Version: 2026-07-30 · v1.0
Data Processing Addendum and Subprocessor Annex
Scope: This DPA automatically applies when we process Customer Personal Data on Customer’s behalf in providing HarnessRouter.
This Data Processing Addendum (the “DPA”) supplements the HarnessRouter Terms of Service (the “Terms”) between Customer and the provider of HarnessRouter, Lumentree Corporation, a California corporation ("we," "us," or "our"). Capitalized terms not defined in this DPA have the meanings given in the Terms.
Who this covers. This DPA governs where we process Customer Personal Data on a Customer's behalf as a processor or service provider, including for organizations and for individuals using the Services for commercial or professional purposes. It is incorporated by reference when applicable (Terms of Service Section 2.6) — no separate signature is required — and does not apply to purely personal or household consumer use, or to our own controller processing described in the Privacy Policy.
Contents
1. Incorporation, Scope, and Priority · 2. Definitions · 3. Roles and Customer Lawfulness · 4. Processing Instructions · 5. Personnel · 6. Security · 7. Personal Data Breach · 8. Subprocessors · 9. Data Subject Requests · 10. DPIAs and Regulatory Assistance · 11. Audits · 12. Return and Deletion · 13. Government Requests · 14. Restricted Transfers · 15. U.S. State Restrictions · 16. Liability · 17. Term · Annex 1 · Annex 2 · Annex 3 · Annex 4 · Annex 5
1. Incorporation, Scope, and Priority
1.1 If we process Customer Personal Data on Customer’s behalf, the version of this DPA identified in the applicable Agreement manifest is automatically incorporated into the Agreement without a separate signature, unless the parties execute a different data processing addendum.
1.2 This DPA applies only to our Processing of Customer Personal Data as a Processor or Service Provider on Customer’s behalf. It does not apply when we Process Personal Data for our own purposes as a Controller or Business, including as described in the Privacy Policy.
1.3 If this DPA conflicts with the Terms on a matter concerning the Processing of Customer Personal Data, this DPA controls that matter. The Terms control all other matters, including general governing law, dispute resolution, disclaimers, remedies, and liability, subject to Section 16.
1.4 The mandatory terms of an applicable EU Standard Contractual Clause, UK transfer mechanism, or other legally required transfer instrument control only for the transfer and rights they cover, and only to the extent they conflict with the Agreement. They do not replace the Agreement’s general governing law or dispute process for unrelated matters.
2. Definitions
2.1 “Applicable Data Protection Law” means the data protection and privacy laws that apply to a party’s Processing under this DPA, in each case only to the extent they apply to that party’s role for a given Processing activity. Depending on the Customer and the Processing, these may include the California Consumer Privacy Act as amended (including by the California Privacy Rights Act) and other applicable U.S. state privacy laws, the EU General Data Protection Regulation (Regulation (EU) 2016/679), the UK General Data Protection Regulation and Data Protection Act 2018, and the Swiss Federal Act on Data Protection.
2.2 “Customer Personal Data” means Personal Data that we Process as a Processor or Service Provider on Customer’s behalf under the Agreement, as further described in Annex 1.
2.3 “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process” or “Processing,” “Processor,” “Controller,” “Business,” “Service Provider,” “Contractor,” “Sale,” “Share,” and “Supervisory Authority” have the meanings given by Applicable Data Protection Law. If a term is not defined by the applicable law, it has its commonly understood privacy-law meaning.
2.4 “Subprocessor” means a third party engaged by us to Process Customer Personal Data on Customer’s behalf.
2.5 “Restricted Transfer” means a transfer of Customer Personal Data that requires a recognized transfer mechanism under Applicable Data Protection Law.
3. Roles and Customer Lawfulness
3.1 The parties’ roles for each Processing activity are determined by Applicable Data Protection Law and the actual data flow. Where Customer is a Controller and we Process Customer Personal Data on Customer’s behalf, Customer is the Controller and we are the Processor. Where Customer is a Processor for another Controller, Customer appoints us as its subprocessor and represents that it has authority to do so. For applicable U.S. state law, the parties intend that we act as Customer’s Service Provider or Contractor for Customer Personal Data.
