1. Roles
For personal data your agents process on your instructions, you are the controller and we are the processor. For data about your own account — the email you signed up with, billing records, our security logs — we are the controller and our Privacy Policy applies.
In plain terms: you decide what your agents look at and why. We run the machinery and do not decide the purpose.
2. Scope of processing
- Subject matter: providing the Founders Office and any build services you engaged us for.
- Duration: for as long as your account is open, plus the deletion window in section 9.
- Nature and purpose: storing your configuration; executing scheduled and manual agent runs; transmitting content to the model providers and tools you connected; storing what an agent reports back.
- Types of personal data: whatever is present in the systems you connect and the instructions you write. You choose this. We do not require any particular category.
- Categories of data subject: determined by you — typically your staff, customers or contacts.
3. Our obligations
- Process personal data only on your documented instructions. Configuring an agent and running it is an instruction. If we believe an instruction breaks applicable data protection law, we will tell you.
- Ensure people with access are bound by confidentiality.
- Implement the security measures in section 4.
- Not sell personal data, and not use it to train models.
- Assist you, at your cost where the effort is substantial, with data subject requests, impact assessments, and consultations with a supervisory authority.
- Make available the information reasonably needed to demonstrate compliance, and allow an audit no more than once a year on 30 days' notice, subject to confidentiality and not disrupting other customers.
4. Security measures
These are the measures actually in place, not a wishlist:
- Credentials: encrypted at rest with AES-256-GCM under a per-connection data key wrapped by a master key held outside the database. Decrypted only into a single run, at the last possible moment. Never logged, rendered or written to a transcript.
- Execution isolation: each agent run executes in its own hardened container as a non-root user, with a read-only root filesystem, no added Linux capabilities, and no-new-privileges set. Secrets are passed on stdin, never in the command line or the environment where another process could read them. An agent granted no tools gets no network at all.
- Least privilege: an agent reaches a connection only when you granted it, and writes through it only when you granted write access separately. Absence of a grant is a denial.
- Network isolation: agent containers are firewalled in the kernel from all private address space — our internal network, other services on the host, and the cloud metadata endpoint — so a compromised agent cannot reach our infrastructure even if it bypasses its own tooling.
- Tenant separation: every query is scoped to your organisation by a guard that resolves the tenant from your session — never from a value a request supplies.
- Authentication: passwords hashed with bcrypt; optional Google sign-in; signed, encrypted session cookies.
- Transport: TLS on everything we serve.
- Auditability: an append-only event log records who did what, when, and on whose authority — including actions taken by agents.
Security is a moving target. We may change a specific measure, but not in a way that materially reduces overall protection.
5. Subprocessors
You give general authorisation for us to use the subprocessors listed at nyza.us/subprocessors. Each is bound by data protection terms no less protective than these, and we remain responsible for their performance.
We will give notice before adding a new subprocessor to customers who ask to be on that list. You may object on reasonable data-protection grounds within 14 days; if we cannot resolve it, you may terminate the affected part of the service without penalty.
Model providers and tools you connect are not our subprocessors — they are your own processors, under your agreement with them.
6. International transfers
We process data in the United States. If you are in the EEA, UK or Switzerland and transfer personal data to us, that transfer relies on the European Commission's Standard Contractual Clauses, which are incorporated into this addendum by reference (module two, controller to processor), with the UK Addendum and the Swiss amendments applying where relevant. This page and the subprocessor list supply the details their annexes require.
7. Personal data breaches
We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data. The notice will describe what happened, the categories and approximate volume affected, the likely consequences, and what we are doing about it — and will be updated as we learn more rather than delayed until it is complete.
8. Data subject requests
If someone contacts us directly about data we process for you, we will not respond substantively. We will pass the request to you promptly and help you answer it. Your administrators can already export and delete data directly in the product.
9. Deletion and return
You can export or delete your data at any time while your account is open. When it closes, agents stop, scheduled runs stop, and stored credentials are deleted. Remaining personal data is deleted or anonymised within 30 days, except where law requires us to retain it — in which case it stays protected by this addendum for as long as we hold it.
10. Liability and precedence
Each party's liability under this addendum is subject to the limitations in the Terms of Service. If this addendum conflicts with those terms on the subject of data protection, this addendum wins.
11. Signing this
Accepting the Terms of Service accepts this addendum. If your procurement process needs a countersigned copy, a security questionnaire completed, or your own DPA reviewed, email hardiktrehan@nyza.us. A person answers, not a form.
Nyza Creations LLC
Bremerton, WA, USA