Trust
Data Processing Agreement
What our DPA covers, and how to get a copy for signature. Last updated 21 August 2026.
Where Automentic processes personal data on your behalf, you are the controller and we are the processor. Our Data Processing Agreement sets out what we may do with that data, what we must do to protect it, and what happens when the relationship ends. It forms part of your master agreement with us.
What the DPA covers
Subject matter and duration. Processing lasts for the term of your subscription, plus a defined deletion window afterwards.
Nature and purpose. Providing the Automentic platform: issuing and validating agent identities, executing the workflows you configure, signing actions, and maintaining the audit trail those actions produce.
Categories of data subject. Typically your employees and contractors who authorise or supervise agent activity, plus any data subjects appearing in the records your workflows touch.
Categories of personal data. Identity and authentication data such as user identifiers, group membership and certificate subjects; audit metadata such as who authorised which action and when; and whatever personal data appears in the systems your workflows are pointed at.
Our commitments under it
- Process personal data only on your documented instructions.
- Bind everyone with access to a duty of confidentiality.
- Apply appropriate technical and organisational measures under Article 32, including encryption in transit and at rest, least-privilege access, and an immutable audit trail.
- Engage sub-processors only under written terms no less protective, with advance notice of changes and a right for you to object. The current list is on our Sub-processors page.
- Assist you with data subject requests, with data protection impact assessments, and with consultations with a supervisory authority.
- Notify you without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the relationship, subject to any retention required by law.
- Make available the information needed to demonstrate compliance, and allow audits on the terms set out in the agreement.
International transfers
Where a transfer of Customer Content is a restricted transfer under the EU GDPR or the UK GDPR — including any transfer from the EEA or the United Kingdom to Automentic in Australia, which is not the subject of an adequacy decision — the signed DPA incorporates:
- The European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (controller to processor) for transfers from the customer to Automentic, and Module Three (processor to processor) for transfers from Automentic to a sub-processor in a third country; and
- The UK International Data Transfer Addendum to those Clauses, for transfers subject to the UK GDPR.
Automentic completes a transfer risk assessment before a restricted transfer begins. Where a sub-processor is certified under the EU–US Data Privacy Framework, that certification is an additional safeguard. It does not replace the Clauses.
The executed Clauses and Addendum are attached to the DPA sent for signature. This page is a description of those instruments, not a substitute for them.
Data residency
The production default is Australia. Region pinning, same-region audit storage, VPC and on-premises are scoped on Enterprise. We will confirm the region in the order form before any customer data is processed.
How to get a copy
Email legal@automentic.com with your legal entity name and the region you operate in, and we will send the current DPA for signature. If your organisation requires its own paper, send it and we will review.
Existing customers can request the countersigned copy on file from the same address.
Related
See our Privacy Policy for data we handle as controller, and our Terms of Service for the terms governing this website.
Request the DPA
Send your legal entity name and operating region to legal@automentic.com.