Legal

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Blackbelt Labs OÜ ("Blackbelt Labs") and the customer of the Daslab service ("Customer"). It governs the processing of personal data that Customer submits to the Service.

It applies from the date Customer's account was created. Execution below produces a countersigned copy naming Customer's entity and does not alter the date from which the obligations apply.

Version 1.0 · September 2026 · Blackbelt Labs OÜ, Narva mnt 5, 10117 Tallinn, Estonia

Summary

Location and Sub-Processors

The application and the database operate in Frankfurt, Germany. Object storage is located in the European Union. Four sub-processors are engaged for all customers; three further sub-processors are engaged only where the relevant feature is used. The controlling list is Annex III below.

A row-by-row account of what is held where, on Daslab Cloud and on Customer-operated servers, is published at daslab.run/security.

Engaged for all customers

Sub-processorProcessing performedPersonal data accessibleLocation
Render Services, Inc.ISO 27001, SOC 2 Type II, EU-US Data Privacy Framework Runs the application and the database Everything in transit, and at rest the scene record, accounts, and connected credentials as ciphertext Frankfurt, Germany
Cloudflare, Inc.SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS Object storage for files a scene writes out, and video streaming for a scene that uses it Files and media uploaded or published by Customer or its agents European Union
Upstash, Inc.SOC 2 (Pro and Enterprise plans) Cache and queues Short-lived job state, sign-in state, and audio while it uploads Frankfurt, Germany
Resend, Inc.SOC 2 Type II Transactional email Recipient address and message body Ireland. The contracting entity is established in the United States

Engaged only where the relevant feature is used

Engaged only where the relevant feature is used. A workspace that does not use the feature is not processed by the sub-processor listed against it.

Sub-processorProcessing performedPersonal data accessibleLocation
Apple Inc.Only when a member of the workspace uses the app. Push notifications to the app The notification's title and body, which carry the message being announced United States
LiveKit, Inc.SOC 2 Type II, EU-US Data Privacy FrameworkOnly when a scene uses live video. Live video The stream itself United States and European Union
Model providers selected by CustomerOnly when the workspace uses Blackbelt Labs' model credentials rather than its own. Answering prompts The content of the prompts submitted by Customer's workspace Per provider, listed at daslab.run/models

Kept current at daslab.run/subprocessors. We give 30 days notice before this list changes.

Terms

Clauses

1Relationship of the Parties

Customer is the controller and Blackbelt Labs OÜ ("Blackbelt Labs") is the processor in respect of Personal Data that Customer submits to the Service. Blackbelt Labs processes such Personal Data solely to provide the Service to Customer.

This DPA applies from the date Customer's account was created. Execution of this DPA produces a countersigned copy for Customer's records and does not alter the date from which the obligations apply.

Blackbelt Labs acts as a controller in respect of account registration, billing and operation of the Service. That processing is described in the privacy notice and is not governed by this DPA.

2Scope and Instructions

Blackbelt Labs processes Personal Data only on Customer's documented instructions. Customer's instructions comprise this DPA, the Terms of Service, and Customer's configuration and use of the Service.

Where Blackbelt Labs is required by applicable law to process Personal Data other than on Customer's instructions, it will inform Customer before processing, unless that law prohibits such notification.

Blackbelt Labs will inform Customer if, in its opinion, an instruction infringes applicable data protection law.

Blackbelt Labs does not sell Personal Data and does not use the contents of Customer's scenes to train models.

3Confidentiality

Access to Personal Data is restricted to personnel who require access in order to provide the Service. Such personnel are bound by confidentiality obligations that survive the termination of their engagement.

4Security of Personal Data

Blackbelt Labs implements the technical and organisational measures set out in Annex II and will not materially reduce them during the term of this DPA.

Measures that are not implemented are stated in Annex II rather than omitted from it.

5Sub-Processors

Customer grants general authorisation for Blackbelt Labs to engage the sub-processors listed in Annex III, which is maintained at daslab.run/subprocessors.

Blackbelt Labs will give Customer 30 days notice before appointing or replacing a sub-processor. If Customer objects within that period, Blackbelt Labs will either refrain from the change in respect of Customer's Personal Data or, where that is not reasonably possible, Customer may terminate the affected part of the Service and receive a refund of the unused portion of any prepaid fees.

Each sub-processor is bound by data protection obligations no less protective than those set out in this DPA. Blackbelt Labs remains liable to Customer for the performance of each sub-processor.

6Rights of Data Subjects

Customer may access, export, rectify and delete Personal Data directly within the Service.

Where Customer is unable to do so, Blackbelt Labs will provide reasonable assistance with requests by data subjects to exercise rights of access, rectification, erasure, restriction of processing, portability and objection, taking into account the nature of the processing.

Where a data subject contacts Blackbelt Labs directly, Blackbelt Labs will not respond on Customer's behalf and will forward the request to Customer without undue delay.

