1. What this agreement covers
This data processing agreement is part of the agreement between you and {{LEGAL_ENTITY}}, registered at {{REGISTERED_ADDRESS}}. It applies whenever we process personal data on your behalf so that we can provide the Service described in the Terms of Service. The words controller, processor, sub-processor, personal data and processing carry the meaning that data protection law gives them.
It lasts as long as your subscription, and for as long after it as we still hold personal data for you. Section 11 says what happens to that data at the end.
2. Roles
You are the controller of the personal data in your workspace, and Collabre is the processor. Where you handle personal data for a client of your own, you are the processor and Collabre is a sub-processor, and every commitment below applies to us in the same way.
You decide which personal data enters the workspace, which platforms and tools it reaches, and who in your organization can open it. You are responsible for having a legal basis for that data and for the notices you give the people it describes.
3. Subject matter, nature, purpose and duration
We process personal data to run the product: to hold Campaigns, briefs, content, approvals, media and reports, to publish to the channels you connect, to answer the AI requests your workspace makes, to send the email the product sends on your behalf, and to support you when you ask.
The categories of personal data are the ones in section 2 of the Privacy Policy. The people they describe are your workspace members, your clients and the people your content is about or addressed to.
4. Your instructions
We process personal data only on your documented instructions. Those instructions are this agreement, the Terms of Service, and the choices you make in the product. We follow an instruction that goes beyond them only when we have agreed to it in writing, or when the law requires it, in which case we tell you first unless the law forbids that. We tell you if an instruction looks to us like a breach of data protection law.
5. Confidentiality
Everyone we let near personal data is bound to keep it confidential, by contract or by a professional duty, and reaches it only as far as their work requires.
6. Security measures
We keep the following measures in place. The security page lists each one with the module that implements it.
- Credentials. Platform access tokens, integration credentials and two-factor secrets are encrypted with AES-256-GCM before they are written to the database. Each record carries its own salt and initialization vector, and the key comes from an environment variable that every deployed environment has to set. The API refuses to start in a deployed environment when that variable is missing.
- Transport. The API sets the standard security headers, including strict transport security.
- Files. Files are stored in S3-compatible object storage that the deployment configures. The endpoint, the bucket and the credentials are required environment variables, so there is no quiet fallback to a local disk.
- Sign-in. Passwords are stored as bcrypt hashes. A magic link is stored only as a hash, works once and expires. Two-factor authentication uses one-time codes from an authenticator app, and the recovery codes are stored as hashes and each works once.
- Access. Roles at the workspace, space, team, Campaign, Content Slot and approval level decide who can open and change what. Collabre support reaches a workspace only when the workspace grants it, read-only by default and always with an end date, and both the grant and the revocation are written to the audit log.
- Audit. Each workspace has one searchable log of who did what, and the detail of every entry is run through a redactor before it is written, so personal data does not land in the log.
- AI governance. Spending caps apply per Agent run, per Agent per day and per workspace per month. Kill switches halt one Agent or every Agent at once. Tool rules allow, deny or require confirmation, and when no rule matches a tool call the answer is to ask a person. Redaction of personal data in Agent inputs and logs is on by default.
7. Sub-processors
You give a general authorization for the sub-processors listed on the subprocessors page, which names each vendor, what it is used for, the data it receives and the region it processes in. We put written terms in place with each of them that are no less protective than this agreement, and we stay responsible to you for what they do.
Before a new sub-processor starts to process personal data for you, we add it to that page and tell the workspace owner by email. If you object on reasonable data protection grounds, write to [email protected] before the change takes effect and we will look for an alternative. If we cannot find one, you may stop using the part of the Service that needs that sub-processor and end the affected subscription, and we refund the part of your prepaid fees you have not used.
8. People who exercise their rights
The product answers most requests on its own: workspace data exports to CSV and PDF, roles show who can reach what, and the audit log shows what was done. Where a request needs more than that, write to [email protected] and we help you answer it, taking account of what we process and what we know. We pass a request that reaches us directly back to you rather than answering it ourselves, unless the law says otherwise.
9. Personal data breaches
We tell you without undue delay after we become aware of a breach of security that leads to the destruction, loss, alteration or unauthorized disclosure of the personal data we process for you. We tell you what we know about it, what we think the effect is, and what we are doing, and we keep you posted as we learn more.
10. International transfers
Personal data is processed in the countries where we and our sub-processors operate, which the subprocessors page names. Where data leaves the European Economic Area, the United Kingdom or Switzerland and the destination has no adequacy decision, we rely on the Standard Contractual Clauses approved by the European Commission and on the equivalent United Kingdom transfer mechanism, together with the measures in section 6.
11. Return and deletion
While your subscription runs, you can export your workspace data from the product at any time. When it ends, and after any export window we have agreed with you, we delete the personal data we hold for you from production systems, and the copies held in encrypted backups age out after that. We keep what the law requires us to keep, and nothing else. We confirm a deletion in writing when you ask for it.
12. Audits and information
We give you the information you reasonably need to show that we meet this agreement, including the security detail on the security page and the subprocessor list. Where that is not enough for an audit your regulator requires, write to [email protected] and we agree the scope, the timing and the cost with you in advance, so that the audit does not disturb other customers.
13. Precedence and changes
Where this agreement and the Terms of Service disagree about the processing of personal data, this agreement wins. We update it when the product or the law changes, and the version and the date at the foot of this page describe the copy you are reading. When a change matters to you, we tell you before it takes effect.
14. Contact
- {{LEGAL_ENTITY}}
- {{REGISTERED_ADDRESS}}
- Data protection: [email protected]
- Legal: [email protected]