Version 2026-09-08. In force from 8 September 2026.
LegalData processing agreement
When a customer uses Carth to handle personal data about other people, this document sets out what Carthagent may do with that data, what we must do to protect it, and what the customer can require of us. It forms part of the terms of service.
- 1. Status of this agreement
- 2. Definitions
- 3. Roles of the parties
- 4. Details of the processing
- 5. Our obligations as processor
- 6. Customer obligations
- 7. Subprocessors
- 8. International transfers
- 9. Personal data breach
- 10. Audits and information
- 11. Return and deletion of data
- 12. Liability
- 13. Signature
1. Status of this agreement
This data processing agreement forms part of the terms of service between the customer and Carthagent. It applies automatically, with no separate signature required, from the moment the customer processes any personal data in Carth. If the customer never puts personal data into their cockpit, this document simply has nothing to bite on.
Where a customer needs a signed counterpart, for example to satisfy their own compliance process, we will sign one. Section 13 is the block for that.
If anything in this document conflicts with the terms of service on a question about personal data, this document wins. On every other question the terms of service win.
2. Definitions
- Data protection law means the laws on the protection of personal data that apply to the processing, including the EU General Data Protection Regulation and the UK version of it, applicable Canadian federal and provincial privacy law, and Tunisian data protection law.
- Personal data, processing, controller, processor, data subject and personal data breach have the meanings given in the GDPR.
- Customer personal data means personal data contained in customer content inside the customer's Carth cockpit, which Carthagent processes on the customer's behalf.
- Subprocessor means a third party engaged by Carthagent to process customer personal data.
- Services means Carth as described in the terms of service.
3. Roles of the parties
For customer personal data, the customer is the controller and Carthagent is the processor. The customer decides what data goes into the cockpit, what missions are run against it and what happens to the output. We process it only to provide the services.
Where the customer is itself a processor for someone else, for example an agency handling data belonging to its own clients, Carthagent is a subprocessor. In that case the customer confirms that it has the authority from its own controller to appoint us, and references in this document to the customer's instructions mean instructions that are consistent with that controller's instructions.
Carthagent is a separate controller for the account, billing, application and technical data described in the privacy policy. That data is outside the scope of this document.
The Enterprise plan is different. A Enterprise deployment runs inside the customer's own infrastructure, with the customer's own AI provider keys. In that arrangement customer personal data normally stays entirely within the customer's environment and Carthagent may process little or none of it. Where we do process any, for example during an agreed support session or a remote installation, this document applies to that processing and to nothing more. The specific scope for a Enterprise deployment is recorded in the written agreement for it.
4. Details of the processing
This table is the record required by Article 28(3) of the GDPR. Because the customer chooses what to bring into their cockpit, some rows describe categories rather than a fixed list.
| Item | Detail |
|---|---|
| Subject matter | Provision of Carth, a cockpit in which AI agents run supervised missions on the customer's content under human approval gates. |
| Duration | For as long as the customer's subscription is in force, plus the retention and backup windows described in section 11. |
| Nature and purpose | Hosting, storage, transmission, retrieval and analysis of customer content so that missions can run; sending the necessary content to AI model providers to generate output; producing evidence for review; recording approvals; backing up; and providing support the customer requests. |
| Types of personal data | Determined by the customer. Typically identification and contact details, employment and role information, business records such as orders, invoices and correspondence, content of documents and messages the customer brings in, and any personal data present in code, databases or files connected to the cockpit. |
| Special category data | Not expected and not required by the services. The customer should not put special category or criminal offence data into Carth without telling us first and agreeing any additional measures in writing. |
| Categories of data subjects | Determined by the customer. Typically the customer's employees and contractors, its clients and their staff, its suppliers, and individuals appearing in records the customer processes. |
| Frequency | Continuous for the duration of the subscription. |
5. Our obligations as processor
Documented instructions
We process customer personal data only on the customer's documented instructions. The terms of service, this document and the customer's use of the services, including the missions they brief and the settings they choose, constitute those instructions. We will not process customer personal data for our own purposes, and we will not use it to train models. If we are required by law to process it beyond the customer's instructions, we will tell the customer first unless the law forbids that notice. If we believe an instruction breaches data protection law, we will tell the customer and may pause that processing until it is resolved.
Confidentiality
Access to customer personal data is limited to the people who genuinely need it to run or support the service. Everyone with such access, whether employee or contractor, is bound by a written confidentiality obligation that survives the end of their engagement, and is briefed on how this data must be handled.