7Personal Data Breaches

Blackbelt Labs will notify Customer of a personal data breach affecting Customer's Personal Data without undue delay and in any event within 72 hours of becoming aware of it.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the measures taken or proposed, and recommended actions. Where the information is not available at the time of notification, it will be provided in phases as it becomes available.

Security issues may be reported to security@daslab.run. Blackbelt Labs responds within two working days and states the action taken.

8Data Protection Impact Assessments

Blackbelt Labs will provide reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, limited to information concerning its processing that is not otherwise available to Customer.

9Return and Deletion of Personal Data

On termination, Customer may export Personal Data for a period of 30 days. Blackbelt Labs will delete it earlier at Customer's written request.

Following that period, Blackbelt Labs deletes Personal Data. Deletion of a scene removes its contents and prunes the commit chain that referenced them. Erasure of a workspace removes its scenes, its credentials and its machines' tokens.

Copies may persist in backups for up to 7 days following deletion, after which they age out. Blackbelt Labs does not restore backups in order to recover deleted data.

Blackbelt Labs retains Personal Data where required to do so by applicable law, including billing records.

10Audit and Information

Blackbelt Labs will make available to Customer the information necessary to demonstrate compliance with this DPA.

Customer may audit Blackbelt Labs once in any twelve month period, on 30 days written notice, at Customer's cost, during business hours, without unreasonable disruption to the Service, and subject to confidentiality. Blackbelt Labs may provide an equivalent third-party report in place of an on-site audit.

Information covering much of this scope is published at daslab.run/security, and a number of the measures in Annex II are implemented in publicly available source code.

11Transfers of Personal Data

Blackbelt Labs is established in the European Union and the Service operates in Frankfurt, Germany. Personal Data submitted by Customer is processed there.

The standard contractual clauses adopted by the European Commission under Implementing Decision (EU) 2021/914, module two (controller to processor), are incorporated into this DPA by reference and apply to any transfer of Personal Data that is subject to a cross-border transfer restriction under applicable data protection law. This DPA, together with its Annexes, constitutes their appendices.

Part A of Annex IV states the mechanism relied on for each regime. Part B states the onward transfers made by Blackbelt Labs in providing the Service.

If a transfer mechanism is invalidated, superseded or amended by a competent authority, Blackbelt Labs will implement the replacement mechanism without undue delay.

12Region-Specific Terms

United Kingdom. Where the UK GDPR applies, the International Data Transfer Addendum to the EU standard contractual clauses, issued under section 119A of the Data Protection Act 2018, applies to the transfer and forms part of this DPA.

Switzerland. Where the Swiss Federal Act on Data Protection applies, the standard contractual clauses apply as amended in accordance with guidance of the Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP, the competent supervisory authority is the FDPIC, and data subjects in Switzerland may enforce their rights in Switzerland.

Thailand. Where the Personal Data Protection Act B.E. 2562 applies, the transfer relies on appropriate safeguards under section 28 of that Act, constituted by the standard contractual clauses incorporated under clause 11.

United States. Where a state privacy law applies, Customer is the business or controller and Blackbelt Labs is the service provider or processor. Blackbelt Labs does not sell or share Personal Data, does not retain, use or disclose it for any purpose other than performing the Service, and does not combine it with Personal Data received from another source except as permitted by that law.

Other jurisdictions. Where any other applicable law restricts cross-border transfer and recognises contractual safeguards, the standard contractual clauses incorporated under clause 11 constitute those safeguards.

13Precedence, Amendment and Liability

In respect of Personal Data, this DPA prevails over the Terms of Service to the extent of any conflict.

Blackbelt Labs may amend this DPA. Material amendments will be notified 30 days in advance to the address recorded on Customer's countersigned copy. That copy records the version Customer agreed. The current version is published at daslab.run/dpa.

Liability under this DPA is subject to the limitations of liability in the Terms of Service, except to the extent applicable law does not permit such limitation.

Annex I

Details of the Processing

Subject matterProvision of the Daslab platform: scenes, the agents that run within them, the systems those agents connect to, and the record of the actions taken.
DurationFor the duration of Customer's account, plus the deletion period in clause 9.
Nature and purposeStorage, structuring, retrieval, transmission and deletion of Personal Data so that Customer's personnel and its agents can work with it, and transmission of that data to the systems and models Customer connects.
Types of personal dataAs determined by Customer. In practice: names, email addresses, telephone numbers and messaging identifiers; the content of conversations in channels Customer connects, including files and images; contact and transaction records Customer imports; and the identities of Customer's personnel.
Categories of data subjectCustomer's customers and other persons who contact Customer, Customer's employees and contractors, and the contacts held in the systems Customer connects.
Special category dataNot required by the Service. Customer shall not submit special category data without first notifying Blackbelt Labs, so that the additional measures required by law can be agreed.
FrequencyContinuous, for the duration of Customer's use of the Service.
Annex II

Technical and Organisational Measures

Each measure listed is implemented as at the version stated above. Where a measure carries a reference, it can be verified independently. The final row states the measures that are not implemented.

