{
  "title": "Data Processing Agreement",
  "path": "/dpa",
  "url": "https://escapev.ai/dpa",
  "summary": "How we process the content you bring to the platform on your behalf, as your processor: instructions, security, subprocessors, transfers, and deletion.",
  "kind": "legal",
  "markdown": "https://escapev.ai/dpa.md",
  "lastUpdated": "September 29, 2026",
  "intro": "This Data Processing Agreement (\"DPA\") applies where you use Escape Velocity as a business or organization and the content you bring to the platform includes personal data. It forms part of our [Terms of Service](/terms) and describes how Escape Velocity AI, Inc. processes that content on your behalf. You are the controller of it; we are the processor. Our [Privacy Policy](/privacy) covers the separate personal data we control in our own right, such as your account, billing, and usage information. If a term here conflicts with the Terms of Service on a question of data protection, this DPA governs.",
  "sections": [
    {
      "number": 1,
      "heading": "Definitions",
      "anchor": "definitions",
      "paragraphs": [
        "\"Customer Content\" means the prompts, context, files, work product, and other material you or your users bring to the platform or direct us to retrieve, to the extent it contains personal data.",
        "\"Data Protection Law\" means every law about the processing of personal data that applies to that processing, including the EU General Data Protection Regulation (2016/679) and the UK GDPR as retained by the European Union (Withdrawal) Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the California Privacy Rights Act.",
        "\"controller,\" \"processor,\" \"personal data,\" \"special category data,\" \"processing,\" \"data subject,\" \"personal data breach,\" and \"supervisory authority\" carry the meanings Data Protection Law gives them. Where two applicable laws define a term differently, the one that applies to the processing in question governs it.",
        "\"Subprocessor\" means a processor we engage to carry out part of our processing of Customer Content. \"SCCs\" means the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, and \"UK Addendum\" means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018."
      ]
    },
    {
      "number": 2,
      "heading": "What This Covers, and What It Does Not",
      "anchor": "what-this-covers-and-what-it-does-not",
      "paragraphs": [
        "This DPA covers Customer Content. You decide what to bring, what agents to run on it, and which third-party tools to connect. We process it to provide the platform to you, and for nothing else.",
        "It does not cover the personal data we control in our own right, which is governed by our [Privacy Policy](/privacy). That is your account and profile information, your billing records, and the usage and telemetry we generate to operate, secure, meter, and bill the service. We are the controller of that data, not your processor, and this DPA does not change that.",
        "It also does not cover a service you connect yourself. When you connect Slack, GitHub, Notion, Linear, or any other tool, you authorize an exchange of data between Escape Velocity and a system you control, and that service acts under its own terms and its own agreement with you. Those services are not our subprocessors, and we are not the processor of what they do with the data once it reaches them. See [Subprocessors](/subprocessors) for the distinction."
      ]
    },
    {
      "number": 3,
      "heading": "Details of the Processing",
      "anchor": "details-of-the-processing",
      "paragraphs": [
        "Subject matter and duration: processing of Customer Content for the term of your agreement with us, plus the deletion window described in section 9.",
        "Nature and purpose: hosting, storing, transmitting, and processing Customer Content so that the platform and the agents you direct can carry out the work you ask for, including sending the material you direct us to send to the model providers listed in [Subprocessors](/subprocessors) for inference and returning the generated output to you, and, where you have agreed to it as section 6 describes, reviewing it to evaluate and improve the quality of the service.",
        "Categories of data subjects: your personnel and users, and any individual whose personal data you choose to bring to the platform, including your own customers, prospects, research participants, or contacts, depending on how you use it.",
        "Categories of personal data: whatever you choose to include. Because you control the inputs, we cannot enumerate the categories in advance. We do not require special category data, and the platform is not designed or offered as a system of record for it. Do not bring health, biometric, genetic, precise geolocation, government identifier, payment card, or children's data to the platform, or any data whose processing is regulated by a scheme we have not agreed to in writing, such as HIPAA, PCI DSS, or FedRAMP.",
        "Frequency of the processing: continuous for the term, on an on-demand basis. Customer Content is processed when you or an agent you have configured brings it to the platform or directs work on it, which may be interactive, scheduled, or triggered by an event in a service you have connected.",
        "Retention period: for the term of your agreement, plus the deletion window in section 9. You decide what to keep on the platform and for how long, and we do not shorten that of our own accord, with one exception that is part of the service you are buying rather than a decision we take separately: analytics event data is retained for twenty-four months from the event timestamp and then deleted. That limit is a documented instruction and applies to every project. It is a storage-limitation control rather than a product constraint, because analytics events describe your end users, accumulate continuously, and are the one category the platform generates in volume without anyone choosing to keep it. Aggregate event counts derived from those events survive the deletion, so your volume reporting does not disappear when the underlying events do; measures that depend on identifying individual visitors, such as unique visitors, cannot be preserved in an aggregate and are not available for periods older than the retention window. Where a Subprocessor applies its own retention window to material we route to it, that window is recorded in our [Privacy Policy](/privacy)."
