Skip to main content
Last Update: July 9, 2026 This Data Protection Addendum (“DPA”) supplements the End User License Agreement (“Agreement”) between SB Technology, Inc. d/b/a SandboxAQ (“SandboxAQ”) and Customer for use of the Flint AI Platform. This DPA applies when SandboxAQ processes Personal Data on behalf of Customer in providing the Flint AI Platform, and such Personal Data is subject to Data Protection Laws. Incorporation: This DPA forms part of the Agreement. If you have questions, contact privacy@sandboxaq.com.

Definitions

“Personal Data” means any information relating to an identified or identifiable natural person contained within Customer Data (as defined in Agreement Section 7(c)). “Data Protection Laws” means applicable data protection and privacy laws, including the EU General Data Protection Regulation (GDPR), UK GDPR, and other applicable laws. “Controller”, “Processor”, “Data Subject”, “Processing”, “Sub-processor” have the meanings given in the GDPR.

Roles and Scope

Customer acts as the Controller of Personal Data submitted to the Flint AI Platform. SandboxAQ acts as the Processor, processing Personal Data only as necessary to provide the Software. What data we process: See Details of Processing below.

How We Process Your Data

Processing Instructions

SandboxAQ processes Personal Data only:
  • As necessary to provide the Software under the Agreement; or
  • On Customer’s documented instructions; or
  • As required by applicable law (we’ll notify you first unless legally prohibited).

Confidentiality

Personal Data is Confidential Information under Agreement Section 6. Our personnel authorized to process Personal Data are subject to confidentiality obligations.

Purpose Limitation

We process Personal Data solely to provide the Software to Customer, and as otherwise permitted under Agreement Section 7(b) (Usage Data).

Security

Our Security Measures

We implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, loss, or disclosure. For details about our security practices, see:
Data Handling Documentation
This includes information about:
  • Encryption (in transit and at rest)
  • Access controls and authentication
  • Network security and monitoring
  • Incident response
  • Employee training
  • Certifications (SOC 2, ISO 27001 status)

Assistance with Your Obligations

We’ll provide reasonable assistance (at your expense) to help you comply with your security obligations under Data Protection Laws, taking into account the nature of processing and information available to us.

Sub-Processors

Authorization

You authorize us to engage Sub-processors to process Personal Data on our behalf. Current sub-processors:
See Sub-processors List

Changes to Sub-Processors

We’ll notify you at least 30 days in advance before adding or replacing any Sub-processor via:
  • Email to your registered contact address; and
  • Updates to the list above
If you object: You may object on reasonable data protection grounds by notifying us in writing within 15 days. If we cannot resolve your objection, you may terminate the affected services.

Our Responsibility

We impose data protection obligations on Sub-processors that are substantially equivalent to this DPA, and we remain fully liable to you for Sub-processor performance.

Data Subject Rights

Requests from Data Subjects

If we receive a request from a Data Subject to exercise their rights under Data Protection Laws (access, deletion, portability, etc.), we’ll promptly notify you so you can respond.

Our Assistance

We’ll provide reasonable assistance (at your expense) to help you respond to Data Subject requests within the timeframes required by law, taking into account the nature of processing.

Data Breaches

Notification

If we become aware of a Personal Data breach affecting your data, we’ll notify you within 72 hours.

Information Provided

Our notification will describe (to the extent known):
  • The nature of the breach and categories/numbers of Data Subjects and records affected
  • Contact point for more information
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

Cooperation

We’ll cooperate with you to investigate and remediate the breach. We won’t publicly disclose the breach without your consent, except as required by law.

Audits and Compliance

Your Audit Rights

You may audit our compliance with this DPA:
  • Frequency: Once per year (unless required by a supervisory authority or following a breach)
  • Notice: At least 30 days in advance
  • Timing: During regular business hours
  • Conditions: Subject to our confidentiality agreement, at your expense

Compliance Information

Instead of an on-site audit, we may provide:
  • Copies of third-party audit reports (SOC 2, ISO 27001)
  • Other certifications or attestations
  • Information demonstrating compliance with this DPA
Reports are subject to confidentiality restrictions.

Data Retention and Deletion

Retention

We retain Personal Data only as long as necessary to provide the Software or as required by law. Retention periods by data type:
See Data Retention

Deletion After Termination

After the Agreement terminates, we’ll delete all Personal Data within 30 days, except:
  • Where required by law to retain it; or
  • For Usage Data (anonymized/aggregated) as permitted by Agreement Section 7(b)

Return Before Deletion

If you request it in writing within 30 days of termination, we’ll return your Personal Data in a commonly used electronic format before deletion.

Certification

Upon your written request, we’ll certify that Personal Data has been deleted.

International Data Transfers

Where We Process Data

Personal Data may be processed in countries where we or our Sub-processors maintain facilities. Processing locations:
See Sub-processors List

Transfers from the EU/UK

Where Personal Data is transferred from the European Economic Area (EEA) or United Kingdom to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs). For EU transfers:
EU Standard Contractual Clauses (2021)
Module 2 (Controller to Processor) applies.
For UK transfers:
UK International Data Transfer Addendum
The Annexes to these SCCs are completed as follows:

If SCCs Become Invalid

If the SCCs are invalidated or unavailable, we’ll implement an alternative lawful transfer mechanism or suspend transfers until one is available.

Liability and Governing Law

Limitation of Liability

The limitation of liability provisions in Agreement Section 9 apply to this DPA, except where Data Protection Laws require otherwise. Nothing in this DPA limits our liability under Data Protection Laws.

Governing Law

This DPA is governed by the laws specified in Agreement Section 12(f), except where Data Protection Laws require otherwise.

Changes to this DPA

We may update this DPA to reflect:
  • Changes in Data Protection Laws
  • Guidance from supervisory authorities
  • Changes to our processing operations
We’ll notify you at least 30 days in advance of material changes. Your continued use of the Software after the effective date constitutes acceptance. If you object to material changes, you may terminate the Agreement in accordance with Section 11.

Order of Precedence

If there’s a conflict between the Agreement and this DPA regarding Personal Data processing, this DPA prevails. In all other respects, the Agreement remains in full force.

Details of Processing

What We Do with Your Data

Purpose: We process Personal Data to provide the Flint AI Platform services:
  • Discover AI agents in your code repositories
  • Analyze agent code for security vulnerabilities
  • Monitor runtime agent sessions and LLM interactions
  • Enforce guardrail policies on agent behavior
  • Provide analytics and compliance reporting
Duration: For the License Period (as defined in the Agreement), or until all Personal Data is deleted or returned, whichever is later.

Types of Personal Data Processed

Note: We do not intentionally collect sensitive personal data. You are responsible for ensuring no Prohibited Data (as defined in Agreement Section 7(c)) is submitted to the Platform. For more details:
Data Handling Documentation

Categories of Data Subjects

Personal Data may relate to:
  • Your employees, contractors, and authorized users
  • Contributors to your code repositories (names/emails in commit history)
  • End users who interact with your AI agents (if session data includes personal prompts/responses)

Your Responsibilities

You represent and warrant that you:
  • Have a lawful basis under Data Protection Laws for processing Personal Data and instructing us to process it on your behalf
  • Comply with Data Protection Laws in your use of the Software
  • Do not submit Prohibited Data to the Platform (per Agreement Section 7(c))

Questions?

Contact: privacy@sandboxaq.com Additional Information: