← All legal documents

Data Processing Addendum

Applies to Autonoma. Last updated August 2026.

Not reviewed by a lawyer. This document was drafted to describe what the software actually does, but it has not had legal review and is not legal advice. Do not rely on it for anything that matters to you without checking. The addresses named below are not yet receiving mail — see contact for what does work today.

Autonoma
Effective Date: August 2026
Last Updated: August 2026


1. INTRODUCTION

This Data Processing Addendum (“DPA”) forms part of the Agreement between Autonoma (“Processor,” “we,” “us”) and the Customer (“Controller,” “you”) for the provision of Autonoma services.

This DPA applies to the processing of Personal Data by the Processor on behalf of the Controller and ensures compliance with applicable data protection laws including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).

This DPA applies to any customer who processes Personal Data through Autonoma as a Controller, on any plan. Our handling of your own account data is described in our Privacy Policy.


2. DEFINITIONS

“Agreement” means the Terms of Service, Software License Agreement, and related agreements.

“Controller” means the entity that determines the purposes and means of processing Personal Data.

“Data Subject” means an identified or identifiable natural person whose Personal Data is processed.

“Personal Data” means any information relating to an identified or identifiable natural person.

“Processing” means any operation performed on Personal Data.

“Processor” means the entity that processes Personal Data on behalf of the Controller.

“Sub-processor” means a third party engaged by the Processor to process Personal Data.

“Supervisory Authority” means an independent public authority responsible for data protection.

“GDPR” means the General Data Protection Regulation (EU) 2016/679.

“CCPA” means the California Consumer Privacy Act of 2018.


3. SCOPE AND APPLICATION

3.1 Scope

This DPA applies to all Processing of Personal Data by the Processor in connection with providing the Services.

3.2 Roles

3.3 Application

This DPA applies when:


4. DATA PROCESSING

4.1 Processing Instructions

The Processor shall:

4.2 Permitted Processing

Processing is permitted for:

4.3 Processing Details

Categories of Data Subjects:

Types of Personal Data:

Processing Activities:

Duration:


5. CONTROLLER OBLIGATIONS

The Controller shall:

5.1 Lawful Basis

5.2 Accuracy

5.3 Instructions

5.4 Data Subject Rights

5.5 Compliance


6. PROCESSOR OBLIGATIONS

The Processor shall:

6.1 Confidentiality

6.2 Security

6.3 Sub-processors

6.4 Assistance

6.5 Data Return/Deletion


7. SUB-PROCESSORS

7.1 Authorized Sub-processors

The Controller authorizes the use of the following Sub-processors:

Sub-processorPurposeLocation
OVH SASHosting for the account server, and DNSFrance
Lemon Squeezy, LLCMerchant of record for licence purchasesUSA
Resend (Plus Five Five, Inc.)Email delivery — licence keys, confirmations, password resetsUSA

That is the whole list. Three parties, one server.

This table previously named seven, and five of them process nothing. It listed Amazon Web Services and Google Cloud Platform (nothing runs on either), Stripe (no payment goes through it — see section 10.3 of the Terms of Service), SendGrid (email goes through Resend), and OpenAI and Anthropic as though we sent your data to them.

That last one is the reason this matters rather than being untidy. We do not call any AI provider on your behalf. You supply your own API keys, they are encrypted on your own machine, and every request goes from your computer directly to the provider you chose. Naming OpenAI and Anthropic as OUR sub-processors described a relationship in which your prompts pass through us. They do not, and there is nowhere for them to pass through: the account server holds email addresses, ranks, licence records and order history, and nothing else.

A sub-processor list is the list a reader uses to decide who holds their data. Padding it is not caution.

7.2 Sub-processor Changes

7.3 Sub-processor Agreements

All Sub-processors are bound by data processing agreements with equivalent protections.


8. SECURITY MEASURES

8.1 Technical Measures

The Processor implements:

Encryption:

Access Controls:

Network Security:

Application Security:

8.2 Organizational Measures

8.3 Physical Security


9. DATA BREACH NOTIFICATION

9.1 Notification Obligation

The Processor shall notify the Controller without undue delay (within 72 hours) upon becoming aware of a Personal Data breach.

9.2 Notification Contents

Notification shall include:

9.3 Cooperation

The Processor shall:

9.4 Documentation

The Processor shall document all breaches including:


10. DATA SUBJECT RIGHTS

10.1 Assistance

The Processor shall assist the Controller in responding to Data Subject requests for:

10.2 Response Time

The Processor shall respond to Controller requests within 10 business days.

10.3 Direct Requests

If Data Subjects contact the Processor directly:


11. INTERNATIONAL TRANSFERS

11.1 Transfer Locations

Personal Data may be transferred to:

11.2 Transfer Mechanisms

For transfers outside the EEA, we rely on:

11.3 Standard Contractual Clauses

The EU Standard Contractual Clauses are incorporated by reference and shall apply to transfers of Personal Data from the EEA to countries without an adequacy decision.


12. AUDIT RIGHTS

12.1 Audit Right

The Controller may audit the Processor’s compliance with this DPA.

12.2 Audit Process

12.3 Documentation

The Processor shall make available:

12.4 Confidentiality

Audit results shall be treated as confidential.


13. LIABILITY

13.1 Limitation

Liability under this DPA is subject to the limitations in the Agreement.

13.2 Allocation

13.3 Indemnification

The Processor shall indemnify the Controller for fines or penalties resulting solely from Processor’s breach of this DPA.


14. TERM AND TERMINATION

14.1 Term

This DPA remains in effect for the duration of the Agreement.

14.2 Termination Effects

Upon termination:

14.3 Survival

Sections regarding confidentiality, liability, and data deletion survive termination.


15. CCPA ADDENDUM (CALIFORNIA)

15.1 CCPA Compliance

For Personal Information of California residents:

15.2 CCPA Certification

The Processor certifies that it:

15.3 Consumer Rights

The Processor shall assist with CCPA consumer rights requests including:


16. GDPR SPECIFIC PROVISIONS

16.1 GDPR Compliance

This DPA incorporates GDPR requirements including:

16.2 Records of Processing

The Processor maintains records of processing activities as required by Article 30.

16.3 Data Protection Contact

Data protection enquiries go to support@autonoma-studio.com, marked for the attention of the data protection contact.


17. AMENDMENTS

This DPA may be amended:


18. CONTACT

All correspondence about this DPA goes to one address:

Email: support@autonoma-studio.com

Mark the message for the attention of the data protection contact, or of legal, as appropriate. We do not operate any other address.


19. EXECUTION

This DPA is incorporated into and forms part of the Agreement. By using the Services, the Controller agrees to this DPA.

If you require a countersigned copy of this DPA, write to support@autonoma-studio.com marking the message for the attention of legal.


This Data Processing Addendum is effective as of the date the Controller begins using the Services.


© 2026 Autonoma. All rights reserved.


Questions about this document? Get in touch.