Legal · Data Processing Agreement
Data Processing Agreement
How Cytra processes personal data on your behalf, and how we put that in writing. Aligned and audit-ready, not certified.
Last updated June 22, 2026
Availability
When Cytra processes personal data on your behalf, we offer a Data Processing Agreement (DPA) that sets out the data-protection terms required by the GDPR (Article 28), the UK GDPR, and comparable laws. Because Cytra is sales-led, the DPA is executed as part of contracting rather than through a click-through page. To request our current DPA for review or signature, email legal@cytra.io or reach us through the contact page. We are happy to review your own DPA template where you require one.
The DPA forms part of, and is governed by, the Cytra customer agreement. Where there is a conflict, the DPA controls for matters of personal-data processing.
What the DPA covers
The Cytra DPA addresses the terms a controller’s privacy team expects from a processor:
- Roles. You are the controller of the personal data you submit to Cytra; Cytra is the processor and acts only on your documented instructions.
- Subject matter, duration, nature, and purpose. Processing to provide the AI-governance platform and managed MCP gateway, for the term of your agreement.
- Categories of data and data subjects. Account and contact data for your authorised users, plus the platform content and governed-action records the product generates.
- Confidentiality and security. Personnel under confidentiality obligations and the technical and organisational measures described on our trust page.
- Sub-processors. Authorisation to engage the sub-processors listed below, with prior notice of changes and an opportunity to object.
- Assistance. Reasonable assistance with data-subject requests, security-incident notification, and your data-protection impact assessments.
- Deletion and return. Deletion or return of personal data at the end of the agreement, subject to retention required by law. Our self-service GDPR export (Article 20) is described in your customer agreement.
- Audit. Information reasonably necessary to demonstrate compliance with Article 28 obligations.
Sub-processors
The DPA incorporates Cytra’s sub-processor list by reference. The enumerated, runtime-accurate inventory — legal entity, location, service, and data category — is maintained on the sub-processors page. We provide notice before a new sub-processor begins processing your personal data so you can object on reasonable data-protection grounds.
International transfers
Cytra production data is processed and stored in the United States. Cytra does not currently offer EU-only or region-pinned data residency. For customers in the European Economic Area, the United Kingdom, or Switzerland, transfers of personal data to the United States are governed by the Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss adaptations, incorporated into the DPA. This is a lawful transfer mechanism — it is not the same as EU data residency, and we do not claim residency we do not have. The full topology is set out on the sub-processors & data-residency page.
Compliance posture
Cytra keeps you aligned and audit-ready; it does not certify you, and it is not itself certified. SOC 2 Type II and a HIPAA Business Associate Agreement (BAA) are in process, not granted. If a signed BAA is a precondition for your use of Cytra with protected health information, raise it during contracting so we can confirm current availability rather than imply a status we do not hold.