Data Processing Agreement
Version 1.1 · effective 2026-10-01
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Zink Labs LLC ("Processor," "we," "us") and you and governs the processing of personal data in connection with the Agent Harness service ("Service"). In this DPA, "you" refers to the individual user of the Service.
Last Updated: October 1, 2026 | Version 1.1
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined by applicable data protection laws (including GDPR and CCPA).
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, transmission, and deletion.
- "Data Subject" means the identified or identifiable person to whom the Personal Data relates.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on your behalf.
2. Scope and Purpose
2.1 Scope
This DPA applies to all Personal Data that the Processor processes on your behalf in connection with providing the Service.
2.2 Purpose
The Processor processes Personal Data solely to provide the Service as described in the Terms of Service, including:
- Running your manager assistant by voice, chat and phone
- Running your agents on isolated cloud computers with the agent tools and AI providers you choose
- Reading and writing code in repositories you connect, and opening, monitoring and merging pull requests there
- Storing credentials and connector tokens in an encrypted vault and making them available only to your own agents
- Preparing drafts of outbound actions for your approval, and carrying out the ones you approve
- Sending you notifications, and processing subscription payments
3. Categories of Personal Data
The Processor processes the following categories of Personal Data:
| Category | Examples |
|---|---|
| Identity Data | Email address, sign-in identifiers |
| Conversation Data | Chats, voice audio (streamed, not stored), transcripts |
| Agent Data | Tasks, plans, terminal sessions, code, files, screenshots, reports, pull requests |
| Credential Data | API keys, passwords and connector tokens (encrypted at rest, isolated per user) |
| Connected-Service Data | Content your agents access in services you connect (for example, email, calendar or repositories) |
| Device Data | Device type, app version, push tokens, web push subscriptions |
| Payment Data | Stripe customer ID, subscription plan, billing status (no full card numbers) |
4. Categories of Data Subjects
- Users of the Service
- People whose information appears in content you or your agents process at your direction (for example, the recipients of an approved email)
5. Processor Obligations
The Processor agrees to:
- (a) Process Personal Data only on your instructions through the Service and as described in the Terms of Service
- (b) Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- (c) Implement appropriate technical and organizational security measures, including:
- Encryption of data in transit (TLS) and at rest
- A separate, isolated cloud computer for each agent, and a separate cell (workspace, vault and storage) for each user
- Credentials scoped to the repository or organization you choose, never shown in chat or logs
- Secure authentication via Supabase Auth
- Access controls limiting data access to authorized personnel
- (d) Not engage Sub-processors without prior disclosure (see Section 6)
- (e) Assist you in responding to Data Subject rights requests
- (f) Delete or return all Personal Data upon termination, subject to the data retention terms in the Terms of Service
- (g) Make available information necessary to demonstrate compliance with this DPA
6. Sub-processors
6.1 Approved Sub-processors
We use the following Sub-processors, which you authorize by using the Service:
| Sub-processor | Purpose | Location | Data Processed |
|---|---|---|---|
| Cloudflare, Inc. | Compute for your manager and your agents' isolated computers; encrypted storage and credential vault; website funnel counts (event name and day only) | United States | Agent tasks, outputs, files, transcripts, encrypted credentials |
| Supabase, Inc. | Authentication; legal acceptance records | United States | Email, sign-in identifiers; accepted document versions with time, IP address and user agent |
| Anthropic, PBC | AI for the manager and agents, under your own Claude account or API key | United States | Messages, tasks, code and context sent for processing. Not used for model training. |
| OpenAI, L.L.C. | Real-time voice | United States | Voice audio and transcripts. Not used for model training by default; abuse-monitoring logs kept up to 30 days. |
| X.AI Corp. | Teammate portrait generation | United States | Teammate role descriptions (no personal data) |
| Stripe, Inc. | Payment processing | United States | Email, subscription data, payment method |
| Plaid Inc. | Linking the bank, card and brokerage accounts a user chooses | United States | Account, balance, transaction, liability and holdings data for linked accounts |
| Apple Inc. | Push notifications and app distribution | United States | Push tokens, notification content |
| Functional Software, Inc. (Sentry) | Error and crash monitoring | United States | Crash reports, device data, user ID |
| Resend, Inc. | Transactional email | United States | Email address, email content |
| Vercel, Inc. | Website and web app hosting | United States (global edge) | IP address, browser metadata |
AI providers you select for an agent (OpenAI for Codex, Google for Gemini CLI, xAI for Grok Build, Meta for Muse, and the providers you configure in OpenCode) process that agent's requests under your own account or key and your agreement with them; they are engaged by you, not by the Processor.