Security
We implement appropriate technical and organisational measures to protect customer personal data, taking account of the state of the art, the cost of implementation, and the risk to the people whose data it is. In practice these include a private container per customer company, encrypted storage volumes, encryption of data in transit, per user access that the customer's Admin can revoke immediately, server side enforcement of role based rights, secret storage for provider keys and credentials, an audit trail of approvals and significant actions, backups, and internal review of changes before release. We may improve or replace a measure, but we will not reduce the overall level of protection.
We hold no security certification or third party audit report today, and we will not claim one. We answer security questionnaires honestly and in writing, and for customers whose requirements cannot be met by a hosted service we offer the Enterprise plan.
Assistance with data subject requests
The services give the customer's Admin the ability to access, correct, export and delete content in their own cockpit, which is normally enough to answer a data subject request without our involvement. Where it is not, we assist the customer with appropriate technical and organisational measures, so far as is reasonably possible. If a data subject contacts us directly about customer personal data, we will not answer the substance ourselves; we will forward the request to the customer without undue delay and tell the data subject we have done so.
Assistance with assessments and consultations
Taking into account the nature of the processing and the information available to us, we assist the customer with data protection impact assessments and any prior consultation with a supervisory authority that follows from them, and with the customer's own obligations to keep the processing secure and to notify breaches.
6. Customer obligations
- The customer is responsible for the lawfulness of the personal data it brings into Carth, including having a valid lawful basis, giving the required privacy notices, and obtaining consent where consent is the basis.
- The customer's instructions must comply with data protection law, and the customer must not require processing that would put Carthagent in breach of it.
- The customer decides who holds which role and therefore who can see what. Assigning roles carelessly is a customer side risk that no measure of ours can correct.
- The customer should avoid putting personal data into a cockpit where the mission does not need it, and should prefer redacted or minimised data where that works.
- The customer must not put special category data, criminal offence data or data about children into Carth without agreeing it with us in writing first.
7. Subprocessors
The customer gives Carthagent a general authorisation to engage subprocessors for the provision of the services, subject to the conditions in this section.
Every subprocessor is engaged under a written contract that imposes data protection obligations no less protective than those in this document. Carthagent remains fully liable to the customer for the performance of each subprocessor's obligations.
If we intend to add or replace a subprocessor, we will give the customer at least thirty days notice by email to the account Admin and on this page. The customer may object on reasonable data protection grounds within that period. We will then work with the customer in good faith to find a solution, for example a different vendor, a different region or a configuration change. If no reasonable solution can be found, the customer may terminate the affected part of the services without penalty and receive a refund of the unused portion of any prepaid fees.
The current subprocessors are set out below. The rows marked in square brackets are placeholders that will be replaced with named vendors before launch.
| Subprocessor | Purpose | Location of processing |
|---|---|---|
| a European cloud hosting provider | Hosting of the customer's private container and its encrypted volume, and storage of backups | European Union or Canada, per the customer's choice at onboarding, European Union by default |
| the payment provider, announced before the first invoice is issued | Processing of subscription payments and issuing of receipts and invoices | The provider's own region, named in the list available on request |
| a transactional email provider | Delivery of service messages such as invitations, renewal notices and security alerts | The provider's own region, named in the list available on request |
| the AI model providers the customer enables (Anthropic and OpenAI today) | Running the models that agents use to carry out missions, under terms that prohibit training on customer content. Not used on the Enterprise plan, where the customer uses their own provider account. | The provider's own region, named in the list available on request |
| operational tooling providers, none of which receives customer content | Collection of crash reports, logs and operational telemetry so that faults can be diagnosed | The provider's own region, named in the list available on request |
The definitive, named list is provided in writing on request before signature, and we will not ask a customer to sign this document without giving them the real names first. Write to apply@carthagent.com and ask for the current subprocessor list, and to be added to the notification list for changes.
8. International transfers
Customer cockpits are hosted in the European Union or in Canada, at the customer's choice, and backups stay in the same region as the cockpit they belong to. Where the customer chooses Canada, transfers from the European Economic Area rely on the European Commission's adequacy decision for Canada in respect of organisations subject to it, and on the safeguards below where that decision does not cover a particular transfer.
Carthagent is established in Tunisia, and some subprocessors operate elsewhere, so a transfer of customer personal data outside the European Economic Area may occur, in particular for administration, support and the AI model providers.
