Data Processing Addendum

How BetterClaw processes personal data on behalf of its customers.

Last updated: September 2026 17 min read

This Data Processing Addendum (“DPA”) forms part of the BetterClaw Terms and Conditions, or any other written or electronic agreement for the BetterClaw services (the “Agreement”), between BitQit Private Limited, a company incorporated in India with registered office at 475-476, Vegas Towers, Sector 14, Dwarka, New Delhi 110078, India (CIN U72900DL2016PTC301193) (“BetterClaw”, “we”, “us”), and the customer that has agreed to the Agreement (“Customer”). BetterClaw and Customer are each a “Party”.

This DPA applies where, and only to the extent that, BetterClaw processes Customer Personal Data on behalf of Customer in providing the Services. It takes effect on the later of the effective date of the Agreement and the date Customer accepts this DPA, whether by clicking to accept, by signing, or by continuing to use the Services after it is made available. No separate signature is required unless Customer requests a countersigned copy at hello@betterclaw.io.

1. Definitions

Capitalized terms not defined in this DPA have the meanings given in the Agreement. In this DPA:

1.1 “Agent” means an AI agent that Customer creates, configures, or runs on the Services, including its instructions, skills, schedules, memories, connected tools, and approval or autonomy settings.

1.2 “AI Model Provider” means a third party that operates a large language model or other AI model used to generate outputs for an Agent.

1.3 “Applicable Data Protection Law” means all laws and regulations relating to privacy, data protection, and data security that apply to the processing of Customer Personal Data under the Agreement, including, as applicable: (a) Regulation (EU) 2016/679 (“EU GDPR”); (b) the EU GDPR as retained in UK law and the UK Data Protection Act 2018 (“UK GDPR”); (c) the Swiss Federal Act on Data Protection (“FADP”); (d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its regulations (“CCPA”), and other United States state comprehensive privacy laws (together, “US State Privacy Laws”); and (e) India’s Digital Personal Data Protection Act, 2023 and its rules (“DPDP Act”).

1.4 “BYOK Provider” means an AI Model Provider or other third party that Customer selects and authenticates with its own credentials, API key, or account (including “Sign in with ChatGPT”), such that data is sent to that provider under Customer’s own account and agreement with that provider.

1.5 “Connected Service” means a third-party application or service (for example, email, calendar, CRM, analytics, advertising, or messaging platforms) that Customer or its users connect to the Services so that Agents can read data from it or take actions in it.

1.6 “Customer Personal Data” means Personal Data contained in Customer Content that BetterClaw processes on behalf of Customer in providing the Services, including messages, files, attachments, Agent instructions and memories, and data that Agents retrieve from Connected Services. It does not include Account Data or Usage Data.

1.7 “Account Data” means information about Customer and its users that BetterClaw processes to manage the customer relationship, such as names, email addresses, billing details, and authentication records. “Usage Data” means information about how the Services are used, such as log, device, performance, and product-analytics data, excluding the content of messages and files.

1.8 “Managed Model Access” means use of an AI Model Provider through credentials or accounts that BetterClaw provides, rather than Customer’s own credentials.

1.9 “Security Incident” means a confirmed breach of security of the Services leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. It does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, or blocked login attempts.

1.10 “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, as amended).

1.11 “Subprocessor” means a third party engaged by BetterClaw that processes Customer Personal Data on BetterClaw’s behalf in providing the Services. BYOK Providers and Connected Services are not Subprocessors.

1.12 “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Supervisory Authority” have the meanings given in Applicable Data Protection Law. Where that law uses other terms for equivalent concepts (for example “business”, “service provider”, “contractor”, “personal information”, “Data Fiduciary”, “Data Processor”, or “Data Principal”), those terms are included.

1.13 “Confidential Information” means non-public information that one Party discloses to the other in connection with the Agreement or this DPA and that is marked as confidential or would reasonably be understood to be confidential, including audit information under Section 10. It does not include information that is or becomes public through no fault of the receiving Party, was lawfully known to or independently developed by the receiving Party, or is lawfully received from a third party without a duty of confidentiality.

