1. Scope and roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Automate HQ Inc. ("Squiid", "Processor") and the customer ("you", "Controller"). It applies whenever Squiid processes personal data on your behalf in providing the platform, and it takes effect automatically when you accept the Terms: no signature is required, though we will countersign a copy on request to legal@squiid.io.
Roles:
- You are the controller of the personal data your code and your agents route through the gateway ("Customer Personal Data"). You decide what is sent, to which provider, and why.
- Squiid is the processor of that data, and a "service provider" under the CCPA/CPRA.
- Squiid is a controller of the account, billing, security and usage-metadata it needs to run its own business. That processing is governed by the Privacy Policy, not this DPA.
- Providers you connect are independent controllers or your own processors under their own terms. Squiid's role for them is limited to routing your request and attaching your credential.
Where this DPA conflicts with the Terms on a data protection matter, this DPA wins.
2. Definitions
"Data Protection Laws" means the EU General Data Protection Regulation (2016/679), the UK GDPR and Data Protection Act 2018, the Swiss FADP, the CCPA as amended by the CPRA, and other applicable privacy laws. "Controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914. "Subprocessor" means a processor engaged by Squiid to process Customer Personal Data.
3. Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Squiid platform: authenticating keys, routing requests to connected providers, metering usage, billing and support. |
| Duration | For as long as you have an account, plus the retention periods in the Privacy Policy. |
| Nature and purpose | Receiving, authenticating, routing, transmitting, logging metadata about, and where you enable it temporarily storing, requests and responses; storing encrypted provider credentials; generating invoices and audit trails. |
| Types of personal data | Whatever your requests contain: determined by you. Typically: identifiers, contact details, message and prompt content, user-generated content, technical identifiers and IP addresses. Plus gateway metadata associated with your end users where you choose to send an end-user identifier. |
| Categories of data subjects | Your end users, your employees and contractors, and anyone whose data your application sends through the platform. |
| Special categories | None expected. Do not route special-category data without telling us first and agreeing appropriate safeguards in writing. |
| Frequency | Continuous, on your instruction, for the duration of the agreement. |
4. Processing on documented instructions
Squiid processes Customer Personal Data only on your documented instructions. Your instructions are: the Terms, this DPA, your configuration in the dashboard (connected services, key scopes, regions, retention and debug-capture settings) and the requests your code and agents send. Squiid will not process Customer Personal Data for its own purposes, will not sell or share it, and will not use it to train or fine-tune any machine learning model.
If Squiid is required by EU, UK or member-state law to process beyond your instructions, it will tell you first unless the law prohibits that notice on important grounds of public interest. Squiid will tell you if, in its opinion, an instruction infringes Data Protection Laws, and may pause that processing until the instruction is corrected.
You warrant that you have a lawful basis for the data you route, that you have given the notices and obtained the consents required, and that your instructions comply with Data Protection Laws. You are responsible for the accuracy and legality of the data you send and for the choice of providers you send it to.
5. Confidentiality and personnel
Squiid limits access to Customer Personal Data to personnel who need it to deliver the platform or to support you. Those personnel are bound by written confidentiality obligations that survive their engagement, receive data protection and security training, and have role-based access that is reviewed regularly and revoked on departure. Access to production requires multi-factor authentication and is logged.
6. Security measures
Squiid implements technical and organisational measures appropriate to the risk (GDPR Art. 32), including:
- TLS 1.2+ in transit; AES-256 at rest; envelope encryption for provider credentials with a managed key-management service and keys separated from the data.
- Data minimisation at the gateway: metadata is retained, request and response bodies are not, unless you enable debug capture.
- Role-based access control, mandatory MFA, least privilege, logged break-glass access, and regular access reviews.
- Network controls: WAF, DDoS protection, bot management and rate limiting at the edge; isolated production environment; secrets never in source control.
- Secure development: code review, dependency and vulnerability scanning, change management, separate staging and production.
- Resilience: encrypted backups, documented restore testing, an incident response plan with defined severities and on-call escalation.
- Logging and monitoring of authentication, credential access, spend anomalies and administrative actions.
Measures may be updated as technology changes, provided the level of protection is not reduced. A current summary is available under NDA from legal@squiid.io.
7. Subprocessors
You give Squiid general written authorisation to engage subprocessors, subject to the notice and objection rights below. Squiid imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains fully liable to you for a subprocessor's performance.