3.2 Customer is responsible for:
(a) the lawfulness, fairness, and transparency of its collection and Processing;
(b) providing required notices and obtaining required consents or other lawful bases;
(c) having all rights and authority needed to give us the instructions in this DPA;
(d) configuring the Services consistently with its legal obligations;
(e) responding to Data Subjects except to the extent this DPA assigns assistance to us; and
(f) ensuring that its instructions do not violate Applicable Data Protection Law.
3.3 Customer will not submit Customer Personal Data that the Agreement prohibits or that the Services are not approved to Process. Customer’s obligations do not reduce our own duties under Applicable Data Protection Law.
4. Processing Instructions and Purpose Limitation
4.1 We will Process Customer Personal Data only:
(a) on Customer’s documented instructions;
(b) as necessary to provide, secure, support, and maintain the Services described in the Agreement and Annex 1;
(c) to perform actions initiated or configured by Customer or its Authorized Users; or
(d) as required by applicable law.
4.2 Customer’s documented instructions include the Agreement, applicable Order Forms, Customer’s use and configuration of the Services, requests submitted through documented support channels, and other written instructions that are consistent with the Agreement. Product use is an instruction only within the documented functionality and permitted scope of the Services. It does not instruct us to perform an unsupported, prohibited, or unlawful act.
4.3 If we are required by law to Process Customer Personal Data other than on Customer’s instructions, we will notify Customer before Processing unless the law prohibits notice.
4.4 We will promptly inform Customer if, in our reasonable opinion, an instruction violates Applicable Data Protection Law. We may suspend the affected Processing while the parties clarify or modify the instruction. We are not required to provide legal advice or independently determine whether Customer’s business or Customer Application complies with law.
4.5 De-identified and aggregated data. As permitted by Applicable Data Protection Law, we may de-identify or aggregate Customer Personal Data and create aggregated and de-identified data, including for the purposes described in Section 7.6 of the Terms. Applicable U.S. state privacy law permits a service provider or contractor to retain, use, and disclose data in de-identified or aggregated form. We maintain such de-identification, do not attempt to reverse it (except as required by law or as necessary to test whether our de-identification measures satisfy applicable law), and do not treat the resulting aggregated or de-identified data as Customer Personal Data, consistent with Section 15. The resulting aggregated and de-identified data is limited as described in Section 7.6 of the Terms — usage, operational, and metadata measurements, not the substance of Customer Content — and is not used to train our AI models except under Section 7.3 of the Terms. This Section does not authorize Processing of identifiable Customer Personal Data for a purpose outside Section 4.1.
5. Personnel Confidentiality and Access
5.1 We will ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
5.2 We will limit access to Customer Personal Data to personnel who need access for the purposes permitted by this DPA and will apply the access controls included in Annex 2.
5.3 We remain responsible for our personnel’s compliance with the obligations applicable to them under this DPA.
6. Security
6.1 Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of Processing, as well as risks to individuals, we will implement and maintain the technical and organizational measures described in Annex 2.
6.2 We may update the measures in Annex 2 to reflect changes in technology, threats, or the Services, provided that an update does not materially reduce the overall protection of Customer Personal Data during the applicable service term.
6.3 Customer is responsible for securely configuring the Services, managing its Authorized Users and credentials, applying least privilege, maintaining appropriate copies of its data, and using available security controls. This allocation does not relieve us of our obligations under this DPA.
7. Personal Data Breach
7.1 We will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 To the extent then known and legally permitted, the notice will describe:
(a) the nature of the Personal Data Breach;
(b) affected data and Data Subject categories and approximate volumes;
(c) likely consequences;
(d) measures taken or proposed to contain, investigate, and remediate the incident; and
(e) a contact for follow-up.