Location of processingThe application and the database operate in Frankfurt, Germany. Object storage is located in the European Union. Check it →
Encryption in transitTLS on every connection to the Service and to every sub-processor.
Encryption of connected credentialsCredentials for systems Customer connects are encrypted under a key held outside the database and decrypted within the process executing the relevant job, for that job only. A copy of the database does not constitute a copy of the credentials. Check it →
Scoping of credentialsA scene's compute instance receives only the credentials linked to that scene. It does not receive other credentials held by the workspace, nor any user's authentication token. Check it →
Access controlRoles are owner, admin, member and viewer. A layer may be restricted to named individuals, including exclusion of administrators. Enforcement occurs at the write operation, so an unauthorised action is refused rather than concealed. Check it →
AuthenticationApple, Google, GitHub, email, API keys, OAuth for MCP clients, and SAML with SCIM provisioning. De-provisioning in Customer's directory revokes sessions and API keys in the Service. Check it →
Isolation of code executionCode executes in a per-scene sandbox with no access to another scene. Execution may be disabled for a scene or for an entire workspace.
Outbound traffic policyA machine paired by Customer carries a policy for outbound traffic: open, an allowlist defined by Customer, or closed. The policy is enforced by the machine, so it can be verified where it runs. Check it →
Share linksA share link is an HMAC over the shared resource and a counter. No per-link record exists. Resetting the counter revokes every link previously issued for that resource.
LoggingEach tool invocation is recorded as an OpenTelemetry span identifying the actor, scene, job, tool, duration and cost. Spans may be directed to an endpoint nominated by Customer.
BackupsManaged PostgreSQL with daily backups and point-in-time recovery, retained 7 days.
Customer-operated deploymentThe Service may be operated by Customer as a single binary against Customer's PostgreSQL, object storage and model credentials, in which case none of the above is performed by Blackbelt Labs. Check it →
Measures not implementedCustomer-managed encryption keys are not available. The equivalent control is Customer-operated deployment, described in the row above.
Annex III

Sub-Processors

As listed above, and maintained at daslab.run/subprocessors.

Annex IV

International Transfers

Part A · Mechanism relied on, by regime

RegimeApplicable lawMechanism
European Economic AreaGDPR (EU) 2016/679Blackbelt Labs is established in Estonia and the Service operates in Germany, so processing of Customer Personal Data takes place within the Union and no transfer mechanism is required for it. The standard contractual clauses, module two, apply to the onward transfers in Part B.
United KingdomUK GDPR and Data Protection Act 2018Standard contractual clauses, module two, together with the International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018.
SwitzerlandFederal Act on Data ProtectionStandard contractual clauses, module two, as amended in accordance with guidance of the Federal Data Protection and Information Commissioner.
ThailandPersonal Data Protection Act B.E. 2562Appropriate safeguards under section 28, constituted by the standard contractual clauses incorporated under clause 11.
United StatesState privacy laws, including the CCPA as amendedNo cross-border transfer restriction applies. Blackbelt Labs acts as a service provider or processor on the terms in clause 12.
Any other jurisdictionApplicable local data protection lawWhere that law restricts cross-border transfer and recognises contractual safeguards, the standard contractual clauses incorporated under clause 11 constitute those safeguards.

Part B · Onward transfers made by Blackbelt Labs

RecipientPurposeLocationMechanism
Resend, Inc.Transactional emailIrelandProcessing takes place within the Union. The standard contractual clauses apply to any access from the United States by the contracting entity
Apple Inc.Push notifications to the appUnited StatesStandard contractual clauses, module two
LiveKit, Inc.Live video, where a scene uses itUnited States and European UnionCertified under the EU-US Data Privacy Framework. Standard contractual clauses, module two, apply in addition for processing outside the Union
Model providers selected by CustomerProcessing prompts submitted by CustomerPer provider, listed at daslab.run/modelsThe provider's own terms, accepted by Customer on connection. Where Customer supplies its own credentials, no transfer is made on Blackbelt Labs' account

Customer Personal Data is processed in Frankfurt, Germany. Part B lists every transfer of it beyond that location made by Blackbelt Labs in providing the Service.

Execution

Signature

Complete the fields below to execute this DPA. A countersigned copy naming Customer's entity, recording version 1.0, is sent to the address given.

By executing this DPA the signatory confirms authority to do so on behalf of the entity named. Blackbelt Labs records the entity, the signatory and the time of execution, and uses the address given to deliver the countersigned copy and to give notice under clauses 5 and 12.

Questions concerning this DPA: privacy@daslab.run. Answered in writing within two working days.