Data Processing Addendum
Effective Date: July 27, 2026
1. Definitions and Roles
“Personal data,” “processing,” “controller,” “processor,” “data subject,” and “personal data breach” have the meanings given to them in the EU General Data Protection Regulation (GDPR) and the UK GDPR. “Customer Personal Data” means personal data contained in the data you or your users submit to, or generate through, the Services.
- You are the controller. You decide what Customer Personal Data goes into the Services, why it is there, and what your agents do with it. You are responsible for having a lawful basis for that processing and for the accuracy of the data you provide.
- We are the processor. Raileon processes Customer Personal Data only to provide the Services, on your instructions, as described in this DPA.
- We are a controller for our own account data.For the information we need to run Raileon as a business — account registration details, authentication records, billing and payment records, support correspondence, and product usage telemetry — we act as an independent controller. That processing is governed by our Privacy Policy, not by this DPA.
Where this DPA refers to your rights and our obligations, those apply to all Customers regardless of location. We do not restrict signup by region, so rather than gating protections by geography we extend the GDPR- and UK GDPR-shaped commitments in this DPA to every Customer.
2. Details of the Processing
Annex-style detail of what we process and why, as required by GDPR Art. 28(3):
| Subject matter | Provision of the Raileon AI workforce platform and the AI agents you configure on it. |
|---|---|
| Duration | For the term of your subscription, plus the 30-day export window described in Section 10. |
| Nature of processing | Storage, retrieval, transmission, structuring, analysis, generation of text and other output, sending of messages and email on your behalf, backup, and deletion. |
| Purpose | Running the workflows and agent tasks you configure, operating and supporting your dedicated instance, and meeting our obligations under the Terms of Service. |
| Categories of data subjects | Your personnel and authorised users; your clients and prospective clients; your suppliers and other contacts; and any individual whose personal data appears in content you connect or upload. |
| Categories of personal data | Identification and contact details; employment and role information; the content of emails, messages, documents, notes, and files you connect or upload; integration metadata; and any other personal data you choose to submit. The Services are not designed for special-category data, and you should not submit it without agreeing a separate written arrangement with us. |
3. Processing on Documented Instructions
We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms of Service, this DPA, the configuration you set in the platform (agents, workflows, prompts, connected integrations, and settings), and any further written instruction you give us. We will not process Customer Personal Data for our own purposes, and we will not use it to train public AI models — training is disabled on the third-party AI provider APIs we use.
If we are required by law to process Customer Personal Data beyond your instructions, we will tell you before doing so unless the law forbids that notice. If we believe an instruction from you infringes GDPR, UK GDPR, or another applicable data protection law, we will tell you promptly and may pause the affected processing until the issue is resolved.
4. Confidentiality
Access to Customer Personal Data is limited to Raileon personnel who need it to operate or support the Services. Everyone with access is bound by written confidentiality obligations that survive the end of their engagement, and access is granted on a need-to-know basis and removed when it is no longer needed.
5. Security Measures
We implement appropriate technical and organisational measures under GDPR Art. 32. The measures actually in place are:
- Per-customer isolation. Each Customer runs in a dedicated container on shared host infrastructure, using a gVisor sandboxed runtime, a per-tenant network, an encrypted volume, a read-only filesystem, a custom seccomp profile, and a non-root user. Customer data is not commingled between tenants.
- Encryption. TLS 1.2 or higher in transit; AES-256 at rest.
- Backups. Daily, per-customer, stored separately from the live instance, with 30-day retention.
- Access control. Authenticated, role-based access for your users; need-to-know administrative access for our personnel; secrets held in environment configuration rather than in code.
- Monitoring. Structured application logging and error monitoring, used to detect and diagnose faults and suspicious activity.
Full detail, including what we do not have, is on our security page. In short: we hold no SOC 2 report, no ISO 27001 certification, no third-party penetration test report, and we do not offer a HIPAA Business Associate Agreement. If your compliance programme requires any of those, tell us before you buy.
6. Sub-processors
You give us general written authorisation to engage sub-processors to help deliver the Services. The current list, with the purpose of each one, is maintained at raileon.com/subprocessors.
- Written terms. Every sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA.