We may provide information in phases as it becomes available.
7.3 We will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach and will reasonably cooperate with Customer’s legally required notifications. Our notice or cooperation is not an admission of fault or liability.
7.4 Customer is responsible for notifying Data Subjects, regulators, or others unless Applicable Data Protection Law directly requires us to do so. The parties will reasonably coordinate public statements about a Personal Data Breach where legally and operationally feasible.
8. Subprocessors
8.1 Customer gives general written authorization for us to engage Subprocessors, including our infrastructure providers, the routing backend (through which requests are routed), and the model or inference providers used to Process Customer Personal Data on managed routes. Our current Subprocessors are identified on the Subprocessor List page referenced in Annex 3, which states legal entity (or, for a Subprocessor whose identity is confidential commercial information, its category, as Section 8.2 provides), service, location, processing role, and, where applicable, the route category or data mode. We give advance notice of a new Subprocessor and an opportunity to object as provided in this Section, and bind each Subprocessor as provided in Section 8.5. If we later make a customer-directed Provider account configuration available, that provider will be governed by the provider's own terms and will not be our Subprocessor for that customer-directed use unless the applicable documentation or agreement expressly says otherwise.
8.2 We will maintain the current Subprocessor List page identified in Annex 3. The list will state each Subprocessor’s legal entity name — or, for a Subprocessor whose identity is confidential commercial information, its category, location, and Processing function, with the legal entity name available to Customers on request through the notice channel identified on that page — together with its location, service, relevant Processing function, and effective or change date. For model and inference providers used on managed routes, the list or an in-product route-specific disclosure will identify the applicable route category, data mode, and transfer mechanism before the route is enabled.
8.3 We will provide notice of a new Subprocessor by updating the Subprocessor List page identified in Annex 3 and, for Customers who subscribe to Subprocessor-change notifications through the mechanism described on that page, by email or another notice channel described there, at least thirty (30) days before the new Subprocessor begins Processing Customer Personal Data, unless an urgent security, legal, or service-continuity need makes advance notice impracticable. In that case, we will provide notice as soon as reasonably practicable. The same thirty (30) day notice period and the objection right in Section 8.4 apply to a Subprocessor change published on the Subprocessor List page. For a change of routing backend on managed routes, where the new backend is bound as Section 8.5 requires, we may provide the notice in this Section by promptly updating the Subprocessor List page (in place of the thirty (30) days' advance notice), and Customer may restrict or exclude affected routes using the controls the Services make available; Section 8.4's objection right and Section 8.5's protections are unaffected.
8.4 Customer may object during the notice period on reasonable data-protection grounds specific to the new Subprocessor. The parties will work in good faith to address the objection through a commercially reasonable change, configuration, or alternative, if one is available. If no reasonable resolution is available, either party may terminate the affected Service as permitted by the Agreement. An objection does not require us to provide a service path it does not offer or to violate an upstream obligation.
8.5 Before a Subprocessor Processes Customer Personal Data, we will enter into a written agreement imposing data-protection obligations that provide materially equivalent protection for the relevant Processing as this DPA requires. We remain responsible to Customer for the Subprocessor’s performance of those obligations to the extent required by Applicable Data Protection Law and the Agreement.
9. Data Subject Requests
9.1 Taking into account the nature of the Processing, we will provide reasonable technical and organizational assistance for Customer to respond to requests by Data Subjects to exercise rights under Applicable Data Protection Law.
9.2 If we receive a request relating to Customer Personal Data directly from a Data Subject, we will, where legally permitted, direct the requester to Customer and notify Customer. We will not independently respond on Customer’s behalf unless Customer instructs it to do so or applicable law requires it.
9.3 Customer is responsible for verifying the requester’s identity and authority and for determining whether and how to fulfill the request. We may require information reasonably necessary to locate the relevant Customer Personal Data and protect account security.
