Legal

Data Processing Agreement

When your business runs on EternalEngine, your customers' data runs through us. This agreement defines exactly what we may do with it: process it on your instructions, protect it, and nothing else.

Effective July 18, 2026

This Data Processing Agreement ("DPA") forms part of theTerms of Service between EternalEngine ("we," "us," the "Processor") and the customer organization identified on the account (the "Customer," the "Controller") and applies whenever we process personal data on the Customer's behalf in the course of providing the EternalEngine platform (the "Service"). Where the GDPR, UK GDPR, CCPA, or similar law applies, this DPA is intended to satisfy the contractual requirements those laws place on controller–processor relationships (including GDPR Article 28).

Roles

You are the controller of the personal data you and your team bring into the Service — your clients' contact records, invoices, bookings, messages, files, and form submissions ("Customer Data"). You decide why and how that data is processed.

We are the processor. We process Customer Data only to provide, secure, and support the Service, on your documented instructions as expressed through the Service's features and settings — never for our own marketing, never for sale, and never to train AI models.

For the limited account data we hold about you directly (your login, billing details, support correspondence), we act as an independent controller as described in the Privacy Policy.

Scope & Instructions

Processing covers the subject matter, duration, nature, and purposes inherent in operating the Service: hosting and storing Customer Data, transmitting it to the recipients you choose (for example, sending an invoice or an email campaign), generating the outputs you request (documents, AI responses, reports), and maintaining backups. Data subjects are your customers, leads, team members, and anyone whose information you process through the Service.

We will not process Customer Data for any other purpose unless required by law — and if the law requires it, we will tell you before processing, unless that law prohibits the notice.

Confidentiality & Security

Everyone authorized to process Customer Data is bound by confidentiality obligations. We implement the technical and organizational measures described on our Security page — including TLS in transit, encrypted backups, an encrypted secrets vault, database-level tenant isolation (row-level security), role-based access control, structured audit logging with no PII in logs, and a secure development lifecycle aligned to OWASP ASVS and NIST SP 800-218. We will not degrade the overall security of the Service during your subscription.

Subprocessors

You authorize the subprocessors below. Each is bound by a written agreement imposing data-protection obligations no less protective than this DPA, and we remain responsible for their performance. We will post changes to this list and, for material changes, notify account owners by email at least 14 days before a new subprocessor processes Customer Data — you may object on reasonable data-protection grounds.

SubprocessorPurposeData involved
StripeSubscription billing and PayGate payment processingBilling contact details, transaction data (card numbers go to Stripe directly, never to our servers)
CloudflareEdge network, DDoS protection, web application firewallTraffic metadata (IP addresses, request headers) in transit
Amazon Web Services (SES)Email delivery for PostFrame and transactional mailRecipient addresses and message content of email you send
AnthropicAI model provider for the built-in assistantPrompts and the workspace context needed to answer them — under terms that prohibit training on your data

Optional connections you make yourself (for example subscribing Google Calendar or Outlook to your BookSlot iCal feed, or bringing your own email provider to PostFrame) are governed by your direct relationship with those providers, not this DPA.

Assistance & Data-Subject Requests

Taking into account the nature of the processing, we will assist you in fulfilling data-subject requests (access, rectification, erasure, portability, objection) — first through the Service's built-in tools (record editing, deletion, CSV export), and where those are insufficient, through direct assistance atinfo@eternalengineos.io. If a data subject contacts us directly about data you control, we will redirect them to you.

We will also provide reasonable assistance with your data-protection impact assessments and consultations with supervisory authorities, where required.

Personal-Data Breach Notification

If we become aware of a personal-data breach affecting Customer Data, we will notify you without undue delay — and in any event within 72 hours of confirmation — with the information we have about the nature of the breach, the categories and approximate number of data subjects affected, likely consequences, and the measures taken or proposed. We will keep you informed as the investigation develops.

Retention, Return & Deletion

Customer Data is processed for the duration of your subscription. After termination, we retain it for up to 90 days so you can export it (per theTerms, Section 13); after that window it will be permanently deleted from production systems — a commitment we honor, not a best effort — and rotated out of encrypted backups on the backup schedule (backup retention is bounded at 14 days or less across every backup path, well inside the 90-day commitment). On written request during the 90-day window we will instead delete it sooner. One disclosed exception: a minimal account ledger — the signup name, email, and deletion record — is retained for fraud and abuse prevention and accurate account history. It never contains Customer Data (your customers' records, files, or content).

Audits & International Transfers

We will make available the information reasonably necessary to demonstrate compliance with this DPA — security documentation, ourpublic security posture, and summaries of relevant assessments. Audits beyond that are available where legally required, on reasonable notice, at the requesting party's cost, and without access to other tenants' data.

Where Customer Data is transferred across borders to a jurisdiction without an adequacy decision, the parties rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated by reference to the extent required.

Precedence & Contact

If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA controls. Liability under this DPA is subject to the limitations in the Terms. Questions, objections, or signature requests (a countersigned copy is available for customers who require one):