Agentria is becoming Pitbot AI. Same product, same team, new name. You have been redirected from agentria.cloud to pitbot.ai, so update your bookmarks.
Version 1 — effective 2026-09-25
This Data Processing Agreement (the “DPA”) forms part of the agreement between Luminbrane AB, org.nr 559523-4245, c/o Helio, Slottsbacken 8, 111 30 Stockholm (“Luminbrane”, the processor) and the Customer (the controller) for the Pitbot service. It applies whenever Luminbrane processes personal data on the Customer’s behalf and is drafted to meet Article 28 of the EU General Data Protection Regulation (“GDPR”). Capitalised terms have the meaning given in the Terms of Service.
1.1 The Customer is the controller of the personal data of its players, staff and contacts that it submits to the Service, and the owner of that data. Luminbrane is the processor, acting only on the Customer’s documented instructions; Luminbrane never becomes the owner of, or a controller for, Customer personal data.
1.2 Where the Customer itself acts as a processor for another operator, the Customer warrants that its own controller has authorised Luminbrane as a sub-processor on these terms.
1.3 Luminbrane is an independent controller only for its own account and billing records, security logs and the aggregated service data described in section 8.4 of the Terms.
| Subject matter | Personal data contained in player-support conversations, knowledge-base content, player profiles and account data that the Customer submits to Pitbot. |
| Duration | The term of the Agreement plus the export and deletion periods in section 11. |
| Nature | Receiving, storing, classifying, pseudonymising, drafting replies with AI models, queueing for human review, sending approved replies, escalating, reporting and deleting. |
| Purpose | Providing the Customer with an AI-assisted player-support service under the Customer's control. |
3.1 Data subjects. The Customer’s players (customers of the Customer’s gambling brands), the Customer’s staff who use the dashboard, and the Customer’s contacts for billing and notices.
3.2 Categories of personal data.
3.3 Special categories. The Service is not designed for special-category data (Article 9 GDPR). Responsible-gambling signals may nonetheless reveal information about a player’s health or financial situation. The Customer confirms it has a lawful basis for processing such data in its support operations, and Luminbrane processes it only as part of the conversation and only on the Customer’s instructions.
4.1 Luminbrane processes personal data only on the Customer’s documented instructions, which consist of the Agreement, the configuration the Customer sets in the dashboard or through the MCP server (including the AI model lane, escalation rules, retention and purge actions), and any further written instructions the Customer gives.
4.2 Luminbrane will inform the Customer without delay if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law, and may suspend that instruction until it is clarified.
4.3 Luminbrane will not process personal data for its own purposes, sell it, or use it to train AI models.
Luminbrane ensures that every person authorised to process personal data — its staff and any contractors — is bound by a contractual or statutory duty of confidentiality, and has access only to the data needed for their role.
Luminbrane implements and maintains appropriate technical and organisational measures, taking into account the state of the art, the costs of implementation and the risks of the processing, including:
A more detailed description of the measures is available to the Customer on request under confidentiality.
7.1 Authorisation. The Customer gives general authorisation for Luminbrane to engage the sub-processors listed in Annex 1, and any replacement or additional sub-processor under this section.
7.2 Change notice. Luminbrane will notify the Customer by email to the account holder at least 30 days before adding or replacing a sub-processor that will process Customer personal data. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service without penalty, and receives a pro-rated refund of any prepaid fees for the remainder of the term.
7.3 AI model providers. The Customer chooses which AI inference lane processes its conversations. Only the provider(s) for the selected lane receive message content. If the Customer configures its own model-provider credentials (“bring your own key”), that provider processes data under the Customer’s own agreement with it, and Luminbrane is not responsible for that provider.
7.4 Flow-down. Luminbrane imposes on each sub-processor data-protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the sub-processor’s performance.
8.1 Luminbrane hosts production data in the European Union. Personal data is transferred outside the EU/EEA only where necessary to provide the Service through a sub-processor in Annex 1 whose processing occurs, in whole or in part, outside the EU/EEA.
8.2 Any such transfer is covered by an appropriate safeguard under Chapter V GDPR: the EU–US Data Privacy Framework where the provider is certified, or the European Commission’s Standard Contractual Clauses (2021/914) with a transfer-impact assessment, or an adequacy decision. Copies of the applicable safeguards are available on request.
8.3 Where the Customer selects a third-party AI model lane, the Customer acknowledges that the provider may process message content on infrastructure outside the EU/EEA as described in Annex 1, protected by the safeguards in 8.2. The Luminbrane-hosted lane (Cortex) keeps inference within the EU.
