Skip to main content
CANLAH AI

Draft · Pending legal review · 2026-09-10. This page is a working draft published for transparency; it is not yet a signed agreement. Where it conflicts with a signed service agreement, the signed agreement prevails.

LEGAL

Data Processing Agreement

Draft dated September 10, 2026

This Data Processing Agreement ("DPA") forms part of the service agreement between the customer named in that agreement ("Customer", "you") and CANLAH AI Pte. Ltd., a company incorporated in Singapore ("CANLAH AI", "we"). It describes how we process personal data and business data on your behalf when you use the Canlah client console (canlah.ai/app) and the AI staff ("bots") we run for you.

1. Roles

For data you bring to the platform — your brand profile, uploaded documents, messages exchanged with your AI staff, content published to your channels, and analytics data you authorise us to read — you are the organisation that determines the purposes (controller / "organisation" under Singapore's PDPA) and CANLAH AI is the data intermediary / processor acting on your instructions.

For your account details (name, email, sign-in method, signed-in devices) and for leads you submit on canlah.ai, CANLAH AI acts as controller. That processing is described in the Privacy Policy, not this DPA.

2. Scope and purpose of processing

We process your data only to deliver the Services described in the Terms of Service and your service agreement, namely:

  • Provisioning and running AI staff (a dedicated container per staff member) that plan, draft, review and publish marketing content for your brand.
  • Building and maintaining your brand profile (facts, tone, positioning, intent ledger, schedules and plan cards) from documents and instructions you provide.
  • Relaying conversations between you and your AI staff in the console, and between your AI staff and the messaging channels you connect.
  • Publishing to social accounts you have authorised, subject to your approval mode setting.
  • Reading analytics and search data you have authorised (Google Analytics 4, Google Search Console, Bing Webmaster, Cloudflare zone analytics) to produce performance reports for you.
  • Auditing websites you ask us to audit and delivering the resulting reports.

3. Categories of data and data subjects

Depending on which features you use, the following data may be processed:

  • Your staff and administrators: name, work email, sign-in provider, passkeys, session and device records, approval decisions.
  • Your brand: profile, positioning, documents and images you upload, published articles synced from your website, intent ledgers, plans, generated drafts and reports.
  • People who message your AI staff through channels you connect (Telegram, WhatsApp, WeChat and similar): their handle and the content of the conversation, as forwarded by that channel.
  • Your social accounts: platform, handle, display name and the publishing permission you granted. Platform access tokens are held by our publishing broker (see sub-processors) and are never written to our own logs or deliverables.
  • Your website visitors, in aggregate only: report data from analytics properties you authorise. We do not attempt to re-identify individuals.
  • Model prompts and outputs: the text, documents and images your AI staff send to AI model providers to do their work.

4. Our obligations as processor

CANLAH AI will:

  • Process your data only on your documented instructions — your configuration in the console, your approvals, and your service agreement — unless required by law, in which case we inform you before processing where legally permitted.
  • Ensure that staff who access your data are bound by confidentiality obligations.
  • Use your data only for your account. Your brand data is never used to train or tune models for other customers.
  • Assist you, within reason, in responding to requests from individuals (access, correction, deletion) and in meeting your own PDPA / GDPR obligations.
  • Delete or return your data at the end of the Services as described in Section 7.
  • Make available the information necessary to demonstrate compliance with this DPA and allow audits as described in Section 10.

5. Sub-processors

We use the following third parties to run the Services. Each acts under its own terms and data processing agreement with us. We will notify registered account holders by email at least 30 days before adding a new sub-processor that will process your data; you may object in writing within that period, in which case we will discuss alternatives or you may terminate the affected Service.

Sub-processorPurposeData involvedLocation
Cloudflare, Inc.Website and console hosting (Workers), databases (D1), object storage (R2), rate limiting, zone analyticsAccount, console, brand, chat, lead data; brand documents and reportsEdge: global. D1 / R2 storage region: [To be confirmed]
Google Cloud (Google Asia Pacific Pte. Ltd.)Virtual machine running the AI staff (Kubernetes / ClawHost), container registry, build serviceAI staff workspaces, task state, channel configurationasia-east1 (Taiwan)
Google Cloud (Cloud Run, Cloud Storage)Website audit services and deep-audit report storageContent of audited websites, audit reports (deep-audit artefacts kept 7 days)asia-southeast1 (Singapore)
Google LLCGmail API for transactional email from admin@canlah.ai; Google Sign-In; read-only Google Analytics 4 and Search Console APIs when you authorise themEmail address and message content; OAuth tokens (encrypted at rest); aggregated analytics reportsUnited States / global
AI model providers via the Canlah AI gateway (Anthropic, OpenAI, Alibaba Cloud Qwen, Google Gemini) and OpenRouter for quick auditsLanguage-model inference for AI staff and auditsPrompts and outputs: brand data, drafts, conversation contentUnited States / provider regions. Exact provider list per staff role and data-retention terms: [To be confirmed]
PostForMe (api.postforme.dev)Authorisation broker and publishing API for social platformsSocial account handles and platform access tokens[To be confirmed]
Cal.com, Inc.Consultation bookingName, email, booking timeUnited States [To be confirmed]
Telegram, WhatsApp (Meta), WeChat (Tencent), Reddit, GitHubChannels and integrations you choose to connectMessages and content exchanged on that channel; for GitHub, repository access you grant to your AI engineerAs operated by each platform; chosen by you
Microsoft (Bing Webmaster API)Read-only search performance dataAggregated search reportsUnited States / global

