Last updated: July 18, 2026
This Data Processing Addendum ("DPA") supplements and forms part of the Terms of Service (the "Agreement") between you ("Customer", "Controller", "you") and AIEmployees ("AIEmployees", "we", "us", or "our"), operator of Terminal Skills — our AI-agent-skills marketplace, open-source skills library, and Agent Playground available at terminalskills.io. It governs the Processing of Personal Data that AIEmployees carries out on your behalf as a Processor in connection with the Service.
AIEmployees is the business name under which an independent entrepreneur operates; it is a sole proprietorship, not an incorporated or registered company, and not a separately registered legal entity. "Terminal Skills" and "AIEmployees" are unregistered trade names, and "Terminal Skills" is an unregistered trademark. Nothing in this DPA asserts any corporate, state, or trademark registration.
When this DPA applies. This DPA applies to the extent that AIEmployees Processes Personal Data on your behalf as a Processor — for example, where a business or agency uses the Agent Playground to run tasks or handle files containing the personal data of its own customers, employees, or other individuals. Many individual users are their own Controller, and for their own account, authentication, billing, and security data AIEmployees acts as an independent Controller governed by the Privacy Policy. This DPA still governs any processor-role Processing that occurs. Where a term is defined in the Agreement, it has the same meaning here; if this DPA conflicts with the Agreement on the subject of data protection, this DPA controls.
2.1 Processor and Controller. As between the parties, and with respect to Customer Personal Data, you are the Controller (or a Processor acting on behalf of a further Controller) and AIEmployees is the Processor. AIEmployees will Process Customer Personal Data only to provide, secure, and support the Service and otherwise in accordance with your documented instructions and this DPA.
2.2 AIEmployees as independent Controller. AIEmployees acts as an independent Controller, governed by its Privacy Policy rather than this Section, when it Processes Personal Data to: operate, maintain, and secure the Service; create and authenticate accounts; meter compute and administer the credit wallet; process payments and maintain billing and usage records; prevent abuse, fraud, and security incidents; and comply with law. Account email, hashed credentials, billing references, and usage counters fall into this category.
2.3 Scope. This DPA applies to Processing carried out by AIEmployees and its Sub-processors in the course of providing the Service, for the duration of the Agreement, and to the limited extent described in Section 10 following termination.
This Section, together with Annex II (Sub-processors) and Annex III (Technical and Organizational Measures), constitutes the description required by Article 28(3) GDPR and, where the SCCs apply, completes their Annexes.
| Element | Description |
|---|---|
| Subject matter | Provision of the Terminal Skills Service — principally the account-gated, credit-metered Agent Playground (prove, inspect, and forge modes) — in accordance with the Agreement and your documented instructions. |
| Nature and purpose | Hosting, storing, transmitting, and Processing Customer Personal Data as necessary to run AI agents on the tasks and files you submit, meter and bill compute, provide support, and secure the Service. |
| Duration | The term of your account and use of the Service, plus the limited post-termination period described in Section 10. |
| Categories of Data Subjects | Your account users, and any individuals whose Personal Data you (or those you act for) include in task prompts, uploaded files, or skill content submitted to the Service. |
| Categories of Personal Data | Account contact details (email); authentication data (a bcrypt hash of the password — never the plaintext); the task prompts, uploaded files (up to 5 files, 20 MB each), and SKILL.md content you submit; per-run diagnostics and usage/cost data; and any Personal Data you choose to include in the foregoing. |
| Special categories | None intended. You must not submit special-category or sensitive Personal Data into task prompts, uploaded files, or skill content. If you do so, you do it on your own responsibility and confirm you have a lawful basis. |
| Frequency | Continuous, for the duration of your use of the Service. |
Where AIEmployees acts as a Processor, it will:
4.1 Documented instructions. Process Customer Personal Data only on your documented instructions — including with regard to international transfers — unless required to do otherwise by law, in which case AIEmployees will inform you of that legal requirement before Processing (unless the law prohibits such notice). The Agreement, this DPA, and your configuration and use of the Service constitute your complete and final instructions. AIEmployees will inform you if, in its opinion, an instruction infringes Data Protection Laws.
4.2 Confidentiality. Ensure that persons authorized to Process Customer Personal Data are bound by an appropriate duty of confidentiality and Process the data only as instructed.
4.3 Security. Implement and maintain the technical and organizational measures described in Annex III (Technical and Organizational Measures), appropriate to the risk. AIEmployees may update these measures provided the level of protection is not materially reduced.
