Data Processing Agreement
This Data Processing Agreement ("DPA") applies when Sanklad Digital Ltd (company number 14223393, "Delegated") processes personal data on behalf of a customer ("Customer") in providing the Service under the Delegated Terms of Service (the "Terms"). It meets the requirements of Article 28 of the UK GDPR and, where it applies, the EU GDPR (together, "Data Protection Law"). Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in Data Protection Law.
1. Scope and roles
- Customer is the controller (or a processor acting for its own controllers) of personal data in Customer's workspace ("Customer Personal Data"). Delegated is Customer's processor (or sub-processor).
- Annex 1 describes the processing.
- Services Customer chooses. The AI Provider Customer connects, and apps Customer connects to its agents, are services Customer engages directly. Data sent to them on Customer's instructions is disclosed by Customer to those parties, and they are not Delegated's sub-processors. Delegated's integration provider, which brokers some app connections on Delegated's behalf, is a sub-processor and is listed in Annex 3.
- Delegated's own apps. Anjal (the team inbox), PandaQueue and PandaCrawl are operated by Delegated itself. When they are turned on for Customer, processing in them is covered by this DPA as processing by Delegated.
- Delegated is a controller of its own account, billing and service-operation data, as described in the Privacy Policy; that data is outside this DPA.
2. Customer's instructions
- Delegated processes Customer Personal Data only on Customer's documented instructions, which are: the Terms and this DPA; Customer's configuration of the Service, including its agents, routines, connections, permissions and approvals; and requests made by Customer or its authorised members through the Service. An instruction given to an agent in the Service is an instruction of Customer.
- Delegated may process Customer Personal Data otherwise if the law requires it, and will tell Customer first unless the law prohibits that.
- Delegated will tell Customer if it believes an instruction breaches Data Protection Law.
- Customer is responsible for having a lawful basis, giving notices and obtaining consents for the processing it instructs, including processing by agents and by the services it connects.
3. Confidentiality
Delegated ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality and accesses it only as needed to provide, secure or support the Service, or as Customer requests (for example when Customer asks for help and grants access).
4. Security
Delegated implements appropriate technical and organisational measures to protect Customer Personal Data, taking into account the nature of the processing and the risks. The current measures are in Annex 2. Delegated may update them provided the overall level of protection is not reduced.
5. Sub-processors
- Customer gives general authorisation for Delegated to use sub-processors. Annex 3 lists the current ones.
- Delegated will give at least 14 days' notice of a new sub-processor by email or on its website. Customer may object on reasonable data protection grounds within that period. If the objection can't be resolved, Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees.
- Delegated imposes data protection terms on each sub-processor that protect Customer Personal Data to the standard of this DPA, and remains responsible for its sub-processors' performance.
6. Data subject requests
Taking into account the nature of the processing, Delegated will help Customer respond to requests from data subjects to exercise their rights, mainly through the Service's own features (reading, editing, exporting and deleting workspace data). If Delegated receives a request directly, it will pass it to Customer and not respond itself except to direct the requester to Customer.
7. Personal data breaches
Delegated will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include what Delegated then knows of the nature of the breach, the data and data subjects likely affected, the likely consequences and the measures taken or proposed, updated as more becomes known. Delegated will take reasonable steps to contain it. Notifying Customer is not an admission of fault.
8. Assistance
Delegated will provide reasonable help, using information available to it, with Customer's data protection impact assessments and prior consultations with supervisory authorities about the Service. Delegated may charge a reasonable fee for help beyond what the Service's features and documentation provide.
9. International transfers
- Cloud workspace servers are located in the EU (Germany). Some sub-processors in Annex 3 process data in other countries, including the United States.
- Where Customer Personal Data is transferred from the UK or the EU to a country without an adequacy decision or regulations, Delegated relies on a valid transfer mechanism: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses (Commission Decision 2021/914), or certification under the UK Extension to the EU–US Data Privacy Framework, as applicable.
- Transfers to an AI Provider or app Customer connects are made on Customer's instructions under Customer's own agreement with that party (section 1).
