Bob by LEVEL7Back to app

Data Processing Addendum

Last updated 17 June 2026 · v2026-06-17

This Data Processing Addendum ("DPA") applies where DT LEVEL 7 TECHNOLOGY LIMITED ("Processor", "we") processes personal data on behalf of a Customer ("Controller", "you") in providing Bob — CmdOS by LEVEL7. It forms part of, and is incorporated into, our Terms of Service. Where you act as a controller of personal data your Agents process, this DPA governs that processing under Article 28 GDPR.

1. Roles & scope

For Customer Content that Agents process on your behalf, you are the controller (or processor for your own customer) and we are your processor (or sub-processor). For account, billing and product data we are an independent controller, governed by our Privacy Policy.

2. Processing instructions

We process Customer personal data only on your documented instructions — which include the Terms, this DPA, your configuration of the Service, and your use of its features — and as required by law (in which case we will inform you unless legally prohibited).

3. Subject-matter, nature & duration

  • Subject-matter & nature: hosting and processing Content to operate Agents (generating Output, sending messages, running schedules, connecting tools).
  • Duration: for the term of your subscription plus the retention period in our Privacy Policy.
  • Data subjects: your Users and the individuals referenced in your Content (e.g. your contacts).
  • Data types: as determined by you — typically contact details and message content; do not submit special-category data unless you have a lawful basis and appropriate safeguards.

4. Confidentiality

We ensure that personnel authorised to process Customer personal data are bound by confidentiality obligations.

5. Security

We implement appropriate technical and organisational measures, including encryption in transit, AES-256-GCM encryption of stored third-party credentials, workspace isolation, access controls and audit logging, taking into account the state of the art and the risks of processing.

6. Sub-processors

You grant general authorisation for us to engage the sub-processors listed at https://getbob.thelevel7.ai/legal/subprocessors. We impose data-protection obligations on them no less protective than this DPA and remain responsible for their performance. We will give notice of changes so you may object on reasonable data-protection grounds.

7. International transfers

Where we transfer Customer personal data outside the EEA/UK, we rely on adequacy decisions or Standard Contractual Clauses with supplementary measures. EU/EEA/UK Customer Content is processed via Anthropic only and not via MiniMax.

8. Assistance to the Controller

Taking into account the nature of processing, we will assist you with data-subject requests, security, breach notification, and data-protection impact assessments and prior consultations, in each case to the extent applicable and reasonable.

9. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer personal data, with the information you reasonably need to meet your own notification obligations.

10. Return & deletion

On termination, and on your request, we will delete or return Customer personal data in accordance with the retention periods in our Privacy Policy, except where law requires us to retain it.

11. Audits

We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and frequency limits.

12. Contact

For a countersigned copy of this DPA or data-protection enquiries, contact privacy@thelevel7.ai.