Skip to content

Data Processing Addendum

Effective Date: July 27, 2026

Read this first:This Data Processing Addendum (the “DPA”) supplements and is incorporated into the Raileon Terms of Servicebetween you (the “Customer”) and Raileon LLC. It applies automatically whenever we process personal data on your behalf — you do not need to sign anything for it to take effect. If your organisation needs a countersigned copy for its records, email admin@raileon.com and we will send one.

1. Definitions and Roles

“Personal data,” “processing,” “controller,” “processor,” “data subject,” and “personal data breach” have the meanings given to them in the EU General Data Protection Regulation (GDPR) and the UK GDPR. “Customer Personal Data” means personal data contained in the data you or your users submit to, or generate through, the Services.

Where this DPA refers to your rights and our obligations, those apply to all Customers regardless of location. We do not restrict signup by region, so rather than gating protections by geography we extend the GDPR- and UK GDPR-shaped commitments in this DPA to every Customer.

2. Details of the Processing

Annex-style detail of what we process and why, as required by GDPR Art. 28(3):

Subject matterProvision of the Raileon AI workforce platform and the AI agents you configure on it.
DurationFor the term of your subscription, plus the 30-day export window described in Section 10.
Nature of processingStorage, retrieval, transmission, structuring, analysis, generation of text and other output, sending of messages and email on your behalf, backup, and deletion.
PurposeRunning the workflows and agent tasks you configure, operating and supporting your dedicated instance, and meeting our obligations under the Terms of Service.
Categories of data subjectsYour personnel and authorised users; your clients and prospective clients; your suppliers and other contacts; and any individual whose personal data appears in content you connect or upload.
Categories of personal dataIdentification and contact details; employment and role information; the content of emails, messages, documents, notes, and files you connect or upload; integration metadata; and any other personal data you choose to submit. The Services are not designed for special-category data, and you should not submit it without agreeing a separate written arrangement with us.

3. Processing on Documented Instructions

We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms of Service, this DPA, the configuration you set in the platform (agents, workflows, prompts, connected integrations, and settings), and any further written instruction you give us. We will not process Customer Personal Data for our own purposes, and we will not use it to train public AI models — training is disabled on the third-party AI provider APIs we use.

If we are required by law to process Customer Personal Data beyond your instructions, we will tell you before doing so unless the law forbids that notice. If we believe an instruction from you infringes GDPR, UK GDPR, or another applicable data protection law, we will tell you promptly and may pause the affected processing until the issue is resolved.

4. Confidentiality

Access to Customer Personal Data is limited to Raileon personnel who need it to operate or support the Services. Everyone with access is bound by written confidentiality obligations that survive the end of their engagement, and access is granted on a need-to-know basis and removed when it is no longer needed.

5. Security Measures

We implement appropriate technical and organisational measures under GDPR Art. 32. The measures actually in place are:

Full detail, including what we do not have, is on our security page. In short: we hold no SOC 2 report, no ISO 27001 certification, no third-party penetration test report, and we do not offer a HIPAA Business Associate Agreement. If your compliance programme requires any of those, tell us before you buy.

6. Sub-processors

You give us general written authorisation to engage sub-processors to help deliver the Services. The current list, with the purpose of each one, is maintained at raileon.com/subprocessors.

7. Assistance with Data Subject Requests

The platform gives you direct access to Customer Personal Data, so in most cases you can handle access, correction, deletion, and portability requests yourself. Where you cannot, we will provide reasonable assistance so you can respond within your legal deadlines.

If a data subject contacts us directly about Customer Personal Data, we will not respond on your behalf beyond acknowledging receipt. We will forward the request to your account contact promptly. Reach us for this at privacy@raileon.com.

8. Personal Data Breach Notification

If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any case within 72 hours of becoming aware of it. The notification will include, to the extent known at the time:

Where we cannot provide all of that at once, we will send what we have and follow up as the investigation develops. We will also help you meet your own notification duties to regulators and data subjects. Notifying you is not an admission of fault. Security matters can be reported to us at security@raileon.com.

9. Data Protection Impact Assessments

On request, we will give you reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority that relates to your use of the Services. In practice this means supplying the information we hold about our processing, security measures, and sub-processors — information that is largely already published on this page, the security page, and the sub-processors page.

10. Deletion or Return on Termination

When your subscription ends, you have 30 days to export your data. We will keep your instance accessible for export during that window and will help you extract data you cannot retrieve yourself.

11. Audits and Information Rights

We will make available the information reasonably necessary to demonstrate compliance with this DPA. Being honest about scale: Raileon is a small company, and we do not host on-site audits or open our production infrastructure to customer-run scans. What we do offer:

If those measures are genuinely insufficient for your regulatory obligations, contact admin@raileon.com and we will discuss what else is workable rather than pretend the standard offer covers it.

12. International Transfers

All processing of Customer Personal Data takes place in the United States. Our infrastructure, our sub-processors, and our personnel operate there. We do not offer regional data residency.

Where you transfer personal data subject to EEA, UK, or Swiss data protection law to us, the following are incorporated into this DPA by reference and take effect on transfer:

Where the Clauses conflict with the rest of this DPA on a transfer matter, the Clauses win.

13. Order of Precedence

This DPA forms part of the Terms of Service. If there is a conflict between this DPA and the Terms of Service on a data protection matter, this DPA prevails. If there is a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail. On everything else, the Terms of Service prevail. Nothing here changes the liability caps, governing law, or dispute resolution terms in the Terms of Service, except as the Clauses require.

This DPA is governed by the law stated in the Terms of Service. Raileon LLC is a Florida limited liability company.

Note on this document: This is Raileon’s standard DPA, published here so you and your counsel can review it before you buy rather than after. It is offered as-is to all Customers. If your organisation has its own DPA, its own Standard Contractual Clause appendices, or specific clauses it needs added, email admin@raileon.com and we will review it with you. Nothing on this page is legal advice.