Data Processing Agreement
Last updated: August 26, 2026. This Data Processing Agreement ("DPA") is incorporated into and forms part of Caybl.ai's Terms of Service by reference. It applies automatically, with no separate signature needed, whenever Caybl.ai processes personal data on your behalf as described below.
1. Definitions
"Controller," "Processor," "Personal Data," "Processing," and "Data Subject" have the meanings given in the GDPR. "Customer" means the entity that has agreed to Caybl.ai's Terms of Service. "Customer Personal Data" means Personal Data within Google Analytics data Caybl.ai processes on Customer's behalf through the Service. "Sub-processor" means any third party Caybl.ai engages to process Customer Personal Data. "Data Protection Laws" means the GDPR and equivalent data protection legislation applicable to the processing under this DPA.
2. Roles of the parties
Where Customer Personal Data includes personal information about Customer's own website visitors (for example, in dimensions like user ID, IP-derived location, or device identifiers within a connected GA4 property), Customer is the Controller and Caybl.ai is the Processor. Caybl.ai processes Customer Personal Data only to provide the Service - running the reports Customer's AI agent requests - and only on Customer's documented instructions, as given through the Service's normal operation (e.g. the specific dimensions, metrics, and date ranges a tool call requests).
3. Processor obligations
Caybl.ai shall:
- Process Customer Personal Data only on Customer's documented instructions;
- Ensure personnel authorized to process it are bound by confidentiality;
- Implement the technical and organizational security measures in Annex 2;
- Not engage a new Sub-processor without giving Customer prior notice, per Section 5;
- Assist Customer, at Customer's reasonable request, in responding to Data Subject rights requests and in meeting its obligations around security, breach notification, and data protection impact assessments, to the extent Caybl.ai's systems make this possible;
- Delete or return all Customer Personal Data at the end of the engagement, per Section 11;
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
4. Confidentiality
Caybl.ai restricts access to Customer Personal Data to personnel and systems that need it to operate the Service, under confidentiality obligations that survive the end of their engagement with Caybl.ai.
5. Sub-processors
Customer authorizes Caybl.ai to engage the Sub-processors listed in Annex 3 to provide the Service. Caybl.ai will give Customer at least 14 days' notice (by email or a notice on this page) before engaging a new Sub-processor, during which Customer may object on reasonable data-protection grounds by contacting support@caybl.ai. Caybl.ai remains responsible for each Sub-processor's performance of its data protection obligations.
6. International transfers
Caybl.ai processes Customer Personal Data in AWS eu-west-1 (Ireland). Where a Sub-processor transfers Customer Personal Data outside the EEA, that transfer relies on Standard Contractual Clauses or an equivalent adequacy mechanism recognized under the GDPR.
7. Security measures
Caybl.ai implements the technical and organizational measures described in Annex 2, appropriate to the risk of the processing.
8. Personal data breach notification
Caybl.ai will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of any breach affecting Customer Personal Data, with the information reasonably available at the time and updates as the investigation progresses.
9. Audits
On reasonable request, no more than once per year (or following a breach), Caybl.ai will provide Customer with the information reasonably necessary to demonstrate compliance with this DPA, or make it available for a remote audit during business hours, with reasonable notice and under confidentiality.
10. Deletion & disconnection
Disconnecting a Google Analytics property in the dashboard immediately deletes the stored credential for it. Customer can request deletion of all Customer Personal Data at any time by contacting support@caybl.ai; Caybl.ai will complete deletion within 30 days unless a shorter period is legally required.
11. Return or deletion of data at termination
On termination of the Terms of Service, Caybl.ai will delete all Customer Personal Data within 30 days, except where retention is required by law, in which case Caybl.ai will continue to protect it under this DPA for as long as it's retained.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
13. Term
This DPA takes effect when Customer Personal Data is first processed under the Terms of Service and remains in effect for as long as Caybl.ai processes Customer Personal Data on Customer's behalf.
14. Governing law
This DPA is governed by the laws of Ireland, consistent with the Terms of Service.
Annex 1 - Details of processing
| Subject matter | Caybl.ai's provision of the Service to Customer |
| Duration | For as long as the Terms of Service are in effect |
| Nature & purpose | Fetching Google Analytics report data via API, on Customer's instruction, to answer questions asked through Customer's connected AI agent |
| Types of personal data | Whatever personal data Customer's connected GA4 property returns for the dimensions/metrics requested - e.g. user identifiers, approximate geography, device data. Caybl.ai does not choose or control what a GA4 property contains |
| Categories of data subjects | Visitors to Customer's website(s) tracked in the connected GA4 property |
Annex 2 - Technical & organizational security measures
- Encryption in transit (TLS) for all traffic to and from the Service;
- Encryption at rest for stored credentials (AES-256-GCM, moving to KMS envelope encryption in production);
- Least-privilege IAM roles per service component - no single role has blanket data access;
- Google Analytics data is fetched on demand and not warehoused - there is no data-at-rest analytics store to secure or breach;
- Access to production infrastructure is limited to authorized personnel;
- Point-in-time recovery on production data stores;
- Audit logging of tool calls per tenant.
Annex 3 - Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, storage, compute | Ireland (eu-west-1) |
| Google LLC | Google Analytics Data/Admin APIs - necessary to fetch the data Customer requests | Per Google's own infrastructure & SCCs |
| Amazon SES | Transactional email delivery | Ireland (eu-west-1) |
Questions about this DPA?
We're happy to walk through it with your legal or procurement team.
Contact support@caybl.ai