# Data Processing Agreement — AgenticRail

> Markdown mirror for AI agents, generated 2026-08-06 from the live page.
> Canonical: https://agenticrail.nz/dpa/
> Site context: https://agenticrail.nz/llms.txt

# Data Processing Agreement

Version 2.0 · Last updated 2026-07-24 · supersedes v1.9 (2026-07-08)

 Between TUARA KURI LIMITED (Processor) and Customer (Controller).

 Effective: upon execution of a paid AgenticRail subscription.

## 1. Definitions

**"Controller"** means the Customer — the entity that determines the purposes and means of processing personal data through the AgenticRail service.

**"Processor"** means TUARA KURI LIMITED, a New Zealand registered company (NZBN: 9429053582867) trading as AgenticRail, 431 Omanaia Road, RD 3, Kaikohe 0473, New Zealand.

**"Subprocessor"** means any third party engaged by the Processor to process personal data on behalf of the Controller. Current subprocessors are listed in Section 8.

**"Personal Data"** means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.

**"Service"** means the AgenticRail API (sequence enforcement, receipt generation, compliance reporting).

**"GDPR"** means Regulation (EU) 2016/679.

## 2. Scope and Purpose of Processing

The Processor processes personal data solely for the purpose of providing the Service:

- Receiving API requests at the Wrapper endpoint
- Authenticating API keys against the Processor's database
- Evaluating enforcement decisions via the Core Worker + Durable Object
- Writing cryptographic receipts to R2 tamper-evident storage
- Generating compliance reports on request

The Controller determines what data is sent in API request payloads. The Processor does not inspect, retain, or use payload data beyond what is necessary for enforcement evaluation.

## 3. Duration

This DPA is effective for the duration of the Controller's paid AgenticRail subscription. Upon termination, at the Controller's choice, the Processor will delete or return all personal data within 90 days and delete existing copies, unless retention is required by applicable law, in accordance with the retention schedule in Section 7. The Controller may exercise this choice by written notice to hello@agenticrail.nz prior to or at termination; absent such notice, the Processor will delete the personal data.

## 4. Processor Obligations

The Processor shall:

- Process personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do otherwise by applicable law (in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits such notice)
- Immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes the GDPR or other applicable data protection law
- Ensure persons authorised to process personal data are committed to confidentiality
- Implement appropriate technical and organisational measures as described in Section 6
- Assist the Controller in fulfilling data subject requests (access, rectification, erasure) where possible
- Assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, including conducting data protection impact assessments and prior consultation with a supervisory authority where relevant
- Notify the Controller without undue delay, and in any event within 48 hours, upon becoming aware of a personal data breach
- Make available to the Controller all information necessary to demonstrate compliance

## 5. Controller Obligations

The Controller shall:

- Ensure a lawful basis exists for processing personal data through the Service
- Not include special categories of personal data in API request payloads unless a specific derogation applies
- Provide necessary notices to data subjects regarding the processing
- Ensure API keys are stored securely and not exposed in client-side code or public repositories

## 6. Technical and Organisational Measures

The Processor implements the following measures:

| Measure | Implementation |
| Encryption in transit | TLS 1.3 for all API endpoints |
| Access control | Bearer token authentication per API key. Timing-safe comparison on all credential checks. |
| Infrastructure isolation | Enforcement core is air-gapped (no public URL). Accessible only via authenticated service bindings between Cloudflare Workers. |
| Audit trail | Ed25519-signed cryptographic receipts on every enforcement decision. Tamper-evident R2 storage, with sealed receipts copied to an independently held write-once archive. |
| Availability | Deployed on Cloudflare's global network (330+ data centers). Durable Objects provide consistent state. |
| Incident response | Personal data breaches notified to the Controller without undue delay and within 48 hours of detection (Section 4). |

## 7. Data Retention and Deletion

| Data | Retention | Automatic Deletion |
| API request payloads | Duration of enforcement evaluation only (not persisted) | N/A — not stored |
| Enforcement receipts | Retained to preserve the integrity of the verifiable receipt chain; no tiered or automated deletion schedule currently applies | None currently — no R2 lifecycle policy is applied to production receipts; a specific retention/deletion arrangement can be agreed by contract |
| API keys (hashed) | Duration of subscription + 30 days | D1 record deletion |
| Usage logs | 90 days | Wrapper cron job (daily) |
| Client account data | Duration of subscription + 30 days | D1 record deletion |

The 90-day deletion commitment in Section 3 applies to personal data. Enforcement receipts retained beyond that period contain only enforcement metadata — cryptographic hashes, nonces, step labels, decision codes, and timestamps — and do not contain personal data from Controller payloads, which are never persisted. Where a Controller's chosen identifiers (for example, a `sequence_id`) could themselves constitute personal data, the Controller is responsible for avoiding the inclusion of personal data in such identifiers.

## 8. Subprocessors

| Subprocessor | Service | Location | Processing |
| Cloudflare, Inc. | Workers, Durable Objects, R2, KV, D1 | Global (data processed at edge) | Hosts the Service infrastructure. All enforcement execution, receipt storage, and API authentication. |
| **AI Provider** — current: Google (Gemini API) | Compliance narrative generation | API endpoint (regional, per provider) | Generates AI compliance narratives for reports. Receives only enforcement summary statistics (no personal data from payloads, no receipt content). The AI Provider operates exclusively in the report worker; it has no role in enforcement decisions and never receives customer agent payloads. |
| Stripe, Inc. | Payment processing | Global | Processes subscription payments. Receives customer email and payment details. |
| Resend, Inc. | Transactional email | Global | Delivers API key welcome emails. Receives customer email address only. |

**AI Provider category.** The "AI Provider" is treated as a category, not a fixed vendor. The current provider is Google (Gemini API). Previous providers used by the Processor have included DeepSeek and Anthropic (Claude). The Processor may change the AI Provider with at least 14 days' notice under the standard subprocessor change process below. Enterprise Controllers may specify an alternative AI Provider (or opt out of AI-generated narratives entirely) under their enterprise contract.

