Data Processing Addendum
⚠ Counsel review required before relying on this DPA. The Standard Contractual Clauses incorporated below and the Annexes must be confirmed by qualified counsel for your jurisdiction and data flows. This document is provided for transparency and is not legal advice.
This Data Processing Addendum (this "DPA") is entered into between the customer that has agreed to the Terms of Service (the "Customer", "you", or "your") and Castawaze LLC, which operates Opsybots (the "Service"). It governs the processing by Castawaze LLC of personal data on the Customer's behalf in connection with the Customer's use of the Service.
Capitalized terms used but not defined in this DPA have the meanings given to them in the Terms of Service. As used in this DPA, "Customer Account Metadata" means the AWS infrastructure metadata — resource configurations, IAM settings, cost and usage figures, and security posture — that the Service reads from a Connected Account to render Findings; "Findings" means the structured results that the Service produces from that metadata; "Connected Account" means an AWS account the Customer connects to the Service through a read-only cross-account role; and "Workspace" means the Customer's tenant within the Service. "Customer Personal Data" means the personal data, if any, contained within Customer Account Metadata that Castawaze LLC processes on the Customer's behalf as a processor under this DPA. "Sub-processor" means a third party engaged by Castawaze LLC to process Customer Personal Data. Where the terms "controller", "processor", "data subject", "personal data", "processing", "personal-data breach", and "supervisory authority" are used, they have the meanings given to them in applicable data-protection law, including Regulation (EU) 2016/679 (the "GDPR").
1. Roles of the parties
For the processing described in this DPA, the Customer is the controller and Castawaze LLC is the processor of the Customer Personal Data within Customer Account Metadata that Castawaze LLC processes to render Findings. Each party will comply with the obligations applicable to it under applicable data-protection law.
This DPA forms part of, and is incorporated into, the Terms of Service at /legal/terms. By accepting the Terms of Service, the Customer accepts this DPA on behalf of itself and, to the extent required, as agent for any of its affiliates whose personal data is processed under the Service.
To the extent the Customer processes any personal data of Castawaze LLC's personnel for its own purposes (for example, the account and billing contacts it provides), each party acts as an independent controller of that data, and that processing is addressed by the Privacy Policy at /legal/privacy and the Terms of Service rather than by this DPA.
2. Subject-matter and details of processing
Nature and purpose of the processing. Castawaze LLC processes Customer Personal Data only to provide the Service: read-only scanning of the Customer's Connected Accounts across the security, cost, availability, operations, and performance pillars; AI-assisted review of the resulting finding metadata to assign and explain severity; and the composition and delivery of a weekly brief derived from that metadata. The agents run within the Customer's own AWS account, are strictly read-only, and write Findings to the Customer's own storage, which remains the system of record. The composed weekly report is likewise written back to the Customer's own storage and is not stored by Castawaze LLC. The hosted dashboard reads Customer Account Metadata from the Connected Account both on demand, when an Authorized User views it, and on an automated schedule, in order to compose the weekly brief. Agent-side inference runs on Amazon Bedrock in the Customer's own account; the weekly brief's inference runs on Amazon Bedrock in Castawaze LLC's account (see Annex III).
Duration of the processing. Processing continues for the duration of the Customer's subscription term. Customer Account Metadata and the reports derived from it are not persisted by Castawaze LLC: metadata is read into memory to render a requested view or to compose the weekly brief, the resulting report is written to the Customer's own storage, and both are then discarded from Castawaze LLC's systems. Castawaze LLC retains no copy of the Customer's Findings, and no copy of the Customer's weekly reports (see §8).
Types of personal data. The Customer Personal Data is limited to identifiers that may appear within infrastructure metadata — such as IAM user names and Amazon Resource Names (ARNs), role names, and AWS account identifiers associated with the Customer's personnel. The processing does not involve special categories of personal data within the meaning of Article 9 of the GDPR, does not involve application data, and must not include protected health information (PHI); the Customer must not submit PHI or other sensitive data to the Service.
Categories of data subjects. The data subjects are the Customer's personnel and the identities represented in the Customer's AWS IAM configuration and infrastructure metadata (for example, the individuals to whom IAM users, roles, and access keys correspond).
3. Processor obligations
Castawaze LLC will:
- process Customer Personal Data only on the Customer's documented instructions, which consist of the scans the Customer configures through the Service, the Terms of Service, and this DPA, and as otherwise agreed in writing — including with regard to transfers of Customer Personal Data to a third country — unless required to process by applicable law, in which case Castawaze LLC will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest;
- promptly inform the Customer if, in its opinion, an instruction infringes applicable data-protection law;
- ensure that personnel authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality;
- implement and maintain the technical and organizational security measures described in §4 and Annex II;
- taking into account the nature of the processing and the information available to it, assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligations to respond to data-subject requests, to ensure the security of processing, to notify and communicate personal-data breaches, and to carry out data-protection impact assessments and prior consultations with supervisory authorities; and
- not engage another processor (a Sub-processor) except as permitted by §5.
