agentspeed.

Data Processing Addendum

Last updated: June 28, 2026

This DPA applies where AgentSpeed processes personal data in your telemetry on your behalf. Because AgentSpeed is metadata-first, the personal data involved is minimal by design.

1. Scope and roles

This Data Processing Addendum (“DPA”) forms part of the agreement between you (the “Customer,” acting as data controller) and Vantlir LLC, a Delaware limited liability company, which operates the AgentSpeed service (“AgentSpeed,” acting as data processor), and applies where AgentSpeed processes personal data contained in Customer Data on the Customer’s behalf.

In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.

2. Subject matter, duration, nature, and purpose

The subject matter is the provision of the AgentSpeed Service. The duration is the term of the agreement plus any retention period described in the Privacy Policy. The nature and purpose of processing is to receive, store, analyze, and display agent run telemetry so the Customer can monitor and operate its AI agents.

3. Types of personal data and data subjects

AgentSpeed is metadata-first: the ingest contract has no field for prompt or output content, content keys are stripped, and unknown keys are rejected. As a result, personal data within Customer Data is expected to be minimal and incidental (for example, an identifier the Customer chooses to place in an agent or run name). Data subjects are the individuals (if any) to whom such incidental data relates, as determined by the Customer.

4. Customer instructions

AgentSpeed will process personal data only on the Customer’s documented instructions, including those set out in the agreement and this DPA, unless required by law. AgentSpeed will inform the Customer if it believes an instruction violates applicable data-protection law.

5. Confidentiality

AgentSpeed ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations.

6. Security

AgentSpeed implements appropriate technical and organizational measures to protect personal data, as described in Annex II below and in our Privacy Policy, taking into account the state of the art, the costs of implementation, and the risks of the processing.

7. Sub-processors

The Customer provides general authorization for AgentSpeed to engage the sub-processors listed on our Sub-processors page. AgentSpeed imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for their performance. AgentSpeed will give notice of new sub-processors and a reasonable opportunity to object.

8. Assistance to the Customer

Taking into account the nature of the processing, AgentSpeed will provide reasonable assistance to the Customer in responding to data-subject requests and in meeting the Customer’s obligations regarding security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities.

9. Personal data breach

AgentSpeed will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Customer meet its notification obligations.

10. Return and deletion

On termination of the Service, and in line with the retention periods in the Privacy Policy, AgentSpeed will delete or de-identify personal data in Customer Data, except where retention is required by law. The Customer may export available data before termination using the Service’s export features.

11. Audits

AgentSpeed will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, scheduling, and frequency limits.

12. International transfers

Where processing involves transferring personal data out of the EEA or the UK to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses are incorporated into this DPA by reference and apply to that transfer.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

Annex I: Details of processing

Data exporter: the Customer. Data importer: AgentSpeed. Categories of data subjects and personal data: as described in Section 3. Nature and purpose: as described in Section 2. Duration: the term of the agreement plus applicable retention. Sub-processors: as listed on the Sub-processors page.

Annex II: Technical and organizational measures

AgentSpeed maintains measures including:

  • encryption of data in transit;
  • hashing of API keys and sign-in tokens at rest;
  • a metadata-first ingest design that strips content keys and rejects unknown fields, minimizing the personal data processed;
  • access controls and least-privilege access for personnel;
  • per-plan retention with automated deletion; and
  • logging and monitoring for security and abuse detection.

How to execute this DPA

This page is a template made available for transparency. If your organization requires a signed DPA, contact legal@agentspeed.com and we will provide a countersignable copy.