10. DPIAs, Prior Consultation, and Regulatory Assistance
10.1 Taking into account the nature of the Processing and information available to us, we will provide reasonable assistance with a legally required data protection impact assessment, prior consultation, or regulator inquiry that relates specifically to our Processing of Customer Personal Data.
10.2 Customer will first use Documentation, self-service tools, security materials, and information we generally make available. Additional assistance is subject to reasonable scope, scheduling, confidentiality, and reimbursement of reasonable costs unless the assistance is required because we breached this DPA.
10.3 We may communicate directly with a Supervisory Authority when required by law and will keep Customer reasonably informed where legally permitted.
11. Demonstrating Compliance and Audits
11.1 We will make available information reasonably necessary to demonstrate compliance with this DPA, starting with then-current independent audit reports, certifications, security summaries, penetration-test summaries, or completed questionnaires that we actually maintain and are legally permitted to disclose.
11.2 If those materials are reasonably insufficient for Customer to meet a specific obligation under Applicable Data Protection Law, Customer may request a remote audit. An on-site audit is available only when required by Applicable Data Protection Law or a competent regulator, or when a material Personal Data Breach or credible evidence of material noncompliance makes a remote review insufficient.
11.3 Audits must:
(a) be conducted by Customer or an independent auditor that is not our competitor;
(b) be subject to appropriate confidentiality and security requirements;
(c) avoid access to other customers’ data, privileged material, source code, vulnerability details that would create material risk, and information we are prohibited from disclosing;
(d) occur during normal business hours on reasonable advance notice;
(e) not unreasonably interfere with our operations; and
(f) occur no more than once in any twelve-month period unless Applicable Data Protection Law, a competent regulator, a material Personal Data Breach, or credible evidence of material noncompliance requires more.
11.4 Customer will bear its audit costs and reimburse our reasonable costs for an audit beyond generally available compliance materials, unless the audit establishes our material breach of this DPA. The parties will promptly discuss reasonable remediation of a verified finding.
12. Return, Deletion, and Backups
12.1 During the service term, Customer may retrieve or delete Customer Personal Data using the features we make available, subject to the Agreement.
12.2 At the end of the applicable Service, and at Customer’s choice where Applicable Data Protection Law requires, we will return or delete Customer Personal Data unless applicable law requires retention. This Section 12 and its retention Annex (Annex 5) are the single source of retention and deletion timing across the Agreement, the Privacy Policy, and this DPA, so that these documents do not state conflicting periods; the return, deletion, and retention periods by data class are set out in the retention schedule in Annex 5. For account Customer Content that is Customer Personal Data held in active systems we control, that schedule provides for deletion within approximately thirty (30) days after account closure or the end of the applicable Service, subject to Section 12.4 and the backup cycle in Section 12.3. During the applicable Service term and the applicable export window described in the Documentation, Customer may export or retrieve Customer Personal Data using the features we make available.
12.3 Customer Personal Data may remain in protected backups until deletion through the ordinary backup cycle identified in the retention schedule in Section 12 and Annex 5. During that period, we will isolate the data from ordinary use, continue to protect it under this DPA, and Process it only for security, disaster recovery, or legal retention.
12.4 We may retain limited Customer Personal Data where required by law or reasonably necessary for fraud prevention, security, financial records, legal claims, or enforcement of the Agreement. Any retained Customer Personal Data remains protected under this DPA and will not be Processed for an incompatible purpose.
13. Government and Legal Requests
13.1 Unless legally prohibited, we will notify Customer before disclosing Customer Personal Data in response to a binding government, court, or law-enforcement request and will provide available information reasonably necessary for Customer to seek protection.
13.2 Where legally permitted and reasonably appropriate, we will review the request for validity, seek clarification or narrowing of an overbroad request, object to an unlawful request, and disclose only the Customer Personal Data legally required.
13.3 If notice is prohibited, we will use reasonable efforts to obtain permission to notify Customer when doing so would not violate law or create material risk.
