Backstop
TermsPrivacyRefundDPA
DRAFT — not yet in force. These documents are templates grounded in how Backstop actually handles data. They must be reviewed and finalized by qualified legal counsel, and the placeholders (in [brackets]) filled in, before Backstop takes its first payment.

Data Processing Addendum

Effective date: [DATE] · Forms part of the Terms of Service

This Data Processing Addendum (“DPA”) applies where [LEGAL ENTITY NAME] (“Backstop,” “Processor”) processes Personal Data on behalf of a Customer (“Controller”) in the course of providing the service. It incorporates the Terms of Service. Where the GDPR, UK GDPR, or CCPA/CPRA applies, this DPA governs that processing.

1. Roles

For business data the Customer routes through Backstop (including journal data), the Customer is the Controller (or processor for its own customers) and Backstop is the Processor (or sub-processor). Backstop processes such data only on the Customer's documented instructions, which include the Terms, this DPA, and use of the service's features (journaling, undo, preview, diff, audit, change-feed).

2. Subject matter and details of processing

ItemDetail
Subject matterProviding a reversible, auditable write layer between the Customer's AI agent and its connected systems
DurationThe term of the agreement, plus retention windows described in §7
Nature/purposeRecording prior/written state to enable undo, preview, diff, and audit; detecting unprotected writes
Categories of data subjectsThe Customer's own contacts, customers, and personnel, as present in the connected systems
Categories of personal dataWhatever fields the Customer's agent writes (e.g., names, emails, order and CRM fields). The Customer can exclude fields from processing.
Special categoriesNot intended; the Customer should exclude sensitive fields it does not wish recorded

3. Processor obligations

Backstop will: (a) process Personal Data only on documented instructions; (b) ensure personnel are bound by confidentiality; (c) implement the technical and organizational measures in §5; (d) not engage a sub-processor except under §4; (e) assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach, and impact-assessment obligations; (f) at the Controller's choice, delete or return Personal Data at the end of the service, subject to legal retention; and (g) make available information necessary to demonstrate compliance.

4. Sub-processors

The Controller authorizes the sub-processors listed in the Privacy Policy (currently Fly.io for hosting and managed database, and Stripe for payment processing). Backstop imposes data-protection terms on each sub-processor no less protective than this DPA and remains liable for their performance. Backstop will give prior notice of changes and a reasonable opportunity to object.

5. Security measures

  • Encryption of platform tokens at rest (AES-256-GCM envelope encryption, per-tenant keys)
  • Database-enforced tenant isolation (row-level security)
  • Encryption in transit (TLS) for all endpoints
  • Authentication on all MCP endpoints and the operator console; least-privilege access
  • Tokens and record values are never written to logs
  • Customer-configurable field exclusions and immediate hard-deletion on request

[Add: access controls, logging/monitoring, vulnerability management, and incident-response specifics as finalized.]

6. Personal-data breaches

Backstop will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data, and will provide information reasonably necessary for the Controller to meet its notification obligations. [Specify notification window, e.g., within 72 hours, with counsel.]

7. Retention and deletion

Journal data is retained per the Customer's plan; a downgrade triggers a 14-day grace window before shorter retention applies. On termination, data is retained for 30 days (export available) then deleted. The Customer may request immediate hard deletion at any time. A failed payment never causes deletion or silent loss of protection.

8. International transfers

Where processing involves transfers subject to the GDPR/UK GDPR, the parties will rely on an approved transfer mechanism (e.g., Standard Contractual Clauses), incorporated by reference and completed as applicable. [Attach SCC module selections with counsel.]

9. Audits

Backstop will make available information to demonstrate compliance and allow for audits by the Controller or its mandated auditor, subject to reasonable confidentiality and frequency limits. [Define scope and cost allocation with counsel.]

10. CCPA/CPRA

To the extent the CCPA/CPRA applies, Backstop acts as a “service provider,” processes Personal Information only to provide the service, and will not sell or share it or retain, use, or disclose it outside the direct business relationship.

11. Order of precedence

In case of conflict, this DPA prevails over the Terms with respect to processing of Personal Data. All other matters are governed by the Terms.

A signable counterpart is available on request: legal@[DOMAIN].