- Advance notice.Before we add or replace a sub-processor, we will update the sub-processors page and give you at least 30 days’ notice by email to your account contact.
- Right to object. If you have a reasonable, data-protection-based objection, tell us within the notice period at privacy@raileon.com. We will work with you to find an alternative. If we cannot, you may terminate the affected Services without penalty and receive a pro-rated refund of prepaid subscription fees for the unused remainder of the term.
- Our liability. We remain fully liable to you for the acts and omissions of our sub-processors as if they were our own.
7. Assistance with Data Subject Requests
The platform gives you direct access to Customer Personal Data, so in most cases you can handle access, correction, deletion, and portability requests yourself. Where you cannot, we will provide reasonable assistance so you can respond within your legal deadlines.
If a data subject contacts us directly about Customer Personal Data, we will not respond on your behalf beyond acknowledging receipt. We will forward the request to your account contact promptly. Reach us for this at privacy@raileon.com.
8. Personal Data Breach Notification
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any case within 72 hours of becoming aware of it. The notification will include, to the extent known at the time:
- the nature of the breach and the data and data subjects affected;
- the likely consequences;
- the measures we have taken or propose to take to address it and mitigate harm;
- a contact point for further information.
Where we cannot provide all of that at once, we will send what we have and follow up as the investigation develops. We will also help you meet your own notification duties to regulators and data subjects. Notifying you is not an admission of fault. Security matters can be reported to us at security@raileon.com.
9. Data Protection Impact Assessments
On request, we will give you reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority that relates to your use of the Services. In practice this means supplying the information we hold about our processing, security measures, and sub-processors — information that is largely already published on this page, the security page, and the sub-processors page.
10. Deletion or Return on Termination
When your subscription ends, you have 30 days to export your data. We will keep your instance accessible for export during that window and will help you extract data you cannot retrieve yourself.
- After the 30-day window closes, your instance and its associated data are permanently deleted.
- Backups age out on their normal 30-day retention cycle after deletion; they are not restored or accessed in the meantime.
- We retain billing and account records where tax, accounting, or other law requires it, and we may retain anonymised aggregate data that cannot identify you or any data subject.
- If you need deletion certified in writing, ask at privacy@raileon.com.
11. Audits and Information Rights
We will make available the information reasonably necessary to demonstrate compliance with this DPA. Being honest about scale: Raileon is a small company, and we do not host on-site audits or open our production infrastructure to customer-run scans. What we do offer:
- the documentation published at /security, /subprocessors, and /privacy;
- written responses to a security or data protection questionnaire, once per twelve-month period, within 30 days of your request;
- a call with an engineer to walk through architecture and controls where the questionnaire leaves something unclear;
- additional information where a supervisory authority specifically requires it.
If those measures are genuinely insufficient for your regulatory obligations, contact admin@raileon.com and we will discuss what else is workable rather than pretend the standard offer covers it.
12. International Transfers
All processing of Customer Personal Data takes place in the United States. Our infrastructure, our sub-processors, and our personnel operate there. We do not offer regional data residency.
Where you transfer personal data subject to EEA, UK, or Swiss data protection law to us, the following are incorporated into this DPA by reference and take effect on transfer:
- EEA: the European Commission Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), with you as data exporter and Raileon LLC as data importer. Docking is permitted; the governing law and forum are those of Ireland; the appendices are populated by Sections 2, 5, and 6 of this DPA and by the sub-processors page.
- United Kingdom:the UK Information Commissioner’s International Data Transfer Addendum to the Standard Contractual Clauses, completed with the same details, with UK law and UK courts governing.
- Switzerland: the Standard Contractual Clauses as adapted by the Swiss Federal Data Protection and Information Commissioner, with references read to include the Swiss FADP.
Where the Clauses conflict with the rest of this DPA on a transfer matter, the Clauses win.
13. Order of Precedence
This DPA forms part of the Terms of Service. If there is a conflict between this DPA and the Terms of Service on a data protection matter, this DPA prevails. If there is a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail. On everything else, the Terms of Service prevail. Nothing here changes the liability caps, governing law, or dispute resolution terms in the Terms of Service, except as the Clauses require.
This DPA is governed by the law stated in the Terms of Service. Raileon LLC is a Florida limited liability company.