Data Processing Addendum

Last updated: June 8, 2026 · Version 1.1

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Switchy ("Processor") and the organization that has accepted them ("Controller") for the use of the Switchy service. Defined terms have the meaning given in the GDPR (Regulation (EU) 2016/679).

1. Scope and Roles

The Controller determines the purposes and means of the processing. The Processor processes Personal Data on the Controller's behalf strictly to provide the Switchy service. This DPA applies whenever Switchy processes Personal Data subject to the GDPR or the UK GDPR.

For the purposes of the California Consumer Privacy Act (CCPA), Switchy is a "Service Provider" with respect to Controller Data, processes such data only for the purposes set out in this DPA, and does not sell or share it.

2. Subject-matter, Duration, Nature, Purpose

  • Subject-matter: Personal Data submitted to or generated by use of the Switchy service.
  • Duration: The term of the Controller's subscription, plus any post-termination retention period set out in /privacy.
  • Nature and purpose: Hosting, transmission, structuring, retrieval, and deletion of Controller Data to provide team chat, multi-model AI access, and persistent memory. This includes ingesting message content from Slack and Microsoft Teams channels the Controller links to a Project; performing autonomous agent tasks on the Controller's connected tools (any write or sensitive action gated behind explicit human approval); importing historical chat from a Slack or Teams export archive at the Controller's direction; and exposing the Controller's team memory to external AI clients (e.g. Claude, ChatGPT, Cursor) through a per-organization MCP server.
  • Categories of data subjects: The Controller's authorised users (members of its organization in Switchy) and any third parties whose Personal Data they choose to submit.
  • Categories of Personal Data: Account data (name, email, OAuth identifier), message and memory content, usage telemetry, billing identifiers.

3. Controller Instructions

Switchy processes Personal Data only on documented instructions from the Controller. The Terms of Service, this DPA, the privacy policy, and the Controller's configuration of its organization (members, MCP integrations bound to Projects, billing plan) constitute the complete and final instructions. Any additional instruction must be agreed in writing and may incur additional fees if it materially changes the service.

4. Sub-processors

The Controller authorises Switchy to engage the sub-processors listed in Section 5 of the privacy policy:

  • OpenRouter (model inference routing) - United States
  • Model providers via OpenRouter - Anthropic, OpenAI, Google, xAI, Meta, Mistral (model inference) - United States / provider regions
  • Google Cloud Platform (hosting, database, Secret Manager credential storage; at-rest encryption is Google-managed, AES-256) - EU (europe-west1)
  • Ably (realtime message delivery) - EU + global edge
  • Stripe (billing and payments; no chat content) - United States
  • Composio (outbound tool execution; holds per-user OAuth tokens, Switchy holds only opaque connection handles) - United States
  • Resend (transactional email) - United States / EU
  • Slack (surface integration; ingests linked-channel and DM message content) - United States
  • Microsoft / Teams (surface integration; ingests added-channel and 1:1 message content) - United States / global
  • PostHog (session replay and product analytics; masks all inputs, excludes auth/billing pages, 30-day retention) - EU
  • Google Analytics (aggregate web analytics, cookieless storage:'none' mode) - United States
  • Google Ads (ad conversion tracking) - United States
  • Amplitude (product analytics) - United States
  • NextAuth / Auth.js (authentication) - self-hosted (EU)
  • Third-party MCP integrations the Controller's admin chooses to connect (GitHub, Notion, custom HTTPS MCPs)

Switchy will notify the Controller at least 30 days before adding or replacing a sub-processor that processes Controller Data. The Controller may object on reasonable data-protection grounds, in which case Switchy will use commercially reasonable efforts to provide an alternative or, failing that, the Controller may terminate the affected service for cause without penalty for the unused portion of the prepaid term.

5. Confidentiality

Switchy ensures that any person it authorises to process Personal Data is bound by an obligation of confidentiality (whether contractual or statutory) and processes Personal Data only as instructed by the Controller.

6. Security

Switchy implements appropriate technical and organisational measures to protect Personal Data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256, managed by Google Cloud across Secret Manager and disk).
  • Storage of all credentials and OAuth tokens in Google Secret Manager - the database holds only an opaque reference, each reference is bound to its owning organization (cross-tenant resolution is refused), and the credential is injected only at the outbound call, never in the database, logs, or model context.
  • Visibility-aware data access enforced at the database query layer (Private / Project / Org); Private memory is scoped to its single owner. Visibility is computed from the source of each memory, not user-picked, and fails closed to the most private option.
  • Explicit human approval required before any side-effecting action on a connected tool; the approver must be an organization member and the credential is re-resolved against the original requester, so an approval cannot escalate scope. This holds even where channel content contains a prompt injection.
  • A consolidated cross-user / cross-tenant leak test suite runs as a required CI merge gate; a red test blocks the merge.
  • Server-side request forgery (SSRF) protection on all outbound MCP calls, including DNS-rebinding defence.
  • Per-API-key rate limits, sub-second key revoke, and idempotency keys on all writes.
  • Quarterly access reviews and least-privilege IAM in the underlying GCP project.
  • Hosting on Google Cloud Platform, which holds ISO 27001 and SOC 2 Type II certification. Switchy's own SOC 2 audit is in progress; Switchy is not itself SOC 2 certified.

A more detailed security overview is available at /security.

7. Data Subject Rights

Switchy will assist the Controller in fulfilling requests from data subjects exercising their rights under GDPR Articles 12–22, taking into account the nature of the processing. Most rights (access, rectification, erasure, portability) can be exercised directly by the data subject in the Switchy UI; for any request that cannot, the Controller may contact contact@switchy.build.

8. Personal Data Breach

Switchy will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting Controller Data, providing all information reasonably required for the Controller to comply with its obligations under GDPR Art. 33.

9. International Transfers

Where Switchy or its sub-processors transfer Personal Data outside the EU/EEA, the transfer is governed by EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or, where applicable, the EU-US Data Privacy Framework. The relevant SCC modules are incorporated into this DPA by reference.

10. Audits

Switchy will make available to the Controller, on reasonable request and not more than once per twelve-month period (except where required by a supervisory authority), the information necessary to demonstrate compliance with Art. 28. Where the Controller wishes to conduct an audit beyond reviewing third-party reports (e.g. SOC 2), the parties will agree the scope, timing, and reasonable cost in advance.

11. Return or Deletion

When an organization is deleted, it enters a 7-day recovery window during which it can be restored and the Controller may export its data in standard formats. After the window, Switchy purges Controller Data - surface-vault secrets, memory, messages, and chat sessions, then the organization record - from the live system. Backups containing Personal Data will be deleted in the ordinary course of business, no later than approximately 90 days after termination.

12. Liability and Order of Precedence

To the extent of any conflict between this DPA and the Terms of Service or any order form, this DPA prevails with respect to the processing of Personal Data. Liability under this DPA is subject to the limitations set out in the Terms of Service.

13. How to Sign

Acceptance of the Terms of Service by an authorised representative of the Controller constitutes acceptance of this DPA. If your procurement process requires a counter-signed copy, email contact@switchy.build with the subject line "DPA counter-sign request" and we will return a PDF within five business days.