Legal
Data Processing Agreement
Effective July 24, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Lucitra, Inc. ("Processor," "we," "us," or "our") and you ("Controller," "you," or "your") for the use of our services (the "Services"), which include software development and research engagements and access to Agent Teams.
This DPA reflects the parties' agreement with respect to the Processing of Personal Data by us on your behalf in connection with your use of the Services. Where an executed master services agreement conflicts with this DPA, that agreement controls.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that is Processed by us on your behalf through your use of the Services.
"Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, or erasure.
"Data Protection Laws" means all applicable laws relating to data protection and privacy, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended ("CCPA"), and, where applicable, the Health Insurance Portability and Accountability Act ("HIPAA").
"Sub-processor" means any third party engaged by us to Process Personal Data on your behalf.
2. Scope and Purpose of Processing
2.1 Subject matter
The subject matter of the Processing is the provision of the Services: the delivery of software development and research work, and the operation of Agent Teams, our platform for running agents on scoped work with budgets, audit, and human approval.
2.2 Nature and purpose
We Process Personal Data solely to provide the Services, which includes:
- Operating the workspaces, tasks, and approvals you configure
- Storing the audit records generated by that work, which are your audit trail
- Providing technical support and maintaining the Services
- Delivering the work product of an engagement to you
2.3 Duration
Processing continues for the duration of your use of the Services, plus any retention period required by law or set out in our Privacy Policy.
2.4 Categories of data subjects
Data subjects may include your personnel, your customers, and, where an engagement involves healthcare systems, patients whose data you instruct us to Process.
2.5 Types of Personal Data
- Identifiers such as names, email addresses, and IP addresses
- Account, role, and access records
- Any data contained in the repositories, documents, or systems you bring into scope
- Protected health information, only under the conditions in section 4
3. Obligations of the Processor
3.1 Compliance with instructions
We Process Personal Data only on your documented instructions, unless required to do otherwise by applicable law. If we are required by law to Process Personal Data, we will inform you of that requirement before Processing, unless the law prohibits it.
3.2 Confidentiality
We ensure that persons authorized to Process Personal Data are bound by confidentiality obligations.
3.3 Security measures
We implement technical and organizational measures appropriate to the risk, including:
- Encryption of Personal Data in transit and at rest
- Scoped, revocable access granted per team, and authentication controls
- An append-only audit log of actions, costs, and approvals, with integrity hashes
- A human approval step before any irreversible action, including merges, deploys, publishing, and spend
- Isolated per-task workspaces, so work in progress cannot reach production systems on its own
- Incident response procedures, and backup and recovery measures
3.4 Automated processing by agents
The Services execute work using AI agents. Those agents reach only the systems you grant them, within limits enforced before a run begins rather than reported afterwards. No agent output that constitutes an irreversible action takes effect without human approval. Personal Data is not used to train Lucitra models, and the model providers listed in section 3.5 do not train on data we submit under our commercial terms.
3.5 Sub-processors
You authorize us to engage the following Sub-processors:
- Google Cloud Platform: Infrastructure, compute, and storage (United States)
- Anthropic: Model provider for agent execution (United States)
- Stytch: Authentication and identity (United States)
- Umami: Website analytics (European Union and United States)
- PostHog: Product analytics (United States and European Union)
- AWS SES: Transactional email (United States)
The current register, including what data reaches each provider, is published at lucitra.ai/trust/subprocessors. We will inform you of any intended addition or replacement of a Sub-processor and give you the opportunity to object.
3.6 Assistance with data subject rights
We assist you in responding to requests from data subjects exercising their rights under Data Protection Laws, including access, rectification, erasure, restriction, portability, and objection.
3.7 Breach notification
We notify you without undue delay after becoming aware of a Personal Data breach affecting Personal Data Processed on your behalf. The notification will include the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
3.8 Audit rights
We make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by you or an auditor you mandate.
3.9 Deletion and return of data
On termination of the Services we will, at your choice, delete or return all Personal Data and delete existing copies, unless applicable law requires that we retain it.
4. Protected Health Information
Where an engagement involves protected health information ("PHI") as defined by HIPAA, the following applies in addition to the terms above:
- A Business Associate Agreement is executed before any PHI is disclosed to us. No PHI may be placed into the Services before that agreement is in effect.
- We hold a Business Associate Agreement with each Sub-processor in the PHI path, and use only services that provider has designated as eligible.
- Model access is matched to the data. Our default execution path runs on a subscription plan that is not covered by a Business Associate Agreement and is never used for PHI. PHI work runs on first-party API or Enterprise plans covered by an executed agreement.
- Access follows the minimum necessary standard, and every access to PHI is recorded in the audit log.
5. International Data Transfers
Our systems are hosted in the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland, Personal Data may be transferred to the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses.
6. Obligations of the Controller
You warrant and represent that:
- You have obtained the consents and authorizations necessary to transfer Personal Data to us for Processing
- Your instructions to us comply with applicable Data Protection Laws
- You will provide accurate and complete information necessary for us to meet our obligations under this DPA
7. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations set out in the Terms of Service or in an executed master services agreement.
8. Term and Termination
This DPA remains in effect for as long as we Process Personal Data on your behalf. On termination we comply with our obligations regarding deletion or return of Personal Data set out in section 3.9.
9. Contact
For questions about this DPA or to request an executed copy:
- By email: legal@lucitra.ai
- Lucitra, Inc., 8080 Westpark Drive, STE 42557, Houston, TX 77063, United States