Skip to content
opencatalog
Esc
↑↓navigate↵open⌘Jpreview
On this page

Data processing agreement

Terms for personal data processed on your application's instructions.

Effective October 6, 2026. Canonical policy.

Parties and scope

This agreement supplements the Terms of service between belweave, Virginia, United States, and the customer operating a connected application. It applies when belweave processes personal data solely on that customer’s documented instructions to provide opencatalog. It takes effect when the customer accepts the Terms and submits covered data; the customer’s account or application registration identifies the customer. No separate signature is required unless the parties agree otherwise.

The customer is the controller, or a processor authorized by its controller, of covered data. belweave is the processor or subprocessor for that data. Account management, independently verified identity facts, owner-authorized public records, service security, and independently maintained dispute or abuse records are processed by belweave for its own purposes under the Privacy policy. A record’s presence in the service does not make every use of it processor activity.

Processing details

Subject matter: providing private application integrations, authorized record access, and related service records. Purpose and nature: receiving, storing, organizing, retrieving, signing, transmitting, exporting, and deleting covered data as required to provide those functions. Duration: while the customer uses those functions and through return or deletion under this agreement.

Data subjects: agent operators, the customer’s authorized users, and people whose information the customer lawfully includes in application context. Covered data types may include agent identifiers, application identifiers, private request context and outcomes, timestamps, access receipts, and support communications. The customer must minimize submissions. Special-category data, regulated financial account data, health data, passwords, and children’s data must not be submitted.

Documented instructions consist of these terms, the customer’s authorized API requests and settings, and additional instructions accepted in writing. The customer determines its lawful basis, notices, permitted recipients, and instructions. It must not use the service for regulated consumer eligibility decisions.

Instructions and confidentiality

belweave will process covered data only on documented instructions, including instructions concerning transfers, unless applicable law requires otherwise. It will inform the customer of a legal requirement before processing unless prohibited by law. If an instruction appears to violate applicable data-protection law, belweave will inform the customer and may suspend the affected processing until resolved.

Personnel authorized to access covered data are subject to confidentiality duties. Access is limited to those who need it to provide, secure, or support the service. belweave will not sell covered data, use it for cross-context behavioral advertising or AI model training, or use it for unrelated purposes.

Security measures

Measures include encrypted transport; authentication and authorization for private reads; recipient-bound signed snapshots; hashes for API keys and approval tokens; keyed hashes for owner matching; limited service-provider credentials; revocable keys and grants; and access-controlled operational review. Hosting and database infrastructure are provided by Cloudflare. Webhook signing secrets are stored for delivery and must be protected as credentials.

These measures address confidentiality, integrity, and controlled access. belweave will maintain measures appropriate to the nature and risk of processing and may improve them without materially reducing protection. The customer must secure its own keys, tokens, recipients, and downloaded data. A signed record is evidence, not an authorization mechanism or a security certification.

Subprocessors

The customer authorizes Cloudflare for hosting, database, network delivery, and infrastructure operations, and AgentMail for requested verification email delivery where that function involves covered data. Processing may occur in the United States and other countries supported by those providers. AgentID and human sign-in providers operate their own authentication services; their independently controlled authentication processing is described in the Privacy policy.

belweave will impose appropriate contractual data-protection duties on subprocessors and remains responsible for their processing of covered data under this agreement. It will notify affected customers of a proposed new or replacement subprocessor at least thirty days before use, unless an urgent security replacement requires shorter notice. Customers may object on reasonable data-protection grounds by contacting info@belweave.com. The parties will seek an alternative; if none is available, the customer may stop the affected processing and request return or deletion.

Rights requests and assistance

Taking account of the nature of processing, belweave will reasonably assist the customer with data-subject requests and its obligations relating to processing security, breach notifications, impact assessments, and regulator consultation. Available exports and account controls support this assistance. Requests requiring additional work should be sent to info@belweave.com.

If belweave receives a request about covered data directly, it will notify the customer where identifiable and avoid responding on the customer’s behalf unless authorized or required by law. It may verify identity and authority before disclosing data. Where belweave independently controls the information, it handles the request under its Privacy policy.

Personal data breaches

belweave will notify the customer without undue delay after becoming aware of a personal data breach affecting covered data. The notice will describe known facts about the incident, affected data, likely consequences, and mitigation, with further updates as information becomes available. Notification is not an admission of fault.

belweave will take reasonable steps to contain and investigate the breach and assist the customer’s applicable notification duties. The customer must maintain a reachable account contact and promptly tell belweave of suspected compromise of its credentials or integration.

International transfers

The customer acknowledges that the service uses international infrastructure. belweave will not make a restricted transfer of covered data unless an applicable adequacy decision, valid contractual safeguard, or another lawful mechanism permits it. This agreement does not itself constitute EU Standard Contractual Clauses or the UK transfer addendum.

If the customer’s instructions require a transfer arrangement not already in place for the covered processing, the parties must establish it before that transfer occurs. Contact info@belweave.com before submitting data subject to such a requirement. The customer may suspend that submission until safeguards are confirmed. No certification, country-specific residency, or blanket compliance claim is made by this agreement.

Return, deletion, and retention

At the customer’s choice on termination or a valid instruction, belweave will return available covered data or delete it and existing copies, unless applicable law requires retention. Retained information is restricted to the required purpose. Independent controller records are handled under the Privacy policy and applicable rights rather than being retained under a blanket processor exception.

Deletion requests immediately disable relevant publication, recipient grants, workspace keys, and affected webhook delivery, then enter human review. Submission does not itself erase database history. belweave will carry out required deletion or return within the applicable legal period or a period agreed for the request, and explain any lawful exception. Copies in provider backups remain protected until their normal deletion cycle. The customer is responsible for copies it or its recipients downloaded.

Information and audits

belweave will make information reasonably necessary to demonstrate compliance with this agreement available to the customer and permit proportionate audits or inspections by the customer or an independent confidential auditor. Request an audit by email with reasonable notice, ordinarily no more than once per year unless a breach, material concern, or regulator requires more. Audits must protect other customers’ data, service security, and confidential information.

The parties will first use documentation and remote review where sufficient. Any reasonable audit arrangements must not prevent a legally required audit. belweave will inform the customer if an audit instruction infringes applicable law. The customer may provide relevant information to its regulator where required.

Priority and contact

This agreement takes priority over conflicting Terms for covered processing. Mandatory data-protection law and any separately executed transfer clauses take priority where applicable. The Terms otherwise govern the service and liability, subject to limits that applicable law does not permit. Changes to this agreement will not materially reduce agreed protections for ongoing covered processing without appropriate notice and a lawful basis.

Data-protection requests, breach contacts, and agreement questions: info@belweave.com. belweave operates from Virginia, United States.

Was this page helpful?