4. Security measures (Annex II reference)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, Castawaze LLC implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include:
- encryption of Customer Personal Data in transit using TLS;
- encryption at rest using AWS Key Management Service (KMS) for the limited control-plane data Castawaze LLC holds;
- least-privilege, read-only cross-account IAM roles for access to Connected Accounts;
- authentication through AWS Cognito with optional multi-factor authentication (MFA) and role-based access control (RBAC);
- data minimization: Customer Account Metadata is not persisted, and the weekly reports derived from it are written to the Customer's own storage rather than retained by Castawaze LLC (see §8); and
- access logging.
The full description of the technical and organizational measures is set out in Annex II, which the parties agree constitutes the description of measures required under Clause 8.6 of the Standard Contractual Clauses and Article 32 of the GDPR.
5. Sub-processors
The Customer gives Castawaze LLC general written authorization to engage the Sub-processors listed at /legal/subprocessors to process Customer Personal Data in connection with the Service. The current Sub-processor for this processing is Amazon Web Services, which provides the hosting, the control-plane database holding the account-administration data described in the Privacy Policy, and Amazon Bedrock, the AI inference used both by the agents within the Customer's account and by the hosted dashboard to compose the weekly brief.
For clarity, where the Customer's administrator enables Slack delivery, Castawaze LLC posts the weekly digest, on the Customer's instruction, to an incoming-webhook URL that the Customer supplies and that points at the Customer's own Slack workspace. That is an onward transfer to a destination the Customer chooses, configures, and can revoke at any time, and the digest comes to rest in the Customer's Slack workspace under the Customer's own agreement with Slack. Slack is therefore not a Sub-processor of Castawaze LLC for that content, and Castawaze LLC does not engage Slack to process Customer Personal Data on its behalf. Slack delivery is off unless the Customer enables it, and the digest does not include resource identifiers.
Castawaze LLC will give the Customer at least 30 days' notice before adding or replacing a Sub-processor that processes Customer Personal Data, by updating the list at /legal/subprocessors and through the notice mechanism described there. During that notice period, the Customer may object to the change on reasonable data-protection grounds. The parties will work in good faith to resolve the objection; if it cannot be resolved, the Customer may, as its sole and exclusive remedy, terminate the affected portion of the Service in accordance with the Terms of Service.
Where Castawaze LLC engages a Sub-processor, it will impose on that Sub-processor, by written contract, data-protection obligations substantially equivalent to those set out in this DPA (including, for restricted transfers, the same data-protection obligations as set out in the Standard Contractual Clauses), and Castawaze LLC remains fully liable to the Customer for the performance of that Sub-processor's obligations.
6. Data-subject requests
Taking into account the nature of the processing, Castawaze LLC will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights under applicable data-protection law. If Castawaze LLC receives a request from a data subject in relation to Customer Personal Data, it will promptly notify the Customer and will not respond to the request directly except on the Customer's documented instruction or as required by applicable law.
7. Personal-data breach
Castawaze LLC will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. The notification will, to the extent then available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Castawaze LLC will provide reasonable assistance to the Customer in connection with the Customer's own obligations to notify supervisory authorities and affected data subjects.
8. Deletion and return
Customer Findings remain in the Customer's own AWS account throughout: the agents run in that account and write Findings to the Customer's own storage, which is the system of record. The weekly reports composed from those Findings are written back to that same storage. Castawaze LLC holds no copy of the Customer's findings history and no copy of the Customer's weekly reports, so there is nothing of either kind to return or delete on termination.
Retention of the Findings and the reports is therefore the Customer's own: they persist in the Customer's bucket until the Customer deletes them or applies an S3 lifecycle rule of its choosing. Castawaze LLC runs no job that deletes them and sets no expiry on them.
For any other incidental Customer Personal Data that Castawaze LLC may hold (for example, within transient logs), Castawaze LLC will, at the Customer's choice, delete or return that data after the end of the provision of the Service and delete existing copies, unless applicable law requires continued storage of the data, in which case Castawaze LLC will protect the confidentiality of that data and process it only as necessary for the required purpose. Upon the Customer's request, Castawaze LLC will provide written confirmation of such deletion.
