Legal
Data processing
Effective date:
August 2026
Introduction
This page describes how Laxcorp Software Design FZCO ("Claws", "we", "us") processes data on your behalf when you run operations on the platform — especially when your agents handle personal data belonging to your own customers or clients.
It exists because of a simple reality: Claws operators often run agent teams for other people. When they do, the operator is the data controller, and Claws is the processor working under their instructions. This page is the plain-language record of that relationship — the roles, the subprocessors, the safeguards, and the timelines.
1. Roles
For your account data (your profile, billing, and platform usage), Claws is the controller — see our Privacy Policy.
For the data your agents process (your leads, your clients' messages, documents, and records flowing through your workspaces), you are the controller and Claws is your processor. We process that data only to operate your workspaces per your configuration — never for our own purposes, never for advertising, never for AI model training.
Your responsibilities as controller: having a lawful basis to process your clients' data, honoring their rights requests, configuring your agents appropriately, and ensuring your use case is one the platform is suited for (see the regulated-data note in Section 6).
2. What processing happens
Your workspace runs in an isolated container that executes your agent configuration: reading connected data sources, generating content via your chosen AI model provider, communicating on your connected channels, and writing activity logs so your dashboard, approvals, and attribution work. Processing happens only while your workspace exists and only per your configuration.
3. Subprocessors
We use a small set of infrastructure providers to deliver the service. Current categories and providers:
Purpose | Provider |
|---|---|
Application hosting | Vercel |
Database | Neon (PostgreSQL) |
Workspace containers | Railway |
Backups & file storage | S3-compatible cloud storage |
Payments (merchant services) | Dodo Payments |
AI model inference | The provider(s) you configure — Anthropic, OpenAI, or Google — under your own API agreement (or ours, while promotional credits apply) |
Tool integrations (OAuth) | Composio, plus the specific tools you connect |
Transactional email | Resend |
Logging & monitoring | Axiom, Sentry, UptimeRobot |
Rate limiting / caching | Upstash (Redis) |
We hold subprocessors to confidentiality and security obligations consistent with this page. If we add or replace a subprocessor that materially affects your data, we'll update this page and notify active customers.
4. Security measures
One isolated container per workspace — no shared runtime between customers. Credentials encrypted at rest with AES-256-GCM; encryption in transit everywhere (TLS). Role-restricted internal access on a need-to-operate basis. Rate limiting, abuse monitoring, and per-workspace budget enforcement. Nightly encrypted backups of workspace volumes with defined retention. Continuous health monitoring with automated recovery.
5. International transfers
Our subprocessors operate across regions that may include the United States and Europe. Transfers rely on the subprocessors' safeguards and standard contractual protections. If your controller obligations require specific transfer mechanisms, contact us before onboarding regulated datasets.
6. Regulated and special-category data
Claws is not a healthcare covered entity and does not offer Business Associate Agreements. Template-level compliance features (such as communication gates in medical or legal templates) are risk-reduction tools, not certifications — activity logs pass through our infrastructure, and the platform is not designed as a system of record for protected health information or similar special-category data. If your use case requires HIPAA-grade or equivalent handling, do not process that data through Claws.
7. Data subject requests
If someone whose data your agents processed exercises rights against you (access, deletion, correction), the tools to comply are yours: activity search and export, memory management, and workspace deletion. If a data subject contacts us directly about data you control, we'll refer them to you and reasonably assist.
8. Retention and deletion
Processing data lives with your workspace and follows the platform lifecycle: intact and resumable for 30 days after subscription cancellation → final encrypted backup restorable until day 90 → permanent deletion at day 90. Account deletion purges everything after a 14-day grace window. Deleting a workspace directly removes its container and data on the same timeline. Backups age out on a fixed schedule (daily retained ~7 days, weekly ~4 weeks, plus the final snapshot above).
9. Incidents
If we become aware of a personal-data breach affecting data we process for you, we will notify you without undue delay with what we know — scope, data involved, and remediation — so you can meet your own controller obligations.
10. Audits and questions
We'll answer reasonable written security questionnaires from active customers and provide summaries of our security practices. For anything on this page: support@buildclaws.ai — Laxcorp Software Design FZCO, IFZA, Dubai, United Arab Emirates.