AgentMessage
FeaturesPricingDocsResourcesAbout
Back to legal
DATA PROCESSING ADDENDUM

The processor terms for AgentMessage.

This Addendum supplements the AgentMessage Terms of Service for customers who need a written processor commitment for compliance with data-protection laws including the California Consumer Privacy Act / California Privacy Rights Act, GDPR, and UK GDPR.

These terms are provided by Y3 Labs LLC, doing business as AgentMessage. AgentMessage is the product and service name of Y3 Labs LLC.

If you enter into a separate signed Order Form, master services agreement, data processing addendum, or other written agreement with Y3 Labs LLC, that agreement controls to the extent of any conflict.

For legal notices: legal@agentmessage.ioFor privacy requests: privacy@agentmessage.ioFor abuse reports: abuse@agentmessage.io

Effective date2026-05-01
Last updated2026-05-01
Versionv1.0
Provided byY3 Labs LLC

1. Parties and structure

This Data Processing Addendum (the “DPA”) is between Y3 Labs LLC, doing business as AgentMessage (“AgentMessage”), and the customer identified in the Order Form or account record (“Customer”), and forms part of the agreement between the parties (the “Agreement”) consisting of the Terms of Service and any signed Order Form. Capitalized terms not defined here have the meaning given in the Terms of Service.

For the purposes of this DPA, “Personal Data”, “Processing”, “Controller”, “Processor”, “Service Provider”, “Business”, “Subprocessor”, and “Data Subject” have the meanings given in the applicable data-protection laws (the “Data Protection Laws”), including the CCPA / CPRA, GDPR (Regulation (EU) 2016/679), and UK GDPR.

2. Roles and scope

For Customer Personal Data Processed by AgentMessage on behalf of Customer in connection with the Service, Customer is the Controller or Business (or, where Customer is itself a Processor or Service Provider for a third party, occupies that role) and AgentMessage is the Processor or Service Provider (or Sub-Processor, as applicable).

Where AgentMessage Processes data for its own account administration, billing, fraud prevention, security, compliance, legal, analytics, product improvement, and business operations, AgentMessage may act as an independent Controller or Business. AgentMessage's Privacy Policy describes that processing.

The subject matter, nature, purpose, duration, and categories of Personal Data and Data Subjects are described in Annex A.

3. Customer instructions

Customer instructs AgentMessage to Process Customer Personal Data as necessary to provide, secure, monitor, support, maintain, and improve the Service; route messages; manage registration and carrier workflows; process opt-outs; maintain suppression records; detect and prevent abuse; comply with law and carrier requirements; and enforce applicable terms and policies. The Agreement (including the Terms of Service, the Privacy Policy, configuration choices Customer makes in the Service, and reasonable Customer instructions communicated through the Service's standard interfaces) constitute Customer's documented instructions. If AgentMessage believes an instruction violates applicable law, it will inform Customer.

4. Confidentiality of personnel

AgentMessage will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and have received reasonable training on data-protection practices.

5. Security measures

AgentMessage will implement appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Annex B. AgentMessage may update the measures from time to time, provided that the overall level of security is not materially reduced.

Customer data is logically segregated by organization using tenant-scoped access controls. AgentMessage does not provide dedicated single-tenant infrastructure unless expressly agreed in writing.

6. Subprocessors

Customer authorizes AgentMessage to engage Subprocessors to Process Customer Personal Data, subject to the conditions in this section. The current list of Subprocessors is published at /legal/subprocessors. Customer authorizes the Subprocessors listed there as of the date of execution of this DPA.

AI subprocessors. Customer authorizes AgentMessage to use AI providers as Subprocessors for limited compliance, abuse-detection, message-classification, account-risk, support, and policy-enforcement purposes. AgentMessage will not authorize AI providers to train their general models on Customer Personal Data. Where the relevant provider tier offers it, AgentMessage configures providers to minimize retention and disable training. Because abuse and compliance review is part of the Service, Customer may not disable all AI-related Subprocessors or all compliance-related processing.

AgentMessage will impose data-protection terms on each Subprocessor that are no less protective of Personal Data than the terms of this DPA, including the requirements of Article 28 GDPR (and equivalents in other applicable Data Protection Laws). AgentMessage remains responsible to Customer for the acts and omissions of its Subprocessors.

Notice and objection. AgentMessage will provide notice of new Subprocessors by updating the Subprocessors page and emailing the billing contact on file. AgentMessage does not commit to a fixed advance-notice window. Customer may object on reasonable, documented data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Service as its sole and exclusive remedy. Any refund will be provided only to the extent required by law or expressly stated in an applicable Order Form.

7. Data subject rights

AgentMessage will, taking into account the nature of the Processing, assist Customer with appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligations to respond to requests from Data Subjects exercising rights under Data Protection Laws (including access, correction, deletion, restriction, portability, and objection). If AgentMessage receives a Data Subject request directly, AgentMessage will, without undue delay, inform the Data Subject to direct the request to Customer (or, where AgentMessage is the relevant Controller or Business, respond directly).