Current infrastructure subprocessors
| Subprocessor | Purpose | Personal data | Location |
|---|---|---|---|
| Stripe, Inc. | Payments, invoicing and Stripe Tax | Billing name and address, email, tax ID, partial card data, transaction history | USA, EU |
| Resend, Inc. | Transactional email: invoices, balance and expiry warnings, 2FA codes, security notices | Email address, name, message content and delivery metadata | USA |
| Cloudflare, Inc. | CDN, WAF, bot management, DNS, R2 object storage in front of the site and gateway | IP address, request headers and metadata, cached content | Global edge |
| Vercel Inc. | Hosting and serverless execution for the marketing site and dashboard | IP address, request logs, application data in transit | USA, EU |
| Supabase, Inc. | Primary application database, authentication and encrypted credential storage | Account, billing and usage metadata; encrypted provider credentials | USA, EU |
Providers you connect
In addition, every provider you connect is a subprocessor (or, under their own terms, an independent controller) for the data you choose to route to them: every service in the catalogue, from OpenAI, Anthropic and Neon to Twilio, Resend, Cloudflare and Stripe. Because you decide which to enable, this part of the subprocessor list is generated by your own configuration:
- Enabling a connected service in the dashboard is your instruction to engage that provider as a subprocessor for the data you send it, and constitutes your authorisation of it.
- Disabling a connected service withdraws that authorisation for future traffic. Data already delivered to a provider is held under that provider's own terms and retention rules, and you must use that provider's controls to delete it.
- Each service page in the catalogue links to that provider's DPA, subprocessor list, security page and data residency options. Review them before routing personal data.
- Squiid's liability for a connected provider is limited to selecting it in good faith, passing your instruction through accurately and maintaining terms with it that permit your use; we do not control the provider's own processing.
- Your live list of authorised connected providers is always visible in the dashboard, and is exportable as a CSV for your Art. 30 record of processing activities.
Notice of new subprocessors and your right to object
- Squiid maintains the infrastructure subprocessor list on this page and will update it at least 30 days before a new infrastructure subprocessor starts processing Customer Personal Data.
- Subscribe to the change notice at legal@squiid.io with the subject "Subprocessor notifications" and we will email the account address before each change. The dashboard also shows a notice.
- You may object on reasonable data protection grounds within 30 days of the notice by emailing legal@squiid.io with your reasons. We will work with you in good faith to offer a commercially reasonable alternative: a different region, a different vendor for your account, or a configuration that avoids the transfer.
- If we cannot resolve it within 30 days of your objection, you may terminate the affected part of the platform without penalty and we will refund prepaid fees and unspent credits for the terminated portion, pro rata.
- Where a change is urgent and necessary for security or availability, we may make it immediately and notify you without undue delay; your objection right still applies afterwards.
- Adding a provider to the public catalogue is not a subprocessor change for your account: nothing is processed until you enable it.
8. Assistance with data subject requests
The platform gives you self-service tools to access, export, correct and delete Customer Personal Data: dashboard exports, audit-log export, per-key retention settings and deletion endpoints. Use those first.
If a data subject contacts Squiid directly about Customer Personal Data, we will not respond substantively; we will tell them to contact you and, where we can identify you, forward the request without undue delay. Taking account of the nature of the processing, we will provide reasonable assistance with requests you cannot fulfil yourself, at no charge for a reasonable volume and at our standard rates for anything unusually burdensome.
Remember that data delivered to a connected provider lives in that provider's systems. A deletion request may need to be actioned there too, using that provider's tools: Squiid cannot delete data from a provider's estate on your behalf unless that provider exposes an API for it.
9. Personal data breach notification
Squiid will notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data, so that you can meet your own 72-hour obligation under GDPR Art. 33. The notice will describe, as far as known: the nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, measures taken or proposed, and a contact point for more information. We will supplement the notice as the investigation develops.
Squiid will take reasonable steps to contain and remediate the breach and will cooperate with your investigation and with any notification you must make to a supervisory authority or to data subjects. An initial notice is not an admission of fault or liability.
A breach at a connected provider is that provider's to report to you under its own terms; we will pass on what we are told and help you understand the traffic involved from the audit trail.
10. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to us, Squiid will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority under GDPR Arts. 35–36. In practice this means providing our security documentation, the processing details in this DPA, subprocessor and transfer information, and answers to a reasonable security questionnaire.