4.4 Sub-processors. You provide general authorization for AIEmployees to engage the Sub-processors listed in Annex II. AIEmployees will: (a) impose data-protection obligations on each Sub-processor that are substantially equivalent to those in this DPA; (b) remain responsible for each Sub-processor's performance; and (c) give you prior notice of any intended addition or replacement of a Sub-processor (by updating this page and its "Last updated" date, or by other reasonable means), giving you a reasonable opportunity to object on reasonable data-protection grounds before that Sub-processor begins Processing Customer Personal Data. If you reasonably object and the parties cannot resolve the matter, you may terminate the affected part of the Service as your sole remedy.
4.5 Assistance with Data-Subject requests. Taking into account the nature of the Processing, assist you by appropriate technical and organizational measures, insofar as possible, in responding to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). Because self-service export and deletion are not yet built into the product, such assistance is currently provided through a manual, email-based process (see Section 10 and the Privacy Policy); if a Data Subject contacts AIEmployees directly regarding Customer Personal Data, AIEmployees will, where lawful, refer them to you.
4.6 Personal-data breach notification. Notify you without undue delay — and, where feasible, within 72 hours — after becoming aware of a personal-data breach affecting Customer Personal Data, and provide information reasonably available to help you meet your own notification obligations.
4.7 DPIAs and prior consultation. Provide reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the Processing and the information available to AIEmployees.
4.8 Records and audits. Make available to you information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, and allow for and contribute to audits, including inspections, conducted by you or an independent auditor you mandate. Audits will be conducted on reasonable prior written notice, no more than once per twelve months (except where required by a supervisory authority or following a breach), during business hours, subject to confidentiality, and in a manner that does not disrupt AIEmployees' operations or compromise the security or data of other customers. AIEmployees may satisfy audit requests by providing relevant documentation about its security measures.
You will:
5.1 comply with your obligations as a Controller (or Processor) under Data Protection Laws, and ensure you have a valid lawful basis for the Processing you instruct;
5.2 provide all required notices to, and obtain all required consents from, Data Subjects for the Processing carried out through the Service;
5.3 ensure you hold the necessary rights in, and that your instructions with respect to, the Customer Personal Data you submit are lawful; and
5.4 be responsible for the accuracy, quality, and legality of the Customer Personal Data and the means by which you acquired it, and for not submitting special-category or sensitive Personal Data except as permitted under Section 3.
6.1 Where data is Processed. AIEmployees' hosting infrastructure is provided by Hetzner Online GmbH (a Germany-based provider) under a self-hosted Coolify control plane; our MongoDB database and authentication are self-hosted on that infrastructure, and per-run agent workspaces are stored on its local filesystem. Several Sub-processors — Google Cloud / Vertex AI (with a "global" region setting), Stripe, and GitHub — Process data in the United States and other regions. The exact data-center region of our hosting is available from AIEmployees on request.
6.2 Transfer mechanisms. Where Customer Personal Data is transferred out of the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer is made under an appropriate safeguard — the Standard Contractual Clauses, the UK IDTA, and/or Swiss adaptations, as applicable. The SCCs are incorporated into this DPA by reference and are deemed completed by the details in Section 3 and Annexes II–III; module two (Controller-to-Processor) or module three (Processor-to-Processor) applies according to your role.
6.3 Order of precedence. In the event of a conflict between the SCCs and this DPA, the SCCs prevail with respect to the transfer they govern. This Section does not alter the governing law of the Agreement.
AIEmployees engages only the following Sub-processors to Process Customer Personal Data. This list reflects the vendors actually used by Terminal Skills.