9. Audit
Castawaze LLC will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits will be conducted on reasonable prior written notice, during business hours, subject to confidentiality obligations, in a manner that does not disrupt Castawaze LLC's operations or the security of other customers' data, and no more than once per calendar year unless a personal-data breach or a competent supervisory authority's requirement gives reasonable cause for an additional audit. Audit obligations may be satisfied, in whole or in part, by Castawaze LLC making available relevant third-party reports, certifications, and attestations — including those of Amazon Web Services — and Castawaze LLC's own audit summaries.
10. International transfers — Standard Contractual Clauses
Where Castawaze LLC processes personal data of data subjects located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland on behalf of the Customer, and that processing constitutes a restricted transfer to the United States, the parties incorporate by reference the following transfer mechanisms, which apply to that transfer:
- the EU Standard Contractual Clauses, Module Two (controller to processor), as approved under Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the "SCCs"), which are hereby incorporated into this DPA and completed as follows:
- Clause 7 (the optional docking clause) applies, allowing a third party to accede to the SCCs by agreement of the parties;
- for Clause 9 (use of sub-processors), Option 2 (general written authorization) applies, with the minimum notice period for changes set at 30 days as provided in §5;
- the optional language in Clause 11 (redress) does not apply;
- for Clause 17 (governing law) and Clause 18 (choice of forum and jurisdiction), the governing law and competent courts of an EU Member State are to be completed by the parties under counsel's direction; and
- Annexes I, II, and III to this DPA serve as the Annexes to the SCCs;
- the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, which applies to restricted transfers subject to UK data-protection law, with the EU SCCs above forming the "Approved EU SCCs" referenced by that Addendum; and
- the Swiss amendments, under which, for restricted transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs above apply with the modifications required by the Swiss Federal Data Protection and Information Commissioner — including that references to the GDPR are understood as references to the Swiss FADP, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and the clauses also protect the data of legal entities until the entry into force of revised Swiss law.
Where any provision of the SCCs conflicts with any provision of this DPA or the Terms of Service, the SCCs prevail with respect to the relevant transfer. Annexes I, II, and III below are referenced as the SCC Annexes.
11. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Terms of Service, and any reference in the Terms of Service to the liability of a party means the aggregate liability of that party under the Terms of Service and this DPA together. Nothing in this DPA limits any liability that cannot be limited under applicable data-protection law, including the liability of the parties to data subjects under the SCCs.
12. Order of precedence
In the event of a conflict regarding the processing of personal data, this DPA prevails over the Terms of Service and any other agreement between the parties. For transfers governed by the SCCs, the SCCs prevail over this DPA. Except as stated in this section, the Terms of Service continue in full force and effect.
13. Annexes
Annex I
A. List of parties.
Data exporter:
- Name: the Customer, as identified in the Terms of Service.
- Role: controller.
- Activities relevant to the data transferred: receiving Findings about its own AWS environment across the security, cost, availability, operations, and performance pillars, through the Service.
- Contact details: the account and privacy contacts the Customer provides in the Service.
Data importer:
- Name: Castawaze LLC (operating Opsybots).
- Role: processor.
- Activities relevant to the data transferred: read-only scanning of the Customer's Connected Accounts and AI-assisted severity review of finding metadata to render Findings, as described in §2.
- Contact details: privacy@opsybots.com.
B. Description of transfer.
- Categories of data subjects: the Customer's personnel and the identities represented in the Customer's AWS IAM configuration and infrastructure metadata, as described in §2.
- Categories of personal data: identifiers within infrastructure metadata, such as IAM user names and ARNs, role names, and AWS account identifiers associated with the Customer's personnel, as described in §2.
- Special categories of personal data: none. The processing does not involve special-category data and must not include PHI.
- Frequency of the transfer: continuous. Customer Account Metadata is read on demand each time an Authorized User views it, and by an automated background job that runs at ten-minute intervals for each active Connected Account in order to compose and refresh the weekly report. The report itself is written once per Connected Account per week, to the Customer's own storage, and refreshed in place during that week as new agent runs land.
- Nature and purpose of the processing: as described in §2 (read-only scanning across the security, cost, availability, operations, and performance pillars, and AI-assisted severity review of finding metadata to render Findings).
- Retention period: none. Customer Account Metadata is not retained by Castawaze LLC: it is read into memory to render a view or to compose the brief, and then discarded. The composed weekly report (counts, cost totals, narrative prose, and a capped subset of findings with their titles, recommendations, severities, and resource identifiers) is written to the Customer's own S3 storage, encrypted with the Customer's own KMS key, and is retained there under the Customer's own retention policy. Castawaze LLC retains no copy of either, and applies no expiry to the Customer's copy. See §8.
