Data Processing Addendum

Last updated October 1, 2026

In short

  • For business customers processing personal data through Macaron. Part of your agreement automatically; a signed copy is available on request.
  • We process your data only on your instructions, never sell it and never use it to train AI.
  • Breaches are reported within 48 hours. Sub-processors are listed, with 14 days' notice of changes.
  • EU, UK and Swiss transfers are covered by the Standard Contractual Clauses and the UK Addendum.

1.Scope and acceptance

This Data Processing Addendum ("DPA") forms part of the agreement between Macaron, Florida, United States("Processor", "we") and a business customer ("Customer") for the Services: the Terms of Service and, for paid plans, the SaaS Agreement (together, the "Agreement"). It applies when we process Customer Personal Data on Customer's behalf in providing the Services. It is effective automatically for business customers when they accept the Agreement; a countersigned copy is available on request from [email protected].

If this DPA conflicts with the Agreement on the processing of personal data, this DPA controls.

2.Definitions

  • Data Protection Laws: all laws on the processing of personal data that apply to the processing under the Agreement, including the EU GDPR (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the CCPA as amended by the CPRA.
  • Customer Personal Data: personal data in Customer Data that we process on Customer's behalf under the Agreement.
  • Controller, processor, data subject, personal data, processing, personal data breach, supervisory authority and sub-processor have the meanings in the GDPR, and business, service provider, sell and share have the meanings in the CCPA.
  • SCCs: the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.

3.Roles of the parties

For Customer Personal Data, Customer is the controller (or a processor acting for its own controller) and Macaron is the processor (or sub-processor) and, under the CCPA, a service provider. Macaron is an independent controller for account, billing, security and website data it processes for its own purposes, as described in the Privacy Policy; this DPA doesn't apply to that data.

4.Details of the processing

Subject matterProviding the Services: running AI agents and Computers on Customer's code and storing related runs, keys and files.
DurationThe term of the Agreement, plus the deletion periods in section 12.
Nature and purposeHosting, storage, transmission, execution of agent runs and commands, encryption, deletion and support, only to provide the Services as Customer instructs.
Categories of data subjectsCustomer's authorized users, and any individuals whose personal data Customer includes in its code, repositories, prompts or files.
Categories of personal dataUser identifiers and usernames; any personal data in Customer's code, files, prompts and outputs, which Customer controls.
Special categoriesNone intended. Customer must not include special-category or criminal data unless it has a lawful basis and appropriate safeguards.
FrequencyContinuous, while Customer uses the Services.

5.Processing on instructions

We process Customer Personal Data only on Customer's documented instructions, which are the Agreement, this DPA and Customer's use and configuration of the Services, unless the law requires otherwise, in which case we'll inform Customer first unless the law forbids it. We will tell Customer if we believe an instruction infringes Data Protection Laws. Customer is responsible for the lawfulness of its instructions and for having a lawful basis and any required notices and consents for the processing.

6.Confidentiality of personnel

Everyone we authorize to process Customer Personal Data is bound by confidentiality obligations and receives appropriate training, and access is limited to what is needed to provide and support the Services.

7.Security measures

We implement and maintain appropriate technical and organizational measures, including:

  • Encryption: TLS for data in transit; AES-256-GCM encryption of stored keys and secrets, with keys held separately from encrypted data.
  • Isolation: each agent run executes in a Computer of its own, separated from other customers and from Customer's own devices.
  • Access control: least-privilege access to production systems, strong authentication, and removal of access when no longer needed.
  • Logging and monitoring: audit logs of actions on Computers and runs, and monitoring for abuse and security events.
  • Secure development: code review, dependency updates and vulnerability remediation.
  • Resilience: infrastructure hosted with reputable providers, with procedures to restore availability after incidents.
  • Data minimization and deletion: automatic deletion of runs after 14 days and of Customer Data on termination.

We may update these measures as long as the overall level of protection is not reduced.

8.Sub-processors

Customer gives general authorization for us to use the sub-processors below. We bind each by written contract to data protection obligations no less protective than this DPA, and remain responsible for their performance. We will give at least 14 days' notice of a new sub-processor by updating this page and notifying Customers who ask to be notified at [email protected]. Customer may object on reasonable data protection grounds within that period; if we can't address the objection, Customer may terminate the affected Services and receive a refund of prepaid fees for the unused period.

