Data Processing Addendum
The terms under which we process personal data contained in your repositories and transcripts, on your instructions.
Last updated 13 August 2026.
This addendum forms part of the Terms of Service between you (“Controller”) and Caret AGI (“Processor”). Where they conflict on the processing of personal data, this addendum wins. It applies automatically — you do not need to sign anything, though we will sign a copy if your procurement process requires one.
1. What is processed
- Subject matter — providing a persistent development environment and running coding agents in it.
- Duration — for as long as your account is open, plus the retention periods in the Privacy Policy.
- Categories of data subject — your personnel, and any individuals whose personal data happens to be in the repositories you check out.
- Categories of personal data — whatever your repositories, commit history, issue text and transcripts contain. We do not control or inspect this.
- Special categories — none are required, and Caret is not designed to process them. If yours contain them, that is your decision and your assessment.
2. Our obligations
- We process personal data only on your documented instructions. Your use of the service is the instruction; we will tell you if we believe an instruction breaks data protection law.
- We do not train models on your data and we do not use it for any purpose of our own.
- Everybody with access is bound by confidentiality.
- We keep appropriate technical and organisational measures — encryption in transit, encryption at rest for secrets with a key per team, revocable credentials, least-privilege production access, and network egress restricted by default on every box.
- We assist you, so far as we reasonably can, with data subject requests, impact assessments and consultations with regulators.
- At the end of the contract we delete your data within 30 days, unless the law requires us to keep it.
- We make available the information you need to demonstrate compliance, and we will answer a reasonable audit questionnaire once a year.
3. Breach notification
We will tell you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data, with what we know at the time — what happened, what data, what we are doing about it and who to talk to. We will not wait until we have a complete picture to tell you there is a problem.
4. Subprocessors
You give general authorisation for the subprocessors below. We will give you 30 days’ notice by email before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve your objection you may terminate the affected part of the service and be refunded for the unused period.
Each is bound by terms no less protective than these.
| Subprocessor | Purpose | Location |
|---|---|---|
| Fly.io | The boxes and the control plane | United States |
| PlanetScale | The control plane's database | United States |
| WorkOS | Accounts, sign-in and organisations | United States |
| Dodo Payments | Payments, as merchant of record | United States / India |
| Vercel | This website and the dashboard | United States |
Your model provider is not a subprocessor of ours. Prompts and code go from your box to Anthropic or OpenAI under your own credential and your own agreement with them. We neither add to nor stand behind that relationship.
5. International transfers
Where personal data of individuals in the EEA, Switzerland or the UK is transferred to a country without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated into this addendum by reference. For the UK, the International Data Transfer Addendum applies to those clauses.
For the purposes of the Clauses: the data exporter is you, the data importer is us, the details in section 1 populate Annex I, the measures in section 2 populate Annex II, and the table in section 4 populates Annex III. The governing law and forum are those of the exporter’s member state.
6. California and other US states
For the CCPA as amended, we are a “service provider”. We do not sell or share personal information, we do not retain, use or disclose it for any purpose other than providing the service, and we do not combine it with data from other sources.
7. Liability
Each party’s liability under this addendum is subject to the limits in the Terms of Service, except where the law does not permit that.
8. Contact
privacy@caretagi.com. If you need a countersigned copy, or your own paper reviewed, say so and we will.