Placeholder — Pending Legal Review

This document is a placeholder pending legal review. Do not rely on it for legal purposes.

Data Processing Agreement

Last updated: June 25, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between AutomateCC (“Processor”) and the Customer (“Controller”) and applies to the processing of personal data under applicable data protection law, including the General Data Protection Regulation (GDPR).

1. Controller and Processor Roles

The Customer acts as the Data Controller, determining the purposes and means of processing personal data. AutomateCC acts as the Data Processor, processing personal data solely on behalf of and under the instructions of the Controller.

AutomateCC will process personal data only as necessary to provide the Service and will not process personal data for any purpose beyond the scope of the Controller’s instructions unless required by applicable law.

2. Security Measures

AutomateCC implements and maintains appropriate technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:

3. Sub-Processors

AutomateCC uses the following categories of sub-processors to deliver the Service:

A current list of sub-processors is available upon request. AutomateCC will provide 30 days’ notice before adding new sub-processors, giving the Controller the opportunity to object.

4. GDPR Compliance Contact

For all GDPR-related inquiries, data subject requests, or to exercise your rights under applicable data protection law, please contact our Data Protection contact at:

AutomateCC Data Protection
dpa@automatecc.com