      ]
    },
    {
      "number": 4,
      "heading": "Our Obligations, and Your Instructions",
      "anchor": "our-obligations-and-your-instructions",
      "paragraphs": [
        "We process Customer Content only on your documented instructions. Your instructions are this DPA, the Terms of Service, any other agreement you sign with us, and the configuration choices, agent directions, connections, and permissions you set in the product. Using the platform as intended is an instruction to process accordingly.",
        "We will not process Customer Content for our own purposes, except to review it where you have agreed to that, as section 6 describes. If we are ever required by law to process it beyond your instructions, we will inform you before doing so unless the law prohibits that notice.",
        "You are responsible for the lawfulness of the personal data you bring: that you have a legal basis for it, that you have given any notices and obtained any consents required, and that your instructions to us comply with applicable data protection law. We will tell you if, in our view, an instruction infringes applicable law."
      ]
    },
    {
      "number": 5,
      "heading": "We Do Not Train On Your Content",
      "anchor": "we-do-not-train-on-your-content",
      "paragraphs": [
        "Customer Content is not training data. We do not use it to train, fine-tune, or improve foundation models, and we do not use it to train any model of our own unless you affirmatively allow it. This is a binding term of this DPA, not only a statement of intent.",
        "We route Customer Content to the model providers listed in [Subprocessors](/subprocessors) under commercial terms that do not train on it by default. Those providers retain content briefly for their own abuse-monitoring purposes under provider-set windows, which they can change; the current windows are described in our [Privacy Policy](/privacy).",
        "This is separate from the usage and telemetry data we control, which we may use to operate and improve the platform as described in our [Privacy Policy](/privacy). For training, the boundary is content versus usage: your material is yours, and how the product performs is ours. Reviewing Customer Content where you have agreed to it, as section 6 describes, does not move that boundary."
      ]
    },
    {
      "number": 6,
      "heading": "Confidentiality and Personnel",
      "anchor": "confidentiality-and-personnel",
      "paragraphs": [
        "We keep Customer Content confidential. Access is limited to personnel who need it to provide, secure, or support the platform, or to comply with law, and those people are bound by confidentiality obligations that survive the end of their engagement.",
        "Customer Content is private by default, and we do not review it as a matter of course. We review it to evaluate and improve the quality of the service only where you have agreed to that in writing, such as in an agreement you sign with us. That review is limited to the personnel described above and is not training; section 5 still applies. Separately, we may access Customer Content to investigate a specific security incident, to respond to a support request you make, to act on a legal or governmental demand, or to address a credible report of abuse or illegal content."
      ]
    },
    {
      "number": 7,
      "heading": "Security",
      "anchor": "security",
      "paragraphs": [
        "We implement technical and organizational measures appropriate to the risk, taking account of the state of the art and the nature of the processing. These include encryption of Customer Content in transit and at rest, authentication and role-based access control with least-privilege access for personnel, network isolation of our infrastructure, logging and monitoring of access and system activity, encrypted storage of the third-party credentials you entrust to us, separation of environments, and change control over the code and infrastructure that handle Customer Content.",
        "Security is a moving target, so we may change specific measures over time. We will not reduce the overall level of protection during your term.",
        "You are responsible for the parts of security you hold: keeping your account credentials and API keys secret, managing who in your organization has access, setting agent permissions and budgets deliberately, and choosing which third-party tools to connect and what scopes to grant them."
