22 Data Processing Agreement
Last updated: 30 September 2026.
This Data Processing Agreement ("DPA") is part of the 22 Terms of Service (the "Agreement") between the customer ("Customer", "you") and DSBC Group, LLC, operator of 22 ("22", "we"). It applies whenever 22 processes personal data on your behalf. You accept it when you accept the Terms; no separate signature is needed (GDPR Art. 28(9) allows the contract to be in electronic form). If you want a countersigned copy, email privacy@22floor.com.
If this DPA and the Agreement conflict about personal data, this DPA wins. If this DPA and the Standard Contractual Clauses conflict, the Clauses win.
1. Definitions
- Data Protection Laws: every privacy and data protection law that applies to the processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, the Israeli Privacy Protection Law, 1981 (as amended, including Amendment 13) and its regulations, and US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (CCPA).
- Customer Personal Data: personal data in Customer Data (as defined in the Agreement) that 22 processes for you.
- Controller, processor, data subject, personal data, processing, personal data breach, supervisory authority have the GDPR meanings. For Israeli law, "controller" means the database controller (owner) and "processor" means the holder. For the CCPA, you are the "business" and 22 is your "service provider"; "sell" and "share" have the CCPA meanings.
- Subprocessor: a third party 22 engages to process Customer Personal Data.
- SCCs: the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914. UK Addendum: the UK International Data Transfer Addendum to the SCCs issued by the ICO.
- Security Incident: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
2. Roles and scope
- You are the controller. 22 is your processor (holder; service provider).
- 22 is a controller only for its own account, billing, security and support data, as described in the Privacy Policy.
- Details of the processing are in Annex I.
3. Your instructions
- 22 processes Customer Personal Data only on your documented instructions, including for transfers abroad, unless the law requires otherwise; in that case 22 will tell you first unless the law forbids it.
- Your instructions are: this DPA and the Agreement; your configuration of 22 (the tools you connect, the company design, Company rules and charter, agent settings, approvals and automatic modes you switch on); and any other written instructions you give that are consistent with the Agreement.
- 22 will tell you promptly if it believes an instruction breaks Data Protection Laws.
- You are responsible for the lawfulness of your instructions, for having a legal basis for the processing, and for giving your data subjects the notices they need (including that you use AI and service providers).
4. 22's duties
22 will:
- process Customer Personal Data only as set out in section 3;
- make sure everyone authorized to process it is bound by confidentiality (by contract or by law), and gets access only as far as their role needs;
- apply the technical and organizational measures in Annex II;
- follow section 6 when using subprocessors;
- help you, taking into account the nature of the processing, answer data subject requests (section 7);
- help you meet your duties on security, breach notification, data protection impact assessments and prior consultation (GDPR Articles 32 to 36), using the information available to 22;
- delete or return Customer Personal Data at the end (section 9);
- make available the information needed to show compliance with this DPA and allow audits (section 10);
- not use Customer Personal Data to train any AI model, and not allow its AI subprocessors to do so under their terms;
- keep a written record of the processing it does for you (GDPR Art. 30(2)).
5. CCPA and US state law terms
For personal information covered by the CCPA and similar US state laws, 22:
- processes it only for the business purposes of providing, securing, supporting and maintaining 22 for you as described in Annex I;
- will not sell or share it;
- will not retain, use or disclose it for any purpose (including any commercial purpose) other than those business purposes, or outside the direct business relationship with you;
- will not combine it with personal information it receives from or on behalf of anyone else, or collects itself, except as the CCPA regulations allow;
- will comply with the CCPA and provide the same level of privacy protection the CCPA requires of you, including reasonable security;
- will tell you if it decides it can no longer meet its CCPA obligations;
- lets you take reasonable and appropriate steps to make sure it uses the information consistently with your CCPA obligations (including the review and audit rights in section 10), and to stop and remediate unauthorized use;
- will help you answer consumer requests (section 7), pass on any request it receives directly, and carry out the requests you send it (for example, deleting or correcting a person's data) as the CCPA requires;
- will tell you which subcontractors it uses (section 6) and bind each by a written contract with terms at least as protective as this section.
You will tell 22 of any consumer request it must act on.
22 certifies that it understands and will comply with these restrictions.
6. Subprocessors
- General authorization. You authorize 22 to use the subprocessors listed in Annex III and on the subprocessors page.