For any such transfer to a country without an adequacy decision, the parties rely on the European Commission's standard contractual clauses, module two or module three as the case requires, which will be incorporated into this document by reference and completed with the details in section 4, the subprocessor list in section 7 and the security measures in section 5. Where the UK GDPR applies, the UK International Data Transfer Addendum where data from the United Kingdom is concerned applies alongside them. We carry out a transfer risk assessment where one is required and provide it to the customer on request.
9. Personal data breach
If we become aware of a personal data breach affecting customer personal data, we will notify the customer without undue delay and in any event no later than 72 hours after becoming aware of it. We will not wait until the investigation is complete to make first contact; we would rather send an incomplete notice quickly and follow it with detail.
The notification will describe, to the extent known at the time:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- when it happened and when we became aware of it;
- the likely consequences;
- the measures taken or proposed to address it and to limit any harm;
- a contact point at Carthagent for further information.
Where we cannot provide all of this at once, we provide it in phases without further undue delay. We will keep a record of the breach and of our response, and we will assist the customer with their own notifications to supervisory authorities and to data subjects, including by providing the information they need to make them within their own deadlines. We will not notify a supervisory authority or a data subject on the customer's behalf unless the customer asks us to in writing, or the law obliges us directly.
Report a suspected breach to us at apply@carthagent.com with "security" in the subject line.
10. Audits and information
We make available to the customer the information necessary to demonstrate compliance with the obligations in this document, and we allow for and contribute to audits and inspections conducted by the customer or an auditor they mandate.
In the ordinary course, this obligation is satisfied by written information: our documentation, a completed security questionnaire, a description of our technical and organisational measures, and answers to specific questions. We prefer this route because it gives the customer more useful detail than a site visit would.
If written information is genuinely not enough, the customer may conduct an audit on these conditions: at least thirty days written notice, during normal business hours, without unreasonable disruption to our operations, limited to information relevant to the processing of that customer's personal data, and subject to confidentiality. The auditor must not be a competitor of Carthagent. Such an audit may take place at most once in any twelve month period, except where a personal data breach has occurred, where a supervisory authority requires it, or where a previous audit found a material deficiency that needs verification. The customer bears the cost of its own audit, and we bear our own reasonable participation costs unless the audit is repeated within the same year at the customer's request.
11. Return and deletion of data
At the end of the provision of the services, the customer chooses whether we return or delete customer personal data. Both are available, and the choice is the customer's, not ours.
- Export. For thirty (30) days after termination, the customer may request an export of their content, which we provide in a common machine readable format at no charge. The customer can also export from the cockpit at any time while the account is live.
- Deletion of the live copy. After the export window closes, or immediately on the customer's written request, we delete the customer's workspace, its encrypted volume and the customer personal data in it, and we instruct our subprocessors to do the same.
- Backups. Deleted data may remain in encrypted backups until those backups expire on their normal rotation, which is at most 7 days on Enterprise and shorter on every plan below it. The cockpit's own plan page states the number your plan keeps. During that period the data is not restored to the live service except to recover from a failure, access is limited to the staff who run the recovery, and it remains subject to this document until it is gone.
- Confirmation. We confirm deletion in writing on request.
We may retain customer personal data where the law requires it, for as long as the law requires and for that purpose alone. Deletion is not reversible, so a customer who is unsure should export first.
12. Liability
Each party's liability under or in connection with this document is subject to the exclusions and the aggregate cap set out in section 14 of the terms of service. This document does not create a separate or additional cap, and the caps are not multiplied by the number of documents or claims. Nothing in this section limits any liability that data protection law does not permit to be limited, including a data subject's rights to compensation directly against a controller or a processor.
13. Signature
This document takes effect without signature as part of the terms of service. Where a customer requires an executed counterpart, the block below is completed and signed by both parties, and the details in it prevail over the general description in section 4 for that customer.
| Party | Details to complete |
|---|---|
| Customer, as controller | [customer legal name], [customer registered address], [customer registration number]. Signed by [name and title of signatory] on [date of signature]. |
| Carthagent, as processor | Carthagent, registered in Tunisia, based in Tunis, Tunisia, with a presence in San Francisco, California, registration details available on request. Signed by [name and title of signatory] on [date of signature]. |
| Attachments | the European Commission's standard contractual clauses, module two or module three as the case requires, where required, and the named subprocessor list current at the date of signature. |
To request a signed counterpart, the current subprocessor list, or a completed security questionnaire, write to apply@carthagent.com.