This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Oz Terms of Service and any applicable order or agreement between the customer ("Customer," "Controller," "you") and AnyReach Inc. ("AnyReach," "Processor," "we") governing Customer's use of the Oz product ("Agreement"). It applies to AnyReach's Processing of Personal Data on Customer's behalf in connection with Oz. In case of conflict on data-protection matters, this DPA controls over the rest of the Agreement.
1. Definitions
Capitalized terms not defined here have the meaning in the Agreement.
- "Data Protection Laws" means all laws applicable to the Processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws including the California Consumer Privacy Act as amended by the CPRA ("CCPA").
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Personal Data Breach," and "Supervisory Authority" have the meanings given under GDPR (and equivalent terms under other Data Protection Laws, including "business," "service provider," and "consumer" under the CCPA).
- "Customer Personal Data" means Personal Data contained in Customer Content and in data Oz accesses from Connected Services, that AnyReach Processes on behalf of Customer under the Agreement. It includes Third-Party Data (Personal Data about individuals who are not users of Oz but whose data is Processed at Customer's direction).
- "Subprocessor" means a third party engaged by AnyReach to Process Customer Personal Data.
- "Standard Contractual Clauses" ("SCCs") means the clauses approved by European Commission Implementing Decision (EU) 2021/914, and the UK International Data Transfer Addendum where applicable.
- "Connected Services," "Customer Content," "Third-Party Data," and "Oz" have the meanings in the Oz Terms of Service.
2. Roles, Scope, and Instructions
2.1 Roles. With respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party controller) and AnyReach is the Processor. Where AnyReach Processes Personal Data as a Controller for its own purposes (for example, account administration, billing, security, and product improvement), that Processing is governed by the Oz Privacy Policy and not this DPA.
2.2 Documented instructions. AnyReach will Process Customer Personal Data only (a) to provide, secure, and support Oz in accordance with the Agreement; (b) as further documented in this DPA and Annex I; and (c) per Customer's other lawful written instructions (including instructions Customer issues through the Oz product, such as connecting a service, configuring automations, or directing Oz to take an action). AnyReach will inform Customer if, in its opinion, an instruction infringes Data Protection Laws (without obligation to provide legal advice).
2.3 Customer obligations. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for having a valid legal basis and providing any notices and obtaining any consents required for AnyReach to Process it as instructed — including for Third-Party Data about individuals who are not Oz users (for example, the Customer's contacts, counterparties, and people copied on communications Oz participates in). Customer warrants that its instructions, including connecting Connected Services and enabling agent actions, comply with Data Protection Laws.
2.4 AI Processing. Customer acknowledges and instructs that, to provide Oz, AnyReach transmits relevant Customer Personal Data to an AI model Subprocessor for Processing to generate outputs. AnyReach will not use Customer Personal Data to train foundation AI models, and will contract so that its AI Subprocessor does not use Customer Personal Data transmitted through its commercial interface to train its foundation models. Oz's per-Customer memory and skill learning is logically isolated to Customer's organization and used only to provide Oz to Customer.
3. Confidentiality and Personnel
AnyReach will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and have received appropriate data-protection training, and will limit access to those who need it to provide Oz.
4. Security
AnyReach will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, costs, and the nature, scope, and risk of the Processing. The current measures are described in Annex II. AnyReach may update its measures provided they do not materially reduce the overall level of protection.
5. Subprocessors
5.1 General authorization. Customer provides general written authorization for AnyReach to engage Subprocessors to Process Customer Personal Data. The current Subprocessors are listed in Annex III.
5.2 Flow-down and liability. AnyReach will impose data-protection obligations on each Subprocessor that are substantially similar to those in this DPA, and remains liable to Customer for each Subprocessor's performance of its data-protection obligations.
5.3 Changes and objection. AnyReach will maintain the Subprocessor list and provide a mechanism for Customer to be notified of new or replacement Subprocessors at least 10 days before authorizing them to Process Customer Personal Data. Customer may object on reasonable, data-protection grounds within the notice period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected portion of the Service as its exclusive remedy.
6. International Transfers
Where Processing of Customer Personal Data involves a transfer from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree the SCCs (and UK Addendum / Swiss amendments as applicable) are incorporated by reference and apply, with: Module Two (controller-to-processor) where Customer is a Controller, and Module Three (processor-to-processor) where Customer is itself a Processor; the Annexes to the SCCs are populated by Annexes I–III of this DPA; and the optional docking clause applies. In the event of conflict, the SCCs prevail for in-scope transfers.
7. Personal Data Breach
AnyReach will notify Customer without undue delay, and in any event within 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, likely consequences, and measures taken or proposed. AnyReach will provide reasonable assistance to Customer in meeting Customer's breach-notification obligations. Notification is not an acknowledgment of fault.
8. Data Subject Requests and Assistance
8.1 Data subject requests. Taking into account the nature of the Processing, AnyReach will provide reasonable assistance, including appropriate technical and organizational measures and self-service controls in Oz, to help Customer respond to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). If AnyReach receives such a request directly, it will not respond except to confirm the request relates to Customer and will refer the Data Subject to Customer, unless legally required to do otherwise.
8.2 DPIAs and consultation. AnyReach will provide reasonable assistance to Customer with data-protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of Processing and the information available to AnyReach.
9. Audits and Information
AnyReach will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports or security certifications where available. To the extent such materials are insufficient, AnyReach will allow and contribute to audits, including inspections, conducted by Customer or an independent auditor: on at least 30 days' prior notice, no more than once per 12 months (except where required by a Supervisory Authority or following a Personal Data Breach), during business hours, subject to confidentiality, and in a manner that does not compromise other customers' data or AnyReach's security. Customer bears its own audit costs.
