Data Processing Addendum
Effective date: 1 November 2026. Published: 8 October 2026.
This DPA is published in advance with the consolidated terms. Until the effective date, the previous SquadraOne DPA remains available.
1. Parties and scope
This Data Processing Addendum forms part of the agreement between the Customer and Eric Leibenguth, entrepreneur individuel (EI), trading as Squadra. Contact: contact@squadra.ai. Address and registration details are provided in the Legal Notice.
It applies when Squadra processes personal data in Customer Data on the Customer’s behalf through the platform or SquadraOne. GDPR terms have their GDPR meanings. The Customer acts as controller or, where it is itself a processor, confirms it has the controller’s authority to engage Squadra as a further processor and transmit its instructions. Processing where Squadra acts as controller is explained in the Privacy Policy.
2. Instructions and confidentiality
Squadra will process personal data only on documented Customer instructions, including the agreement, agent configuration, authorized integrations, retention settings and lawful support requests, including instructions about transfers. If law requires other processing, Squadra will inform the Customer before processing unless legally prohibited. Squadra will immediately inform the Customer if, in its opinion, an instruction infringes GDPR or other applicable EU or Member State data-protection provisions.
Persons authorized to process Customer Data must be subject to confidentiality obligations or an appropriate statutory duty. Content from customer-managed platform organizations will not be used for our own product improvement or model training. SquadraOne retains its specific functionality, prompt and workflow improvement permission under the terms, subject to lawful instructions and any authorization or legal basis required for personal-data reuse. That permission does not authorize AI-model training or unrestricted processing outside the Customer's instructions. Processing for an independent controller purpose is governed by the Privacy Policy and applicable law rather than treated as processor activity merely because Squadra manages the organization. Necessary inference, provider security processing and temporary retention are disclosed in the Privacy Policy and provider list; they must be covered by appropriate provider arrangements.
3. Security and access
Squadra will implement appropriate technical and organizational measures under Article 32, taking account of risk, the state of the art, implementation costs and the nature of the processing. The measures are described in Annex 2. Material changes will not reduce the overall level of protection below that required by the agreement and applicable law.
The Customer manages its organization membership, agent permissions, approval requirements and retention settings, and must take appropriate measures for its own accounts, integrations and Users. This allocation does not remove Squadra’s own security obligations.
4. Subprocessors and international transfers
The Customer generally authorizes the subprocessors identified in the provider list for the applicable service. The list distinguishes core providers, optional connected services and additional SquadraOne providers. An independent payment provider or a tool contracted directly by the Customer is not automatically a Squadra subprocessor for every activity.
Squadra will impose data-protection obligations on subprocessors providing equivalent protection to the obligations applicable under this DPA, and remains responsible to the Customer for their performance of those obligations. Squadra will provide prior notice of intended additions or replacements by email to affected Customers and update the provider list, allowing an opportunity to object on reasonable data-protection grounds. If an objection cannot reasonably be resolved, the Customer may terminate the affected service. Refunds follow the agreement and applicable law.
Transfers outside the EEA must comply with Chapter V of GDPR, including appropriate adequacy decisions or Standard Contractual Clauses and necessary supplementary measures where applicable. Squadra will provide relevant information about safeguards on request. EU database hosting does not represent that all provider processing remains in the EU.
5. Assistance and incidents
Taking account of the nature of processing and information available, Squadra will assist the Customer through appropriate measures with data-subject requests and compliance with Articles 32–36, including security, breach notification, impact assessments and prior consultations. Requests received directly about Customer-controlled data will be referred to the Customer unless law requires otherwise.
Squadra may charge reasonable fees for excessive or repetitive assistance requests, as under the previous DPA, without restricting assistance that must be provided under applicable law.
Squadra will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. Information will include, as available, the nature of the breach, affected data and people, likely consequences, measures taken or proposed and a contact point. Further information may be provided in stages without undue further delay. The Customer remains responsible for notifications it must make as controller; Squadra will cooperate in investigation and remediation.
6. Return and deletion
During the service, conversation and file retention follows the Customer's organization settings, with a default of 12 months. Deleting an organization deletes its data from active service storage as part of the deletion operation, without a 90-day waiting period. A subscription cancellation is separate from an organization-deletion instruction. At the end of the processing service, at the Customer's choice, Squadra will delete or return personal data and delete existing copies unless EU or Member State law requires retention. Customers should request return/export before deleting an organization; return uses an industry-standard format supported by the service where available. This does not promise bespoke export functionality or continuing storage after deletion, without limiting the Customer's rights under Article 28.