| Sub-processor | Role / Service | Data Processed | Location |
|---|---|---|---|
| Google LLC — Google Cloud / Vertex AI (Gemini) | Powers the Agent Playground: all agent reasoning runs on Gemini models via Vertex AI; the "forge" pipeline may use Google Search grounding for research. | Task prompts, staged SKILL.md content, tool-call inputs/outputs, generated outputs, and (in forge mode) research queries. | Google Cloud, region set to "global" (multi-region routing). |
| Stripe, Inc. | Payment processing for credit packs and the Pro subscription, the billing portal, and subscription webhooks. | Customer email, an internal reference to the account and pack/credits purchased, and card/payment details entered directly on Stripe-hosted checkout. | United States (global processing). |
| GitHub, Inc. (Microsoft) | Hosts the public open-source skills library, powers the sync pipeline and CLI downloads, and (only when explicitly enabled) receives forge-mode pull requests. | Repository reads (no personal data); contributor GitHub usernames as skill "author" metadata; generalized, PII-stripped skill content in optional pull requests. | United States. |
| Google LLC — Google Tag Manager | Client-side tag/analytics container (GTM-KZ98N24T) loaded on every page. | Browsing behavior, page views, IP address, device/user-agent, and cookies configured within the container. | Google (global). |
| Google LLC — Google Fonts | Web fonts. Fonts are self-hosted at build time (no runtime user request to Google); dynamic social-preview image routes fetch a font file server-side. | Build-time font download (no user data); server-to-server font fetch (server IP only, no end-user PII). | Google (fonts.gstatic.com). |
| Hetzner Online GmbH + self-hosted Coolify | Underlying compute and hosting for the entire platform, its self-hosted MongoDB database, and per-run agent workspaces. Coolify is self-operated infrastructure, not a third-party managed hosting service. | All platform data at rest and in transit lives on this infrastructure. | Hetzner (Germany-based provider); exact region available on request. |
| jsDelivr (CDN) | Loads the API-reference viewer script on a single API-docs page only. | The visiting browser's IP and user-agent on that one page (no application data). | Global CDN. |
Our database and authentication are self-hosted — we do not use a managed database service (such as MongoDB Atlas) or a third-party identity/OAuth provider. We do not use a third-party object-storage or CDN service for your uploaded files.
AIEmployees maintains the following measures, described accurately rather than aspirationally:
httpOnly, SameSite=Lax cookie (ts_session) marked Secure in production and expiring after ~7 days. Logging out clears the cookie. Because sessions are stateless, an individual token cannot be centrally revoked before it expires; administrative role changes are re-checked against the database on every privileged request.Secure in production.At-rest protection. AIEmployees does not currently apply field-level or application-layer encryption to data at rest; any at-rest protection is provided at the database/host layer, not per field. We do not operate an AES-256-GCM token-encryption scheme, a Redis-backed token revocation list, or short-lived (e.g. 15-minute) tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
AIEmployees will provide reasonable cooperation to help you comply with Data Protection Laws in connection with the Processing described in this DPA, including the assistance described in Sections 4.5–4.8, taking into account the nature of the Processing and the information available to AIEmployees.
10.1 On termination. Following expiry or termination of the Agreement, and on your written request, AIEmployees will delete or return Customer Personal Data Processed on your behalf, except to the extent retention is required by law or for legitimate business records (such as billing and tax records).
10.2 Current mechanism. Because self-service export and deletion are not yet built into the product, return and deletion are currently handled through a manual, email-based request to support@terminalskills.io (subject "Attn: Privacy"). AIEmployees will action valid requests within a reasonable period consistent with applicable law.
10.3 Retention baseline. As described in the Privacy Policy, account records, security-scan records, the Stripe billing-event ledger, and the MongoDB run summary are currently retained indefinitely absent a deletion request; on-disk run workspaces, run files, and event transcripts are intended to be short-lived (the Agent Playground states uploaded files are deleted after 7 days); and transient caches and the in-memory rate-limiting IP window are short-lived (seconds to minutes).
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement (including its Limitation of Liability section), and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together. These limitations extend, to the fullest extent permitted by law, to AIEmployees' Sub-processors.
This DPA takes effect on your first use of the Service (or acceptance of the Agreement) and remains in force for as long as AIEmployees Processes Customer Personal Data on your behalf. The obligations that by their nature should survive — including confidentiality, international transfers, data return and deletion, and liability — survive termination until fulfilled.
We may update this DPA as the Service and applicable law evolve. The "Last updated" date at the top reflects the most recent revision, and changes to the Sub-processor list are notified as described in Section 4.4. Continued use of the Service after an update constitutes acceptance of the revised DPA.
This DPA applies automatically as part of the Agreement and requires no signature to be effective. If your organization requires a countersigned copy, email support@terminalskills.io with the subject "Attn: Legal", and we will arrange one on reasonable terms. Data-subject and privacy requests should be sent to the same address with the subject "Attn: Privacy". You may also reach AIEmployees at aiemployees.us.
See also our related policies: Privacy Policy, Terms of Service, Cookies Policy, Acceptable Use Policy, and Do Not Sell or Share My Personal Information.