Legal
Data Processing Addendum
- Effective:
- October 1, 2026
- Last updated:
- October 1, 2026
This Data Processing Addendum ("DPA") is incorporated by reference into, and forms part of, the Terms of Service between you ("Account Holder," "Controller," "you") and Pluto Agent LLC, a Pennsylvania limited liability company doing business as "Pluto Agent" ("Company," "Processor," "we"). This DPA applies automatically, without any additional signature, whenever you submit End User Data (as defined below) to the Service. If you require a separately countersigned version of this DPA for your own internal or contractual purposes, contact us at [email protected].
Capitalized terms not defined in this DPA have the meaning given in the Terms of Service or the Privacy Policy. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.
1. Definitions#
"Controller" means the entity that determines the purposes and means of the Processing of Personal Data. With respect to End User Data, Account Holder is the Controller.
"Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA").
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
"End User Data" means Personal Data of your End Users that is submitted to, or passes through, the Service in connection with your use of an Agent Build, as described in the Privacy Policy.
"Personal Data" means any information relating to an identified or identifiable natural person, as further defined under applicable Data Protection Laws.
"Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion, and "Process" and "Processed" have corresponding meanings.
"Processor" means the entity that Processes Personal Data on behalf of, and under the instructions of, a Controller. With respect to End User Data, Company is the Processor.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, End User Data.
"Standard Contractual Clauses" or "SCCs," means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as approved by the European Commission (Commission Implementing Decision (EU) 2021/914), and, where applicable, the UK International Data Transfer Addendum issued by the UK Information Commissioner's Office.
"Sub-processor" means any third party engaged by Company to Process End User Data on Company's behalf.
2. Roles of the Parties#
This DPA applies only to End User Data. With respect to End User Data: you are the Controller and determine why and how End User Data is submitted to the Service; Company is the Processor and Processes End User Data only as described in this DPA and on your instructions.
This DPA does not apply to Company's Processing of your own Account Holder data (such as your name, email, and billing information), which is governed by the Privacy Policy, under which Company acts as controller.
3. Processing Instructions#
Company will Process End User Data only: (a) to provide the Service in accordance with the Terms of Service; (b) in accordance with your documented instructions, which include the instructions reflected in your configuration of an Agent Build and the Tools you grant to it; and (c) as required by applicable law, in which case Company will inform you of that legal requirement before Processing, unless the law prohibits such notice.
You will ensure that your instructions to Company, including the content and configuration of your Agent Builds, comply with Data Protection Laws. Company will promptly notify you if it becomes aware that an instruction infringes Data Protection Laws, without obligation to conduct affirmative legal review of every instruction.
4. Confidentiality#
Company will ensure that personnel authorized to Process End User Data are subject to a duty of confidentiality with respect to that data, whether contractual or statutory.
5. Security Measures#
Company will implement and maintain appropriate technical and organizational measures designed to protect End User Data against Security Incidents, taking into account the nature of the Processing and the risks involved, as described in Annex 2 to this DPA.
6. Sub-processors#
You provide general authorization for Company to engage Sub-processors to Process End User Data, subject to this Section. Company's current Sub-processors are listed in Annex 3 and in the Privacy Policy.
Before engaging a new Sub-processor to Process End User Data, Company will provide notice by updating Annex 3 or the Privacy Policy and, where reasonably practicable, by email or in-product notice. If you have a reasonable, documented data-protection objection to a new Sub-processor, you may notify Company within 10 days of that notice; the parties will work in good faith to resolve the objection, and if they cannot, you may terminate the portion of the Service that relies on that Sub-processor as your sole remedy.
Company will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA with respect to End User Data, and remains responsible for each Sub-processor's performance of those obligations.
