This Data Processing Agreement ("DPA") applies where you use Escape Velocity as a business or organization and the content you bring to the platform includes personal data. It forms part of our
Terms of Service and describes how Escape Velocity AI, Inc. processes that content on your behalf. You are the controller of it; we are the processor. Our
Privacy Policy covers the separate personal data we control in our own right, such as your account, billing, and usage information. If a term here conflicts with the Terms of Service on a question of data protection, this DPA governs.
1. What This Covers, and What It Does Not
This DPA covers "Customer Content": the prompts, context, files, work product, and other material you or your users bring to the platform or direct us to retrieve, to the extent it contains personal data. You decide what to bring, what agents to run on it, and which third-party tools to connect. We process it to provide the platform to you, and for nothing else.
It does not cover the personal data we control in our own right, which is governed by our
Privacy Policy. That is your account and profile information, your billing records, and the usage and telemetry we generate to operate, secure, meter, and bill the service. We are the controller of that data, not your processor, and this DPA does not change that.
It also does not cover a service you connect yourself. When you connect Slack, GitHub, Notion, Linear, or any other tool, you authorize an exchange of data between Escape Velocity and a system you control, and that service acts under its own terms and its own agreement with you. Those services are not our subprocessors, and we are not the processor of what they do with the data once it reaches them. See
Subprocessors for the distinction.
2. Details of the Processing
Subject matter and duration: processing of Customer Content for the term of your agreement with us, plus the short deletion window described in section 8.
Nature and purpose: hosting, storing, transmitting, and processing Customer Content so that the platform and the agents you direct can carry out the work you ask for, including sending the material you direct us to send to the model providers listed in
Subprocessors for inference and returning the generated output to you.
Categories of data subjects: your personnel and users, and any individual whose personal data you choose to bring to the platform, including your own customers, prospects, research participants, or contacts, depending on how you use it.
Categories of personal data: whatever you choose to include. Because you control the inputs, we cannot enumerate the categories in advance. We do not require special category data, and the platform is not designed or offered as a system of record for it. Do not bring health, biometric, genetic, precise geolocation, government identifier, payment card, or children's data to the platform, or any data whose processing is regulated by a scheme we have not agreed to in writing, such as HIPAA, PCI DSS, or FedRAMP.
3. Our Obligations, and Your Instructions
We process Customer Content only on your documented instructions. Your instructions are this DPA, the Terms of Service, and the configuration choices, agent directions, connections, and permissions you set in the product. Using the platform as intended is an instruction to process accordingly.
We will not process Customer Content for our own purposes. If we are ever required by law to process it beyond your instructions, we will inform you before doing so unless the law prohibits that notice.
You are responsible for the lawfulness of the personal data you bring: that you have a legal basis for it, that you have given any notices and obtained any consents required, and that your instructions to us comply with applicable data protection law. We will tell you if, in our view, an instruction infringes applicable law.
4. We Do Not Train On Your Content
Customer Content is not training data. We do not use it to train, fine-tune, or improve foundation models, and we do not use it to train any model of our own unless you affirmatively allow it. This is a binding term of this DPA, not only a statement of intent.
We route Customer Content to the model providers listed in
Subprocessors under commercial terms that do not train on it by default. Those providers retain content briefly for their own abuse-monitoring purposes under provider-set windows, which they can change; the current windows are described in our
Privacy Policy.
This is separate from the usage and telemetry data we control, which we may use to operate and improve the platform as described in our
Privacy Policy. The boundary is content versus usage: your material is yours, and how the product performs is ours.
5. Confidentiality and Personnel
We keep Customer Content confidential. Access is limited to personnel who need it to provide, secure, or support the platform, or to comply with law, and those people are bound by confidentiality obligations that survive the end of their engagement.
We do not review Customer Content as a matter of course. We may access it to investigate a specific security incident, to respond to a support request you make, to act on a legal or governmental demand, or to address a credible report of abuse or illegal content.
6. Security
We implement technical and organizational measures appropriate to the risk, taking account of the state of the art and the nature of the processing. These include encryption of Customer Content in transit and at rest, authentication and role-based access control with least-privilege access for personnel, network isolation of our infrastructure, logging and monitoring of access and system activity, encrypted storage of the third-party credentials you entrust to us, separation of environments, and change control over the code and infrastructure that handle Customer Content.
Security is a moving target, so we may change specific measures over time. We will not reduce the overall level of protection during your term.
You are responsible for the parts of security you hold: keeping your account credentials and API keys secret, managing who in your organization has access, setting agent permissions and budgets deliberately, and choosing which third-party tools to connect and what scopes to grant them.
7. Subprocessors
You authorize us to engage the subprocessors listed at
Subprocessors, which is incorporated into this DPA and kept current. That page names each one, what it does, the categories of data it handles, and where it operates.
We impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain responsible to you for their performance.
When we intend to add or replace a subprocessor, we will update that page and give you notice before it begins processing Customer Content, so you have a chance to review the change. If you have a reasonable, data-protection-based objection, tell us and we will work with you in good faith; if we cannot resolve it, you may stop using the affected part of the platform and terminate the affected subscription, with the unused paid credit balance refunded as described in our
Credit Terms.
