Tech Driven Agent LLC · StreamAgent
Data Processing Addendum
Last updated: October 7, 2026
This Data Processing Addendum (the DPA) forms part of the Terms of Service (the Agreement) between Tech Driven Agent LLC, a California limited liability company doing business as StreamAgent (StreamAgent, we), and the customer that accepted the Agreement (Customer, you). It applies whenever StreamAgent processes Personal Data on your behalf in providing the Service. It is accepted by continuing to use the Service after it is published; a signed copy is available on request at support@streamagent.io. In a conflict between this DPA and the Agreement, this DPA governs the processing of Personal Data.
1. Definitions
Data Protection Laws means all laws that apply to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA). Personal Data, Controller, Processor, Data Subject, Processing and Supervisory Authority have the meanings given in the GDPR; under the CCPA, Controller reads as Business, Processor as Service Provider, and Data Subject as Consumer. Customer Personal Data means the Personal Data that you (or your viewers, leads and teammates) put into the Service and that StreamAgent processes on your behalf, as described in Annex 1. Subprocessor means a third party StreamAgent engages to process Customer Personal Data. Standard Contractual Clauses or SCCs means the clauses approved by the European Commission in Decision 2021/914, and UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
2. Roles and scope
For Customer Personal Data you are the Controller (or a Processor acting for your own client, in which case you warrant that your client has authorised this DPA) and StreamAgent is your Processor. For the account data StreamAgent holds about you as its customer (billing contact, sign-in, usage) StreamAgent is an independent Controller, as described in the Privacy Policy; that processing is outside this DPA. An agency running client workspaces under one Enterprise plan is the Controller for every client workspace unless it tells us otherwise in writing.
3. StreamAgent’s obligations as Processor
StreamAgent will:
- Process on instructions only. Process Customer Personal Data only on your documented instructions, which are the Agreement, this DPA, and your use of the Service’s settings and features (including what you connect, export, erase and retain). We will tell you if we believe an instruction breaks Data Protection Laws, unless the law prevents us. We never sell Customer Personal Data, share it for cross-context behavioural advertising, or use it to train AI models.
- Confidentiality. Ensure that everyone we authorise to process Customer Personal Data is bound to confidentiality and has access only to what their role needs.
- Security. Implement and maintain the technical and organisational measures in Annex 2, appropriate to the risk, and not reduce them during the term of the Agreement.
- Subprocessors. Engage only the Subprocessors in Annex 3 (also published at streamagent.io/trust), under written terms at least as protective as this DPA, and remain responsible for their performance. We will give Enterprise customers at least 30 days’ notice of a new Subprocessor by email to the workspace owner; you may object on reasonable data-protection grounds within that period, and if we cannot resolve the objection you may terminate the affected subscription for a pro-rated refund of prepaid fees.
- Data Subject requests. Give you the means to answer Data Subject requests yourself (per-lead export and erasure, access to every record in the dashboard), and assist you where you cannot. A request that reaches us directly about your data is forwarded to you without a substantive reply.
- Assistance. Assist you, taking account of the nature of the processing and the information available to us, with security, breach notification, data-protection impact assessments and consultations with a Supervisory Authority.
- Personal Data breach. Notify you without undue delay, and in any case within 72 hours of confirming a breach affecting Customer Personal Data, with what happened, the categories and approximate number of Data Subjects and records involved, the likely consequences, and the measures taken or proposed. We will not name you in any public statement about a breach without your consent, unless the law requires it.
- Deletion and return. Let you export Customer Personal Data at any time during the term (leads to CSV, a lead’s full record to JSON, videos as downloads, and the API). When the Agreement ends, or you delete a workspace, we delete Customer Personal Data after the grace windows in the Privacy Policy (90 days after a lapsed subscription, 30 days after a deletion request) unless the law requires us to keep some of it, in which case it stays confidential and is processed for no other purpose. Backups are overwritten on their regular cycle.
- Audits. Make available the information needed to show compliance with this DPA: this page, the trust page, our answers to your security questionnaire, and any third-party audit report we hold. Where that is not enough to meet a legal requirement, you may audit once in any twelve months on 30 days’ written notice, during business hours, without disrupting the Service, under confidentiality, at your cost; a Supervisory Authority’s audit is accommodated as the law requires.
4. Your obligations as Controller
You are responsible for the lawfulness of the Customer Personal Data you put into the Service and of your instructions: a lawful basis for collecting leads through your videos, the notices and consents your viewers need (including for the ad pixels and CRM tools you connect, and the consent banner the player records), and the accuracy of what you collect. You will not put special-category data (health, biometric, criminal, and the like) into the Service unless you have told us in writing and we have agreed. You configure retention, erasure, redaction and team access in the Service.
5. International transfers
StreamAgent processes Customer Personal Data in the United States. Where you transfer Personal Data to us from the EEA, the SCCs are incorporated into this DPA, Module Two (controller to processor), or Module Three (processor to processor) where you act for your own client, with: Clause 7 (docking) included; Option 2 of Clause 9 with the 30-day notice in section 3; the optional language in Clause 11 not included; Clause 13 and Annex I.C naming the Supervisory Authority of your establishment; Clause 17 Option 1 with the law of Ireland; Clause 18 the courts of Ireland; Annex I from Annex 1 of this DPA and Annex II from Annex 2. For transfers from the United Kingdom the UK Addendum applies, with its tables completed from the same annexes and either party able to end it as its section 19 allows. For transfers from Switzerland the SCCs apply with the Federal Data Protection and Information Commissioner as the authority and Swiss law for Swiss data. Should a transfer mechanism above be invalidated, the parties will cooperate in good faith to put a lawful one in place.
