Compliance is a feature, not fine print.
GDPR-aligned controls, a Data Processing Addendum, data export and erasure, documented sub-processors - and we don't claim certifications we don't hold.
GDPR-aligned by design
We align our controls with the EU General Data Protection Regulation. You own your data, you can take it with you, and you can have it erased. We act as a data processor for the content you automate and as a data controller for your account and billing data.
- Right to access & portability: export your account data from Settings.
- Right to erasure: delete your account or organization; deletion cascades across tenant-scoped resources.
- Lawful basis & consent: you are responsible for a lawful basis on the data you collect; we honor consent and erasure requirements.
- Data minimization: secrets are encrypted at rest and never returned by the API, shown to the AI, or written to logs.
Data Processing Addendum
We offer a Data Processing Addendum (DPA) that sets out how we process personal data on your behalf, the security measures in place, and the sub-processors we rely on. Request the current version for your organization, or read the published terms.
What we hold
GDPR alignment
In placeData rights, DPA, sub-processor transparency, and erasure are available today.
Encryption & isolation
In placeSecrets encrypted at rest, strict tenant isolation, and least-privilege access across every run.
How your data is handled
- Sensitive material (passwords, 2FA seeds, vault secrets, tokens, sessions) is encrypted at rest with the platform key.
- Every record is tenant-scoped and filtered at the data layer; no cross-tenant access.
- Marketplace recipes are stripped of creator credentials at publish - every run uses the installer's own data.
- Run logs redact secrets; resolved values exist only inside a single run.
Compliance questions
Is Writ GDPR compliant?
Do you have a DPA I can sign?
What is your certification posture?
How do I request data export or deletion?
Where is my data processed?
Need our compliance documents?
Request a DPA, ask about our data controls, or get a current security review.