Data Processing Addendum
How we handle personal data that passes through the platform on your behalf, and what we commit to as your processor.
Version 2026-09-23
1. Roles
For the personal data inside your prompts, responses and attribution tags, you are the controller and we are the processor: we act on your instructions, and using the platform as documented is the instruction. For your own account and billing data we are the controller, and the Privacy Policy governs it.
This addendum forms part of the Terms of Service and prevails over them on data protection.
2. Subject matter and duration
Processing lasts for as long as your account is open, plus the retention windows below. Categories of data subject: your employees, contractors and end users, as determined by what you send. Categories of data: whatever appears in prompts, responses, attribution tags and masked client addresses.
We have no control over what you put in a prompt. If you send special-category data, you are responsible for having a lawful basis and for choosing settings — retention, masking, zero data retention, provider restrictions — that match it.
3. Our obligations
We process only on your documented instructions; we keep personnel who touch the data under confidentiality; we implement the measures described below; we assist you with data subject requests, impact assessments and consultations, as far as our role allows; and we delete or return the data at the end of the service.
We tell you if an instruction appears to breach applicable data protection law, and we will not act on it until it is resolved.
4. Subprocessors
We engage subprocessors in three categories: inference providers that serve routed requests, infrastructure vendors that host the platform, deliver email and prevent abuse, and a payment processor. Each is bound to terms no less protective than these, and we remain responsible for their performance.
We do not publish the list. The current list, with each subprocessor's role and processing location, is attached to a signed copy of this addendum and is available to any customer on request to [Privacy contact — to be stated before these terms take effect]. We give organisation owners thirty days' notice by email before adding or replacing a subprocessor, and you may object; if we cannot resolve the objection you may stop using the affected capability or close the account with a refund of unused paid credit.
Routing preferences let you restrict which routes may serve your traffic, and a zero-data-retention organisation is only routed to providers that have committed not to retain request content.
5. Security measures
Encryption in transit for all traffic and encryption at rest for credentials and upstream keys. Access to production data is role-based, requires a second factor and is recorded in an append-only audit log. Organisation, project and key boundaries are enforced on every request.
Content logging is off by default, opt-in per project, capped at thirty days, and masks configured sensitive values before storage; every read or export of stored content is recorded in the organisation's audit log. Backups are encrypted, and we test restoring them at least every quarter.
6. Personal data breach
We notify you without undue delay and in any case within seventy-two hours of becoming aware of a breach affecting your data, with what we know: what happened, which data and roughly how many records, the likely consequences and what we are doing about it. We follow up as the picture becomes clearer.
7. International transfers
Where data leaves its region of origin, the transfer relies on an adequacy decision or on standard contractual clauses with the recipient. A project can be pinned to a region, and requests that would leave it are refused rather than silently routed.
The processing location of each subprocessor is given in the subprocessor list described above. Where you send personal information collected in a place that restricts transfers abroad, you are responsible for the transfer mechanism that place requires before you send it.
8. Audits and deletion
We answer reasonable written questions about this addendum and share the evidence exports the console can produce. Where a law gives you an audit right, we accommodate it once a year, on notice, without disrupting other customers.
On termination we delete your data within the retention windows above, except what we must keep by law; we confirm deletion in writing on request.