10. Audits
On written request, and no more than once a year unless a breach or a supervisory authority requires it, Delegated will make available the information reasonably necessary to demonstrate compliance with this DPA. This will normally be written answers and documentation. If that is not sufficient, Customer may carry out an audit, at its own cost, by an independent auditor bound by confidentiality, on 30 days' notice, during business hours and without unreasonably disrupting Delegated's operations.
11. Deletion and return
Customer can export its workspace at any time. After the Service ends, Delegated deletes Customer Personal Data as set out in section 13 of the Terms (the workspace after 30 days, with any backup copies deleted within a further 30 days), unless the law requires Delegated to keep it. Customer may ask for earlier deletion.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where Data Protection Law does not allow this. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data. If it conflicts with any Standard Contractual Clauses or Addendum that apply, those prevail.
Annex 1: Processing details
| Subject matter | Providing the Service: AI agents and the workspace they work in. |
|---|---|
| Duration | The term of Customer's plan or licence, plus the deletion period in section 11. |
| Nature and purpose | Hosting and storing workspace data; running agents that read, draft, send, post, schedule and organise on Customer's instructions; syncing with connected apps; sending notifications; support and security. |
| Data subjects | Customer's workspace owner and members; Customer's own customers, leads, prospects, suppliers and contacts; people who correspond with Customer's inbox; other people whose data Customer or its agents bring into the workspace. |
| Types of personal data | Names and contact details; email, message and chat content; calendar entries; social media, advertising and website data; CRM and lead data; accounting and transaction records Customer connects; files and documents; usage and audit logs. Customer should not bring special category data into the Service unless it has a lawful basis and appropriate safeguards. |
| Frequency | Continuous while the Service is used. |
Annex 2: Security measures
- Isolation: each cloud workspace runs on its own server, not shared with other customers' workspaces.
- Encryption in transit: HTTPS/TLS for the console, apps and APIs. The phone app's link to a desktop computer is end-to-end encrypted.
- Access control: each workspace has its own access tokens; owner-only controls for settings, connections and exports; role-based member permissions; approvals before sensitive agent actions.
- Credential handling: connection credentials are held on the workspace server or in our backend and are not sent to browsers or phones; Claude sign-ins stay inside Anthropic's own software.
- Least privilege for agents: each agent only receives the tools and apps its role needs; owner permissions are enforced outside the AI model.
- Logging: an audit log of agent tool use is kept in the workspace and visible to the owner.
- Operations: access to production systems is limited to authorised personnel; workspace servers receive security updates through regular image updates; suspected incidents are investigated and handled under section 7.
Annex 3: Sub-processors
Delegated's own apps (Anjal, PandaQueue, PandaCrawl) are not listed: they are operated by Delegated itself. Their own sub-processors are included in the table above (for example, Amazon SES and ZeptoMail for sending email from workspace inboxes). AI Providers and apps Customer connects are Customer's own choice and are not sub-processors (section 1).
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud workspace servers; hosting of our website | Germany |
| Convex, Inc. | Account, workspace and connection records; backend | United States |
| Cloudflare, Inc. | Network connections to workspaces; storing email attachments in workspace inboxes (Anjal) | United States / global network |
| Stripe Payments UK Ltd | Billing | United Kingdom / United States |
| Resend (Plus Five Five, Inc.) | Service and notification emails | United States |
| Composio, Inc. | Brokering some app connections (for example Gmail and Google Calendar) on cloud workspaces | United States |
| Apple Inc. | Delivering phone notifications (title and short text only) | United States |
| Functional Software, Inc. (Sentry) | Desktop app crash and error reports | United States |
| AI model provider for the setup guide (named to Customer on request) | The setup guide before Customer's own AI plan is connected (the setup conversation and the business profile it saves). After that, Customer's agents use the AI plan Customer connects | Provider's regions |
| Amazon Web Services, Inc. (Amazon SES) | Sending email from workspace inboxes (Anjal) | United States |
| Zoho Corporation (ZeptoMail) | Sending email from workspace inboxes (Anjal) | Provider's regions |
| TypeSafe | Sorting incoming email in workspace inboxes (Anjal) | Provider's regions |
| Retell AI, Inc. and Twilio Inc. | Voice calls, only if Customer adds the AI Receptionist | United States |
| Recall.ai, Inc. and AssemblyAI, Inc. | Meeting recording and transcription, only if Customer turns on meeting notes | United States |