14. Restricted Transfers
14.1 The parties will not make a Restricted Transfer unless a valid transfer mechanism applies. Where a Restricted Transfer is required, we use an appropriate transfer mechanism (such as the Standard Contractual Clauses), executed where required before we rely on it for that transfer, as set out in Annex 4. The applicable mechanism may include the European Commission's Standard Contractual Clauses (EU SCCs) for transfers subject to the EU/EEA GDPR and the UK International Data Transfer Addendum to the EU SCCs (the "UK Addendum") for transfers subject to the UK GDPR.
14.2 If the European Commission’s Standard Contractual Clauses are required, the official clauses will be incorporated as specified in Annex 4. If a UK transfer mechanism is required, the official UK Addendum as completed in Annex 4 will apply. The parties will complete only selections and variables the official instrument permits and will not rewrite mandatory text.
14.3 We will provide information reasonably available to us for Customer’s assessment of a Restricted Transfer and will implement supplementary measures identified in Annex 2 where required and actually supported.
14.4 If a competent authority or change in law invalidates a transfer mechanism, the parties will reasonably cooperate to implement a valid replacement. We may suspend the affected Processing if no lawful transfer path is available.
15. U.S. State Service Provider and Contractor Restrictions
15.1 To the extent an applicable U.S. state privacy law applies to Customer Personal Data, we will Process that data only for the limited and specified business purposes described in the Agreement, Customer’s documented instructions, and Annex 1.
15.2 We will not:
(a) Sell or Share Customer Personal Data;
(b) retain, use, or disclose Customer Personal Data outside the direct business relationship between Customer and us or for a commercial purpose other than the limited and specified purposes in the Agreement;
(c) combine Customer Personal Data with Personal Data received from another person or collected from our own interaction with an individual, except as permitted by Applicable Data Protection Law to provide the Services or for security and fraud prevention; or
(d) retain, use, or disclose Customer Personal Data other than as permitted by the applicable service-provider or contractor provisions.
15.3 We will provide the same level of privacy protection required of Customer for the relevant Customer Personal Data, notify Customer if we determine it can no longer meet an applicable obligation, and allow Customer to take reasonable and appropriate steps to stop and remediate unauthorized use, subject to Section 11.
15.4 The parties acknowledge that Customer makes Customer Personal Data available to us only for the limited and specified purposes in the Agreement and not in exchange for monetary or other valuable consideration.
16. LIABILITY; SINGLE AGREEMENT CAP
16.1 This DPA does not create a separate liability cap, a per-document cap, or an additional recovery pool. The single aggregate limitation of liability in the Terms applies to this DPA and all claims arising from the same or related facts across the Agreement.
16.2 For clarity, the single aggregate cap uses the amounts-paid cap base defined in the Terms of Service, Section 21.2; this DPA does not create a separate or different cap, does not restate or vary the scope of that cap base, and any change to the cap amount is made in the Terms. Any signed Order Form that expressly and validly changes that cap controls only to the extent it says so.
16.3 Nothing in this DPA limits a Data Subject’s rights or either party’s liability to the extent that limitation is prohibited by Applicable Data Protection Law or an applicable mandatory transfer instrument. This sentence does not voluntarily create a separate cap, super-cap, or unlimited contractual liability where law permits limitation.
17. Term, Termination, and General Relationship
17.1 This DPA begins when Section 1.1 applies and continues for as long as we Process Customer Personal Data on Customer’s behalf.
17.2 Termination or expiration of the Agreement terminates this DPA except for provisions that by their nature must continue while we retain Customer Personal Data, including confidentiality, security, deletion, government-request, transfer, audit, and liability provisions.
17.3 The Terms govern notices, assignment, changes, disputes, governing law, and other general matters. A transfer of the Agreement or change in the legal entity acting as Processor does not replace any notice, Subprocessor, transfer, or other obligation required by Applicable Data Protection Law. Where a successor assumes this DPA, the protections and Customer instructions applicable to retained Customer Personal Data continue.