6. Where your data is stored

The Services run in a small number of clearly separated places:

ComponentStorageRegion
Website and console (canlah.ai, canlah.ai/app)Cloudflare WorkersGlobal edge
Account, sessions, passkeys, staff records, chat history, brand profile, plans, approvals, social account linksCloudflare D1 database "canlah-hive"[To be confirmed]
Audit leads, inquiries, GA4 connection tokens (encrypted)Cloudflare D1 database "canlah-leads"[To be confirmed]
Brand documents, synced articles, delivered reportsCloudflare R2 bucket "canlah-brand-docs"[To be confirmed]
AI staff runtime: workspace, memory, skills, output files, channel configuration; ClawHost metadata (PostgreSQL); inter-agent ledger (hive-hub, SQLite)Persistent volumes on a single Google Compute Engine hostasia-east1 (Taiwan)
Quick website auditsCloud Run; results streamed to your browser, not persisted server-side [To be confirmed]asia-southeast1 (Singapore)
Deep website audits (HTML / PDF report)Google Cloud Storage, 7-day lifecycle; summary kept in the D1 brand audit tableasia-southeast1 (Singapore) [To be confirmed]

7. Retention, deletion and return

Retention periods per data category, what happens when an AI staff member is deleted, and what backups exist are set out on the Data Retention page, which forms part of this DPA.

On termination of the Services, we retain your data for 30 days to allow export, after which it is permanently deleted from live systems (Terms of Service, Section 9). You may request earlier deletion by emailing privacy@canlah.ai. Deletion from Cloudflare's point-in-time recovery follows Cloudflare's own window (see Data Retention).

8. Export

Today you can download your brand documents and delivered reports from the console, and receive intent ledgers, schedules and quotations as spreadsheets delivered by CANLAH AI. A complete export of all data held for your account (chat history, brand profile, plans, staff configuration) is available on request to privacy@canlah.ai; we aim to deliver it within 30 days. A self-service full export from the console is planned [To be confirmed].

9. Security measures

Measures currently in place, as implemented in the platform code and deployment:

  • Transport encryption (TLS) for all traffic to canlah.ai, the console, the AI staff gateway and every sub-processor API.
  • Encryption at rest provided by Cloudflare (D1, R2) and Google Cloud (persistent disks, Cloud Storage). Third-party tokens held in our databases (staff app tokens, GA4 refresh tokens) are additionally encrypted at the application layer with AES-GCM before being written.
  • Tenant isolation: each AI staff member runs in its own container with its own persistent volume, secrets and per-bot API keys; those keys are revoked when the staff member is deleted.
  • Access control: the console databases have no public endpoint; every request is checked against your account's ownership of the bot or brand before any data is read or written.
  • Authentication: Google Sign-In or email + password, passkeys (WebAuthn), device/session list with remote sign-out, sessions expire after 30 days of inactivity.
  • Publishing safeguards: AI staff can only publish to accounts you have connected, and only after your approval when approval mode is on; published URLs are verified before they are recorded.
  • Abuse controls: per-IP rate limits on public forms and audit endpoints; security headers (HSTS, nosniff, frame denial) on every response.
  • Secrets management: service credentials are stored as Cloudflare Worker secrets and Kubernetes Secrets, never in source control.
  • Regular independent penetration testing and SOC 2 attestation: [To be confirmed].

10. Audit and assistance

On written request, not more than once per year unless required by a supervisory authority or following a security incident, we will provide the information reasonably needed to demonstrate compliance with this DPA, including a current list of sub-processors and a summary of security measures. Where that is insufficient, we will allow an audit by you or an independent auditor bound by confidentiality, at reasonable notice and at your cost.

11. Security incident notification

If we become aware of a breach affecting your data, we will notify your account email without undue delay after confirming it, and in any case within 48 hours [To be confirmed], with what we know at that time: the nature of the incident, the data and individuals likely affected, measures taken, and a contact point. We will update you as the investigation progresses.

Where Singapore's PDPA applies and the breach is likely to result in significant harm or affects 500 or more individuals, we notify the PDPC within 3 calendar days of assessing it as notifiable. Where GDPR applies, we support you in meeting the 72-hour notification deadline. Report a suspected incident to privacy@canlah.ai.

12. Term and governing law

This DPA applies for as long as we process data on your behalf and survives termination until all your data has been deleted or returned. It is governed by the laws of Singapore, and disputes are subject to the exclusive jurisdiction of the courts of Singapore, consistent with the Terms of Service.

13. Contact

Data requests and incident reports: privacy@canlah.ai. General enquiries: admin@canlah.ai. Our designated Data Protection Officer is Haoyang Pang.