Legal
Data Processing Addendum
Last updated 2026-09-02. iResolved, LLC.
This addendum applies when you are the controller and iResolved, LLC processes personal data on your behalf through a chained.tools product. It supplements the Terms of Service and the Privacy Policy.
1. Scope
This Data Processing Addendum (“DPA”) is part of the Terms of Service between you (the “Customer”) and iResolved, LLC (“Processor”). It applies only where we process personal data as a processor for a product you use: hosted rusty or suite auth, gbrowse sessions, agentpass grants metadata, accounts on this domain, and similar features. It does not turn the public website into a processing service. Browsing chained.tools is described in the Privacy Policy, where we are controller.
If a data-protection law (including GDPR, UK GDPR, or similar) does not apply to the processing, this DPA still states how we handle that Customer personal data.
2. Definitions
- Personal data means information relating to an identified or identifiable person.
- Customer personal data means personal data Customer provides or that is processed through a product on Customer’s instructions (for example account emails of Customer’s users, agent identifiers, or session metadata).
- Controller determines purposes and means. Customer is controller of Customer personal data.
- Processor processes on the controller’s documented instructions. iResolved, LLC is processor under this DPA.
- Sub-processor is a processor engaged by us.
Secrets stored in agentpass, source in a toolchain, and page content in gbrowse may or may not be personal data. Where they are, they are Customer personal data. The product design for agentpass is that secret values are not written into model context; that is a security measure, not a claim that no metadata exists.
3. Instructions
We process Customer personal data only to provide the product, to secure it, and as required by law. The Terms of Service, this DPA, and your configuration in the product are the documented instructions. We will not sell Customer personal data or use it to train a model for our own products.
If we are required by law to process data outside those instructions, we will tell you unless the law forbids that notice.
4. What is processed
Depending on the product you actually enable:
- Identity and contact data for users you invite (email, name, auth subject)
- Session, grant, and audit metadata (who asked, what action, when)
- Telemetry you have not disabled: errors, performance, feature use
- Content you submit to a hosted feature (browser session artifacts, toolchain metadata)
Data subjects are Customer’s users, operators, and people whose data Customer puts through the product. Duration is the subscription or account life plus the retention in section 8.
5. Security
We will implement technical and organizational measures appropriate to the processing: encryption in transit, access limited to people who need it, logging of administrative access, and a process for security incidents. agentpass is intended to keep secret values out of model context and ordinary logs. No measure is a warranty that a system cannot be broken.
We will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, with the facts we have: nature, likely consequences, and measures taken.
6. Sub-processors
Customer authorizes us to use sub-processors needed to run the products. Current core sub-processors:
- Vercel: hosting and edge delivery
- PostHog: product analytics, when enabled
- Sentry: error monitoring
- Auth and identity providers configured for the product (including Clerk-based suite auth where rusty and siblings use it)
We will impose written terms on sub-processors that are no less protective than this DPA. We will remain responsible for their processing under this DPA. A material change to this list will be reflected here or told to paying customers with time to object before the new sub-processor processes their data.
7. Assistance
We will reasonably assist Customer with data-subject requests, DPIAs, and consultations with authorities, to the extent the request concerns our processing. We will not answer a data subject over Customer’s head when Customer is the controller, unless required by law.
8. Retention and return
During the service, Customer personal data is kept as needed to provide it. After the service ends, we will delete or return Customer personal data on request within 30 days, except copies in backups that age out on the backup cycle, or data we must keep by law. Certification of deletion is available on written request.
9. International transfers
We and our sub-processors may process data in the United States and other countries where they operate. Where a restricted transfer requires a safeguard, the parties agree that the applicable Standard Contractual Clauses (controller-to-processor or processor-to-processor) are incorporated by reference, with Customer as data exporter and iResolved, LLC as data importer, and with the details in this DPA completing the annexes. If those clauses are replaced by a successor mechanism, the successor applies.
10. Audits
On reasonable written notice, no more than once per year unless a competent authority or a documented incident requires more, Customer may audit our compliance with this DPA through questionnaires and, where those are not enough, a review of relevant documentation. On site inspection is by mutual agreement and at Customer’s expense, with confidentiality intact. We may satisfy an audit with a current independent report if we have one.
11. Liability
Each party’s liability under this DPA is subject to the limits in the Terms of Service, except that nothing here limits liability for a party’s own willful misconduct, or liability that cannot be limited under data-protection law.
12. Order of documents
If this DPA conflicts with the Terms of Service on data protection, this DPA controls. If it conflicts with a signed order or enterprise agreement that explicitly amends the DPA, that signed paper controls.
13. Contact
iResolved, LLC
Processor contact: intake@solved.gg
Austin: Book a chat