Data Processing Addendum
Default data-processing terms for customer content handled by the standard Almond service.
This addendum is a baseline contract template, not a claim that every deployment or use case is automatically compliant. It applies only when incorporated into an Agreement between the customer and the Almond contracting entity identified there.
1. Roles
For Customer Personal Data, Customer is the controller or processor as applicable, and Almond is the processor or subprocessor. Each party will comply with data protection law applicable to its role. Customer determines the purposes of processing, the data sent to Almond, permitted users and agents, collection fields, public visibility, retention, and the lawfulness of its instructions.
2. Instructions and details
Almond will process Customer Personal Data only to provide, secure, maintain, and support the service; follow documented instructions in the Agreement and product configuration; or comply with law. Processing lasts for the Agreement term and any limited deletion or backup period.
| Subject matter | Lightweight publication, persistence, forms, files, records, revisions, domains, authorization, export, and diagnostics. |
|---|---|
| Data subjects | Customer personnel, collaborators, site visitors, form respondents, and other people whose data Customer submits. |
| Data types | Account data, online identifiers, customer-defined form and record fields, content and files, authorization metadata, and diagnostics. Sensitive or regulated data is not intended unless expressly agreed. |
| Operations | Collection, transmission, organization, storage, retrieval, display, modification, export, restriction, security monitoring, and deletion. |
3. Customer instructions and harness controls
Customer instructs Almond through its users, API and MCP calls, product configuration, and connected agentic harness. Customer is responsible for confirming that people and machines issuing instructions are authorized, limiting scopes, protecting credentials, validating generated schemas and collection fields, and preventing a harness from sending prohibited or unnecessary data. Almond is not required to inspect prompts or infer whether an instruction is legally appropriate.
4. Confidentiality and security
Almond will ensure personnel authorized to process Customer Personal Data are subject to confidentiality duties and will maintain technical and organizational measures appropriate to the service risk. Standard measures include logical tenant separation, scoped and revocable capabilities, digest storage for high-entropy credentials, password hashing, transport encryption through service providers, request bounds, abuse controls, and restricted domain-management credentials.
5. Subprocessors
Customer generally authorizes Almond to use subprocessors to provide the service. Almond remains responsible for imposing data-protection obligations appropriate to their services. The standard categories and currently identified providers are application hosting, compute, database, and storage (Convex); optional identity (Google); and optional managed domain and certificate infrastructure (Amazon Web Services). Almond will provide notice of material new subprocessors through an agreed channel where required by the Agreement.
6. Assistance
Considering the nature of processing and information available to it, Almond will provide reasonable assistance with data-subject requests, security obligations, impact assessments, regulator consultations, and evidence of compliance. Customer is responsible for receiving and validating requests and for costs beyond standard product functionality unless law or a signed agreement provides otherwise.
7. Security incidents
Almond will notify Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data under Almond's control. Notice will include available information reasonably needed for Customer's obligations. Unsuccessful attacks, customer or harness credential exposure outside Almond, and events not involving Customer Personal Data are not Personal Data Breaches under this addendum.
8. Return, deletion, and audits
On termination or valid instruction, Almond will delete or return Customer Personal Data as required by the Agreement, except where law requires retention and subject to backup aging. Exports may not include credentials, sessions, active domain-provider resources, or security data. Almond will make available information reasonably necessary to demonstrate compliance and may satisfy audits through current reports, questionnaires, or a scoped independent review under confidentiality and reasonable limits.
9. Restricted data and transfers
Customer must not submit protected health information, payment-card data, government identification numbers, biometric templates, precise location, children's data, or other sensitive or specially regulated data unless a signed agreement expressly permits it. If a restricted international transfer requires standard contractual clauses or another mechanism, the parties will incorporate the applicable module and supplementary terms in their signed Agreement.
10. Conflict
This addendum controls over conflicting Agreement terms only for processing of Customer Personal Data. Undefined capitalized terms have the meanings in applicable data protection law or the Agreement.