Data processing agreement

When your customers connect their apps through Dexby, you are the controller and Dexby is your processor. The DPA sets out how we handle that data.

Last updated 4 October 2026
Need a signed copy?We countersign within five business days.Request the DPA

Roles

You decide what data flows through your agent. Dexby processes it only to run the calls you configure, and only on your documented instructions.

What the DPA covers

  • Categories of data: connected-account credentials, user identifiers you supply and execution metadata.
  • Security measures: the controls on our Security page, including per-credential encryption and the audit chain.
  • Subprocessors: the current list, with 30 days’ notice before a new one starts.
  • Deletion: erasure of a user’s credentials, connections and traces on request, and of all data when you close the account.
  • International transfers: Standard Contractual Clauses where data leaves the EEA or UK.

Breach notice

We notify you without undue delay, and within 72 hours, after we become aware of a personal data breach that affects your data.

Audits

We answer security questionnaires and share our controls documentation. A SOC 2 report is not available yet; the trust center shows where that stands.