9.1 Data-subject requests. Luminbrane will forward to the Customer without undue delay any request it receives from a data subject relating to the Customer’s data, and will not respond except to direct the person to the Customer. The dashboard provides tools to search for, export and purge a player’s conversations and profile so the Customer can answer access, portability and erasure requests itself; Luminbrane will assist with anything the tools do not cover.
9.2 Compliance obligations. Taking into account the nature of the processing and the information available to it, Luminbrane will assist the Customer with security, breach notification, data-protection impact assessments and prior consultation with a supervisory authority (Articles 32–36 GDPR). Assistance that goes beyond what the Service provides as standard may be charged at Luminbrane’s then-current rates, agreed in advance.
10.1 Luminbrane will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting the Customer’s personal data. The notice goes to the account holder and any security contact the Customer has registered.
10.2 The notice will describe, as far as known at the time and supplemented as information becomes available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point.
10.3 Luminbrane will cooperate with the Customer in investigating, mitigating and documenting the breach and in any notification the Customer must make to a supervisory authority or to data subjects. Luminbrane will not notify authorities or data subjects on the Customer’s behalf unless required by law or asked by the Customer.
11.1 During the term. The Customer can purge conversations and player data from the dashboard at any time. Conversation data beyond the plan’s hot-retention period is deleted automatically.
11.2 On termination. For 30 days after the Agreement ends, the Customer may export all personal data in a machine-readable format. After that period Luminbrane deletes all Customer personal data from live systems and, within a further 30 days, from backups, unless EU or Swedish law requires storage — in which case the data stays protected under this DPA until deleted.
11.3 Certification. On request, Luminbrane confirms deletion in writing.
12.1 Luminbrane makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR: this DPA, the security description in section 6, its sub-processors’ current certifications and audit reports, and a written response to reasonable security questionnaires (no more than once per year, unless a breach or a supervisory authority requires otherwise).
12.2 Where the above is insufficient, the Customer or an independent auditor bound by confidentiality may audit Luminbrane’s processing on at least 30 days’ written notice, during business hours, no more than once per 12 months, in a manner that does not disrupt other customers or expose their data. Luminbrane’s reasonable costs of an on-site audit beyond one day are chargeable, agreed in advance.
The liability of each party under this DPA is subject to the limitations and exclusions in section 12 of the Terms (including the exclusion of liability during a free trial and the 3-month cap on paid plans), which apply in aggregate across the Terms and the DPA. Nothing in this section limits either party’s liability to data subjects or supervisory authorities under Article 82 GDPR to the extent it cannot be limited.
This DPA applies for as long as Luminbrane processes personal data on the Customer’s behalf. On data-protection matters it prevails over the Terms and any order form. If a supervisory authority or a change in law requires changes to this DPA, the parties will agree them in good faith; Luminbrane may update Annex 1 under section 7.
Current as of 2026-09-25. Changes are notified under section 7.2.
| Sub-processor | Service | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase, Inc. | Database, authentication, storage, edge functions | All Customer Data incl. conversations, player profiles, staff accounts | EU (eu-north-1, Stockholm) | Support access from outside the EU under SCCs / DPF |
| Fly.io, Inc. | Application hosting (dashboard, API) | Data in transit through the application; application logs | EU (Frankfurt) | Support access from outside the EU under SCCs |
| Cloudflare, Inc. | DNS, CDN, WAF, DDoS protection | Request metadata (IP address, headers); content in transit | Global edge network; EU regional services where configured | DPF / SCCs |
| Resend, Inc. | Transactional email (account codes, notices; outbound player email where the Customer routes email through the Service) | Recipient email address, message content | EU region; US for provider support under DPF / SCCs | DPF / SCCs |
| Google LLC (Gemini) | AI inference — only when the Customer selects the Gemini lane | Pseudonymised conversation content, brand configuration | EU region where the model is offered, otherwise US under SCCs / DPF | DPF / SCCs; no training on API data |
| Anthropic, PBC (Claude) | AI inference — only when the Customer selects the Claude lane | Pseudonymised conversation content, brand configuration | US (EU region where offered) under SCCs / DPF | DPF / SCCs; no training on API data |
| OpenAI, L.L.C. (GPT) | AI inference — only when the Customer selects the OpenAI lane | Pseudonymised conversation content, brand configuration | US (EU data residency where offered) under SCCs / DPF | DPF / SCCs; no training on API data; retention opt-out set |
| Luminbrane AB (Cortex) | Self-hosted AI inference — only when the Customer selects the Cortex lane | Pseudonymised conversation content, brand configuration | EU (Sweden) | Not a transfer |
Providers of internal tooling that never see Customer personal data (source control, CI, alerting, metrics dashboards that receive counts only) are not sub-processors and are not listed.