8. Assistance with controller obligations

AgentMessage will provide reasonable assistance to Customer in meeting Customer's obligations under Articles 32 to 36 GDPR (and equivalent provisions of other Data Protection Laws) relating to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of the Processing and the information available to AgentMessage. AgentMessage may charge reasonable fees for substantial assistance not foreseeable at the time the Service is offered.

9. Personal data breach notification

AgentMessage will notify Customer without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data breach affecting Customer Personal Data. The notice will, to the extent known and as further details become available, describe (a) the nature of the breach, (b) the categories and approximate number of Data Subjects and records affected, (c) the likely consequences, (d) the measures taken or proposed to address the breach and mitigate adverse effects, and (e) the contact point for further information. AgentMessage's notice is not an acknowledgement of fault or liability.

10. Audits

AgentMessage will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. AgentMessage satisfies this obligation through written responses, security documentation, policy summaries, and, once obtained, summary reports of independent audits or certifications such as SOC 2 or ISO 27001. Information is provided subject to confidentiality undertakings and reasonable scope and frequency limits.

On-site or remote inspection audits are not available as of right under this DPA. AgentMessage may, in its discretion, agree to an on-site or remote inspection audit by mutual written agreement, on terms that include reasonable scope, scheduling to avoid Service disruption, confidentiality undertakings no less protective than the Agreement, compliance with AgentMessage's reasonable security policies, and Customer's payment of the auditor's fees and reasonable AgentMessage time at its then-current rates. Where a supervisory authority orders an audit, AgentMessage will cooperate as required by law.

11. Return and deletion

Upon termination or expiration of the Agreement, AgentMessage will, at Customer's choice, delete or return Customer Personal Data in its possession, except that AgentMessage may retain data as necessary for legal, tax, billing, security, backup, fraud-prevention, consent, opt-out, suppression, carrier, dispute, and compliance purposes. Customer may request return or deletion within 60 days of termination by emailing privacy@agentmessage.io. Otherwise, AgentMessage will delete Customer Personal Data within 90 days of termination, subject to the retained categories listed above and the retention periods in the Privacy Policy.

12. Sensitive and special category data

Customer may not submit protected health information, special category data, or sensitive personal information requiring heightened legal protections unless AgentMessage expressly agrees in a signed written addendum. AgentMessage does not currently offer HIPAA-compliant services or sign Business Associate Agreements.

13. International transfers

The Service is currently offered to customers in the United States. AgentMessage does not currently sign DPAs covering international data transfers from the EEA, the United Kingdom, or Switzerland. If you require international-transfer protections (Standard Contractual Clauses, UK IDTA, Swiss adequacy equivalents, or a Data Privacy Framework reliance statement), contact privacy@agentmessage.io before signing this DPA so we can determine whether the Service is a fit and, if so, agree on the appropriate transfer mechanism in a separate written addendum.

14. California-specific terms

For Personal Data subject to the CCPA / CPRA, AgentMessage is a “service provider” (and where applicable, a “contractor”) and certifies that it: (a) will not sell or share Personal Data; (b) will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, including for any commercial purpose other than the business purposes, or as otherwise permitted by the CCPA / CPRA; (c) will not retain, use, or disclose Personal Data outside the direct business relationship with Customer; and (d) will comply with applicable obligations under the CCPA / CPRA and provide the same level of privacy protection as required by it. AgentMessage will notify Customer if it determines it can no longer meet these obligations and will, on Customer's reasonable request, take appropriate steps to stop and remediate any unauthorized use of Personal Data.

15. Liability

The total liability of each party arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the limitations of liability set out in the Terms of Service. Nothing in this DPA limits or excludes any liability that cannot lawfully be limited or excluded under applicable Data Protection Laws.

16. Conflict and order of precedence

In the event of conflict between this DPA and the Terms of Service, this DPA prevails with respect to the Processing of Customer Personal Data.

17. Term

This DPA takes effect on the later of (a) the effective date of the Agreement and (b) the effective date listed at the top of this page, and continues until the Agreement terminates, with the obligations relating to data return / deletion surviving termination as described.

18. Contact

For DPA questions, requests for a counter-signed copy, or breach notifications under this DPA, contact privacy@agentmessage.io with a copy to legal@agentmessage.io.

Y3 Labs LLC
845 Houston Northcutt Blvd #1079
Mt Pleasant, SC 29464
United States
Attn: Legal
legal@agentmessage.io

Annex A: Description of Processing

Subject matter and nature of Processing. Operation of the AgentMessage platform: receipt, storage, transmission, and audit of SMS and MMS messages and related metadata; account administration; customer support; compliance with carrier and regulatory requirements; AI-assisted compliance and abuse review; billing.

Purposes of Processing. To provide, secure, support, and improve the Service for Customer; to comply with carrier rules and applicable law; to bill Customer; to respond to Customer support requests; to detect and respond to suspected abuse and policy violations.

