Legal — dpa
Data Processing Addendum
Version 1.0 · Last updated September 6, 2026 · Owner: Cyphra
In brief
This Data Processing Addendum ("DPA") records how Cyphra LLC processes personal data on your behalf when operating your Agent Instance, in accordance with the EU GDPR, the UK GDPR, and comparable laws. It applies where you act as a controller of personal data and we act as your processor. It forms part of the Terms and Conditions ("Terms").
1. Parties and roles
1.1 Parties
This DPA is entered into between:
- Cyphra LLC, 31 Gloucester Road, Summit, NJ 07901, USA ("Processor", "we", "us"); and
- the legal entity or individual that purchases the Plan ("Controller", "you", "Customer"),
each a "Party" and together the "Parties".
1.2 Roles
Where we process personal data on your instructions, you are the controller and we are the processor. Where we determine the purposes and means of processing for our own account (for example, account and billing administration), we act as an independent controller and the Privacy Policy applies.
1.3 Scope of this DPA
We offer this DPA to Customers located in the European Economic Area ("EEA") and the United Kingdom, where the EU GDPR or UK GDPR applies to the processing described in Section 2. We also offer it to Customers elsewhere as a voluntary data-protection commitment: even where the GDPR does not apply to you, we will process personal data under the terms of this DPA as a matter of contract. Where local law imposes additional mandatory requirements — for example, the reasonable administrative, technical, and physical safeguards that US state data-security laws expect of businesses like ours — we comply with those requirements in addition to this DPA.
2. Details of processing
2.1 Subject matter
Processing of personal data contained in Customer Content and operational data to host and operate the Agent Instance, including the Web Interface and Control Panel used to access it.
2.2 Nature and purpose
Hosting, storage, transmission, inference support, backup, restoration, technical administration, and support of the Agent Instance and Customer Content. We do not train models on Customer Content. Where you use Cyphra-provided model access, prompts and outputs are processed by upstream model providers under their own terms; those providers are listed in the Subprocessor List where they act on our behalf.
2.3 Duration
For the term of the Terms, plus the retention periods in Section 7 after termination.
2.4 Categories of data subjects and data
Data subjects: your end users and authorized users, and individuals appearing in Customer Content. Categories: account identifiers, authentication data, usage and log data, and any personal data included in Customer Content (prompts, uploads, agent memory/configuration, and AI outputs).
3. Processor obligations
3.1 Documented instructions
We process personal data only on your documented instructions, including as set out in this DPA, the Terms, and your configuration choices in the Control Panel, unless required to process otherwise by applicable law (in which case we inform you before processing, where lawful to do so). Additional instructions may be given in writing and, once accepted, incorporated into this DPA. We promptly inform you if we believe an instruction infringes data protection law.
3.2 Confidentiality
We ensure that personnel authorized to process personal data are bound by confidentiality obligations, receive appropriate data protection training, and access personal data only on a need-to-know basis.
3.3 Security measures
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, and the risks to data subjects, we implement and maintain appropriate technical and organizational measures consistent with Article 32 of the EU GDPR and the equivalent provision of the UK GDPR, and reasonable administrative, technical, and physical safeguards consistent with applicable United States law, including at minimum:
- encryption of personal data in transit using TLS;
- encryption of Customer Content and account data at rest;
- access controls, including role-based access, least privilege, and multi-factor authentication for administrative access;
- for customer-supplied API keys ("BYOK"): encryption of keys at rest, no logging of key material, and key isolation so that keys remain your property;
- audit logging of administrative and security-relevant actions;
- vulnerability management, patching, and secure development practices;
- backup and restoration procedures.
You are responsible for the security of your credentials and your configuration choices within the Control Panel.
4. Subprocessors
4.1 Authorization
You agree that we may engage subprocessors to assist in providing the Services. Our current subprocessors are listed in the Subprocessor List (our "Subprocessor List" document), which is incorporated into this DPA.
4.2 Notice and objection
We will give you advance notice (through the Subprocessor List and, for material additions, by email) of any new subprocessor or material change in a subprocessor's role, at least 30 days before engagement. You may object on reasonable data protection grounds by writing to [email protected] within the notice period. If we cannot reasonably provide the Services without the objected-to subprocessor, either Party may terminate the affected Plan before the subprocessor takes effect, with repayment of unused prepaid fees in accordance with the Terms.
4.3 Flow-down
We impose on each subprocessor data protection obligations that are no less protective than those in this DPA, by written contract. We remain fully liable to you for the performance of our subprocessors' data protection obligations. Where personal data is transferred outside the EEA or the UK by a subprocessor, an appropriate transfer safeguard (such as the mechanism described in Section 8) applies.
