Parties and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Knomatic (“we”, the processor) and your organization (“you”, the controller). It applies to personal data that your apps hold on the CodeMonster platform and that we process on your behalf.
For your builders’ account data and the platform’s operation records, we act as a controller under the Privacy Policy, not under this DPA.
Scope of processing
- Subject matter. Hosting and operating the apps your builders create, and the data those apps store.
- Duration. The term of the license plus the export and deletion window in the Terms of Service.
- Nature and purpose. Storing, retrieving, and processing data through the objects, forms, workflows, and screens your builders define; sending the workflow email, push, and PDF outputs you configure.
- Categories of data and data subjects. Determined by you. Your apps may hold data about employees, customers, suppliers, or members of the public. Do not load special-category data unless this DPA expressly allows it. [PLACEHOLDER: whether special-category or health data is permitted at all.]
Our obligations
We process personal data only on your documented instructions: the Terms of Service, this DPA, and the configuration your builders apply through the platform. Everyone who processes your data on our side is bound by confidentiality. We help you respond to data subject requests and, where the processing calls for it, with data protection impact assessments.
Subprocessors
Our current subprocessors, with the purpose and data categories for each, are listed on the subprocessors page. We remain responsible for their performance. We will give you [PLACEHOLDER: notice period] days’ notice before adding or replacing one, and you may object on reasonable data protection grounds within that period. [PLACEHOLDER: notice mechanism — email to account owner, page update, or both.]
Security measures
- Every authenticated request carries a bearer token validated on every call, and the agent control surface rejects an unauthenticated request with a bare 401 — no tool list, no schema, no server information. Forms you explicitly publish as public accept anonymous end-user submissions by design; those rows still land under an explicit tenant and can carry a change log.
- Authorization is enforced server-side with the calling user’s own permissions. AI agents act with your builders’ permissions, never their own.
- Object data is separated per tenant at the row level, and every data write requires an explicit tenant context.
- Every app URL is served over HTTPS; artifact storage is closed to the public.
- Deployments are recorded in an append-only log; agent edits are staged and previewable before commit; object change logs can be enabled per app.
- Apps and data run on managed cloud infrastructure we operate, built primarily on AWS.
The security overview and compliance status pages describe these controls and their attestation status. [PLACEHOLDER: encryption at rest, backup schedule, and access-control policy detail once confirmed.]
Personal data breach
If we become aware of a personal data breach affecting your data, we will notify your account owner without undue delay and no later than [PLACEHOLDER: hours] hours after becoming aware, with what we know at the time and updates as we learn more.
Audit rights
Once per year, on [PLACEHOLDER: notice period] days’ notice and under a confidentiality agreement, you or an independent auditor you appoint may audit our compliance with this DPA. Where a current third-party report answers the question, we may answer with that report. [PLACEHOLDER: which reports exist — see compliance status.]
Return and deletion
You can export your data at any time during the term through the documented API. When the license ends you have [PLACEHOLDER: export window] to export it. After that we delete it from live systems and, on request, confirm deletion in writing. [PLACEHOLDER: deletion timeline for backups.]
International transfers
[PLACEHOLDER: processing regions and the transfer mechanism, such as standard contractual clauses or an adequacy decision, for data leaving them.]
Precedence and contact
If this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails. Requests to sign this DPA go through the contact page; privacy questions go to privacy@codemonster.ai.