1.14 “Customer Content” means all data and materials that Customer or its users submit to the Services, or that Agents retrieve from Connected Services on Customer’s behalf, including messages, files, attachments, Agent instructions and memories, and the outputs the Services generate for Customer.

1.15 “Services” means the BetterClaw AI agent platform, websites, and iOS app, and related support, that BetterClaw provides to Customer under the Agreement.

2. Scope and roles

2.1 Customer as Controller. For Customer Personal Data, Customer is the Controller (or, where Customer acts on behalf of its own clients, a Processor), and BetterClaw is the Processor (or, as applicable, a sub-processor). Where Customer is a Processor, Customer warrants that its instructions, including its appointment of BetterClaw, have been authorized by the relevant Controller.

2.2 BetterClaw as independent Controller. BetterClaw processes Account Data and Usage Data as an independent Controller, in accordance with its Privacy Policy at https://www.betterclaw.io/privacy-policy, for purposes such as account administration, billing, security, fraud prevention, legal compliance, and improving the Services. This DPA does not apply to that processing, except that BetterClaw will not use Customer Personal Data for those purposes other than as permitted by this DPA.

2.3 BYOK Providers and Connected Services. When Customer configures an Agent to use a BYOK Provider, or connects a Connected Service, Customer instructs BetterClaw to transmit Customer Personal Data to, and receive it from, that third party. That third party processes the data under Customer’s own account and Customer’s agreement with it, and is not BetterClaw’s Subprocessor. BetterClaw is not responsible for the processing, security, retention, or training practices of BYOK Providers or Connected Services. Customer is responsible for entering into any agreement required by Applicable Data Protection Law with those third parties.

2.4 Details of processing. The subject matter, duration, nature, and purpose of the processing, and the types of Personal Data and categories of Data Subjects, are described in Annex I.

3. Customer instructions

3.1 BetterClaw will process Customer Personal Data only on Customer’s documented instructions, unless required to do otherwise by applicable law, in which case BetterClaw will inform Customer of that legal requirement before processing unless the law prohibits it.

3.2 Customer’s documented instructions are: (a) the Agreement and this DPA; (b) Customer’s configuration and use of the Services, including the instructions, schedules, skills, models, Connected Services, credentials, and approval or autonomy settings Customer gives each Agent; and (c) any other reasonable written instructions that the Parties agree are consistent with the Agreement.

3.3 Agents act on Customer’s configuration. Customer acknowledges that Agents generate outputs and may take actions in Connected Services based on Customer’s configuration, and that AI-generated outputs may be inaccurate. Customer is responsible for configuring Agents, their permissions, and their approval settings appropriately, and for reviewing outputs before relying on them.

3.4 BetterClaw will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. BetterClaw is not obliged to perform a comprehensive legal review of Customer’s instructions.

4. Customer obligations

4.1 Customer is responsible for the accuracy, quality, and lawfulness of Customer Personal Data and the means by which it was obtained, and for providing any notices and obtaining any consents or other legal bases required for BetterClaw to process it under this DPA.

4.2 Unless agreed in writing, Customer will not use the Services to process: (a) special categories of Personal Data under Article 9 of the EU GDPR or “sensitive personal information” under US State Privacy Laws, beyond what is incidental to ordinary business correspondence; (b) protected health information subject to HIPAA; (c) payment card data subject to PCI DSS; (d) government identification numbers; or (e) Personal Data of children under 13 (or the higher age of consent under applicable law). BetterClaw is not a “business associate” under HIPAA.

4.3 Customer is responsible for the security of its accounts, credentials, API keys, and Connected Service authorizations, and for managing which users and Agents can access them.

5. BetterClaw obligations

5.1 Purpose limitation. BetterClaw will process Customer Personal Data only to provide, maintain, secure, and support the Services for Customer in accordance with Section 3.

