Data Processing Addendum
Last updated: September 2, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service between the customer accepting those Terms ("Customer") and the individual founder who currently operates the free, pre-commercial Ruligent service from New York, United States ("Ruligent"). No separately registered Ruligent entity or completed assumed-name filing is represented. It applies when Ruligent processes personal data on Customer's behalf.
1. Roles and instructions
For personal data contained in customer-controlled agent activity, Customer acts as controller/business and Ruligent acts as processor/service provider to the extent applicable. Ruligent will process that data only to provide, secure, support, and maintain the service; comply with Customer's documented configuration and lawful instructions; and comply with applicable law.
2. Processing details
- Subject matter: AI-agent governance, policy evaluation, approvals, audit logging, spend controls, kill switches, evidence generation, and webhook delivery.
- Data: governance and tool-call metadata, identifiers, timestamps, decision information, approval metadata, estimated cost information, and bounded payload summaries supplied by Customer systems.
- Data subjects: determined by Customer and may include Customer personnel and individuals referenced in Customer-controlled activity.
- Duration: for the subscription or service relationship plus applicable retention, backup, security, tax, legal, and deletion periods.
3. Confidentiality and security
Ruligent will use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the service. Current controls include TLS in transit, organization-scoped authorization, hashed or digested credentials, signed webhooks, security headers, retention controls, logging, and incident-response procedures. No control eliminates all risk.
4. Subprocessors
Customer authorizes the subprocessors listed at /legal/subprocessors. Ruligent may update that list as providers change. Where required by an applicable data-protection agreement or law, Ruligent will provide reasonable notice of material new subprocessors and a mechanism to raise a good-faith data-protection objection.
5. Data-subject requests
Taking into account the nature of processing, Ruligent will provide reasonable assistance to Customer with verified requests to access, correct, delete, restrict, or export personal data when Customer cannot reasonably fulfill the request through the service itself.
6. Security incidents
Ruligent will notify affected Customers without undue delay after confirming a personal-data breach involving Customer personal data where notification is required, and will provide information reasonably available to support Customer's legal obligations.
7. Deletion and return
At the end of the service relationship, Customer data will be deleted or made unavailable in accordance with product retention, the Data Deletion Policy, backup-expiry practices, and legal retention obligations. Customers should export data they are entitled to retain before termination where the service provides an export mechanism.
8. International transfers
If Customer and Ruligent enter into a commercial relationship requiring the EU Standard Contractual Clauses, UK Addendum, Swiss adaptations, or another transfer mechanism, those terms must be incorporated through a written order form, countersigned DPA, or other legally effective agreement identifying the parties and required annex details. This web DPA does not by itself claim that all transfer modules or annexes have been validly executed for every customer.
9. Audits and information
Ruligent will make available information reasonably necessary to evaluate the security and privacy controls described in the service documentation, subject to confidentiality, security, and abuse-prevention restrictions. Ruligent does not currently represent that it holds SOC 2 or ISO 27001 certification unless expressly stated on the live Security page.
10. Commercial identity notice
Ruligent is currently operated by its founder as an individual. No separately registered Ruligent entity or completed assumed-name filing is represented. New paid contracts are closed, and requests for countersigned enterprise DPAs, SCCs, or agreements requiring a registered entity will be deferred until the approved commercial identity and required review are complete.
11. Contact
For privacy or DPA inquiries, use the Ruligent contact page.