11. Return and deletion
On termination, and at your choice, Squiid will delete or return Customer Personal Data. Export tooling remains available for 30 days after closure; after that we delete Customer Personal Data from active systems within a further 30 days and from encrypted backups within 90 days as those backups rotate. Provider credentials held in custody are deleted and the ones we issued are revoked.
Squiid may retain data where required by law (invoices and tax records for 7 years) and retains de-identified aggregate statistics that cannot be linked back to you or to a data subject. Retained data stays subject to this DPA for as long as we hold it. A deletion certificate is available on request.
12. Audits and information rights
Squiid will make available the information reasonably necessary to demonstrate compliance with GDPR Art. 28 (including our security summary, subprocessor list, transfer documentation and any third-party audit reports or certifications we hold) on request to legal@squiid.io, under NDA.
Where that documentation is not sufficient, you may audit, once in any 12-month period, on at least 30 days' written notice, during business hours, without disrupting the platform, and subject to confidentiality. Audits may be conducted by an independent auditor you appoint who is not a competitor of Squiid. You bear the cost of the audit unless it reveals a material breach of this DPA, in which case we bear the reasonable cost of the audit and of remediation. A supervisory authority exercising its statutory powers is not subject to these limits.
13. International transfers
Squiid operates from the United States and uses global infrastructure. Where Customer Personal Data is transferred out of the EEA, the UK or Switzerland to a country without an adequacy decision:
- The EU Standard Contractual Clauses (Decision (EU) 2021/914) are incorporated into this DPA by reference and apply automatically. Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you are yourself a processor for your own customer. Clause 7 (docking) applies; under Clause 9, option 2 applies with a 30-day notice period as set out in Subprocessors; under Clause 11 the optional redress body is not used; under Clause 17 the governing law is Irish law, and under Clause 18(b) the forum is the courts of Ireland. Annexes I, II and III are populated by Details of the processing, Security measures and the subprocessor table respectively.
- The UK International Data Transfer Addendum (version B1.0) applies to UK transfers, with the SCCs as the approved clauses, Tables 1–4 populated by this DPA, and the importer permitted to end the addendum under Section 19.
- For Switzerland, references to the GDPR are read as references to the FADP, the Swiss FDPIC is the competent authority, and the clauses protect data of legal entities where the FADP requires it.
- Where a vendor is certified under the EU–US Data Privacy Framework (and its UK extension and Swiss counterpart), we may rely on that certification instead for transfers to that vendor.
Supplementary measures: encryption in transit and at rest, minimisation to metadata by default, strict access control, a published policy of reviewing and challenging overbroad government access requests, and notifying you of a request for Customer Personal Data unless legally prohibited. Regional routing options, where a provider offers them, are configurable per connected service.
14. CCPA / CPRA service provider terms
For personal information subject to the CCPA, Squiid acts as a service provider. We are provided personal information only for the limited and specified business purpose of delivering the platform under the Terms, and we:
- do not sell or share it, as those terms are defined by the CCPA;
- do not retain, use or disclose it for any purpose other than the business purposes specified, including not for our own commercial purpose, and not outside our direct business relationship with you;
- do not combine it with personal information received from other sources, except as permitted to detect security incidents or prevent fraud;
- comply with the obligations the CCPA places on service providers, provide the same level of privacy protection the CCPA requires, notify you if we determine we can no longer meet those obligations, and permit you to take reasonable steps to stop and remediate unauthorised use; and
- flow these obligations down to our own subprocessors.
You may monitor our compliance through the audit and information rights above.
15. Liability, term and precedence
Each party's liability under this DPA is subject to the exclusions and limitations in Terms, Section 19, except where Data Protection Laws or the SCCs prohibit that limitation: in particular, nothing here limits a data subject's rights under the SCCs.
This DPA takes effect when you accept the Terms and continues until Squiid stops processing Customer Personal Data. If a provision is held invalid, the rest stays in force. Where this DPA conflicts with the SCCs, the SCCs prevail; where it conflicts with the Terms on a data protection matter, this DPA prevails.
16. Contact
Data protection matters, countersigned DPA requests, subprocessor notifications and audit requests: legal@squiid.io. Data subject requests and privacy questions: privacy@squiid.io. Security: security@squiid.io.
Automate HQ Inc.
50 Alberigi Drive, Jessup, PA 18434, United States