5. Assistance with data subject rights and consultations
5.1 Data subject requests
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under EU GDPR and UK GDPR Articles 15–22 (for example, access, rectification, erasure, restriction, portability, and objection). You may make requests through [email protected] or [email protected]. We will respond within a reasonable time and may charge a reasonable fee for exceptional volumes of assistance, disclosed in advance.
5.2 Consultations
We assist you in ensuring compliance with your obligations relating to the security of processing, breach notification, data protection impact assessments, and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to us.
6. Personal data breach
We notify you of a personal data breach affecting personal data processed under this DPA without undue delay, and in any event no later than 72 hours after we become aware of the breach. The notification will describe, to the extent known and as information becomes available: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, likely consequences, and measures taken or proposed. We provide reasonable further information on request and coordinate on any regulatory notification you must make.
7. Return and deletion
7.1 End of services
On termination of the Terms, you may export Customer Content through the Web Interface where features allow. We delete Customer Content within 30 days after termination. Backups containing Customer Content are purged within 14 days of the last backup cycle.
7.2 Legal hold
Where applicable law requires us to retain some personal data, we retain only what is required, inform you where lawful to do so, and apply the protections of this DPA to the retained data.
8. International transfers
We may process personal data in the the United States region and, where subprocessors are used, in other countries. Where personal data subject to the EU GDPR or UK GDPR is transferred to a country not recognized as providing an adequate level of protection, the transfer is made under an appropriate safeguard: for EEA personal data, the standard contractual clauses adopted by the European Commission in 2021, in the module matching the Parties' roles for the processing; and for UK personal data, those clauses as varied by the UK International Data Transfer Addendum. The Parties execute those modules (including Annexes I–III describing the Parties, the processing, and the technical and organizational measures in Section 3.3) upon or before the first such transfer, and we make the executed safeguard for each transfer available on request to [email protected]. Where a subprocessor makes such a transfer, an equivalent safeguard applies under Section 4.3.
9. CCPA / CPRA (California)
To the extent the California Consumer Privacy Act as amended, and its implementing regulations (collectively "CCPA/CPRA"), apply to our processing of "personal information" on your behalf, we act as a "service provider". We: (a) process personal information only for the limited and specified business purposes in the Terms and this DPA and pursuant to the CCPA/CPRA's permitted service-provider terms; (b) do not sell or share personal information, and do not retain, use, or disclose it for any purpose other than the specified business purposes, including outside the direct business relationship between the Parties, except as permitted by the CCPA/CPRA; (c) do not combine personal information received from you with personal information received from other sources, except as permitted by the CCPA/CPRA; and (d) notify you if we determine we can no longer meet our obligations under the CCPA/CPRA. You may take reasonable and appropriate steps to ensure our processing is consistent with our obligations, and we provide the information necessary to demonstrate such compliance. Where other US state privacy laws require comparable service-provider commitments for processing on your behalf, the terms of this Section 9 apply to those laws as well.
10. Audit rights
10.1 Security review
You may, no more than once per year (plus after a confirmed personal data breach affecting your data), request a written summary of our security posture. Upon at least 30 days' notice, we will provide: (a) a security review questionnaire completed by us; and/or (b) a summary of a third-party audit report covering our controls, if and when we make one available; and/or (c) reasonable supplementary written answers.
10.2 On-site audits
Where the foregoing is insufficient to demonstrate compliance and where required by applicable law or a supervisory authority, we will permit a confidential on-site audit at your reasonable expense, subject to: reasonable advance notice; scope limited to processing under this DPA; conduct during business hours; and your obligation to avoid unreasonably disrupting our operations or compromising the security of other customers. Information obtained is used solely to verify compliance and is treated as confidential.
11. Order of precedence
In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. In the event of a conflict between this DPA and the Subprocessor List regarding subprocessor engagement, the Subprocessor List governs which entities are engaged, and this DPA governs the conditions of engagement. Nothing in this DPA limits either Party's liability to the extent the Terms provide for higher limits, or limits liability that cannot be limited under applicable law.
12. Contact point
Controller contact point for data protection matters relating to this DPA: [email protected]. Processor contact point: [email protected] (attention: data protection contact). If a named data protection officer or EU/UK representative becomes legally required for us, we will appoint one and update this section.
13. Version history
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | September 6, 2026 | Initial publication. |
| 1.1 | September 15, 2026 | Updated surface descriptions: browser-based Web Interface on desktop and mobile; no companion mobile app. |