Sub-processorPurposeLocation
Railway CorporationApplication hosting and data storageUnited States
Stripe, Inc.Payment processing (billing data only)United States
Cloudflare, Inc.DNS and email routingUnited States / global
Cloud computer providers chosen at Computer creationHosting Computers on which agents runAs shown when the Computer is created

AI model providers and services that Customer connects with its own keys (such as Anthropic, OpenAI or Vercel) are engaged by Customer directly under Customer's own agreements with them, not as our sub-processors.

9.Data subject requests

Taking into account the nature of the processing, we assist Customer by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights. Customer can access, export and delete Customer Data through the Services. If we receive a request directly that relates to Customer Personal Data, we will redirect the data subject to Customer and won't respond ourselves except as the law requires.

10.Personal data breaches

We will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, likely consequences, and measures taken or proposed. We will take reasonable steps to contain and remedy the breach and assist Customer with its notification obligations. Notifying Customer isn't an admission of fault.

11.Impact assessments and consultation

We provide reasonable information and assistance to help Customer carry out data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Data Protection Laws and taking into account the nature of the processing and the information available to us.

12.Return and deletion

Customer can export Customer Data at any time during the Agreement and for 30 days after it ends. After that, we delete Customer Personal Data from active systems, and from backups within a further 30 days, unless the law requires us to keep it, in which case we keep it confidential and process it only for that purpose. We confirm deletion in writing on request.

13.Audits

We make available the information reasonably necessary to demonstrate compliance with this DPA, including written answers to reasonable security questionnaires once a year. If that information isn't sufficient, or a supervisory authority requires it, Customer may conduct an audit, at its own cost, with at least 30 days' notice, during business hours, no more than once a year, subject to confidentiality and without access to other customers' data or unreasonable disruption.

14.International transfers

We process Customer Personal Data in the United States and in the locations of our sub-processors. For transfers of personal data from the EEA, the UK or Switzerland to a country without an adequacy decision, the parties agree that:

  • EEA: the SCCs are incorporated by reference, with Module Two (controller to processor) or Module Three (processor to processor) as applicable; the optional docking clause in Clause 7 applies; in Clause 9, option 2 (general written authorization) applies with the notice period in section 8 of this DPA; the optional wording in Clause 11 does not apply; Clause 17 is governed by the law of Ireland; the courts of Ireland are chosen in Clause 18; and Annexes I to III are completed by sections 4, 8 and 9 of this DPA.
  • UK: the UK International Data Transfer Addendum to the SCCs (version B1.0) issued by the Information Commissioner applies, with the tables completed by this DPA, and either party may end it as allowed by section 19 of the Addendum.
  • Switzerland: the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, Swiss law as governing law where required, and references to the GDPR read as references to the Swiss FADP.

Where a sub-processor is certified under the EU–U.S. Data Privacy Framework or its UK and Swiss extensions, transfers to it may rely on that certification. We assess the laws of destination countries and apply supplementary measures, such as encryption, where appropriate, and will challenge government requests for Customer Personal Data that we consider unlawful.

15.U.S. state privacy laws

For Customer Personal Data subject to the CCPA or similar U.S. state laws, we act as a service provider or processor and we:

  • process it only for the limited and specified business purposes of providing the Services under the Agreement;
  • do not sell or share it, and do not retain, use or disclose it outside our direct business relationship with Customer or for any purpose other than those purposes;
  • do not combine it with personal information we receive from other sources, except as the law permits;
  • comply with applicable obligations and provide the same level of privacy protection the law requires of Customer;
  • notify Customer if we can no longer meet our obligations, and allow Customer to take reasonable steps to stop and remediate unauthorized use.

We certify that we understand and will comply with these restrictions.

16.Liability

Each party's liability arising from this DPA is subject to the limitations of liability in the Agreement, except where Data Protection Laws or the SCCs don't allow liability towards data subjects to be limited.

17.Term

This DPA lasts as long as we process Customer Personal Data under the Agreement. We may update it to reflect changes in Data Protection Laws or the Services, without reducing the protection it provides; material changes are notified as described in the Agreement.

Macaron, Florida, United States. Questions about this document: [email protected]