5.2 No AI model training. BetterClaw will not use Customer Personal Data to train, fine-tune, or otherwise improve any AI model, and will not permit any Subprocessor to do so. BetterClaw engages AI Model Providers as Subprocessors only on terms that prohibit the use of submitted data for training or improving their models.

5.3 No sale, advertising, or profiling. BetterClaw will not sell or rent Customer Personal Data, use it for advertising, or build profiles from it for any purpose unrelated to providing the Services.

5.4 Confidentiality. BetterClaw will ensure that personnel authorized to process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and access it only as needed to provide the Services.

5.5 Google user data. Where Customer Personal Data is received from Google APIs, BetterClaw’s use and transfer of that data will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

6. Security

6.1 BetterClaw will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against Security Incidents, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to Data Subjects. Those measures include the measures described in Annex II.

6.2 BetterClaw may update its security measures from time to time, provided that the updates do not materially decrease the overall level of protection of Customer Personal Data.

7. Subprocessors

7.1 General authorization. Customer gives BetterClaw general written authorization to engage Subprocessors. The Subprocessors in use on the effective date of this DPA are listed in Annex III and at https://www.betterclaw.io/legal/subprocessors (the “Subprocessor List”).

7.2 Flow-down. BetterClaw will enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the services the Subprocessor provides. BetterClaw remains responsible for each Subprocessor’s performance of its obligations.

7.3 Notice of new Subprocessors. BetterClaw will give at least 30 days’ notice before a new Subprocessor begins processing Customer Personal Data, by updating the Subprocessor List and notifying users who have signed up with BetterClaw.

7.4 Objection. Customer may object to a new Subprocessor on reasonable grounds relating to the protection of Customer Personal Data by notifying BetterClaw in writing within 15 days of the notice. The Parties will discuss the objection in good faith. BetterClaw may, at its option, offer a commercially reasonable alternative, such as a configuration that avoids the new Subprocessor. If no alternative is agreed within 30 days, Customer may terminate the affected Services on written notice and receive a refund of any prepaid fees for the terminated portion of the subscription term.

7.5 Urgent replacement. Where BetterClaw must replace a Subprocessor urgently for reasons outside its reasonable control, such as a Subprocessor’s security failure or insolvency, BetterClaw may do so immediately and will notify Customer as soon as practicable, and Section 7.4 will apply from that notice.

8. Security Incidents

8.1 BetterClaw will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident.

8.2 The notice will describe, to the extent then known: the nature of the Security Incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Where information is not available at once, BetterClaw will provide it in phases without undue delay.

8.3 BetterClaw will take reasonable steps to contain, investigate, and mitigate the Security Incident, and will provide reasonable cooperation so that Customer can meet its own notification obligations to Supervisory Authorities (including the Data Protection Board of India) and Data Subjects.

8.4 Notices will be sent to the email address associated with Customer’s account owner, or another address Customer designates. BetterClaw’s notification of or response to a Security Incident is not an acknowledgment of fault or liability.

9. Assistance

9.1 Data Subject requests. The Services let Customer access, export, correct, and delete Customer Personal Data, including by deleting Agents, conversations, files, memories, and Connected Service authorizations. To the extent Customer cannot do so itself, BetterClaw will provide reasonable assistance, taking into account the nature of the processing, to help Customer respond to Data Subject requests. If BetterClaw receives a request directly from a Data Subject that identifies Customer, BetterClaw will direct the Data Subject to Customer and will not respond itself, except to confirm the request was received.

9.2 Impact assessments. Taking into account the nature of the processing and the information available to BetterClaw, BetterClaw will provide reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities that Applicable Data Protection Law requires of Customer in relation to the Services.

9.3 Government requests. If a public authority requests access to Customer Personal Data, BetterClaw will, unless legally prohibited, promptly notify Customer, attempt to redirect the authority to Customer, and challenge requests it reasonably considers unlawful. BetterClaw will disclose only the minimum Customer Personal Data required to comply.