Duration. For the term of the Agreement, plus the wind-down period described in Section 11 of this DPA, and longer where required by law for billing, audit, consent records, opt-out records, suppression records, or legal hold.

Categories of Data Subjects. Customer's employees, contractors, and agents (account holders); Customer's end users and message recipients; in limited cases, individuals identified in support correspondence.

Categories of Personal Data.

  • Account-holder identity (name, email, profile image, role).
  • Organization data (business name, EIN, website, vertical, employee range, billing contact).
  • Recipient phone numbers (E.164 format).
  • Message content (body, media URLs) and metadata (sender, recipient, channel, status, error details, timestamps, segment counts).
  • Consent records, opt-out records, and suppression records, with full audit history.
  • Billing data (Stripe customer / subscription identifiers; payment instruments held directly by Stripe under its own terms).
  • Technical data (IP address, user agent, request id, response status, timing).

Special category data. AgentMessage does not support Processing of special category Personal Data (Article 9 GDPR), criminal-conviction data (Article 10 GDPR), or U.S. HIPAA Protected Health Information unless a specific written addendum is signed.

Frequency of transfer. Continuous, for the duration of the Agreement.

Annex B: Technical and organizational measures

The following measures describe AgentMessage's baseline security posture. Specific implementation details may evolve; the overall level of protection will not be materially reduced.

  • Encryption in transit. All connections to the Service and between Service components use TLS with modern cipher suites and certificate validation.
  • Encryption at rest. Customer Personal Data is stored on infrastructure with disk-level encryption.
  • Tenant isolation. Customer data is logically segregated by organization using tenant-scoped access controls applied at every layer of the Service. Single-tenant infrastructure is not provided unless expressly agreed in writing.
  • Authentication. Customer access is authenticated through a third-party identity provider supporting strong password policies, MFA, and organization-aware session management. API access uses long, hashed bearer tokens; plaintext is shown only at creation.
  • Authorization. Per-organization data isolation is enforced at every layer: HTTP middleware derives a tenant identifier from the bearer token; every resource lookup is org-scoped at the repository signature; cross-tenant misses return not-found rather than forbidden, to prevent identifier enumeration.
  • Webhook signing. Outbound webhook deliveries to Customer endpoints are signed with a per-organization HMAC-SHA256 secret. Customer can rotate the secret on demand with a documented grace window.
  • Secret handling. API keys are stored as cryptographic hashes of the plaintext; webhook secrets as raw random bytes returned only at creation or rotation. Plaintext credentials are never logged.
  • Logging and audit. Privileged actions and webhook delivery attempts are logged. Logs strip credentials and truncate response bodies to limit the amount of recipient content held in audit data.
  • Retention controls. Customer- configurable retention windows for message bodies (default 90 days, bounded between 30 and 365 days). A retention sweeper redacts message bodies and media URLs once the window elapses.
  • Access control. Role-based access for AgentMessage personnel. Production access is limited to personnel whose role requires it, audited, and revoked on role change or separation.
  • Vulnerability management. Regular dependency updates, security review of changes, and response procedures for vulnerability reports. A coordinated-disclosure channel is available at security@agentmessage.io.
  • Incident response. Documented incident response process, including escalation, containment, root-cause review, and customer notification per Section 9.
  • Subprocessor diligence. Reputable Subprocessors with their own data-protection programs and contractual commitments.
  • Secure software development. Code review is required before changes reach production. Continuous integration runs dependency vulnerability scanning, and secrets scanning runs on commit.
  • Personnel. Background checks for personnel with production access. Role-based offboarding revokes credentials and access on separation or role change.
  • Business continuity. Daily database backups with documented restore procedures. Multi-region object storage is used where applicable for media and webhook artifacts.
  • Vendor risk management. Subprocessors are reviewed before onboarding, including data-protection terms, security posture, and breach notification commitments.
  • Key management.Encryption keys are managed by the cloud provider's key management service. Root keys are not held in application code or configuration.
  • Penetration testing. Internal security review of major releases is performed today. Annual third-party penetration testing will be added once production traffic and budget support it.

Security certifications. AgentMessage has not completed a SOC 2 examination as of the effective date of this DPA. We may pursue security certifications or third-party assessments in the future.

Annex C: Authorized Subprocessors

The current list of authorized Subprocessors is maintained at /legal/subprocessors. That list is incorporated into this DPA by reference and is the canonical authorization for Subprocessor engagement. Customer authorizes the Subprocessors listed at the time of DPA execution and any future Subprocessors added in compliance with Section 6.

Need a counter-signed copy?

Email us and we will get the paperwork moving.

Contact AgentMessage →
AgentMessage

SMS built for AI agents. Compliance infrastructure built into the product flow.

Product

  • Features
  • Pricing
  • Resources
  • Changelog

Developers

  • Documentation
  • API reference
  • SDKs
  • Webhooks

Company

  • About
  • Blog
  • Contact
  • Complaints
  • Legal
© 2026 AgentMessage · A Y3 Labs companyv0.1.0-beta