      ]
    },
    {
      "number": 8,
      "heading": "Subprocessors",
      "anchor": "subprocessors",
      "paragraphs": [
        "You authorize us to engage the subprocessors listed at [Subprocessors](/subprocessors), which is incorporated into this DPA and kept current. That page names each one, what it does, the categories of data it handles, and where it operates.",
        "We impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain responsible to you for their performance.",
        "When we intend to add or replace a subprocessor, we will update that page and give you notice before it begins processing Customer Content, so you have a chance to review the change. If you have a reasonable, data-protection-based objection, tell us and we will work with you in good faith; if we cannot resolve it, you may stop using the affected part of the platform or close your account, with the unused paid credit balance refunded as described in our [Credit Terms](/credit-terms)."
      ]
    },
    {
      "number": 9,
      "heading": "Deletion and Return",
      "anchor": "deletion-and-return",
      "paragraphs": [
        "You can ask us for an export of Customer Content, and we will produce it in a common machine-readable format. Write to privacy@escapev.ai from your account email; [Your Data: Export and Deletion](/data-deletion) describes the process.",
        "On termination, or on your written request, we will delete Customer Content, and instruct our subprocessors to do the same, within thirty days. Access ends immediately on deletion; the thirty days is the window for the permanent purge to complete across our systems and theirs. Where you make a formal request under Data Protection Law, we will acknowledge it within ten business days. We may retain a limited set of records where the law requires it, or in de-identified form that can no longer be linked to an individual, and anything retained stays subject to the confidentiality and security terms of this DPA for as long as we hold it.",
        "These commitments do not apply where we must act on illegal content, a legal or governmental demand, a security or safety risk, or abuse, in which case we may retain or preserve content and may be unable to provide an export."
      ]
    },
    {
      "number": 10,
      "heading": "Assisting You With Data Subject Requests",
      "anchor": "assisting-you-with-data-subject-requests",
      "paragraphs": [
        "Because you control Customer Content, requests from individuals about it come to you, not to us. The product gives you direct access to that content, so finding and correcting it yourself is usually the fastest route. For an export or a deletion covering that content, use the routes in [Your Data: Export and Deletion](/data-deletion), or write to privacy@escapev.ai and we will carry it out on your instructions.",
        "Where you cannot fulfill a request through the product, we will assist you with reasonable and timely measures, taking account of the nature of the processing. If an individual contacts us directly about content that is yours, we will not respond substantively; we will refer them to you and tell you promptly. Reach us at privacy@escapev.ai."
      ]
    },
    {
      "number": 11,
      "heading": "Incidents, Impact Assessments, and Consultation",
      "anchor": "incidents-impact-assessments-and-consultation",
      "paragraphs": [
        "If we become aware of a personal data breach affecting Customer Content, we will notify you without undue delay after becoming aware of it, and provide the information reasonably available to us so that you can meet your own notification obligations: what happened, the categories and approximate volume of data and individuals affected, the likely consequences, and the measures we have taken or propose to take. We will keep you updated as we learn more. Our notice is not an admission of fault. Make sure the contact details on your account are current, and send security reports to privacy@escapev.ai.",
        "We will provide reasonable assistance with a data protection impact assessment or a prior consultation with a supervisory authority, to the extent it relates to our processing of Customer Content and the information is not otherwise available to you."
      ]
    },
    {
      "number": 12,
      "heading": "Information and Audit",
      "anchor": "information-and-audit",
      "paragraphs": [
        "On reasonable request, we will make available the information necessary to demonstrate our compliance with this DPA, ordinarily by responding to a security questionnaire and providing the documentation we maintain about our security measures. We hold no third-party security certification or audit report today, and we will not imply otherwise; if that changes we will make the report available in place of a questionnaire.",
        "Where applicable law entitles you to an audit or inspection beyond that, we will agree the scope, timing, and cost with you in advance. An audit must be at your expense, on reasonable prior notice, no more than once a year absent a specific incident, subject to confidentiality, and conducted so that it does not compromise the security or availability of the platform or the confidentiality of other customers' data."