10. Audits

10.1 BetterClaw will make available to Customer, on written request, information reasonably necessary to demonstrate compliance with this DPA, including its ISO/IEC 27001 certificate, summaries of relevant security policies, and responses to a reasonable written security questionnaire no more than once in any 12-month period.

10.2 Where the information in Section 10.1 is not sufficient to demonstrate compliance, or where required by Applicable Data Protection Law or a Supervisory Authority, Customer (or an independent auditor bound by confidentiality and not a BetterClaw competitor) may audit BetterClaw’s compliance with this DPA. Audits require at least 30 days’ written notice, take place during business hours no more than once in any 12-month period (unless following a Security Incident or required by a Supervisory Authority), are conducted in a way that minimizes disruption, and do not extend to other customers’ data or to Subprocessors’ facilities. Customer bears its own audit costs. All audit information is BetterClaw’s Confidential Information.

11. International transfers

11.1 BetterClaw is established in India, and it and its Subprocessors may process Customer Personal Data in India, the United States, and the other locations listed in Annex III. BetterClaw will ensure that any transfer of Customer Personal Data is made in accordance with Applicable Data Protection Law.

11.2 EEA transfers. To the extent Customer Personal Data subject to the EU GDPR is transferred to BetterClaw in a country not recognized as providing an adequate level of protection, the Parties incorporate the SCCs by reference as follows: (a) Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) applies where Customer is a Processor; (b) the optional docking clause in Clause 7 applies; (c) in Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 7.3; (d) the optional language in Clause 11 does not apply; (e) in Clause 13, the competent Supervisory Authority is the one determined by Clause 13 based on Customer’s establishment or representative; (f) in Clause 17, the SCCs are governed by the law of Ireland; (g) in Clause 18, disputes are resolved by the courts of Ireland; and (h) Annexes I, II, and III of the SCCs are completed by Annexes I, II, and III of this DPA.

11.3 UK transfers. To the extent Customer Personal Data subject to the UK GDPR is transferred, the UK Addendum is incorporated by reference and completed as follows: Table 1 is completed with the Parties’ details in Annex I; Table 2 refers to the SCCs as incorporated under Section 11.2; Table 3 is completed by Annexes I to III of this DPA; and in Table 4, neither Party may end the UK Addendum under Section 19 of the UK Addendum.

11.4 Swiss transfers. To the extent Customer Personal Data subject to the FADP is transferred, the SCCs as incorporated under Section 11.2 apply with these changes: references to the EU GDPR are read as references to the FADP; the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner; references to “Member State” include Switzerland so that Data Subjects in Switzerland can enforce their rights there; and the SCCs also protect data of legal entities until the revised FADP excludes them.

11.5 Onward transfers. BetterClaw will ensure that transfers to Subprocessors in third countries are covered by an appropriate safeguard under Applicable Data Protection Law, such as the SCCs (Module Three) or an adequacy decision or recognized framework applying to the Subprocessor.

11.6 Conflict and alternative mechanisms. If there is a conflict between this DPA and the SCCs or the UK Addendum, the SCCs or the UK Addendum prevail. If a transfer mechanism is invalidated or replaced, the Parties will cooperate in good faith to adopt a lawful alternative.

12. US State Privacy Laws

12.1 For Customer Personal Data subject to US State Privacy Laws, BetterClaw acts as Customer’s “service provider” or “processor”, and the business purpose of the processing is providing the Services as described in the Agreement and Annex I.

12.2 BetterClaw will not: (a) sell or share (as those terms are defined in the CCPA) Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose, including any commercial purpose, other than the business purposes specified in the Agreement, or as otherwise permitted by US State Privacy Laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between BetterClaw and Customer; or (d) combine Customer Personal Data with personal information BetterClaw receives from or on behalf of others, or collects from its own interactions with a consumer, except as permitted by US State Privacy Laws.

