Varlet

Data Processing Agreement

Version 1.1 · effective 2026-10-01

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Zink Labs LLC ("Processor," "we," "us") and you and governs the processing of personal data in connection with the Agent Harness service ("Service"). In this DPA, "you" refers to the individual user of the Service.

Last Updated: October 1, 2026 | Version 1.1

1. Definitions

2. Scope and Purpose

2.1 Scope

This DPA applies to all Personal Data that the Processor processes on your behalf in connection with providing the Service.

2.2 Purpose

The Processor processes Personal Data solely to provide the Service as described in the Terms of Service, including:

3. Categories of Personal Data

The Processor processes the following categories of Personal Data:

CategoryExamples
Identity DataEmail address, sign-in identifiers
Conversation DataChats, voice audio (streamed, not stored), transcripts
Agent DataTasks, plans, terminal sessions, code, files, screenshots, reports, pull requests
Credential DataAPI keys, passwords and connector tokens (encrypted at rest, isolated per user)
Connected-Service DataContent your agents access in services you connect (for example, email, calendar or repositories)
Device DataDevice type, app version, push tokens, web push subscriptions
Payment DataStripe customer ID, subscription plan, billing status (no full card numbers)

4. Categories of Data Subjects

5. Processor Obligations

The Processor agrees to:

6. Sub-processors

6.1 Approved Sub-processors

We use the following Sub-processors, which you authorize by using the Service:

Sub-processorPurposeLocationData Processed
Cloudflare, Inc.Compute for your manager and your agents' isolated computers; encrypted storage and credential vault; website funnel counts (event name and day only)United StatesAgent tasks, outputs, files, transcripts, encrypted credentials
Supabase, Inc.Authentication; legal acceptance recordsUnited StatesEmail, sign-in identifiers; accepted document versions with time, IP address and user agent
Anthropic, PBCAI for the manager and agents, under your own Claude account or API keyUnited StatesMessages, tasks, code and context sent for processing. Not used for model training.
OpenAI, L.L.C.Real-time voiceUnited StatesVoice audio and transcripts. Not used for model training by default; abuse-monitoring logs kept up to 30 days.
X.AI Corp.Teammate portrait generationUnited StatesTeammate role descriptions (no personal data)
Stripe, Inc.Payment processingUnited StatesEmail, subscription data, payment method
Plaid Inc.Linking the bank, card and brokerage accounts a user choosesUnited StatesAccount, balance, transaction, liability and holdings data for linked accounts
Apple Inc.Push notifications and app distributionUnited StatesPush tokens, notification content
Functional Software, Inc. (Sentry)Error and crash monitoringUnited StatesCrash reports, device data, user ID
Resend, Inc.Transactional emailUnited StatesEmail address, email content
Vercel, Inc.Website and web app hostingUnited States (global edge)IP address, browser metadata

AI providers you select for an agent (OpenAI for Codex, Google for Gemini CLI, xAI for Grok Build, Meta for Muse, and the providers you configure in OpenCode) process that agent's requests under your own account or key and your agreement with them; they are engaged by you, not by the Processor.

6.2 Changes to Sub-processors

We will notify you of any intended changes to Sub-processors by updating this DPA. You may object to a new Sub-processor by contacting us within 30 days of notification. If we cannot reasonably accommodate your objection, you may terminate the Service.

7. Data Transfers

Personal Data is processed and stored in the United States. Where Personal Data is transferred from the EU/EEA to the United States, such transfers are conducted in compliance with applicable data protection laws, including through:

By using the Service, you acknowledge that Personal Data will be transferred to and processed in the United States. When you direct an agent to send information to a website, service or person, it is sent there at your direction.

8. Security Measures

The Processor maintains the following security measures:

9. Data Breach Notification

9.1 Notification

In the event of a security breach that affects Personal Data, we will notify you without undue delay and in any event within 72 hours of becoming aware of the breach.

9.2 Breach Notice Content

The notification will include:

9.3 Cooperation

We will cooperate with you in investigating and mitigating the breach and in meeting any legal notification obligations.

9.4 Florida Information Protection Act (FIPA) Compliance

In addition to the general breach notification obligations above, the Processor will comply with the Florida Information Protection Act of 2014 (FL § 501.171) for breaches affecting Florida residents:

Non-compliance with FIPA notification timelines may result in civil penalties of up to $500,000 ($1,000 per day for the first 30 days, $50,000 per subsequent 30-day period, capped at $500,000). The Processor acknowledges this obligation and commits to meeting these deadlines.

10. Data Subject Rights

We will assist you in exercising your data rights, including:

Data Subjects may exercise these rights through the Service's account settings or by contacting legal@zinklabs.dev.

11. Term and Termination

This DPA remains in effect for the duration of the Terms of Service. Upon termination:

12. Governing Law

This DPA is governed by the same governing law as the Terms of Service (the laws of the State of Florida).

13. Contact

For questions about this DPA or to exercise data rights:

Zink Labs LLC

Email: legal@zinklabs.dev