7. International Transfers#
End User Data is currently Processed in the United States. Where the transfer of End User Data from the EEA, UK, or Switzerland to Company in the United States is subject to Data Protection Laws requiring a specific transfer mechanism, the Standard Contractual Clauses are incorporated into this DPA by reference, with Company as "data importer" and you as "data exporter," Module Two (Controller to Processor) applying, and Annex 1 (comprising the List of Parties, Description of Transfer, and Competent Supervisory Authority), Annex 2 (Technical and Organisational Security Measures), and Annex 3 (List of Sub-processors) to this DPA serving as the corresponding Annex I, Annex II, and Annex III to the Standard Contractual Clauses, respectively. The official text of the Standard Contractual Clauses is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.
8. Assistance With Data Subject Requests#
Taking into account the nature of the Processing, Company will provide reasonable assistance to help you respond to requests from Data Subjects to exercise their rights under Data Protection Laws (such as access, correction, deletion, or portability requests), including by providing self-service tools where available in the Service, or by carrying out a request you direct through [email protected]. If a request is manifestly unfounded, excessive, or requires disproportionate effort, Company may charge a reasonable fee reflecting its administrative cost, which it will disclose to you in advance.
9. Security Incident Notification#
Company will notify you without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting End User Data, except where providing notice within that timeframe is not reasonably feasible (for example, because the scope of the incident is still being determined), in which case Company will notify you as soon as reasonably practicable and will keep you reasonably informed as its investigation progresses.
Company's notification will describe, to the extent then known, the nature of the Security Incident, the categories and approximate number of Data Subjects and records affected, and the measures taken or proposed to address it. You are responsible for making any notifications to Data Subjects or regulators that Data Protection Laws require of you as Controller.
10. Data Protection Impact Assessments#
Taking into account the nature of Processing and information available to Company, Company will provide reasonable assistance to you in connection with any data protection impact assessment, or prior consultation with a supervisory authority, that you reasonably determine is required by Data Protection Laws with respect to your use of the Service.
11. Deletion and Return of End User Data#
Company's ordinary retention practices for End User Data are described in the Privacy Policy. In addition to those practices, upon your verified written request specifically identifying the End User Data to be deleted or returned, Company will delete or, at your election, provide a copy of that End User Data within 30 days of the request, except to the extent Company is required to retain it under applicable law or Section 12 (Term and Termination) of the Terms of Service.
Deleting your Account revokes API access immediately; the deletion or return of specific End User Data under this Section is a separate process handled through the request described above.
12. Audits#
On reasonable request, no more than once every 12 months, Company will make available to you information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a written questionnaire response, a summary of the security measures in Annex 2, or an equivalent report, at Company's discretion.
If a written response is not sufficient to satisfy a legal or regulatory audit requirement that applies to you, Company will discuss with you a mutually agreeable audit process, which may include a remote or on-site audit conducted by you or an independent third party, subject to at least 30 days' prior written notice, reasonable confidentiality protections, and reimbursement of Company's reasonable costs. Any audit will be conducted in a manner that minimizes disruption to Company's operations and to the confidentiality of Company's other customers' data.
13. Liability#
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitation of liability set out in the Terms of Service, applied in the aggregate and not per-incident, except to the extent applicable Data Protection Laws prohibit such limitation.
14. Term and Termination#
This DPA takes effect when it first applies to your Processing of End User Data and remains in effect for as long as Company Processes End User Data on your behalf, notwithstanding the termination of the Terms of Service, solely to the extent necessary to give effect to Sections 9, 11, 12, and 13.
15. Governing Law#
This DPA is governed by the same governing law and venue provisions as the Terms of Service.
16. Contact#
Questions about this DPA may be directed to:
Pluto Agent LLC d/b/a Pluto Agent
121 S Broad St.
15th Floor PMB 1166
Philadelphia, PA 19107
[email protected]
Annex 1 — Details of Processing#
A. List of Parties#
Data exporter: The Account Holder, as identified in its Account registration details with Company. Role: Controller.
Data importer: Pluto Agent LLC d/b/a Pluto Agent, 121 S Broad St., 15th Floor PMB 1166, Philadelphia, PA 19107. Contact: [email protected]. Role: Processor.