- Same protection. 22 will have a written contract with each subprocessor that protects Customer Personal Data at least as well as this DPA, and remains responsible to you for each subprocessor's work.
- Notice of changes. 22 will give you at least 30 days' notice (by email and on the subprocessors page) before adding or replacing a subprocessor. In an emergency (for example, a provider fails and the service must continue), 22 may give shorter notice and will explain why.
- Objection. You may object on reasonable data protection grounds within those 30 days. 22 will try in good faith to offer a change that avoids the subprocessor for you. If it can't, you may end the affected part of the service.
- Apps you connect are not subprocessors. Gmail, Outlook, Shopify, Meta, Google, Zoho Desk, Zendesk, Amazon and other apps you connect are your own providers under your own agreements with them. 22 accesses them for you.
7. Data subject requests
- If 22 receives a request from one of your data subjects, it will send it to you within 5 business days and will not answer it itself unless you tell it to (except to say the request was passed on).
- 22 gives you tools to handle requests yourself: you can find, edit and delete memory items, knowledge documents and learned answers; disconnect tools; and delete a company or your account, which erases its data at once.
- For anything the tools don't cover yet (for example, exporting all data about one person: in-app export is in progress), 22 will help within 10 business days of your written request.
8. Security Incidents
- 22 will notify you without undue delay after becoming aware of a Security Incident affecting your Customer Personal Data, and in any case within 48 hours after 22 confirms it. (Our internal target, under our incident response plan, is to tell affected customers within 24 hours of detection.)
- The notice will include what 22 knows then, and more as it learns: what happened and when; the categories and approximate number of data subjects and records; the likely consequences; what 22 has done and will do; and a contact person.
- 22 will take reasonable steps to contain and fix the incident and to help you meet your own notification duties (for example, the 72-hour notice to a supervisory authority under GDPR Art. 33, notice of a severe security incident to the Israeli Privacy Protection Authority, or notice to individuals).
- Notice is not an admission of fault.
9. Deletion and return
- During the service you can delete data yourself at any time. Deleting a company or account removes its data from 22's database immediately, and removes its connections at Composio.
- At the end of the Agreement, you choose: 22 returns your data (an export you ask for within 30 days), or deletes it. Within 30 days after that export window closes, 22 deletes all Customer Personal Data, unless the law requires 22 to keep some of it (in which case 22 keeps it confidential and uses it for nothing else).
- Our hosting provider's database restore points expire within 30 days; deleted data leaves them on that schedule.
- On request, 22 will confirm deletion in writing.
10. Audits and information
- Documentation first. On request (no more than once a year, unless there is a Security Incident or a regulator asks), 22 will give you the information reasonably needed to show compliance: this DPA, the security procedure, the risk assessment summary, the subprocessor list and their terms, and written answers to a reasonable security questionnaire.
- On-site audit. If that is not enough, or a regulator requires it, you may audit 22 (yourself or through an independent auditor bound by confidentiality) once a year, at your cost, with at least 30 days' notice, during business hours, without disrupting the service or other customers' data. 22 is a small company; audits are by remote review of documents and systems unless a physical visit is required by law.
- Holder report (Israel). Where Israeli law applies, 22 will report to you at least once a year, on request, on how it meets its obligations under this DPA and the Data Security Regulations, and will tell you of any Security Incident.
- 22 has no third-party certification (such as SOC 2 or ISO 27001) at this time and will tell you if that changes.
11. International transfers
- 22 may process Customer Personal Data outside the country where it was collected, including in the United States, Israel and the countries where subprocessors operate (Annex III), only with the safeguards below.
- EU/EEA. Where a transfer from the EEA goes to a country without an adequacy decision, the SCCs are incorporated by reference: Module 2 (controller to processor) where you are a controller, Module 3 (processor to processor) where you are a processor. For them: Clause 7 (docking) applies; Clause 9 option 2 (general authorization, 30 days' notice) applies; the optional wording in Clause 11 does not apply; Clause 13: the supervisory authority of your EU establishment, or of your EU representative; Clauses 17 and 18: the law and courts of Ireland. Annex I and II of this DPA are the SCCs' Annexes I and II; Annex III is the list of subprocessors.
- UK. For transfers from the UK, the UK Addendum is incorporated, with the SCCs above and the details in the Annexes; both sides may end it as allowed in its Section 19.
- Switzerland. The SCCs apply with the FADP read in place of the GDPR, and the Swiss FDPIC as the competent authority.