6.2 Changes to Sub-processors
We will notify you of any intended changes to Sub-processors by updating this DPA. You may object to a new Sub-processor by contacting us within 30 days of notification. If we cannot reasonably accommodate your objection, you may terminate the Service.
7. Data Transfers
Personal Data is processed and stored in the United States. Where Personal Data is transferred from the EU/EEA to the United States, such transfers are conducted in compliance with applicable data protection laws, including through:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable with our Sub-processors
- The EU-U.S. Data Privacy Framework, where our Sub-processors are certified participants
By using the Service, you acknowledge that Personal Data will be transferred to and processed in the United States. When you direct an agent to send information to a website, service or person, it is sent there at your direction.
8. Security Measures
The Processor maintains the following security measures:
- Isolation: One cloud computer per agent; one cell per user; credentials released only to that user's agents and scoped per repository or organization
- Encryption: TLS 1.2+ for data in transit; encryption at rest for storage and the credential vault
- Authentication: Email sign-in links bound to the requesting browser (PKCE); session-based authentication via Supabase Auth
- Approvals: Outbound messages, calls, purchases and builds wait for the user's explicit approval
- Monitoring: Logs of routing decisions, agent runs and approvals; error monitoring
9. Data Breach Notification
9.1 Notification
In the event of a security breach that affects Personal Data, we will notify you without undue delay and in any event within 72 hours of becoming aware of the breach.
9.2 Breach Notice Content
The notification will include:
- (a) A description of the nature of the breach, including the categories and approximate number of Data Subjects affected
- (b) The name and contact details of the Processor's point of contact
- (c) A description of the likely consequences of the breach
- (d) A description of the measures taken or proposed to address the breach
9.3 Cooperation
We will cooperate with you in investigating and mitigating the breach and in meeting any legal notification obligations.
9.4 Florida Information Protection Act (FIPA) Compliance
In addition to the general breach notification obligations above, the Processor will comply with the Florida Information Protection Act of 2014 (FL § 501.171) for breaches affecting Florida residents:
- (a) Notification to affected individuals will be provided no later than thirty (30) days after determination of the breach or reason to believe a breach occurred.
- (b) If the breach affects 500 or more individuals, the Processor will notify the Florida Department of Legal Affairs within 30 days of the breach determination.
- (c) If the breach affects 1,000 or more individuals at the same time, the Processor will also notify all consumer reporting agencies.
Non-compliance with FIPA notification timelines may result in civil penalties of up to $500,000 ($1,000 per day for the first 30 days, $50,000 per subsequent 30-day period, capped at $500,000). The Processor acknowledges this obligation and commits to meeting these deadlines.
10. Data Subject Rights
We will assist you in exercising your data rights, including:
- Access: Providing copies of Personal Data
- Rectification: Correcting inaccurate data
- Deletion: Deleting Personal Data (subject to legal retention requirements)
- Portability: Exporting data in a machine-readable format
- Restriction: Restricting processing upon request
- Objection: Ceasing processing where the Data Subject objects
Data Subjects may exercise these rights through the Service's account settings or by contacting legal@zinklabs.dev.
11. Term and Termination
This DPA remains in effect for the duration of the Terms of Service. Upon termination:
- (a) You may request export of your Personal Data within 30 days
- (b) The Processor will delete all Personal Data within 30 days after the data export period, unless retention is required by law
- (c) Deletion will be performed using secure, industry-standard methods
12. Governing Law
This DPA is governed by the same governing law as the Terms of Service (the laws of the State of Florida).
13. Contact
For questions about this DPA or to exercise data rights:
Zink Labs LLC
Email: legal@zinklabs.dev