Definitions
“Personal Data” means any information relating to an identified or identifiable natural person contained within Customer Data (as defined in Agreement Section 7(c)). “Data Protection Laws” means applicable data protection and privacy laws, including the EU General Data Protection Regulation (GDPR), UK GDPR, and other applicable laws. “Controller”, “Processor”, “Data Subject”, “Processing”, “Sub-processor” have the meanings given in the GDPR.Roles and Scope
Customer acts as the Controller of Personal Data submitted to the Flint AI Platform. SandboxAQ acts as the Processor, processing Personal Data only as necessary to provide the Software. What data we process: See Details of Processing below.How We Process Your Data
Processing Instructions
SandboxAQ processes Personal Data only:- As necessary to provide the Software under the Agreement; or
- On Customer’s documented instructions; or
- As required by applicable law (we’ll notify you first unless legally prohibited).
Confidentiality
Personal Data is Confidential Information under Agreement Section 6. Our personnel authorized to process Personal Data are subject to confidentiality obligations.Purpose Limitation
We process Personal Data solely to provide the Software to Customer, and as otherwise permitted under Agreement Section 7(b) (Usage Data).Security
Our Security Measures
We implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, loss, or disclosure. For details about our security practices, see:→ Data Handling Documentation This includes information about:
- Encryption (in transit and at rest)
- Access controls and authentication
- Network security and monitoring
- Incident response
- Employee training
- Certifications (SOC 2, ISO 27001 status)
Assistance with Your Obligations
We’ll provide reasonable assistance (at your expense) to help you comply with your security obligations under Data Protection Laws, taking into account the nature of processing and information available to us.Sub-Processors
Authorization
You authorize us to engage Sub-processors to process Personal Data on our behalf. Current sub-processors:→ See Sub-processors List
Changes to Sub-Processors
We’ll notify you at least 30 days in advance before adding or replacing any Sub-processor via:- Email to your registered contact address; and
- Updates to the list above
Our Responsibility
We impose data protection obligations on Sub-processors that are substantially equivalent to this DPA, and we remain fully liable to you for Sub-processor performance.Data Subject Rights
Requests from Data Subjects
If we receive a request from a Data Subject to exercise their rights under Data Protection Laws (access, deletion, portability, etc.), we’ll promptly notify you so you can respond.Our Assistance
We’ll provide reasonable assistance (at your expense) to help you respond to Data Subject requests within the timeframes required by law, taking into account the nature of processing.Data Breaches
Notification
If we become aware of a Personal Data breach affecting your data, we’ll notify you within 72 hours.Information Provided
Our notification will describe (to the extent known):- The nature of the breach and categories/numbers of Data Subjects and records affected
- Contact point for more information
- Likely consequences of the breach
- Measures taken or proposed to address the breach
Cooperation
We’ll cooperate with you to investigate and remediate the breach. We won’t publicly disclose the breach without your consent, except as required by law.Audits and Compliance
Your Audit Rights
You may audit our compliance with this DPA:- Frequency: Once per year (unless required by a supervisory authority or following a breach)
- Notice: At least 30 days in advance
- Timing: During regular business hours
- Conditions: Subject to our confidentiality agreement, at your expense
Compliance Information
Instead of an on-site audit, we may provide:- Copies of third-party audit reports (SOC 2, ISO 27001)
- Other certifications or attestations
- Information demonstrating compliance with this DPA
Data Retention and Deletion
Retention
We retain Personal Data only as long as necessary to provide the Software or as required by law. Retention periods by data type:→ See Data Retention
Deletion After Termination
After the Agreement terminates, we’ll delete all Personal Data within 30 days, except:- Where required by law to retain it; or
- For Usage Data (anonymized/aggregated) as permitted by Agreement Section 7(b)
Return Before Deletion
If you request it in writing within 30 days of termination, we’ll return your Personal Data in a commonly used electronic format before deletion.Certification
Upon your written request, we’ll certify that Personal Data has been deleted.International Data Transfers
Where We Process Data
Personal Data may be processed in countries where we or our Sub-processors maintain facilities. Processing locations:→ See Sub-processors List
Transfers from the EU/UK
Where Personal Data is transferred from the European Economic Area (EEA) or United Kingdom to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs). For EU transfers:→ EU Standard Contractual Clauses (2021)
Module 2 (Controller to Processor) applies. For UK transfers:
→ UK International Data Transfer Addendum The Annexes to these SCCs are completed as follows:
- Annex I (Parties and transfer details): See Details of Processing below
- Annex II (Technical and organizational measures): Data Handling Documentation
- Annex III (Sub-processors): Sub-processors List
If SCCs Become Invalid
If the SCCs are invalidated or unavailable, we’ll implement an alternative lawful transfer mechanism or suspend transfers until one is available.Liability and Governing Law
Limitation of Liability
The limitation of liability provisions in Agreement Section 9 apply to this DPA, except where Data Protection Laws require otherwise. Nothing in this DPA limits our liability under Data Protection Laws.Governing Law
This DPA is governed by the laws specified in Agreement Section 12(f), except where Data Protection Laws require otherwise.Changes to this DPA
We may update this DPA to reflect:- Changes in Data Protection Laws
- Guidance from supervisory authorities
- Changes to our processing operations
Order of Precedence
If there’s a conflict between the Agreement and this DPA regarding Personal Data processing, this DPA prevails. In all other respects, the Agreement remains in full force.Details of Processing
What We Do with Your Data
Purpose: We process Personal Data to provide the Flint AI Platform services:- Discover AI agents in your code repositories
- Analyze agent code for security vulnerabilities
- Monitor runtime agent sessions and LLM interactions
- Enforce guardrail policies on agent behavior
- Provide analytics and compliance reporting
Types of Personal Data Processed
Note: We do not intentionally collect sensitive personal data. You are responsible for ensuring no Prohibited Data (as defined in Agreement Section 7(c)) is submitted to the Platform.
For more details:
→ Data Handling Documentation
Categories of Data Subjects
Personal Data may relate to:- Your employees, contractors, and authorized users
- Contributors to your code repositories (names/emails in commit history)
- End users who interact with your AI agents (if session data includes personal prompts/responses)
Your Responsibilities
You represent and warrant that you:- Have a lawful basis under Data Protection Laws for processing Personal Data and instructing us to process it on your behalf
- Comply with Data Protection Laws in your use of the Software
- Do not submit Prohibited Data to the Platform (per Agreement Section 7(c))
Questions?
Contact: privacy@sandboxaq.com Additional Information:- Data Handling Documentation - Security practices, sub-processors, retention
- Privacy Policy - How we handle data when we act as a Controller
- End User License Agreement - Main terms of service