      ]
    },
    {
      "number": 13,
      "heading": "International Transfers",
      "anchor": "international-transfers",
      "paragraphs": [
        "We operate in the United States, and our subprocessors process in the United States, as recorded at [Subprocessors](/subprocessors). If you are in the United Kingdom, the European Economic Area, or Switzerland, providing the platform to you involves transferring Customer Content to the United States.",
        "Where personal data protected by UK or EU data protection law is transferred to us, the transfer is made under the SCCs, Module Two (controller to processor), with the UK Addendum where UK law applies, which are incorporated into this DPA by reference. Section 3 of this DPA supplies the description of the processing that Annex I.B of the SCCs calls for, section 7 supplies the technical and organisational measures for Annex II, and [Subprocessors](/subprocessors) supplies the list for Annex III. Where a clause of those instruments conflicts with this DPA, the clause governs.",
        "The SCCs require a competent supervisory authority to be named in Annex I.C. Ours is the Irish Data Protection Commission, which follows from our EU representative being established in Ireland. That answer is the same for every customer, so we state it here rather than leaving it to be settled case by case.",
        "Annex I.A identifies the parties, and that can only be completed once we know who you are. Contact us at privacy@escapev.ai and we will complete and execute the annexes with you. Until they are executed for your organization, treat the clauses as incorporated in substance and not yet countersigned.",
        "Some of our subprocessors are also self-certified under the EU-US, UK Extension, and Swiss-US Data Privacy Framework, and where that applies to a given transfer it operates alongside the clauses above rather than instead of them. We do not claim Data Privacy Framework coverage for subprocessors that do not hold it.",
        "To put the transfer instruments in place for your organization, contact us at privacy@escapev.ai and we will execute them with you."
      ]
    },
    {
      "number": 14,
      "heading": "California and Other US State Laws",
      "anchor": "california-and-other-us-state-laws",
      "paragraphs": [
        "Where the California Consumer Privacy Act applies, we act as a service provider with respect to Customer Content, and you are the business. We process it only to provide the platform to you, and for the limited purposes the statute permits. We do not sell it, and we do not share it for cross-context behavioral advertising. We do not retain, use, or disclose it outside our agreement with you, and we do not combine it with personal data from another source except as the statute permits to provide the service.",
        "We hold to the equivalent standard, with equivalent roles, under the other US state privacy laws that use the same processor model."
      ]
    },
    {
      "number": 15,
      "heading": "Agents Acting on Your Behalf",
      "anchor": "agents-acting-on-your-behalf",
      "paragraphs": [
        "The platform runs agents that act under your direction, within the permissions, budgets, schedules, and credentials you set. When an agent reads from or writes to a service you connected, it is acting as your electronic agent, and those actions are attributable to you, not to us. You remain the controller of the personal data involved, including personal data an agent retrieves from a connected service and brings onto the platform.",
        "You are responsible for deciding what the agents you run may access and do, and for the lawfulness of processing personal data that arrives that way. We are responsible for processing it as your processor once it is on the platform, exactly as this DPA describes for any other Customer Content."
      ]
    },
    {
      "number": 16,
      "heading": "Term, Liability, Governing Law, and Changes",
      "anchor": "term-liability-governing-law-and-changes",
      "paragraphs": [
        "This DPA takes effect when you begin using the platform for content that includes personal data, and continues for as long as we process Customer Content for you. The obligations that by their nature should survive termination do, including confidentiality, security of anything retained, and deletion.",
        "Each party's liability under this DPA is subject to the limitations and exclusions in our [Terms of Service](/terms). Nothing in this DPA limits either party's liability to a data subject, or any liability that cannot be limited under applicable law.",
        "This DPA is governed by the law that governs the [Terms of Service](/terms), and disputes about it are resolved the way the Terms provide. That does NOT extend to the SCCs or the UK Addendum: those instruments carry their own governing law and their own choice of forum, a data subject's right to bring a claim under them is unaffected by anything here, and where they conflict with this paragraph they govern.",
        "We may update this DPA to reflect a change in law, in our processing, or in our subprocessors. We will not make a change that materially reduces the protection of Customer Content without giving you notice first. If you need a countersigned copy for your records, or your organization requires its own paper, write to privacy@escapev.ai."
      ]
    }
  ]
}