The Parties agree that acceptance of the Terms of Service by the Account Holder constitutes execution of this Annex I.A (List of Parties) for purposes of the Standard Contractual Clauses, in lieu of a separate signature page for each Account Holder.
B. Description of Transfer#
| Item | Description |
|---|---|
| Subject matter | Company's provision of the Pluto Agent platform to Account Holder, and the Processing of End User Data that results from Account Holder's configuration and use of Agent Builds. |
| Duration | For as long as Company Processes End User Data on Account Holder's behalf under the Terms of Service, as described in Section 14 of this DPA. |
| Nature and purpose of Processing | Receiving, storing, and processing End User messages and related context to generate Agent responses; storing conversation history to maintain context across a session; executing Account Holder-configured Tools that may retrieve End User-related records from third-party systems Account Holder controls; logging requests and responses for operation, security, and billing of the Service. |
| Categories of Data Subjects | End Users of Account Holder's Agent Builds — i.e., the individuals who interact with Account Holder's product or application. |
| Categories of Personal Data | Determined by Account Holder based on what it configures its application and Agent Build to submit. May include End User messages (free text), any additional context Account Holder's application attaches about the End User, records retrieved from a third-party application Account Holder connects via a Tool, and technical identifiers such as a session identifier. Company does not require or request any special category of Personal Data (as defined under GDPR Article 9) and Account Holder should not submit special category data through the Service. |
| Frequency of transfer | Continuous, for as long as Account Holder's Agent Builds are in use. |
C. Competent Supervisory Authority#
The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses: (a) where the data exporter is established in an EU Member State, the supervisory authority of that Member State; (b) where the data exporter is not established in an EU Member State but has appointed a representative pursuant to Article 27(1) of the GDPR, the supervisory authority of the Member State in which that representative is established; or (c) where the data exporter is not established in an EU Member State and is not required to appoint such a representative, the supervisory authority of the Member State in which the data subjects whose personal data is transferred are located.
Annex 2 — Technical and Organizational Security Measures#
Company implements the following measures, as they may be updated from time to time provided the update does not materially decrease the overall level of protection:
- Encryption in transit for data sent to and from the Service using industry-standard protocols (TLS).
- Access to production systems and infrastructure consoles is restricted to authorized personnel on a least-privilege basis.
- Account authentication is handled through a dedicated, managed authentication provider rather than Company's own credential storage.
- Tool credentials and other secrets supplied by Account Holders are stored in a restricted-access configuration store, separate from ordinary application data, and are not returned to the browser once stored.
- Logging and monitoring of production systems, including automated alerting for operational and security anomalies.
- Infrastructure is hosted with established cloud infrastructure providers that maintain their own independent security and compliance programs.
- Backups are maintained for a limited retention period to support disaster recovery, consistent with the retention practices described in the Privacy Policy.
- New Sub-processors are evaluated for their data protection and security practices before engagement.
Annex 3 — Sub-processors#
As of the date of this DPA, Company engages the following Sub-processors to Process End User Data. An up-to-date list is also maintained in the Privacy Policy.
| Sub-processor | Purpose | Location of Processing |
|---|---|---|
| Cloud infrastructure provider — Amazon Web Services, Inc. (AWS) | Compute, storage, logging, and monitoring for the Service | United States |
| API gateway / portal hosting provider — Zuplo, Inc. | Hosting the developer portal and routing API requests | United States |
| Content delivery / network security provider — Cloudflare, Inc. | Front-line network routing and security | Global network, United States processing |
| Authentication provider — Clerk, Inc. | Account sign-up, login, and session management | United States |
| AI Model Provider — Google LLC (Gemini) | Generating Agent responses from End User prompts and Agent Build instructions | United States |
| Third-party application connected via a Tool | Only where Account Holder configures a Tool to read from an application or database it controls | As determined by Account Holder's own configuration |