DPA

Data Processing Addendum

This addendum forms part of the Terms of Service. It sets out how 8Seneca, as processor, handles personal data in the content your organisation, as controller, puts into Alicorn, as Article 28 of the GDPR requires. A signed agreement with 8Seneca that includes its own data processing terms prevails over this page.

Effective date: 2 October 2026 · Last updated: 2 October 2026

1. Subject matter, duration, nature and purpose

  • Subject matter: hosting and operating the Alicorn control plane for your organisation.
  • Duration: for as long as your organisation uses Alicorn, and afterwards until the data is deleted or returned under section 10.
  • Nature: storing, organising, indexing, retrieving, transmitting, displaying, exporting and deleting data.
  • Purpose: providing the service your organisation uses: projects, tasks, workflow and gates, knowledge, reports, notifications, and coordination of the runners your organisation operates.

2. Data subjects and categories of data

  • Data subjects: your organisation's people, client guests, and any person named in the content your organisation adds.
  • Categories: names, email addresses, roles and seats; content of projects, tasks, comments, requirements, decisions and sign-offs; knowledge facts and uploaded documents; time entries and, where recorded, cost and rate data; assistant conversations where history is kept; runner and device records; ledger and audit records.
  • Special categories: Alicorn is not designed for them. Your organisation should not put special-category data (Art. 9 GDPR) into Alicorn.

Agent work, source code, model prompts and model answers stay on your organisation's runners and its model gateway. They are not processed by 8Seneca.

3. Documented instructions

We process the data only on your organisation's documented instructions: these terms, the settings your Owners and Admins choose in the product, and any further written instruction. If the law requires other processing, we tell you first unless the law forbids it. If we think an instruction breaks data protection law, we tell you.

4. Confidentiality of personnel

Everyone at 8Seneca authorised to process the data is bound by confidentiality, by contract or by law, and has access only as far as their work needs.

5. Security

We implement the technical and organisational measures in the annex, appropriate to the risk, as Article 32 requires, and keep them under review.

6. Sub-processors

Your organisation gives general authorisation for the sub-processors listed in thePrivacy Policy. We bind each one to data protection terms that give at least the protection this addendum gives, and we remain responsible for them.

Before we add or replace a sub-processor, we tell your organisation's Owners by email at least 30 days ahead. Your organisation may object on reasonable data protection grounds in that time. We will then try to find a solution; if we cannot, your organisation may end the affected service and we refund any prepaid fees for the unused period.

7. International transfers

Where data leaves the EEA, we rely on an adequacy decision, the EU–US Data Privacy Framework for a certified provider, or the European Commission's Standard Contractual Clauses (2021). The service is hosted in Singapore. For transfers from your organisation to 8Seneca, including to our hosting in Singapore and to 8Seneca in Vietnam, the Standard Contractual Clauses, Module 2 (controller to processor), apply and are incorporated by reference.

8. Assistance

  • Data-subject requests: if a person asks us directly, we pass the request to your organisation and do not answer it ourselves unless you instruct us to. We help you answer requests, taking into account what the product already lets Owners and Admins do.
  • Impact assessments: we give you the information you reasonably need for a data protection impact assessment, or a prior consultation with a supervisory authority, about the service.

9. Personal data breaches

We notify your organisation without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting its data. We tell you what we know, what we are doing about it, and keep you updated as we learn more.

10. Deletion or return at the end

When your organisation's use of Alicorn ends, we return its data (as an export) or delete it, as your organisation chooses, and delete remaining copies, unless the law requires us to keep them. Copies in backups are deleted as the backups expire, within 12 months. Ask at [email protected].

11. Audits

We make available the information needed to show we meet Article 28. Your organisation, or an auditor it mandates who is bound to confidentiality, may audit us, with at least 30 days' notice, during business hours, at most once a year unless a supervisory authority requires it or a breach gives reason, and at your organisation's cost.

Annex: technical and organisational measures

  • Tenant isolation: every database row carries its organisation, and Postgres row-level security is forced on the tables, so the database itself refuses a query reaching another organisation's rows.
  • Encryption in transit: the service's public endpoints use TLS.
  • Scoped agent tokens: an agent acts with a short-lived token exchanged from its owner's, scoped to one project and task, and always narrower than the owner's own rights.
  • People decide the hard stops: merge, release and money always need a person in the named role; no agent passes them.
  • Append-only audit trail: access changes, connection changes and looks at people-cost data are written to an audit log the application cannot edit or delete; the measurement ledger is append-only in the same way.
  • No model keys on the control plane: 8Seneca hosts no model and holds no model key; model calls go through your organisation's own gateway.
  • Execution on your runners: agent work and source code stay on machines your organisation operates; agent transcripts stay on the runner.
  • No stored connection secrets: a connection stores the name of a secret held in a vault, never its value.
  • Sign-in: passwordless email links that are signed, single use, valid for 10 minutes and only in the browser that asked, with rate limits against abuse; optional Google and Microsoft sign-in.
  • Least privilege: roles and grants decide what each person sees; information outside them is hidden, and client guests see only what is shared with them.
  • Removal takes effect at once: a removed person's sessions end, their runners are revoked and their agents retired.
  • Backups: regular database backups, with restores tested.

Contact

8Seneca, Vietnam. Privacy contact:[email protected].