The previous SquadraOne period of up to 90 days after an individual user's service terminates remains subject to earlier lawful deletion instructions and shorter configured retention, and does not delay organization deletion. It is not a general 90-day platform retention or recovery guarantee. Database recovery copies expire through backup rotation: the current configuration retains seven automated backups and seven days of recovery logs. Cloud Storage soft delete retains deleted files for seven additional days. Copies awaiting expiry must be restricted to recovery or lawful preservation and not used for ordinary processing; deletion instructions must be reapplied after a restoration. Provider-held copies follow the applicable provider safeguards and retention described in the Privacy Policy and provider list. Squadra will provide available information about completion on request.
7. Accountability and audits
Squadra will make available information necessary to demonstrate compliance with Article 28 and allow and contribute to audits, including inspections, by the Customer or its mandated auditor. As under the previous DPA, Customer audits are limited to once per year unless a material incident occurs, with reasonable notice and safeguards for confidentiality, security and other customers' data. Squadra may satisfy an audit through documentation, security summaries and limited inspection where appropriate. These arrangements do not exclude an audit or inspection required by applicable law or a competent authority, or otherwise restrict mandatory Article 28 rights.
This DPA prevails over conflicting provisions of the agreement concerning processor obligations. It does not restrict a supervisory authority’s powers or mandatory rights and obligations.
Annex 1 — Processing details
- Subject matter and purpose: operation of an AI-agent platform and SquadraOne, storage and retrieval of Customer Data, authorized tool actions, inference, support, maintenance and security on Customer instructions. Customer-managed platform content is not used for our own product improvement or model training; SquadraOne's specific improvement permission is subject to the scope and safeguards in section 2.
- Duration: the service period, followed by return/deletion and the restricted recovery-copy retention described above.
- Nature of processing: collection, access, storage, organization, retrieval, transmission to authorized providers/tools, generation of outputs, modification, deletion and related technical logging.
- Data subjects: Customer personnel and Users, their clients, prospects, suppliers, contacts and people referenced in Customer Data or connected tools.
- Data categories: identifiers and contact details; organization memberships; conversations and prompts; uploaded documents and knowledge-base content; calendar, Notion or other connected-tool data; generated outputs; action logs; and technical connection credentials. Actual categories depend on Customer configuration. Customers must avoid unnecessary sensitive or regulated data and ensure appropriate safeguards if their use entails it.
- Instructions and control: organization settings and authorized use determine the agents, integrations, approval requirements and retention. Knowledge bases are held at organization level, not per end user. For SquadraOne, Squadra administers the dedicated organization and agents while processing a user’s business content under that user’s instructions.
Annex 2 — Technical and organizational measures
-
Infrastructure: Google Cloud Platform
services including Cloud Run, Cloud SQL, virtual machines
and Cloud Storage. Core workloads are described in the
existing architecture as based in
europe-west9(Paris); the confirmed SQL backup location is the EU multiregion. Provider-specific processing and transfers are separately disclosed. - Access: organization roles govern application access. Owners/admins can access stored organization data for support and administration. The service operator has separate infrastructure access for necessary support, maintenance, security and compliance.
- Authentication: strong authentication for infrastructure and administrative consoles, including MFA where available.
- Secrets: API keys are stored as secrets and not displayed after entry; the server inserts them into requests. End-user connection tokens are not exposed to organization owners/admins, whose role alone does not permit use of end-user connections.
- Secret access safeguards: OAuth tokens and credentials are stored using industry-standard safeguards and access controls. Access to secrets is restricted and audited.
- Transmission and storage: use of encrypted network connections and the protections of the underlying managed infrastructure, with access restricted to authorized accounts.
- Recovery: automated SQL backups retaining seven backups; point-in-time recovery logs retained for seven days; SQL backups in the EU multiregion. Cloud Storage soft delete retains deleted files for seven days, with object versioning disabled on the reported file buckets.
- Retention: application controls apply the organization’s conversation and file retention settings. Deleted data in recovery copies remains subject to restricted use and eventual expiry.
- Incident handling: a documented incident-response process, including investigation, containment, breach escalation and Customer notification without undue delay, with assistance for the Customer’s own GDPR obligations.