Make Agent Fast huquqiy hujjatlari
Maʼlumotlarni qayta ishlash qoʻshimchasi
This Data Processing Addendum (the “Addendum”) forms part of the Make Agent Fast Terms of Service between Make Agent Fast (“we”, “us”, the “Processor”) and the customer that accepted those Terms (the “Customer”, the “Controller”). It applies whenever we process personal data on the Customer’s behalf, takes effect when the Customer starts using the platform, and needs no negotiation; a countersigned copy is available on request. Where this Addendum and the Terms conflict about the processing of personal data, this Addendum prevails.
- Oxirgi yangilanish
- 2026-09-03
1. Roles of the parties
The Customer is the controller of the personal data it submits and of the personal data its end users submit through an agent. We are the processor and act only on the Customer’s documented instructions. For our own account, billing, and support records we are an independent controller, and our Privacy Policy rather than this Addendum governs that processing.
Where the Customer is itself a processor acting for another controller, this Addendum applies to us as a sub-processor.
2. Subject matter and duration
The subject matter is the operation of the Make Agent Fast platform for the Customer: building, configuring, publishing, and running customer-facing AI agents on a website widget, on connected messaging channels, and by voice, together with the analytics, request capture, notification, and billing features the Customer enables.
Processing starts when the Customer first submits personal data and continues for the term of the Terms, plus the period needed to complete the deletion in section 14.
3. Nature and purpose of processing
We process personal data to receive and answer end-user messages, to retrieve the Customer’s approved knowledge, to route each message to the providers the configuration requires, to record conversations and captured requests for review and follow-up, to meter usage for billing, to detect abuse, and to keep the service secure and available.
We do not sell personal data, use it for advertising, or train models of our own on Customer content. Where the Customer supplies its own provider key, that provider’s agreement with the Customer governs the content routed to it.
4. Categories of personal data
- Account data: name, work email address, a hashed password or a federated sign-in identifier, organization and role, session records, and audit events.
- Agent knowledge the Customer supplies: uploaded documents, pages crawled from its own site, and question-and-answer pairs, which contain personal data if the Customer puts it there.
- End-user conversation data: message text, voice audio and transcripts where voice is enabled, timestamps, locale, coarse device and referrer information, and a pseudonymous visitor identifier.
- Contact and request data an end user chooses to give an agent: name, email address, phone number, company, booking or enquiry details, and free text.
- Channel identifiers where a messaging channel is connected: the user or chat identifier issued by Telegram, WhatsApp, Messenger, Instagram, Discord, or KakaoTalk.
- Billing data: plan, credit balance, and usage counters. Card details are handled by our merchant of record and never reach our systems.
5. Categories of data subjects
The Customer’s personnel who hold platform accounts; the end users who talk to the Customer’s agents, as visitors to its website or on a connected messaging channel; and any individuals whose personal data the Customer places in an agent’s knowledge base.
6. The Customer’s instructions and responsibilities
We process personal data only on the Customer’s documented instructions — this Addendum, the Terms, and the platform’s settings — unless a law that applies to us requires otherwise, in which case we will tell the Customer before processing unless that law forbids it. We will say so if, in our opinion, an instruction infringes applicable data protection law.
The Customer is responsible for the lawfulness of the data it submits, for giving its end users the notices its own law requires, for obtaining consent where it relies on consent, for choosing a retention window that fits its purpose, and for not placing special categories of personal data in an agent’s knowledge base without a lawful basis.
7. Confidentiality
Personal data processed for the Customer is confidential. Access is limited to the people who need it to operate or support the service, each bound by a written confidentiality obligation that survives their engagement, granted on a least-privilege basis and withdrawn when the role ends.
We do not disclose personal data to any third party other than the sub-processors covered by section 9, except where a binding legal order compels us. If we receive such an order, we will redirect the requester to the Customer where lawful and possible, and notify the Customer unless the order forbids it.
8. Security measures
We implement appropriate technical and organizational measures to protect personal data, as required by Article 32 GDPR. The measures in place — password hashing, envelope encryption of customer credentials, tenant and role boundaries, signed and SSRF-restricted outbound webhooks, rate and spend limits, encrypted backups, and the retention windows enforced by scheduled jobs — are described on our security page at /security, which forms part of this Addendum and is kept current.
9. Sub-processors
The Customer gives a general authorization for us to engage sub-processors. The current list, with each sub-processor’s purpose and processing region, is published at /security. Each is engaged under a written contract that imposes data protection obligations no less protective than those in this Addendum, and we remain fully liable to the Customer for the performance of each sub-processor.
We announce any addition or replacement on our changelog at least 30 days before that sub-processor starts processing personal data for the Customer. The Customer may object on reasonable data protection grounds within those 30 days; if we cannot offer a reasonable alternative, the Customer may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
10. International transfers
The primary application and database run on our own infrastructure in Seoul, Republic of Korea. Personal data is transferred outside Korea where a sub-processor requires it — chiefly to the United States and the European Union — and an encrypted standby copy of the database is held in the United States.