12.3 BetterClaw will comply with applicable obligations under US State Privacy Laws, provide the same level of privacy protection they require, and notify Customer if it determines it can no longer meet its obligations under them. Customer may, on notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.

12.4 If BetterClaw receives deidentified data from Customer, it will take reasonable measures to ensure the data cannot be associated with an individual, publicly commit to maintain and use it only in deidentified form, and not attempt to reidentify it. BetterClaw certifies that it understands and will comply with the restrictions in this Section 12.

13. India’s DPDP Act

13.1 For Customer Personal Data subject to the DPDP Act, Customer is the Data Fiduciary and BetterClaw is a Data Processor engaged under this valid contract. BetterClaw will process such data only on Customer’s behalf and in accordance with this DPA.

13.2 BetterClaw will provide reasonable assistance to enable Customer to meet its obligations to Data Principals, to intimate personal data breaches to the Data Protection Board of India and affected Data Principals as the DPDP Act requires, and to erase Customer Personal Data when Customer withdraws its instruction or the specified purpose is no longer being served, subject to Section 14.

14. Return and deletion

14.1 During the term, Customer can export and delete Customer Personal Data using the features of the Services.

14.2 Within 30 days after termination or expiry of the Agreement, BetterClaw will delete Customer Personal Data from its production systems, and will instruct its Subprocessors to do the same. Copies in backups will be deleted in the ordinary course of backup rotation, and in any event within 90 days, and remain protected by this DPA until deleted. Customer should export any data it wishes to keep before termination.

14.3 BetterClaw may retain Customer Personal Data to the extent required by applicable law, in which case this DPA continues to apply and BetterClaw will process that data only for the purposes the law requires. On written request, BetterClaw will confirm in writing that deletion has been completed.

15. Liability

15.1 Each Party’s liability arising out of or relating to this DPA, whether in contract, tort, or otherwise, is subject to the exclusions and limitations of liability in the Agreement, and any reference in the Agreement to a Party’s liability means its aggregate liability under the Agreement and this DPA together.

15.2 Nothing in this Section limits either Party’s liability to Data Subjects under the third-party beneficiary provisions of the SCCs or the UK Addendum, or any liability that cannot be limited under applicable law.

16. General

16.1 Order of precedence. If there is a conflict between the documents, the following order applies: (a) the SCCs and UK Addendum, where applicable; (b) this DPA; and (c) the Agreement. Otherwise, the Agreement continues unchanged.

16.2 Term. This DPA remains in effect for as long as BetterClaw processes Customer Personal Data under the Agreement.

16.3 Changes. BetterClaw may update this DPA to reflect changes in Applicable Data Protection Law, guidance from a Supervisory Authority, or changes to the Services, provided the update does not materially reduce the protection of Customer Personal Data. BetterClaw will give at least 30 days’ notice of material updates.

16.4 Governing law. Except where the SCCs or UK Addendum require otherwise, this DPA is governed by the law and dispute resolution provisions of the Agreement.

16.5 Severability. If any provision of this DPA is held invalid or unenforceable, the rest of this DPA remains in effect, and the provision will be modified to the minimum extent necessary to make it enforceable.

16.6 Contact. Privacy questions and notices under this DPA should be sent to hello@betterclaw.io, or by post to BitQit Private Limited, 475-476, Vegas Towers, Sector 14, Dwarka, New Delhi 110078, India.

Annex I: Details of processing

A. List of parties

Data exporter
Customer, as identified in the Agreement or its BetterClaw account. Role: Controller (or Processor on behalf of its clients). Contact: the account owner, or as Customer designates.
Data importer
BitQit Private Limited (operating BetterClaw), 475-476, Vegas Towers, Sector 14, Dwarka, New Delhi 110078, India. Role: Processor (or sub-processor). Contact: Shabnam Katoch, CMO, hello@betterclaw.io.
Activities
Provision of the BetterClaw AI agent platform under the Agreement.
Signature and date
By accepting this DPA, each Party is deemed to have signed this Annex on the effective date of this DPA.

