Data Processing Addendum
Last updated: 2026-09-09
This Data Processing Addendum (‘DPA’) supplements the Terms of Service and governs Claws.io processing of Personal Data on your behalf when you use the Service.
1. Roles
You are the Controller. Claws is the Processor. Where you determine the purpose and means of processing message content, prompts, and plugin outputs your agents produce, Claws processes it only on your documented instructions.
2. Scope
Claws processes Personal Data solely to (a) run the Service, (b) bill accurately, (c) prevent abuse, and (d) comply with law.
3. Sub-processors
We rely on the following sub-processors. We will give you 14 days notice before adding a new one.
- MongoDB Atlas — primary application database. Region: EU.
- Hetzner Online GmbH — container hosting. Region: DE.
- Stripe — payments processor. Region: US/EU.
- Vercel — web/app hosting. Region: global edge.
- Model providers — OpenAI, Anthropic, Google, and other providers selected in your agent config. Data sent to a provider is governed by that provider’s terms.
- Mail provider — transactional email (verification, invoice).
4. International transfers
Where personal data is transferred out of the UK/EEA (e.g. to a US sub-processor), Claws relies on Standard Contractual Clauses and the UK IDTA. A copy is available on request.
5. Security measures
- TLS 1.3 in transit; encryption at rest for secrets and tokens.
- Per-workspace key isolation.
- Least-privilege team access with quarterly review.
- Append-only audit log for admin actions.
- Backups: daily, 30-day retention, tested restore quarterly.
- Vulnerability scans on push; dependency alerts monitored.
6. Incident notification
Claws will notify affected customers of a personal-data breach without undue delay and within 72 hours of confirmed detection. Notifications go to the account owner’s email on file.
7. Data subject requests
If a data subject contacts Claws directly with a request about data we hold on your behalf, we will forward it to you and assist with response within a reasonable time frame.
8. Audits
On reasonable request and under NDA, we will provide our current security and sub-processor documentation. On-site audits by mutual agreement and at the requester’s cost.
9. Return or deletion on termination
On termination you can export your data from the dashboard or request an export by email. 30 days after termination, remaining Personal Data is deleted from primary storage; backups age out within 30 further days.
10. Contact
Data protection: privacy@claws.io.
See also: Terms · Privacy · Data Processing Addendum