For transfers of personal data out of the EEA, the European Commission’s Standard Contractual Clauses (Implementing Decision 2021/914) are incorporated into this Addendum by reference: Module Two (controller to processor), or Module Three (processor to processor) where the Customer acts as a processor. The Customer is the data exporter and we the data importer; the Annexes are populated by sections 2 to 5, 8, and 9 and the sub-processor list at /security; the docking clause applies; Clause 9(a)’s general authorization option applies with the 30-day notice in section 9; and the governing law and forum are those of Ireland. For transfers out of the United Kingdom, the UK International Data Transfer Addendum to those Clauses applies with the same annexes.
11. Korea (PIPA)
Where the Personal Information Protection Act of the Republic of Korea applies, we act as an entrusted party (수탁자) processing personal information on the Customer’s behalf under Article 26 PIPA. We process entrusted personal information only within the scope of the entrustment, never for our own purposes, and we supervise our sub-processors on the same terms.
Where the cross-border provisions of Articles 28-8 and 28-9 PIPA apply, we support the Customer’s disclosure and consent obligations by keeping sub-processor names, purposes, and destination countries current at /security. The Customer remains responsible for disclosing this entrustment in its own privacy notice.
12. Assistance with data-subject requests and compliance
We assist the Customer in responding to end-user requests to access, correct, delete, restrict, object to, or port their personal data. The platform provides self-service export and erasure for captured request and conversation data; where those tools do not reach, we assist by other reasonable means.
We also assist with data protection impact assessments and prior consultations with a supervisory authority, so far as the information is available to us. If an end user contacts us directly about personal data we process for the Customer, we will not answer on the merits: we refer them to the Customer and notify it without undue delay.
13. Personal data breach
We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed for the Customer. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures taken, and a contact point.
Where the full picture is not yet available, we send what we have within that window and follow up as the investigation develops. We do not make regulatory or data-subject notifications on the Customer’s behalf unless asked to.
14. Deletion and return
On termination or expiry of the Terms, and at any time on the Customer’s written request, we will delete or return the personal data we process for the Customer, at its choice. Unless return is requested, deletion follows the windows published at /security: the Customer’s own export and erasure tools act immediately, a deleted company is purged in full after 30 days, and backups fall out of retention on their own schedule — 14 days on the server and 30 days offsite — after which no copy remains.
We may retain personal data where a law that applies to us requires it: only what that law requires, for only as long as it requires, and still protected under this Addendum.
15. Audits and information rights
We will make available the information reasonably necessary to demonstrate compliance with this Addendum, ordinarily through our security page, our answers to the Customer’s security questionnaire, and any third-party report we hold.
Where that is not sufficient for the Customer’s own audit obligations or for a supervisory authority, the Customer may audit us, or appoint an independent auditor who is not our competitor, on 30 days’ written notice, once in any twelve-month period unless a breach or a regulator requires otherwise, without disrupting the service, and subject to confidentiality. The Customer bears the cost of an audit it initiates, unless the audit reveals a material breach.
16. Liability, precedence, and changes
Each party’s liability under this Addendum is subject to the limitations and exclusions in the Terms of Service. Where this Addendum conflicts with the Terms or the Privacy Policy about the processing of personal data, this Addendum prevails; where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
We may update this Addendum when the law, our sub-processors, or our security measures change; a material change is announced on our changelog at least 30 days before it takes effect, and the date at the top of this page identifies the current version.
Til haqida
English
This Addendum is published in English. The Korean and Uzbek paragraphs below are summaries offered for convenience; if they differ from the English text in any way, the English text governs.
한국어
본 데이터 처리 부속서는 영문으로만 작성되며, 아래 요약은 이해를 돕기 위한 것으로 법적 효력은 영문 원문에만 있습니다. 요약하면 Make Agent Fast는 고객이 위탁한 개인정보를 고객의 지시 범위에서만 처리하고, 수탁 업체 목록과 보안 조치를 /security 페이지에 공개하며, 목록 변경은 최소 30일 전에 고지하고, 개인정보 유출을 인지하면 72시간 이내에 고객에게 통지하며, 국외 이전에는 EU 표준계약조항을 적용하고, 개인정보 보호법 제26조에 따른 수탁자로서 의무를 지며, 계약 종료 시 고객의 선택에 따라 개인정보를 삭제하거나 반환합니다.
Oʻzbekcha
Ushbu qoʻshimcha faqat ingliz tilida chiqariladi; quyidagi bayon tushunish uchun boʻlib, huquqiy kuchga ingliz tilidagi matn ega. Qisqacha: Make Agent Fast mijoz topshirgan shaxsiy maʼlumotni faqat mijozning koʻrsatmasi doirasida qayta ishlaydi, subprotsessorlar roʻyxati va xavfsizlik choralarini /security sahifasida eʼlon qiladi, roʻyxat oʻzgarishidan kamida 30 kun oldin xabar beradi, maʼlumot buzilishini bilgach 72 soat ichida mijozga xabar qiladi, chegaradan oʻtkazishda EI standart shartnoma bandlarini qoʻllaydi va shartnoma tugagach maʼlumotni mijoz tanloviga koʻra oʻchiradi yoki qaytaradi.
Questions, audit requests, data-subject escalations, and countersignature requests go to legal@makeagent.fast; security reports go to security@makeagent.fast.