Data Processing Agreement

Last updated: August 26, 2026. This Data Processing Agreement ("DPA") is incorporated into and forms part of Caybl.ai's Terms of Service by reference. It applies automatically, with no separate signature needed, whenever Caybl.ai processes personal data on your behalf as described below.

1. Definitions

"Controller," "Processor," "Personal Data," "Processing," and "Data Subject" have the meanings given in the GDPR. "Customer" means the entity that has agreed to Caybl.ai's Terms of Service. "Customer Personal Data" means Personal Data within Google Analytics data Caybl.ai processes on Customer's behalf through the Service. "Sub-processor" means any third party Caybl.ai engages to process Customer Personal Data. "Data Protection Laws" means the GDPR and equivalent data protection legislation applicable to the processing under this DPA.

2. Roles of the parties

Where Customer Personal Data includes personal information about Customer's own website visitors (for example, in dimensions like user ID, IP-derived location, or device identifiers within a connected GA4 property), Customer is the Controller and Caybl.ai is the Processor. Caybl.ai processes Customer Personal Data only to provide the Service - running the reports Customer's AI agent requests - and only on Customer's documented instructions, as given through the Service's normal operation (e.g. the specific dimensions, metrics, and date ranges a tool call requests).

3. Processor obligations

Caybl.ai shall:

  • Process Customer Personal Data only on Customer's documented instructions;
  • Ensure personnel authorized to process it are bound by confidentiality;
  • Implement the technical and organizational security measures in Annex 2;
  • Not engage a new Sub-processor without giving Customer prior notice, per Section 5;
  • Assist Customer, at Customer's reasonable request, in responding to Data Subject rights requests and in meeting its obligations around security, breach notification, and data protection impact assessments, to the extent Caybl.ai's systems make this possible;
  • Delete or return all Customer Personal Data at the end of the engagement, per Section 11;
  • Make available the information reasonably necessary to demonstrate compliance with this DPA.

4. Confidentiality

Caybl.ai restricts access to Customer Personal Data to personnel and systems that need it to operate the Service, under confidentiality obligations that survive the end of their engagement with Caybl.ai.

5. Sub-processors

Customer authorizes Caybl.ai to engage the Sub-processors listed in Annex 3 to provide the Service. Caybl.ai will give Customer at least 14 days' notice (by email or a notice on this page) before engaging a new Sub-processor, during which Customer may object on reasonable data-protection grounds by contacting support@caybl.ai. Caybl.ai remains responsible for each Sub-processor's performance of its data protection obligations.

6. International transfers

Caybl.ai processes Customer Personal Data in AWS eu-west-1 (Ireland). Where a Sub-processor transfers Customer Personal Data outside the EEA, that transfer relies on Standard Contractual Clauses or an equivalent adequacy mechanism recognized under the GDPR.

7. Security measures

Caybl.ai implements the technical and organizational measures described in Annex 2, appropriate to the risk of the processing.

8. Personal data breach notification

Caybl.ai will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of any breach affecting Customer Personal Data, with the information reasonably available at the time and updates as the investigation progresses.

9. Audits

On reasonable request, no more than once per year (or following a breach), Caybl.ai will provide Customer with the information reasonably necessary to demonstrate compliance with this DPA, or make it available for a remote audit during business hours, with reasonable notice and under confidentiality.

10. Deletion & disconnection

Disconnecting a Google Analytics property in the dashboard immediately deletes the stored credential for it. Customer can request deletion of all Customer Personal Data at any time by contacting support@caybl.ai; Caybl.ai will complete deletion within 30 days unless a shorter period is legally required.

11. Return or deletion of data at termination

On termination of the Terms of Service, Caybl.ai will delete all Customer Personal Data within 30 days, except where retention is required by law, in which case Caybl.ai will continue to protect it under this DPA for as long as it's retained.

12. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.

13. Term

This DPA takes effect when Customer Personal Data is first processed under the Terms of Service and remains in effect for as long as Caybl.ai processes Customer Personal Data on Customer's behalf.

14. Governing law

This DPA is governed by the laws of Ireland, consistent with the Terms of Service.

Annex 1 - Details of processing

Subject matterCaybl.ai's provision of the Service to Customer
DurationFor as long as the Terms of Service are in effect
Nature & purposeFetching Google Analytics report data via API, on Customer's instruction, to answer questions asked through Customer's connected AI agent
Types of personal dataWhatever personal data Customer's connected GA4 property returns for the dimensions/metrics requested - e.g. user identifiers, approximate geography, device data. Caybl.ai does not choose or control what a GA4 property contains
Categories of data subjectsVisitors to Customer's website(s) tracked in the connected GA4 property

Annex 2 - Technical & organizational security measures

  • Encryption in transit (TLS) for all traffic to and from the Service;
  • Encryption at rest for stored credentials (AES-256-GCM, moving to KMS envelope encryption in production);
  • Least-privilege IAM roles per service component - no single role has blanket data access;
  • Google Analytics data is fetched on demand and not warehoused - there is no data-at-rest analytics store to secure or breach;
  • Access to production infrastructure is limited to authorized personnel;
  • Point-in-time recovery on production data stores;
  • Audit logging of tool calls per tenant.

Annex 3 - Sub-processors

Sub-processorPurposeLocation
Amazon Web ServicesHosting, storage, computeIreland (eu-west-1)
Google LLCGoogle Analytics Data/Admin APIs - necessary to fetch the data Customer requestsPer Google's own infrastructure & SCCs
Amazon SESTransactional email deliveryIreland (eu-west-1)

Questions about this DPA?

We're happy to walk through it with your legal or procurement team.

Contact support@caybl.ai