Data processing agreement

Not yet offered, and here is exactly why.

Current version. Creobot opens to teams in order. Last updated 15 August 2026. This page is revised as things are settled. It is not legal advice. Items marked as not finalised are genuinely undecided rather than withheld, and they are published as they are settled.

Status: not yet offered

We do not currently offer a data processing agreement, because the terms that would sit in one are not settled. Publishing a DPA that references providers, retention periods and processing regions we have not confirmed would be worse than publishing nothing.

What a DPA would need to specify

When we do offer one, it will have to state at minimum:

  • The roles of each party under applicable data protection law.
  • The categories of personal data processed and the purposes.
  • The full subprocessor list and how changes to it are notified.
  • Retention and deletion terms, including how deletion propagates to subprocessors.
  • The processing location.
  • Security measures.
  • Audit and assistance obligations.
  • International transfer mechanisms where relevant.

Every one of those is currently open

That is the honest position today. We would rather say so than produce a template with plausible values filled in.

If you need one to evaluate us

Tell us what your requirements are. That information is useful to us while these terms are being decided, and it is better input than guessing at what buyers will need.

Not legal advice

Nothing on this page is legal advice. A DPA is a contract and it should be reviewed by a lawyer in your jurisdiction before you rely on it.

Trust

A DPA is planned, not signed

There is no signed data processing agreement today. It is planned before paid rollout, and saying so beats pointing at a template.