- Israel. Transfers out of Israel follow the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 2001: the recipient undertakes by contract to protect the data at least as required by Israeli law and not to transfer it onward except under the same terms.
- 22 relies on the EU-US Data Privacy Framework where a subprocessor is certified, and on SCCs with each subprocessor otherwise.
- Transfer assessment. On request, 22 will give you the information you reasonably need for your transfer impact assessment (SCCs Clause 14), including how it handles requests from public authorities (Clause 15). 22 has received no such request to date.
12. Liability and term
This DPA lasts as long as 22 processes Customer Personal Data for you. Each side's liability under this DPA is subject to the limits in the Agreement, except where Data Protection Laws or the SCCs do not allow a limit.
13. HIPAA
22 is not offered for protected health information (PHI) under the US HIPAA rules. Do not send PHI through 22 unless both sides have signed a business associate agreement.
Annex I: Details of the processing
A. Parties
- Data exporter / controller: the Customer, as identified in its 22 account. Contact: the account owner's email. Role: controller (or processor for its own client, in which case SCCs Module 3).
- Data importer / processor: DSBC Group, LLC, operator of 22. Contact: privacy@22floor.com. Role: processor. Activities: providing the 22 service.
B. Description
| Item | Details |
|---|---|
| Subject matter | Providing 22: an AI CEO (Atlas) and AI agents that work in the Customer's connected tools. |
| Duration | The term of the Agreement plus the deletion period in section 9. |
| Nature | Collection through connected tools, storage, organization, retrieval, AI analysis and drafting, transmission to the Customer's tools when approved or switched to automatic, deletion. |
| Purpose | To run the Customer's AI team: read and summarize mail, tickets, orders, ads and social activity; keep company memory and knowledge; draft and (on approval or under an automatic mode) send replies; build the P&L; hold meetings; support and secure the service. |
| Frequency | Continuous while the Customer uses 22; scheduled tasks every 5 minutes for enabled automatic features. |
| Categories of data subjects | (1) The Customer's owners, staff and users of 22. (2) The Customer's end customers and prospects (people who email, open tickets, order, comment, or appear in documents). (3) Other people named in the Customer's content (suppliers, partners). |
| Categories of personal data | Names; email addresses; phone numbers; postal addresses (from orders); order history, products and amounts; support ticket and email content; social media handles and comments; ad performance (usually no personal data); documents the Customer uploads; conversation content; voice (transcribed, audio not stored). |
| Sensitive / special category data | Not required by the service. The Customer decides whether its content contains any (for example, a support ticket that mentions a health matter). If it does, the Customer is responsible for its legal basis, and the measures in Annex II apply. Payment card numbers, bank account numbers and government IDs are not wanted (a masking guard is in progress). |
| Retention | As set by the Customer (deletion controls), the defaults in the Privacy Policy (for example, conversations 12 months once stored on the server), and section 9. |
| Subprocessors | See Annex III: what each does, for how long and where. |
C. Competent supervisory authority: as in section 11.2.
Annex II: Technical and organizational measures
Each measure is marked [In place] (true today) or [In progress] (being built; not yet true). We will update this annex as work ships.
1. Encryption - [In place] HTTPS/TLS for all traffic to 22 and to every provider. - [In place] Database encrypted at rest by our host (Cloudflare D1: AES-256-GCM). - [In place] Connection secrets we hold (for example, a Shopify app's client secret and access tokens, Google refresh keys) are sealed with AES-GCM before storage, with a key kept only in Cloudflare's secret store. They are never returned by the API or written to logs. - [In place] Keys for apps connected through Composio are held by Composio; 22 never receives them. - [In progress] Per-company encryption keys (today one sealing key covers all companies).
2. Access control and isolation - [In place] Every request that touches a company's data checks that the signed-in person owns that company. Company documents carry the company's id and a save stamped for another company is refused. - [In place] Requests from other websites that change data are refused. - [In place] The admin panel is open only to the named owner accounts; every admin change is written to an admin log. - [In place] Staff access: only the incident lead (Tal Sagie) and the engineering assistant working under his direction; no other staff have production access. - [In place] Agents act only within the owner's approvals; risky actions need an Approve click; Meta Ads access is read only; automatic modes need the owner to switch them on (social replies also need a training period and a typed confirmation), and stop at daily checkpoints.
