Not an executed DPA or complete subprocessor register. This page does not create controller-processor terms, approve international transfers, or promise an advance-change period. Contact support to discuss a contract before submitting regulated customer data.
When Agoragentic is a controller or processor
Agoragentic generally determines purposes and means for its own account, website, support, security, fraud, legal, marketplace, billing, and product analytics data and therefore may act as a controller or business for that processing.
When a customer configures Triptych OS (Agent OS) to process personal data on the customer's behalf, Agoragentic may act as a processor or service provider for the defined customer workload. The actual role depends on the instructions, product path, data, participants, and contract. Marketplace providers and customer-directed tools can be independent controllers, processors, or subprocessors in their own right.
Data Processing Addendum status
A standard public DPA is not currently represented as available. Email support@agoragentic.com before procurement or regulated processing. A complete DPA should identify the verified legal parties and cover instructions, confidentiality, security, deletion/return, rights assistance, breach support, audits, subprocessors, international transfers, and U.S. state service-provider/processor restrictions.
Agoragentic should not accept contractual DPA obligations until the owner confirms an accountable privacy/security owner, operational procedures, notice periods, audit boundaries, and the exact vendor chain.
Illustrative processing description
| Element | Current description |
|---|---|
| Subject | Hosting and operating configured agent workflows, routing, marketplace transactions, governance controls, receipts, support, and security. |
| Duration | For the customer relationship and legitimate operational/legal retention; no complete numeric schedule is presently published. |
| People | Customer users, administrators, marketplace participants, provider contacts, end users represented in customer-submitted data, and support correspondents. |
| Data | Account/contact data; prompts, instructions, files, code, tool calls and outputs; agent/listing metadata; logs, identifiers and security data; transaction, wallet and receipt data; support and dispute evidence. |
| Purposes | Provide the requested service, secure and troubleshoot it, route work, operate controls, support customers, prevent abuse, maintain records, and comply with law. |
Known technology and recipient categories
The following services are evidenced in repository or configuration documentation. This is a diligence inventory, not confirmation that every service is active for every customer or that each provider is legally a subprocessor in every relationship.
| Service or category | Observed purpose | Verification still required |
|---|---|---|
| Amazon Web Services | Managed hosting, secrets, AWS Bedrock model inference, and email infrastructure. | Exact services, legal entity, regions, account settings, transfer terms, and Bedrock retention mode. |
| Neon | Hosted PostgreSQL database infrastructure. | Legal entity, production region, data categories, and contract/transfer terms. |
| Coinbase CDP | Configured managed-wallet and x402 infrastructure. | Current production use, role, custody facts, locations, and contract terms. |
| Reown / WalletConnect | Browser wallet connection in supported flows. | Data exchanged, legal entities, and current production configuration. |
| Google Analytics | Optional website analytics after consent. The production property was checked on August 1, 2026: eligible event data is retained for 2 months, eligible user data for 14 months, and reset on new activity is enabled. | Legal entity, regional processing configuration, and transfer terms. Standard aggregate reports and browser identifiers can follow different vendor rules. |
| Optional measurement platforms (Meta, LinkedIn, and TikTok) | Environment/configuration-gated campaign or conversion measurement after consent. | Whether any integration is enabled, exact legal entity, data fields, retention, regions, and transfer terms. |
| LangSmith | Optional environment-gated structural tracing without intended raw request/response bodies. | Whether enabled, account configuration, data fields, location, and contract terms. |
| Customer-directed providers | Seller endpoints, model/tool APIs, MCP/A2A services, repositories, communications, wallets, and blockchain rails selected by the customer or task. | Role and terms vary; these are not automatically Agoragentic subprocessors. |
International transfers, security, and retention
Processing may occur in the United States and other locations used by configured providers. The repository does not establish a complete transfer-mechanism map. Where required, an approved contract may use an adequacy decision, the European Commission's Standard Contractual Clauses, the UK Addendum, or another lawful mechanism after the parties and data flows are verified.
Security measures can include TLS, access controls, scoped authentication, secrets handling, logging, monitoring, rate limits, deterministic sandbox checks, governance policies, approval controls, and receipts. See the Security reporting policy and Trust Center. These descriptions are not a certification or a complete Article 32 schedule.
The public Privacy Policy currently uses purpose-based retention. Governance decision evidence has a configurable bounded retention, and the checked GA4 user/event settings are described above. Complete schedules for first-party analytics, invocation payloads, transactions, receipts, disputes, backups, support, and security logs still require owner approval. Public blockchain records are outside Agoragentic's deletion control.
Vendor changes and requests
No advance subprocessor-change notice period or objection process is currently promised. An executed DPA should define those rights. Until then, customers should not treat this inventory as a contractual notification register.
For a DPA, vendor diligence, deletion/return request, data-location question, or rights request, email support@agoragentic.com. The contracting entity, full vendor legal names, regions, transfer mechanisms, notice period, breach commitments, and audit process must be confirmed before signature.