names, email addresses, phone numbers, job titles, company details, CRM and support records, and free-text content in prompts, conversations, and documents |
| Categories of Data Subjects | Your employees, contractors, customers, prospects, and other individuals referenced in Customer Data |
| Special category data | Not contemplated. The Service is not designed for special category data under GDPR Article 9 or for data subject to HIPAA, PCI-DSS, or comparable sectoral regimes. Do not submit such data without a separate written agreement |
4. Our Obligations as Processor
We will:
- Process Personal Data only on your documented instructions, which comprise this DPA, the Terms of Service, and your configuration of the Service (agents, workflows, integrations, and knowledge sources you set up);
- Notify you if, in our opinion, an instruction infringes applicable data protection law, unless legally prohibited from doing so;
- Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations;
- Implement the technical and organizational measures described in Section 6;
- Not sell Personal Data, and not use Customer Data to train our own or any third party's foundation models;
- Assist you, taking into account the nature of processing, with your obligations under GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments, and prior consultation).
5. Your Obligations as Controller
- You are responsible for the lawfulness of the Personal Data you submit and for having a valid legal basis for its processing;
- You must provide any notices and obtain any consents required from Data Subjects;
- You control what data your agents can reach. Configuring an agent to read a source, or connecting an integration, is an instruction to process that data;
- You are responsible for managing workspace access, roles, and credentials, and for promptly removing members who should no longer have access.
6. Security Measures
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit: All traffic to and from the Service uses HTTPS/TLS;
- Encryption at rest: Integration credentials, OAuth tokens, and API keys are encrypted with AES-256 at the application layer; the underlying database and object storage are encrypted at rest;
- Tenant isolation: All data is scoped to a workspace and enforced by authorization policies on every request;
- Access control: Role-based access within workspaces; least-privilege access for our own personnel, granted only where needed to operate or support the Service;
- Authentication: Support for two-factor authentication (TOTP) and OAuth-based sign-in;
- Network and infrastructure: Hosted on Amazon Web Services with managed, private database instances not exposed to the public internet;
- Logging and retention limits: Agent execution logs are retained for 90 days and then purged.
We may update these measures over time, provided the overall level of security is not reduced.
7. Sub-processors
You give general written authorization for us to engage Sub-processors. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain liable for their performance.
Our current Sub-processors are:
| Sub-processor | Purpose | Primary location |
|---|---|---|
| Amazon Web Services | Cloud hosting, database, object storage, and Bedrock model inference | India (ap-south-1); United States for Bedrock |
| OpenAI | LLM inference and embeddings, where selected | United States |
| Anthropic | LLM inference, where selected | United States |
| LLM inference, where selected; OAuth sign-in | United States | |
| Mistral AI | LLM inference and embeddings, where selected | European Union |
| Cohere, Jina AI, Voyage AI | Embedding generation, where selected | United States / European Union |
| Pinecone, Qdrant | Vector storage for knowledge sources, where selected | United States / European Union |
| PayPal | Subscription billing and payment processing | United States |
Model provider selection is yours. Prompts and context are sent only to the provider configured on the agent that executes. If you restrict an agent to a single provider, no other provider receives that data.
Integrations you connect are not our Sub-processors. When an agent writes to Slack, HubSpot, or another service you have authorized, that data flows to a Controller or Processor of your own choosing, under your agreement with them.
To be notified of new Sub-processors, email privacy@ideople.com with the subject "Sub-processor notifications." We will give at least 30 days' notice before a new Sub-processor begins processing Personal Data. If you reasonably object on data protection grounds within that period, we will work with you in good faith on an alternative; if none is available, you may terminate the affected part of the Service.
8. International Transfers
Personal Data may be transferred to and processed in countries other than where it was collected, including India and the United States. Where a transfer from the EEA, UK, or Switzerland is not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where applicable, which are incorporated into this DPA by reference. Module Two (Controller to Processor) applies where you are a Controller; Module Three (Processor to Processor) applies where you are a Processor.
We carry out transfer impact assessments where required and apply supplementary measures, including encryption in transit and at rest, and minimization of data sent to model providers.
9. Deletion and Return of Data
- You can export or delete Customer Data yourself at any time through the Service;
- On termination of your subscription, we delete Customer Data within 30 days, unless you request an export first;
- Agent execution logs are purged on a rolling 90-day cycle;
- Backups are overwritten on their normal rotation cycle, not exceeding 35 days after deletion;
- We retain billing records for 7 years where required by tax and accounting law. These do not contain Customer Data.
10. Data Subject Requests
The Service gives you direct access to Customer Data so you can respond to access, correction, deletion, and portability requests yourself. Where you cannot fulfil a request through the Service, we will provide reasonable assistance at no additional cost. If a Data Subject contacts us directly about Customer Data, we will refer them to you rather than respond on your behalf, unless legally required to do otherwise.
11. Personal Data Breach Notification
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate volume of data and Data Subjects affected, the likely consequences, and the measures taken or proposed. We will keep you updated as the investigation progresses. Notification is not an acknowledgement of fault or liability.
12. Audits and Information Rights
On written request, no more than once per year, we will provide the information reasonably necessary to demonstrate compliance with this DPA — including responses to a security questionnaire and copies of any third-party audit reports or certifications we hold. Where such documentation is insufficient to satisfy a Supervisory Authority, you may request an on-site audit on at least 30 days' notice, conducted during business hours, subject to confidentiality obligations, and at your expense.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA limits a Data Subject's rights under applicable data protection law.
14. Term, Conflicts, and Changes
This DPA takes effect when you accept the Terms of Service and continues for as long as we process Personal Data on your behalf. In the event of a conflict, this DPA prevails over the Terms of Service in respect of the processing of Personal Data, and the Standard Contractual Clauses prevail over this DPA.
We may update this DPA to reflect changes in law, our Sub-processors, or our security measures. Material changes will be posted on this page with a revised date and, where they affect your rights, notified to you by email.
15. Contact
For privacy questions, Data Subject requests, Sub-processor notifications, or a countersigned copy of this DPA:
- Email: privacy@ideople.com
- Company: Noetic IT Services
- Contact page: ideople.com/contact
Related documents: Privacy Policy · Terms of Service · Cookie Policy