This Data Processing Addendum ("DPA") applies where DT LEVEL 7 TECHNOLOGY LIMITED ("Processor", "we") processes personal data on behalf of a Customer ("Controller", "you") in providing Bob — CmdOS by LEVEL7. It forms part of, and is incorporated into, our Terms of Service. Where you act as a controller of personal data your Agents process, this DPA governs that processing under Article 28 GDPR.
For Customer Content that Agents process on your behalf, you are the controller (or processor for your own customer) and we are your processor (or sub-processor). For account, billing and product data we are an independent controller, governed by our Privacy Policy.
We process Customer personal data only on your documented instructions — which include the Terms, this DPA, your configuration of the Service, and your use of its features — and as required by law (in which case we will inform you unless legally prohibited).
We ensure that personnel authorised to process Customer personal data are bound by confidentiality obligations.
We implement appropriate technical and organisational measures, including encryption in transit, AES-256-GCM encryption of stored third-party credentials, workspace isolation, access controls and audit logging, taking into account the state of the art and the risks of processing.
You grant general authorisation for us to engage the sub-processors listed at https://getbob.thelevel7.ai/legal/subprocessors. We impose data-protection obligations on them no less protective than this DPA and remain responsible for their performance. We will give notice of changes so you may object on reasonable data-protection grounds.
Where we transfer Customer personal data outside the EEA/UK, we rely on adequacy decisions or Standard Contractual Clauses with supplementary measures. EU/EEA/UK Customer Content is processed via Anthropic only and not via MiniMax.
Taking into account the nature of processing, we will assist you with data-subject requests, security, breach notification, and data-protection impact assessments and prior consultations, in each case to the extent applicable and reasonable.
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer personal data, with the information you reasonably need to meet your own notification obligations.
On termination, and on your request, we will delete or return Customer personal data in accordance with the retention periods in our Privacy Policy, except where law requires us to retain it.
We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and frequency limits.
For a countersigned copy of this DPA or data-protection enquiries, contact privacy@thelevel7.ai.