FLEETRUN LEGAL
Data Processing Addendum
When you use FleetRun to process personal data about other people, you are the controller and we are your processor. This page outlines the terms that govern that relationship for Enterprise customers.
Last updated 25 July 2026 · Operated by Leonenko Group LLC — full registered entity name, jurisdiction of incorporation and registered address to be confirmed
This page is an outline, not an executed agreement
Nothing on this page creates a data processing agreement between you and Leonenko Group LLC. It describes what our DPA is intended to cover. The signable document — including the Standard Contractual Clauses, the processing Annex, and the subprocessor list as of the signature date — is issued on request as part of an Enterprise agreement. Until it is signed by both parties, no DPA is in force.
1. Roles of the parties
Where you use FleetRun to process personal data about your own customers, employees, or contacts — for example in a mission brief, a knowledge source, or a connected mailbox — you act as the controller and Leonenko Group LLC acts as your processor.
Where we process data about you as our own customer, such as your account details and billing records, we act as controller. That processing is described in our Privacy Policy.
2. Subject matter of the processing
- Subject matter: provision of the FleetRun AI workforce platform.
- Duration: the term of your subscription, plus any agreed retention period.
- Nature and purpose: hosting, storing, transmitting, and processing customer data so agents can run missions, and transmitting mission content to AI model providers to generate output.
- Types of personal data: determined by you. Typically account identifiers, names, email addresses, and whatever personal data appears in mission briefs, agent instructions, and connected account content.
- Categories of data subject: determined by you. Typically your Fleet members, and the people referenced in the content your agents process.
3. Our commitments as processor
The executed DPA is intended to commit us to:
- Process personal data only on your documented instructions, including for international transfers, unless required otherwise by law — in which case we will tell you before processing, where the law permits.
- Ensure that personnel authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational security measures.
- Engage subprocessors only under written terms no less protective than these, and give you notice of intended changes with an opportunity to object.
- Assist you, taking into account the nature of processing, in responding to data subject rights requests.
- Assist you with data protection impact assessments and with prior consultation of a supervisory authority where required.
- Notify you without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the service, subject to legal retention obligations.
- Make available the information reasonably necessary to demonstrate compliance, and allow for audits on reasonable notice and terms.
4. Subprocessors
We use subprocessors to deliver the Service, including infrastructure, payment processing, and AI model providers. The current list is published in our Privacy Policy, and the executed DPA fixes the list as of its signature date and sets the notice period for changes.
5. International transfers
Our subprocessors operate in the United States and elsewhere. For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, the executed DPA is intended to incorporate the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable.
Reviewer note:the SCC module selection, the completed Annexes I–III, and a transfer impact assessment all need to be prepared by counsel. They do not exist yet.
6. Technical and organisational measures
The following measures are implemented in the platform today and would form the basis of the DPA’s security annex:
- Encryption in transit for all connections to the Service.
- AES-256-GCM authenticated encryption of connector credentials at rest, under one application key held outside the database.
- Row-level access control scoped to Fleet membership, enforced at the database rather than in application code alone.
- Server-side authorisation re-verified on every privileged action, including a fresh role check at the moment an action is taken.
- Least-privilege OAuth scopes, with granted scopes recorded and revocation performed at the provider on disconnect.
- Append-only audit logging of internal administrative actions, with staff access gated on a database record rather than configuration.
- Signature-verified, replay-resistant payment webhooks.
FleetRun does not hold SOC 2, ISO 27001, HIPAA, or PCI DSS certification, and the DPA will not represent that it does. Independent penetration testing, vendor risk review, and a formal incident response programme are planned and not yet complete. We will not sign a DPA that asserts a control we have not implemented.
7. What we cannot currently support
To be direct about the limits, so no one plans around a capability that does not exist:
- We do not offer a Business Associate Agreement and FleetRun must not be used to process protected health information under HIPAA.
- We are not a PCI DSS service provider. Do not put cardholder data into agent briefs or Fleet content.
- We do not currently offer data residency guarantees or a choice of processing region.
- We do not currently offer contractual restriction of model routing to a named provider. If you need this, raise it during the Enterprise conversation so we can tell you honestly whether and when it is possible.
8. Requesting the DPA
Enterprise customers and prospects can request the current draft from legal@fleetrun.app. Please include your legal entity name, the jurisdictions you operate in, and any regulatory regime you need us to address.
Questions about this document
Write to privacy contact address — not yet provisioned or use the contact form. Reminder: this page is an unreviewed template and does not constitute legal advice.