17.4 The Annexes form part of this DPA. A dynamic fact page such as the Subprocessor List does not independently amend the parties’ legal obligations. Changes to this DPA follow the Agreement’s update process and applicable data protection notice or objection requirements.
# Annex 1: Details of Processing
The following describes the Processing of Customer Personal Data for the HarnessRouter Services as currently offered at a category level. Categories are described generally and are not an exhaustive, field-level inventory.
On a managed route, our transmission of Customer Personal Data to a model or inference provider to deliver the Services is Processing on Customer's behalf, and those providers are Subprocessors (or onward Subprocessors) covered by Section 8 and Annex 3. If we later make a customer-directed Provider account configuration available, that provider will act as an independent third party or the Customer's own processor under its own terms for that customer-directed use, outside our Processor role, unless the applicable documentation or agreement expressly says otherwise.
| Required detail | Description (HarnessRouter Services as currently offered) |
|---|---|
| Subject matter and purpose | Our provision of the HarnessRouter Services to Customer under the Agreement. The purpose of Processing is to provide, secure, support, and maintain the Services, including generating outputs and in-page authenticated previews from Customer prompts and inputs, routing requests to the applicable model provider, storing session and run state and generated artifacts, and providing related support, security, and administrative functions. |
| Nature of Processing and product operations | Collection, transmission, storage, retrieval, routing to model providers, generation of outputs and previews, logging (excluding API keys and secrets), support, security, and deletion, as described in the Documentation. |
| Duration of Processing | For the duration of the applicable Service term and thereafter only as described in the retention periods described in Section 12 and this Annex. |
| Frequency of transfer or Processing | Continuous and ongoing for the duration of the Agreement, as determined by Customer’s and its Authorized Users’ use of the Services. |
| Categories of Data Subjects | Customer’s Authorized Users and other individuals whose Personal Data Customer or its Authorized Users choose to include in Customer Content submitted to or generated through the Services. |
| Categories of Personal Data | Described at a category level: account or workspace identifiers needed to authorize the requested Processing; Customer Content submitted to the Services (such as prompts, files, code, and configurations) and the Output and Artifacts generated through the Services for Customer, each of which may contain Personal Data that Customer chooses to include; and service technical records needed to execute, secure, troubleshoot, and evidence the requested Processing, such as run metadata, provider, model, region, data-mode, policy-version indicators, input references, artifact manifests, and a minimized region-decision result rather than a raw IP address. Logs are configured to exclude API keys, secrets, and unnecessary personal data. |
| Sensitive or special-category data and safeguards | The Services are not intended for, and Customer must not submit, special-category or sensitive Personal Data except under the conditions set out in Terms Section 11. Prohibited and restricted data categories are set out in Terms Section 11.2. Secrets must not be placed in prompts, files, or traces, as set out in Terms Section 11.3. Customer is responsible for excluding such data from its inputs. |
| Processing locations and data regions | Processing occurs primarily in the United States, where our cloud infrastructure and the Subprocessors identified in Annex 3 are located. To the extent our personnel access Customer Personal Data from another location, such access remains subject to this DPA. |
| Retention and deletion by data class | As described in Section 12 and the retention schedule in Annex 5. |
| Controller instructions where Customer is a Processor | Where Customer acts as a Processor for a third-party Controller, the relevant Controller instructions are those in Customer’s agreement with that Controller or an applicable Order Form. Customer is responsible for ensuring those instructions are consistent with this DPA. |
# Annex 2: Technical and Organizational Measures
We maintain the technical and organizational measures described below for the HarnessRouter Services as currently offered. These measures are described at a general level, are subject to the update right in Section 6.2, and do not represent any specific certification, audit result, cryptographic algorithm, or guaranteed recovery objective. Measures that are not implemented for the Services as currently offered are not included in this Annex.