3. Authentication - [In place] Passwords stored as PBKDF2-SHA256 hashes (100,000 rounds, a salt per user). Sessions are random tokens in HttpOnly, Secure cookies; only a hash is stored. - [In place] Five wrong passwords lock an email for 15 minutes; sign-up and reset requests are rate-limited; reset links expire after 30 minutes and are never logged. - [In progress] Two-step sign-in with an authenticator app.
4. Data minimization and AI safety - [In place] Personal details are removed from closed-ticket text before the AI learns from it, and again from what it produces. - [In place] Stored text, emails, tickets and comments are treated as data, never as instructions; while outside text is in a conversation the AI cannot change Company rules on its own. - [In place] Anthropic and OpenAI are used under business terms that exclude training on API data. - [To confirm before publishing] ElevenLabs' "improve the models for everyone" setting is switched off in 22's account (ElevenLabs trains on data by default below its Enterprise plan). - [In progress] Sensitive-data guard that masks card, bank and ID numbers, passwords and keys before storing.
5. Logging and monitoring - [In place] Admin log of every admin action; logs of automatic email and social replies; per-account daily usage counts with caps. - [In progress] Per-company activity log of access and actions, visible to the owner, kept 24 months.
6. Availability and backups - [In place] Hosting on Cloudflare's network (DDoS protection, isolated Workers). Database point-in-time restore (Cloudflare D1 Time Travel, up to 30 days). - [In progress] A tested restore drill, written down.
7. Retention and deletion - [In place] Owner can delete a company or account; deletion is immediate and includes Composio connections, memory, knowledge, social, desk, P&L and ads data. - [In place] Demo sessions are deleted automatically after 30 days. - [In progress] Conversation storage with a retention setting (default 12 months); data export controls; automatic deletion of logs after 24 months. - [In progress] Deleting stored Facebook and Instagram data (cached posts and comments, drafted replies) automatically when the owner disconnects that app. Today it goes when the company is deleted or on request.
8. Secure development - [In place] Source code in a private GitHub repository with no customer data; secrets only in Cloudflare's secret store. - [In place] Security headers: X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy, Permissions-Policy. - [In progress] Further security headers (HSTS, Content Security Policy) and a public Security page.
9. Incidents - [In place] Written incident response plan: contain within 1 hour; notify affected customers (and Amazon, for Amazon data) within 24 hours of detection; written review within 7 days; plan reviewed every 6 months.
10. Vendors - [In place] Cloudflare, Anthropic, ElevenLabs and Composio: their data processing terms (with SCCs) apply through their online terms. - [To confirm before publishing] OpenAI's Data Processing Addendum has been executed for 22's account (OpenAI asks API customers to execute it through a form).
11. Not in place (stated so nobody assumes otherwise) - No SOC 2, ISO 27001 or other certification. No external penetration test yet. No independent security audit yet.
Annex III: Subprocessors
The live list, with links to each provider's terms, is on the subprocessors page. As of this date:
| Subprocessor | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, serverless functions, database (D1) | Global network; database in Cloudflare's Eastern Europe location (not locked to the EU) |
| Anthropic, PBC | AI models (Claude) | United States |
| OpenAI, L.L.C. | Voice transcription, live voice, text-to-speech, backup AI answers | United States |
| ElevenLabs (Eleven Labs, Inc.) | Text-to-speech | United States / EU |
| Composio (Sampark Inc. d/b/a Composio) | Connections to the Customer's apps; holds the app keys the Customer grants | United States |
| Resend (Plus Five Five, Inc.), planned, only if enabled | Transactional email (password reset) | United States |
How long: each subprocessor processes Customer Personal Data for the term of the Agreement. Anthropic and OpenAI keep API data up to 30 days by default (Anthropic longer only for content flagged under its Usage Policy); Composio keeps app keys until the Customer disconnects the app or deletes the company; Cloudflare holds what 22 stores until 22 deletes it, plus restore points up to 30 days.
Sources
- EU GDPR Art. 28, 32 to 36, 44 to 46: EUR-Lex
- SCCs, Decision (EU) 2021/914: EUR-Lex; UK Addendum: ICO
- CCPA service provider contract terms: 11 CCR § 7051; CCPA statute (eff. 1 Jan 2026)
- Israel Privacy Protection Law and Amendment 13: IAPP; Data Security Regulations 2017 (Reg. 15, outsourcing; Reg. 11, incidents): English text
- GDPR Art. 30(2) (processor records): EUR-Lex
- Subprocessor terms: see subprocessors