- Sub-processors: as listed at /legal/subprocessors and described in Annex III; transfers to Sub-processors are for the subject matter, nature, and duration described above.
C. Competent supervisory authority.
The competent supervisory authority is [competent supervisory authority]. (This is determined by the data exporter's place of establishment in the EEA or, where applicable, the EEA establishment of its representative or its EEA lead supervisory authority, and is to be completed by the Customer as controller in accordance with Clause 13 of the SCCs.)
Annex II
Technical and organizational measures, including measures to ensure the security of the data.
Castawaze LLC implements and maintains at least the following measures with respect to Customer Personal Data:
- Encryption in transit: all network communication carrying Customer Personal Data is encrypted using TLS.
- Encryption at rest: the limited control-plane data Castawaze LLC holds is encrypted at rest using AWS Key Management Service (KMS), including the KMS-encrypted cross-account ExternalId used to scope access to Connected Accounts.
- Least-privilege access: access to Connected Accounts uses least-privilege, read-only cross-account IAM roles; the agents are strictly read-only against the scanned account and cannot write to it.
- Authentication and access control: access to the hosted dashboard is authenticated through AWS Cognito, with optional TOTP multi-factor authentication (MFA) and role-based access control (RBAC) restricting actions by user role.
- Data minimization: Customer Account Metadata is not persisted by Castawaze LLC, and the weekly reports composed from it are written to the Customer's own storage rather than retained by Castawaze LLC. The evidence packet sent for narrative composition is bounded by design: a capped set of findings rather than the Customer's findings history (see Annex III). This minimizes the volume of Customer data at rest in Castawaze LLC's systems to nil (see §8).
- Tenant isolation: every stored record is scoped to a single Workspace, so two Workspaces connecting the same AWS account never share a record.
- Network isolation: the control-plane database runs in a private subnet and is not publicly reachable.
- Customer-held encryption keys: the Findings and the weekly reports are encrypted in the Customer's own S3 bucket with a KMS key in the Customer's own account, which the Customer controls and can revoke.
- Logging: access and administrative actions are logged to support monitoring, incident detection, and accountability.
- Sub-processor controls: Sub-processors are bound by written contracts imposing data-protection obligations substantially equivalent to those in this DPA, as described in §5.
These measures may be updated over time to reflect evolving security practices, provided that the updates do not materially reduce the overall level of protection for Customer Personal Data.
Annex III
List of Sub-processors.
The Customer has authorized the use of the Sub-processors on the authoritative, current list at /legal/subprocessors, which forms part of this Annex III. For the processing of Customer Account Metadata, the Sub-processor is Amazon Web Services, which provides the hosting, the control-plane database holding account-administration data, and Amazon Bedrock.
Amazon Bedrock is used in two places, which differ in whose account the inference runs in: by the agents, running in the Customer's own AWS account under the Customer's credentials, to assign and explain severity; and by the hosted dashboard, running in Castawaze LLC's AWS account in us-east-1 under Castawaze LLC's credentials, to compose the weekly brief's narrative prose from a capped slice of data. That slice comprises the week's counts, cost totals, posture, and per-pillar status including the names of the agents that ran; the Customer's configured organization context; the week's top 25 candidate findings; and, for each pillar's detail section, up to six further findings from that pillar. Those per-pillar findings overlap with the top 25 rather than being wholly additional, so the total number of distinct findings transferred is a few dozen at most. Each carries its title, recommendation, severity, resource identifiers, estimated monthly cost impact, tags, and internal finding, agent, and pillar identifiers. The composed result is written back to the Customer's own storage and is not retained by Castawaze LLC. In both cases, Amazon Bedrock does not retain prompts or outputs and does not use them to train foundation models, and no Customer Account Metadata or Findings are sent to any third-party model API.
For clarity, Stripe processes the Customer's billing and account-contact data, for which Castawaze LLC acts as an independent controller (not as the Customer's processor); that processing falls outside this DPA and is described in the Privacy Policy. Stripe is not a Sub-processor of Customer Personal Data within Customer Account Metadata and does not process it.
Slack is likewise not a Sub-processor. Where the Customer enables Slack delivery, Castawaze LLC posts the weekly digest, on the Customer's instruction, to a webhook the Customer supplies that points at the Customer's own Slack workspace; see §5.
Changes to the Sub-processor list are governed by the 30-day change-notice process and the Customer's right to object, as described in §5.
14. Contact
Castawaze LLC — Opsybots
Privacy & data requests: privacy@opsybots.com
Legal notices: legal@opsybots.com
Security disclosures: security@opsybots.com
Support & billing: support@opsybots.com