- Identity and access management. Access to Customer Personal Data is limited to authorized personnel and system components that need it for the purposes permitted by this DPA, using role-based access controls and authentication. Provider and model API keys are held server-side only and are not exposed to end users.
- Tenant isolation and authorization. The Services enforce per-user and per-tenant isolation with fail-closed authorization, so that a request that is not affirmatively authorized is denied.
- Secrets management. Secrets and credentials used by the Services are kept out of application code and are not exposed to users. Customer-supplied secrets may be provided only through a documented secrets channel if one is expressly made available for that purpose.
- Encryption. Customer Personal Data is encrypted in transit over public networks and at rest in our cloud storage.
- Logging and monitoring. We maintain logging and monitoring to support security and operations. Logs are configured to exclude API keys, secrets, and unnecessary personal data.
- Personnel confidentiality. Personnel authorized to access Customer Personal Data are bound by confidentiality obligations, as described in Section 5.
- Subprocessor management. We engage Subprocessors under written agreements imposing data-protection obligations as described in Section 8, and maintain the Subprocessor List page identified in Annex 3.
- Data minimization, retention, and deletion. We collect and retain Customer Personal Data for the purposes described in this DPA and apply the retention and deletion practices described in Section 12 and Annex 5.
Scope and exceptions. These measures apply to the production HarnessRouter Services. Certain measures are provided by or inherited from our cloud infrastructure provider.
# Annex 3: Authorized Subprocessor List
Current Subprocessor List page: https://harnessrouter.ai/legal/subprocessors
The Authorized Subprocessor List comprises (a) the infrastructure Subprocessors and routing backend on the Subprocessor List page, and (b) the model and inference providers used on managed routes, as identified in the Services or in a route-specific disclosure, which the parties treat as the versioned onward-subprocessor list for those routes. The list is maintained dynamically; changes follow the notice-and-objection mechanics in Section 8, and each Subprocessor is bound as provided in Section 8.5. If we later make a customer-directed Provider account configuration available, providers used through that configuration are excluded for that customer-directed use and are governed by their own terms unless the applicable documentation or agreement expressly says otherwise.
The Subprocessor List page forms part of this Annex by reference. Whether a given vendor acts in a particular instance as our Subprocessor or as an independent controller is determined by the actual data flow and Applicable Data Protection Law; for example, a payment provider may act as an independent controller for certain payment data. A provider that is not used in production to Process Customer Personal Data on our behalf is not a current Subprocessor and is not listed.
As of the effective date of this DPA, our authorized infrastructure Subprocessors and routing backend fall into the following categories:
| Subprocessor category | Purpose | Location |
|---|---|---|
| Cloud hosting, compute, and storage provider (including AI model processing) | Host and operate the Services; store service data; process model requests | United States |
| Routing backend / inference gateway | Routing and forwarding of requests (prompts, parameters) to model or inference Providers on managed routes, on our behalf | United States |
| Payment processor | Subscription payment processing | United States |
| Website hosting and analytics provider | Host the marketing website and measure website usage | United States |
| Website datastore provider | Store marketing-site records (such as the waitlist) | United States |
The specific legal entity for each category is identified on the Subprocessor List page referenced above (or, for a Subprocessor whose identity is confidential commercial information, is available to Customers on request as Section 8.2 provides). Model and inference providers used on managed routes are identified on the Subprocessor List page or in the applicable route-specific disclosure before the route is enabled.
# Annex 4: International Transfer Terms
Our Subprocessors for the Services as currently offered are located in the United States. Where a Restricted Transfer requires them, the parties use the transfer mechanisms below; each is completed and executed where required before it is relied on for that transfer, and once executed forms part of this Annex for that transfer, consistent with Section 14.
A. EEA transfers — EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914):
- Modules. Module Two (Controller-to-Processor) applies where Customer is a controller; Module Three (Processor-to-Processor) applies where Customer acts as a processor for a third-party controller.
- Clause 7 (Docking clause). Does not apply.