The Processor will notify the Controller of any intended changes to subprocessors at least 14 days in advance. The Controller may object on reasonable data protection grounds. The current authoritative subprocessor list is the version of this DPA in force at the time of any given enforcement decision; the document fingerprint at the bottom of this page identifies that version cryptographically.

**Subprocessor obligations and liability.** The Processor shall impose, by written contract, data protection obligations on each subprocessor that are no less protective than those set out in this DPA, in particular the obligation to implement appropriate technical and organisational measures meeting the requirements of the GDPR. Where a subprocessor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of that subprocessor's obligations.

## 9. International Data Transfers

The Processor is established in New Zealand, which has been recognised by the European Commission as providing an adequate level of data protection (Adequacy Decision, 2012, reaffirmed 2024). Cloudflare processes data at the edge — the data center closest to the Controller's users. For EU-based Controllers, data is processed within the EU where possible. Where data is transferred internationally, it is protected under Cloudflare's Data Processing Addendum, which incorporates the EU Standard Contractual Clauses (SCCs) where applicable.

## 10. Audit Rights

The Controller may audit the Processor's compliance with this DPA by:

- Requesting the Processor's most recent security documentation
- Verifying enforcement receipts independently through the public verification portal at `report.agenticrail.nz`
- Requesting a remote audit (no more than once per 12-month period, at the Controller's expense)

The Processor will provide reasonable cooperation for any audit required under Article 28(3)(h) of the GDPR.

## 11. Governing Law

This DPA is governed by the laws of New Zealand. Any dispute arising from this DPA shall be subject to the exclusive jurisdiction of the courts of New Zealand.

## 12. Execution

This DPA is incorporated into the AgenticRail Terms of Service and takes effect upon the Controller's first paid API call to the Service. No separate signature is required.

**TUARA KURI LIMITED** — trading as AgenticRail

431 Omanaia Road, RD 3, Kaikohe 0473, New Zealand · NZBN 9429053582867

hello@agenticrail.nz

Incorporated by reference into the AgenticRail [Terms of Service (v1.6)](https://agenticrail.nz/terms/) and [API Terms of Use (v2.7)](https://agenticrail.nz/api-terms/). Read alongside the [Privacy Policy (v2.6)](https://agenticrail.nz/privacy/).

Document Fingerprint — SHA-256 — v2.0

2b43a67a3da4bd3280cd2c12235644b34c3f24a9a0bf99d5047efe31b6313498

 Reproducible independently using any SHA-256 implementation over the pipe-delimited canonical string below.

 **Canonical string (UTF-8, no trailing newline):**

 `Data Processing Agreement|2.0|2026-07-24|TUARA KURI LIMITED|GDPR|Cloudflare,Google Gemini,Stripe,Resend|no tiered plans; receipts retained to preserve chain integrity|Ed25519|k2_2026-06-07_ed25519|NZBN 9429053582867|New Zealand|automatic on first paid API call|AgenticRail Terms of Service v1.6`

 Version: 2.0 · Effective date: 2026-07-24 · Operator: TUARA KURI LIMITED · NZBN 9429053582867 · Supersedes v1.9 (2026-07-08)

 **v2.0 (2026-07-24):** corrects the description of receipt storage. Two clauses described R2 as "immutable storage", which overstates the guarantee: the primary receipt store is tamper-evident, meaning an alteration is detectable through the signature and the hash chain, and it is not write-protected. Only the independent archive bucket carries a write-once lock rule. Both clauses now say tamper-evident, and the audit-trail row records the independently held archive copy of each sealed receipt. No change to processing activities, subprocessors, retention, or any party's obligations. This fingerprint supersedes the v1.9 hash `33976762fd264192febb6828b6d73d73ea3f89251b0963dd3736b04ee9229491`.

 **v1.9 (2026-07-08):** (1) completes the v1.8 NZBN correction — the Section 1 "Processor" definition still cited the wrong NZBN (9429052428098) after v1.8 shipped; now corrected to 9429053582867 in the body text itself, not just the fingerprint block. (2) Removes the tiered (Free/Growth/Scale/Enterprise) receipt retention schedule from Section 7 and the "R2 lifecycle policy" automatic-deletion claim — neither exists in the deployed system. Replaced with an accurate statement: receipts are retained to preserve chain integrity, no automated tiered deletion currently applies, and a specific schedule is available by direct agreement. (3) Updates the Terms of Service / API Terms of Use cross-references (Section 12/Execution) to their current versions (v1.6 / v2.7). This fingerprint supersedes the v1.8 hash `9a9c40bf04fc8a2bd06d8844e19a56d0a90236e52fc8b6a8a77c773c1a4405f5`.

[agenticrail.nz](https://agenticrail.nz) · [Terms of Service](https://agenticrail.nz/terms/) · [Privacy Policy](https://agenticrail.nz/privacy/) · [API Terms of Use](https://agenticrail.nz/api-terms/)

Last updated: 2026-07-24

He toi whakairo, he mana tangata
