TRUST & TRANSPARENCY

Data-processing readiness

Launch checklist, not an executed DPA · Updated September 21, 2026

Current status

There is no completed customer-specific data-processing agreement for this pilot. Do not upload real customer records. This page documents requirements to resolve before production; it is not a blanket declaration of U.S. or EU compliance.

Agreement and instructions

Define the parties and their controller/processor or business/service-provider roles, permitted purposes, data types, data subjects, confidentiality, documented instructions and assistance with individual-rights requests.

Security and incident handling

Finalize role-based access, tenant isolation, credential storage and rotation, audit logging, incident response, appropriate notification duties, backup/restore checks and vulnerability handling. The current owner-scoped database and review rules are individual controls, not a comprehensive assurance program.

Subprocessors and transfers

Approve the actual hosting, authentication, email, calendar, payment, automation and AI providers used by each deployment. Confirm regions, subprocessors, contractual safeguards, international transfers and any restrictions on model training or secondary use. No U.S.-only residency promise is made.

Retention and service end

Agree retention periods, deletion and export procedures, backup expiry, assistance on termination and verification of deletion. The workspace retention job (closed requests after 365 days by default, adjustable between 30 and 3,650 days; unmatched mailbox imports after 90 days) does not cover backups or copies held by connected providers.

U.S. market obligations

Assess applicable state privacy laws, contractual customer requirements, communication rules and record retention for the actual business model and locations. The German provider also needs an EU/German-law assessment. Legal and tax review is a launch dependency, not an automated feature.

Contact the provider about data or privacy →