- Clause 9 (Use of subprocessors). Option 2 (general written authorization); the advance-notice period is thirty (30) days as stated in Section 8.3. For Restricted Transfers governed by the Clauses, the thirty (30) day advance-notice period applies to every Subprocessor change, including a change of routing backend, notwithstanding the prompt-update alternative in Section 8.3.
- Clause 11 (Redress). The optional independent dispute-resolution body is not selected.
- Clause 17 (Governing law). The Clauses are governed by the law of Ireland.
- Clause 18 (Choice of forum and jurisdiction). Disputes arising from the Clauses are resolved before the courts of Ireland.
- Competent supervisory authority (Annex I.C). Where the data exporter is established in an EEA member state, the supervisory authority of that member state, per Clause 13; otherwise (where the exporter falls within Article 3(2) GDPR without an appointed representative), the Irish Data Protection Commission.
B. UK transfers. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs (the "UK Addendum") applies, with the Information Commissioner’s Office (ICO) as competent authority and the law and courts of England and Wales. The UK Addendum’s Tables are completed as follows: Table 1 (Parties) — the parties and their details as set out in SCC Annex I and Annex 1; Table 2 (Selected SCCs, Modules and Selected Clauses) — the Module Two / Module Three EU SCCs as selected and completed in Part A; Table 3 (Appendix Information) — Annexes 1–3 of this DPA (serving as SCC Annexes I–III); Table 4 (Ending the Addendum when the Approved Addendum changes) — the Importer may end the Addendum as set out in Section 19 of the Addendum.
C. Swiss transfers. For transfers subject to the Swiss FADP, the EU SCCs apply as adapted for Switzerland: references to the GDPR are read as references to the FADP; the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent authority; the Clauses are governed by Swiss law insofar as the transfer is governed exclusively by the FADP (Clause 17); and disputes relating to Swiss data protection law are resolved by the courts of Switzerland, and a data subject habitually resident in Switzerland may bring proceedings before the Swiss courts of their habitual residence (Clause 18) — Clause 18’s EU-Member-State forum requirement does not preclude this.
D. SCC Annexes. SCC Annex I (parties, description of processing, competent authority) is populated by Section 3, Annex 1, and this Annex; SCC Annex II (technical and organizational measures) is Annex 2; SCC Annex III (subprocessors) is Annex 3 and the Subprocessor List page. The specific data categories, data-subject types, and retention are those stated in Annex 1.
E. Priority. Where the SCCs, the UK Addendum, or the Swiss adaptation conflict with this DPA or the Agreement, the mandatory terms of those instruments prevail solely for, and to the extent of, the transfer and rights they cover, consistent with Section 1.4.
# Annex 5: Retention Schedule
This Annex, together with Section 12, is the single source of retention and deletion timing for Customer Personal Data across the Agreement, the Privacy Policy, and this DPA, so that those documents do not state conflicting periods. The periods below apply to Customer Personal Data that we hold as Processor and are subject to any longer retention permitted under Section 12.4 or required by applicable law.
| Data class | Retention and deletion period |
|---|---|
| Account Customer Content in active systems we control — account content, uploaded files, and generated Artifacts and outputs that constitute Customer Personal Data | Deleted within approximately thirty (30) days after account closure or the end of the applicable Service, unless a longer period is required by applicable law or the data is retained under Section 12.4. |
| Protected backups | Customer Personal Data isolated in protected backups is purged through the ordinary backup cycle after deletion from active systems, as described in Section 12.3, and is protected and isolated from ordinary use in the interim. Customer Personal Data in protected backups is purged no later than ninety (90) days after its deletion from active systems, unless a longer period is required by applicable law or the data is retained under Section 12.4. |
| Limited data retained under Section 12.4 (fraud prevention, security, financial records, legal claims, or Agreement enforcement) | Retained only for as long as reasonably necessary for, or as required by law for, the stated purpose, then deleted; remains protected under this DPA and is not Processed for an incompatible purpose. |