10. Deletion and Return
Upon termination or expiry of the Agreement, AnyReach will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies, within a commercially reasonable period, except to the extent retention is required by law. AnyReach will make Customer Content available for export for the period stated in the Agreement before deletion. Routine backups are deleted on AnyReach's standard backup cycle.
11. CCPA / US State Privacy Terms
To the extent AnyReach Processes Personal Data subject to the CCPA on Customer's behalf, AnyReach acts as a service provider (or contractor). AnyReach will not: (a) sell or share such Personal Data; (b) retain, use, or disclose it for any purpose other than performing the Service or as permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship; or (d) combine it with Personal Data from other sources except as permitted by the CCPA. AnyReach certifies that it understands and will comply with these restrictions and will notify Customer if it can no longer meet its obligations. Equivalent terms apply under other US state privacy laws.
12. Liability
Each party's liability under this DPA, including the SCCs, is subject to the limitations and exclusions of liability in the Agreement.
13. Term, Conflict, and Governing Law
This DPA takes effect on the Effective Date stated above and remains in effect for as long as AnyReach Processes Customer Personal Data under the Agreement. Except as stated in Section 6 (SCCs prevail for in-scope transfers) and the introduction (this DPA controls on data-protection matters), the Agreement's terms, including governing law and venue, apply to this DPA.
Annex I — Details of Processing
A. Parties. The data exporter / Controller is the Customer, as identified in the Agreement. The data importer / Processor is AnyReach Inc.; data-protection contact: support@anyreach.ai.
B. Subject matter and nature of Processing. Provision of Oz, an AI teammate that, at Customer's direction and authorization, accesses Connected Services and messaging channels to read information, generate outputs (drafts, summaries, recaps, documents), maintain a per-Customer memory, and take actions on Customer's behalf, including transmission of Personal Data to an AI model Subprocessor for Processing. Operations include collection, recording, organization, storage, retrieval, use, transmission to Subprocessors and (at Customer's direction) recipients, and deletion.
C. Purpose. To provide, secure, and support Oz in accordance with the Agreement and Customer's instructions.
D. Duration. For the term of the Agreement and until deletion or return of Customer Personal Data under Section 10.
E. Categories of Data Subjects.
- Customer's authorized users (employees and contractors who use Oz);
- Customer's contacts, customers, prospects, counterparties, and other individuals whose Personal Data appears in Connected Services or in conversations Oz participates in, including individuals who are not Oz users (Third-Party Data — for example, email correspondents, meeting participants, CRM contacts, and people copied on or participating in threads Oz is part of).
F. Categories of Personal Data.
- Identity and account data (from SSO): name, email address, profile image, locale, organization / workspace identifiers, role. (No passwords are collected or stored.)
- Connected-service content: email content and metadata, calendar events and attendees, contacts, CRM records, files and documents, and messaging content, to the extent within the scopes Customer grants.
- Conversation and instruction data: messages, prompts, uploads, and approvals provided to Oz.
- Derived data: memory profiles, learned preferences, summaries, and skills derived from Customer's use.
- Usage and technical data: IP address, device / browser information, log and diagnostic data.
- Third-Party Data: any of the above categories relating to non-user individuals, as brought into Oz by Customer.
G. Special categories of Personal Data. Not intended or required. Oz is not designed to Process special-category data; Customer should not direct Oz to Process such data without appropriate safeguards and instructions.
H. Frequency of transfer. Continuous, as Customer uses Oz.
I. Competent Supervisory Authority (for SCCs). Determined under the SCCs based on the Customer's EU representative or place of establishment.
Annex II — Technical and Organizational Measures
AnyReach maintains measures including, at a minimum:
- Tenancy isolation: logical separation of each organization's data; access scoped to the organization and enforced on data-access paths.
- Authentication: single sign-on only via supported identity providers; no password storage; session integrity protection.
- Access control: role-based access; least-privilege internal access; access to Customer Personal Data limited to personnel who need it.
- Encryption: encryption of Personal Data in transit using industry-standard protocols; encryption at rest where supported by the underlying infrastructure.
- Connected-service authorization: access to Connected Services only via Customer-granted authorization scopes, revocable by Customer; tokens stored securely.
- Agent-action safeguards: default "propose" mode requiring human approval before consequential external actions; configurable automation controls.
- Logging and monitoring: audit logging of significant actions; security monitoring and error tracking.
- Resilience and backup: routine backups; measures to restore availability after an incident.
- Vendor management: Subprocessor due diligence and contractual data-protection obligations.
- Incident response: a documented process for detecting, responding to, and notifying Personal Data Breaches.
- Data minimization and retention: accessing Connected Services only as needed for requested features; deletion or return per Section 10.
Annex III — Subprocessors
Current Subprocessors authorized to Process Customer Personal Data to provide Oz. For each, we list the purpose, processing location, and the categories of Personal Data involved:
- Anthropic — AI model Processing to generate Oz outputs (United States). Conversation data and Connected-service content transmitted for Processing.
- Pipedream — connecting to and exchanging data with Connected Services (United States). Connected-service content and authorization tokens.
- Logto — single sign-on authentication and identity management (United States). Identity and account data.
- Stripe — billing and payment Processing (United States). Billing contact and payment metadata.
- Railway — application hosting and data storage for the Oz backend (United States). All categories.
- Vercel — hosting and content delivery for the Oz web application (United States). Usage and technical data.
- Resend — sending email notifications and messages at Customer's direction (United States). Recipient and message data.
Customer-connected applications (such as Gmail, Google Calendar, Google Drive, and Slack) are Connected Services that Customer authorizes directly, not AnyReach Subprocessors. We maintain this Subprocessor list and notify Customers of changes under Section 5.3.
Questions about this DPA: support@anyreach.ai · AnyReach Inc. · 11596 Southwood Dr, Saratoga, CA 95070.

