Data processing agreement

Not yet offered, and here is exactly why.

Launch draft. Creobot is in development. This page is a launch draft, last updated 15 August 2026, and is subject to change before general availability. It is not legal advice. Items marked as not finalised are genuinely undecided rather than withheld, and they will be published before general availability.

Status: not yet offered

We do not currently offer a data processing agreement, because the terms that would sit in one are not settled. Publishing a DPA that references providers, retention periods and processing regions we have not confirmed would be worse than publishing nothing.

What a DPA would need to specify

When we do offer one, it will have to state at minimum:

  • The roles of each party under applicable data protection law.
  • The categories of personal data processed and the purposes.
  • The full subprocessor list and how changes to it are notified.
  • Retention and deletion terms, including how deletion propagates to subprocessors.
  • The processing location.
  • Security measures.
  • Audit and assistance obligations.
  • International transfer mechanisms where relevant.

Every one of those is currently open

That is the honest position for a product in development. We would rather say so than produce a template with plausible values filled in.

If you need one to evaluate us

Tell us what your requirements are. That information is useful to us while these terms are being decided, and it is better input than guessing at what buyers will need.

Not legal advice

Nothing on this page is legal advice. A DPA is a contract and it should be reviewed by a lawyer in your jurisdiction before you rely on it.