8. Deletion and Return
You can export Customer Content at any time during your term and for thirty days after you close your account, in a common machine-readable format, as described in
Your Data: Export and Deletion.
On termination, or on your written request, we will delete Customer Content, and instruct our subprocessors to do the same, within the period described in that page. We may retain a limited set of records where the law requires it, or in de-identified form that can no longer be linked to an individual, and anything retained stays subject to the confidentiality and security terms of this DPA for as long as we hold it.
These commitments do not apply where we must act on illegal content, a legal or governmental demand, a security or safety risk, or abuse, in which case we may retain or preserve content and may be unable to provide an export.
9. Assisting You With Data Subject Requests
Because you control Customer Content, requests from individuals about it come to you, not to us. The product gives you direct access to that content so you can find, correct, export, or delete it yourself, which is usually the fastest route.
Where you cannot fulfill a request through the product, we will assist you with reasonable and timely measures, taking account of the nature of the processing. If an individual contacts us directly about content that is yours, we will not respond substantively; we will refer them to you and tell you promptly. Reach us at
privacy@escapev.ai.
10. Incidents, Impact Assessments, and Consultation
If we become aware of a personal data breach affecting Customer Content, we will notify you without undue delay after becoming aware of it, and provide the information reasonably available to us so that you can meet your own notification obligations: what happened, the categories and approximate volume of data and individuals affected, the likely consequences, and the measures we have taken or propose to take. We will keep you updated as we learn more. Our notice is not an admission of fault. Make sure the contact details on your account are current, and send security reports to
privacy@escapev.ai.
We will provide reasonable assistance with a data protection impact assessment or a prior consultation with a supervisory authority, to the extent it relates to our processing of Customer Content and the information is not otherwise available to you.
11. Information and Audit
On reasonable request, we will make available the information necessary to demonstrate our compliance with this DPA, ordinarily by responding to a security questionnaire and providing the documentation we maintain about our security measures. We hold no third-party security certification or audit report today, and we will not imply otherwise; if that changes we will make the report available in place of a questionnaire.
Where applicable law entitles you to an audit or inspection beyond that, we will agree the scope, timing, and cost with you in advance. An audit must be at your expense, on reasonable prior notice, no more than once a year absent a specific incident, subject to confidentiality, and conducted so that it does not compromise the security or availability of the platform or the confidentiality of other customers' data.
12. International Transfers
We operate in the United States, and our subprocessors process in the United States, as recorded at
Subprocessors. If you are in the United Kingdom, the European Economic Area, or Switzerland, providing the platform to you involves transferring Customer Content to the United States.
Where personal data protected by UK or EU data protection law is transferred to us, the transfer is made under the European Commission's Standard Contractual Clauses, Module Two (controller to processor), with the UK International Data Transfer Addendum where UK law applies, which are incorporated into this DPA by reference. Sections 2 and 7 of this DPA supply the details those clauses require about the processing and the subprocessors. Where a clause of those instruments conflicts with this DPA, the clause governs.
Some of our subprocessors are also self-certified under the EU-US, UK Extension, and Swiss-US Data Privacy Framework, and where that applies to a given transfer it operates alongside the clauses above rather than instead of them. We do not claim Data Privacy Framework coverage for subprocessors that do not hold it.
To put the transfer instruments in place for your organization, contact us at
privacy@escapev.ai and we will execute them with you.
13. California and Other US State Laws
Where the California Consumer Privacy Act applies, we act as a service provider with respect to Customer Content, and you are the business. We process it only to provide the platform to you, and for the limited purposes the statute permits. We do not sell it, and we do not share it for cross-context behavioral advertising. We do not retain, use, or disclose it outside our agreement with you, and we do not combine it with personal data from another source except as the statute permits to provide the service.
We hold to the equivalent standard, with equivalent roles, under the other US state privacy laws that use the same processor model.
14. Agents Acting on Your Behalf
The platform runs agents that act under your direction, within the permissions, budgets, schedules, and credentials you set. When an agent reads from or writes to a service you connected, it is acting as your electronic agent, and those actions are attributable to you, not to us. You remain the controller of the personal data involved, including personal data an agent retrieves from a connected service and brings onto the platform.
You are responsible for deciding what the agents you run may access and do, and for the lawfulness of processing personal data that arrives that way. We are responsible for processing it as your processor once it is on the platform, exactly as this DPA describes for any other Customer Content.
15. Term, Liability, and Changes
This DPA takes effect when you begin using the platform for content that includes personal data, and continues for as long as we process Customer Content for you. The obligations that by their nature should survive termination do, including confidentiality, security of anything retained, and deletion.
Each party's liability under this DPA is subject to the limitations and exclusions in our
Terms of Service. Nothing in this DPA limits either party's liability to a data subject, or any liability that cannot be limited under applicable law.
We may update this DPA to reflect a change in law, in our processing, or in our subprocessors. We will not make a change that materially reduces the protection of Customer Content without giving you notice first. If you need a countersigned copy for your records, or your organization requires its own paper, write to
privacy@escapev.ai.