6. California (CCPA)
To the extent the CCPA applies, StreamAgent is your Service Provider. We will not sell or share Customer Personal Data, retain, use or disclose it for any purpose other than the business purpose of providing the Service under the Agreement, or combine it with Personal Data we hold for anyone else except as the CCPA permits a Service Provider to. We certify that we understand these restrictions and will comply with them, will tell you if we can no longer meet them, and grant you the right to take reasonable steps to stop and remediate unauthorised use.
7. Liability and term
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, read together as one cap, except where Data Protection Laws do not allow that. This DPA lasts as long as StreamAgent processes Customer Personal Data for you, and section 3’s deletion and confidentiality obligations survive its end. We may update this DPA by posting a new version at this address; a change that reduces a protection takes effect 30 days after posting and never for processing that already happened.
Annex 1 · Details of the processing
- Subject matter and nature. Hosting interactive videos; capturing, scoring, storing and routing the leads who respond to them; booking calls; taking in-video payments on your own payment account; sending lead-facing email you configure; syncing leads and outcomes to the tools you connect; reporting on all of it; and AI-generated enrichment (captions, chapters, summaries, suggestions, a support assistant).
- Purpose. Providing the Service to you under the Agreement, on your instructions.
- Duration. The term of the Agreement plus the deletion windows in section 3.
- Data Subjects. Your viewers and leads; your teammates and the clients you give access; the people your connected tools send to the Service.
- Categories of Personal Data. Names, email addresses, phone numbers and company; the answers a viewer gives inside a video; viewing behaviour (plays, watch time, choices, drop-off); approximate location from IP; device and browser data; consent records; booking details; purchase records (payment card data is held by the payment processor, never by us); notes and tags your team adds; anything else you choose to put in a video, a form, a note or a connected tool.
- Special categories. None intended; see section 4.
- Frequency. Continuous, for as long as the Service is used.
Annex 2 · Technical and organisational measures
- Encryption. TLS 1.2 or higher for every connection; encryption at rest (AES-256) for the database, file storage and backups; connected-app credentials and pixel secrets encrypted again at the application layer with a key held outside the database.
- Tenant isolation. Row-level security enforced by the database on every table that holds customer data, audited automatically in every test run; service credentials used only by server code, never by the browser.
- Identity and access. Password rules, Google sign-in, SAML single sign-on with optional enforcement, SCIM provisioning and deprovisioning, two-factor sign-in with an authenticator app that a workspace can require, roles (owner, admin, member), approval for member edits, time-boxed and audited support access that the customer can see on screen.
- Logging and monitoring. A per-workspace audit log of human actions exportable to CSV or a webhook; a ledger of every automated change with undo; error monitoring without lead data; external uptime probes every five minutes published on the status page.
- Data minimisation and lifecycle. Per-lead export and erasure; retention windows for untouched leads; PII redaction for connected AI assistants; workspace deletion with a grace window; daily backups on a rolling cycle.
- Secure development. Code review, automated tests and a database security audit on every change, dependency vulnerability audits, secret scanning and static analysis in continuous integration, no production credentials in developer environments.
- Incident response. A defined process for detecting, assessing, containing and notifying incidents, with the 72-hour notice in section 3.
- Vendors. Subprocessors chosen for their own certifications (every infrastructure Subprocessor in Annex 3 holds SOC 2 Type II and ISO 27001 or equivalent) and bound by written data-protection terms.
Annex 3 · Subprocessors
As of October 7, 2026. The current list is always at streamagent.io/trust.
- Amazon Web Services, Inc. — Cloud infrastructure for the database, authentication and file storage (via Supabase). Data: All customer and lead data at rest. Location: United States (us-west-2, Oregon).
- Supabase, Inc. — Managed database, authentication and file storage. Data: All customer and lead data at rest. Location: United States.
- Vercel, Inc. — Application hosting, edge network and serverless compute. Data: Data in transit through the app and API; server logs. Location: United States (global edge for static assets).
- Mux, Inc. — Video ingest, encoding, streaming and viewer playback analytics. Data: Uploaded videos, playback events. Location: United States.
- Stripe, Inc. — Subscription billing, and in-video payments on the customer’s own Stripe account. Data: Billing contact, payment details (held by Stripe), purchase records. Location: United States.
- Resend, Inc. — Transactional and lead-facing email delivery. Data: Recipient addresses and message content. Location: United States.
- Anthropic, PBC — AI features: the in-app support assistant, AI-generated summaries, captions and suggestions. Data: The text of the request (transcripts, questions, workspace notes); not used to train models. Location: United States.
- OpenAI, L.L.C. — AI features: text embeddings for search and retrieval. Data: Transcript and knowledge text; not used to train models. Location: United States.
- Google LLC — Google sign-in, and the AI search-visibility check (Gemini). Data: Sign-in identity; public page text for the visibility check. Location: United States.
- Functional Software, Inc. (Sentry) — Error monitoring. Data: Error traces with the user and workspace id; no lead data. Location: United States.
Contact
Privacy and security questions, DPA execution and Data Subject requests: support@streamagent.io, or Tech Driven Agent LLC, 2108 N St Ste N, Sacramento, CA 95816, United States.