Data Processing Agreement
Need a signed DPA?
Contact us to execute a Data Processing Agreement for your organization.
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Agreement") between Skuld, LLC ("Skuld", "Processor", "we", "us") and the customer ("Controller", "you", "your") that has executed an Agreement with Skuld for the provision of SkuldBot enterprise automation platform services (the "Services").
Important scope note: Skuld does not host, access, or Process the business data your automations operate on — including any Personal Data about your own customers, clients, or patients — in any subscription, regardless of size. That data remains, and is Processed, entirely within your own infrastructure or environment. This DPA governs only the limited Personal Data Skuld does Process on your behalf: your automation configuration (prompts, workflow code, connector settings) and account/telemetry data about your use of the Services, as detailed in Section 3.
This DPA reflects the parties' agreement with regard to the Processing of Personal Data in accordance with the requirements of applicable Data Protection Laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable privacy laws.
2. Definitions
- "Controller" means the entity that determines the purposes and means of Processing Personal Data.
- "Data Protection Laws" means all applicable laws relating to data protection and privacy, including GDPR, CCPA, and other applicable regulations.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is Processed.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion.
- "Processor" means an entity that Processes Personal Data on behalf of the Controller.
- "Sub-processor" means any third party engaged by Processor to Process Personal Data on behalf of Controller.
- "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
3. Scope and Roles
3.1 Scope
This DPA applies only to the Personal Data Skuld actually Processes on behalf of the Controller: automation configuration data (prompts, workflow code, connector settings, and related metadata) and account/telemetry data describing use of the Services. It does not apply to, and Skuld does not Process, the business data an automation operates on, including any Personal Data about the Controller's own customers, clients, or patients — that data is Processed entirely within the Controller's own infrastructure and is never received, hosted, or stored by Skuld, in any subscription tier. The subject matter, duration, nature, and purpose of Processing, and the types of Personal Data and categories of Data Subjects actually within Skuld's scope, are described in Annex 1.
3.2 Roles of the Parties
The Controller determines the purposes and means of Processing Personal Data, including any Personal Data an automation operates on within the Controller's own infrastructure. Skuld acts as a Processor only for the limited automation-configuration and telemetry data described in Section 3.1, Processing it only on documented instructions from the Controller.
4. Controller Obligations
The Controller shall:
- Ensure it has a lawful basis for Processing Personal Data
- Provide clear and documented instructions for Processing
- Ensure compliance with Data Protection Laws in its use of the Services
- Respond to Data Subject requests and notify Skuld when assistance is required
- Implement appropriate security measures in its systems
- Notify Skuld of any changes to Processing requirements
5. Processor Obligations
Skuld shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure persons authorized to Process Personal Data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Respect conditions for engaging Sub-processors
- Assist the Controller in responding to Data Subject requests
- Assist the Controller in ensuring compliance with security, breach notification, DPIAs, and prior consultation obligations
- Delete or return all Personal Data upon termination, at Controller's choice
- Make available information necessary to demonstrate compliance
6. Security Measures
Skuld implements and maintains appropriate technical and organizational measures to protect Personal Data, including:
Encryption
AES-256 encryption at rest, TLS 1.3 in transit
Access Controls
Role-based access control, multi-factor authentication, least privilege principle
Monitoring
Comprehensive logging, anomaly detection, security monitoring
A full description of our security measures is available in our Security documentation.
7. Sub-processors
7.1 Authorization
The Controller provides general authorization for Skuld to engage Sub-processors. A current list of Sub-processors is available on request, and Skuld will provide at least 30 days' notice before adding a new Sub-processor.
7.2 Objection to Sub-processors
The Controller may object to the addition of a new Sub-processor within 14 days of receiving notice. If an objection is raised, the parties will work in good faith to resolve the concern. If no resolution is reached, the Controller may terminate the affected Services.
8. Data Subject Rights
Skuld will assist the Controller in responding to requests from Data Subjects exercising their rights under Data Protection Laws, including:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of Processing
- Right to data portability
- Right to object
If Skuld receives a request directly from a Data Subject, we will promptly notify the Controller unless prohibited by law.
9. Personal Data Breach
In the event of a Personal Data Breach, Skuld will:
- Notify the Controller without undue delay and within 48 hours of becoming aware
- Provide details of the nature of the breach, categories and approximate number of Data Subjects affected, and likely consequences
- Describe measures taken or proposed to address the breach and mitigate potential adverse effects
- Cooperate with the Controller in investigating and remediating the breach
- Assist the Controller in meeting its breach notification obligations to supervisory authorities and Data Subjects
10. International Data Transfers
When Personal Data is transferred outside the European Economic Area (EEA), UK, or Switzerland to a country not providing adequate protection, Skuld ensures appropriate safeguards through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreement or Addendum where applicable
- Supplementary measures where required by applicable law
The applicable SCCs are incorporated into this DPA by reference.
11. Audits
Skuld will make available to the Controller information necessary to demonstrate compliance with this DPA. The Controller may conduct audits, subject to:
- 30 days' prior written notice
- Reasonable scope and duration
- Confidentiality obligations
- Scheduling during normal business hours to minimize disruption
- Controller bearing audit costs (unless audit reveals material non-compliance)
Skuld's security control documentation, designed to align with SOC 2 criteria, may be provided in lieu of certain audit requests.
12. Data Retention and Deletion
Upon termination of the Agreement or upon Controller's request:
- Skuld will delete or return all Personal Data within 90 days, at Controller's choice
- Controller's data remains under Controller's control in accordance with the applicable deployment model
- Metadata and configuration data will be deleted from Skuld systems
- Retention may continue where required by applicable law
13. HIPAA Addendum
Skuld's architecture ensures Skuld never receives, hosts, or Processes Protected Health Information (PHI) — PHI stays within the Controller's own infrastructure at all times, regardless of subscription tier. For Controllers who require a Business Associate Agreement (BAA) as a contractual matter, Skuld will discuss executing one; the BAA reflects this architecture rather than describing Skuld as a party that Processes PHI. Where applicable, it addresses:
- Use and disclosure limitations
- Safeguards for PHI
- Breach notification requirements
- Sub-contractor flow-down requirements
Contact us to discuss executing a BAA before Processing PHI.
Annex 1: Processing Details
Subject Matter of Processing
Provision of the SkuldBot control plane and orchestration platform: managing automation configuration (prompts, workflow code, connector settings) and account/telemetry data. Skuld does not Process the business data an automation operates on.
Duration
Duration of the Agreement plus retention period
Nature and Purpose
Collection, storage, and deletion of automation configuration and account/telemetry data as directed by Controller through the Services. Skuld does not collect, store, transform, or transfer the business data Controller's automations operate on within Controller's own infrastructure.
Types of Personal Data
Account and platform-user data (names, emails, and roles of Controller's own personnel authorized to access the Services) and telemetry/system-health data describing automation runs. Does not include Personal Data about Controller's own customers, clients, patients, or other end users — Skuld never receives that data, in any subscription tier.
Categories of Data Subjects
Controller's own personnel and authorized users of the Services. Does not include Controller's customers, clients, patients, or other end users of Controller's business — Skuld never receives Personal Data about those individuals.
14. Contact
For questions about this DPA or to request a signed copy: