Data Processing Addendum
Template — effective June 4, 2026. This DPA forms part of the Terms of Service when ExecOS processes personal data on a customer's behalf in connection with the service.
1. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", and "Processing" have the meanings given in the GDPR. "Customer" is the entity that subscribes to ExecOS. "We" or "ExecOS" act as Processor in respect of Customer Personal Data.
2. Subject matter and duration
We process Personal Data only to provide the service for the duration of the Customer's subscription and as instructed through Customer's use of the service.
3. Nature and purpose of processing
Hosting, storage, retrieval, generation of AI-assisted summaries, transactional email, and any other processing reasonably necessary to operate the features the Customer enables.
4. Categories of Data Subjects and Personal Data
- Data Subjects: Customer's employees, contractors, executives, and the contacts they record.
- Personal Data: names, business email addresses, calendar entries, meeting notes, contact details, and any content Customer chooses to upload.
5. Processor obligations
- Process Personal Data only on documented Customer instructions.
- Ensure personnel authorised to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Schedule 1).
- Assist Customer in responding to Data Subject requests via the in-product export and delete tools.
- Notify Customer without undue delay (and in any event within 72 hours) of a confirmed Personal Data Breach.
- Delete or return Personal Data at the end of the service, subject to legal retention requirements.
6. Sub-processors
Customer authorises ExecOS to engage the sub-processors below. We will give 30 days' notice of additions or changes; the Customer may object on reasonable data-protection grounds.
- Supabase, Inc. — managed Postgres, authentication, file storage (EU/US).
- Cloudflare, Inc. — edge runtime, DNS, CDN (global).
- Lovable AI Gateway — routing of AI inference requests (US).
- Stripe, Inc. — subscription billing and payment processing (US/EU).
- Google LLC — Calendar, Gmail, Drive workspace integrations; engaged only when an executive connects their own Google account (US/EU).
- Slack Technologies, LLC — workspace messaging integration; engaged only when a workspace admin connects Slack (US).
- Email delivery provider — transactional email for authentication, invites, and billing receipts (US/EU).
7. International transfers
Where Personal Data is transferred outside the EEA/UK, transfers rely on the European Commission's Standard Contractual Clauses (2021/914) or an equivalent UK mechanism.
8. Audits
On reasonable notice and no more than once per year, Customer may request information needed to demonstrate compliance with this DPA. Independent third-party reports may be provided in lieu of on-site audits.
9. Liability
Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service.
Schedule 1 — Security measures
- Encryption in transit (TLS 1.2+) and at rest (managed database provider).
- Row-level security policies enforcing per-workspace tenant isolation.
- Role-based access via a dedicated
user_rolestable and security-definer checks. - Server-only service-role credentials; never shipped to browsers.
- Audit logging of sensitive workspace actions (role changes, invites, deletions, exports).
- Least-privilege admin access and quarterly access reviews.
- Per-executive OAuth tokens (Google, Slack) stored encrypted at rest; assistant access to each executive's integrations is explicit, revocable, and audited.
Schedule 2 — Integrations and scopes
The following scopes are requested only when an executive (or, for Slack, a workspace admin) elects to connect the integration. Tokens are scoped per executive, encrypted at rest, and revocable from Settings → Integrations.
- Google Calendar —
calendar.events,calendar.readonly. Surface meetings in the executive's dashboard and create/update events scheduled through ExecOS. - Gmail —
gmail.send,gmail.modify. Send follow-ups from the executive's address and mark triaged inbox items as handled. Full-mailbox reads are not performed. - Google Drive —
drive.file(restricted). ExecOS only accesses files it creates or files the user explicitly opens with it. - Slack —
chat:write,channels:read. Post digests and notifications to admin-selected channels.
Customer content obtained through these integrations is never used to train third-party models. Revocation by the Customer or end user immediately stops further use of the relevant scopes.
10. Signing & contact
To execute this DPA, email legal@execos.app with your company name, billing email, and ExecOS workspace ID. We return a counter-signed copy within 5 business days. For data-protection questions, breach notifications, or sub-processor objections, contact privacy@execos.app.