B. Description of processing

Categories of Data Subjects
Customer’s authorized users; and individuals whose Personal Data is included in Customer Content or retrieved from Connected Services, such as Customer’s customers, prospects, employees, contractors, suppliers, and correspondents.
Categories of Personal Data
Identification and contact details (such as names, email addresses, phone numbers); the content of messages, conversations, files, and attachments; Agent instructions and memories; data retrieved from Connected Services (such as emails, calendar events, CRM records, analytics and advertising account data); credentials, API keys, and OAuth tokens (stored encrypted); and technical data needed to run Agents (such as logs and identifiers).
Sensitive data
None intended. Customer will not submit sensitive data except as permitted by Section 4.2. Any such data is protected by the measures in Annex II.
Frequency of transfer
Continuous, for the duration of the Agreement.
Nature of processing
Hosting and storage; running Agents in isolated containers; sending data to AI Model Providers to generate outputs; generating conversation titles and maintaining Agent long-term memory; retrieving data from and taking actions in Connected Services as configured by Customer; delivering notifications; providing support; and deletion.
Purpose of processing
Providing, maintaining, securing, and supporting the Services for Customer under the Agreement.
Retention
For the term of the Agreement, subject to Customer’s plan retention settings and deletion choices, and then deleted under Section 14. Credentials are purged from active Agent memory five minutes after use. Cached Google Ads data is purged after 30 days.
Subprocessor processing
As described in Annex III, for the duration of the Agreement.
Competent Supervisory Authority
As determined under Clause 13 of the SCCs.

Annex II: Technical and organizational security measures

BetterClaw maintains the following technical and organizational measures.

Isolation and access control

  • Each Agent runs in its own sandboxed Docker container with network isolation, so one Agent cannot reach another.
  • Workspace scoping: Agents can access only the resources Customer explicitly allows.
  • Per-Agent credential grants: a secret or connected account is usable only by the Agents Customer grants it to, and access can be revoked per Agent at any time.
  • Role-based access control for team workspaces (admin and member roles).
  • User authentication through a dedicated identity provider (Clerk).
  • Internal access to production systems is limited to authorized personnel on a need-to-know basis, using multi-factor authentication.

Encryption and credential handling

  • API keys, OAuth tokens, and secrets are encrypted at rest with AES-256, with encryption keys protected by Google Cloud KMS.
  • Credentials are decrypted only in memory at the moment they are needed, are never written to logs, and are purged from active Agent memory after five minutes.
  • Data in transit is encrypted using TLS.
  • Customer data at rest is encrypted, including in databases, object storage, and backups.

Monitoring and logging

  • Secrets audit log: every read, grant, and revoke of a secret is recorded with the key, Agent, skill, time, and whether access was granted or denied, visible to Customer in its dashboard.
  • Real-time health monitoring of Agents, with automatic pause when anomalies are detected.
  • Kill switch allowing Customer to stop an Agent immediately.
  • Cryptographic gateway pairing for connections between Agents and the platform.

Governance and resilience

  • An information security management system certified to ISO/IEC 27001.
  • Written confidentiality obligations and security awareness training for all personnel with access to Customer Personal Data.
  • Documented incident response process supporting the notification commitments in Section 8.
  • Regular backups and documented disaster recovery procedures.

Data minimization and deletion

  • Customer controls retention through plan settings and can delete Agents, conversations, files, memories, and connected accounts at any time.
  • Google Calendar and Search Console data is processed in memory and not retained beyond the request.
  • Customer Personal Data is not used to train AI models.

Annex III: Subprocessors

BYOK Providers that Customer selects with its own credentials (for example Anthropic, OpenAI including Sign in with ChatGPT, or Google) are not BetterClaw Subprocessors; see Section 2.3.

The Subprocessors, their purposes, locations, and the customers they apply to are listed on the Subprocessor List at https://www.betterclaw.io/legal/subprocessors, which is updated as described in Section 7.