Legal
Data Processing Addendum
Effective 3 September 2026 · Last updated 3 September 2026
This Data Processing Addendum (“DPA”) applies when [COMPANY LEGAL NAME] (“Processor”) processes personal data on behalf of a customer (“Controller”) in connection with Qwythos, and GDPR or similar laws require a processing agreement.
Standard SaaS DPA outline. Execute a signed version with schedules (sub-processors, TOMs, SCCs) before enterprise deals.
1. Roles
Customer is Controller (or a processor instructing us). We act as Processor for Customer Content processed to provide the Service. Account/billing data may be processed as independent controller as described in the Privacy Policy.
2. Subject matter
Processing of prompts, messages, files metadata, and related identifiers as needed to provide inference, chat, API, support, and security.
3. Duration
For the subscription term plus deletion/return periods in the Privacy Policy or this DPA.
4. Instructions
We process Customer personal data only on documented instructions (including the Agreement and configuration of the Service), unless required by law.
5. Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations.
6. Security
We implement appropriate technical and organizational measures (access control, encryption in transit, logging, least privilege). Details available on request under NDA.
7. Sub-processors
Customer authorizes sub-processors necessary to operate the Service (hosting, auth/database, payments, GPU inference). We will impose data protection terms no less protective than this DPA and remain responsible for sub-processors we appoint. A current list can be requested at privacy@qwythos.ai.
8. International transfers
Where required, transfers outside the EEA/UK use SCCs or other lawful mechanisms.
9. Assistance
Taking into account the nature of processing, we will assist with data subject requests, DPIAs, and breach notifications as required by Articles 28, 32–36 GDPR.
10. Breach notice
We will notify Controller without undue delay after becoming aware of a personal data breach affecting Customer personal data.
11. Deletion / return
Upon termination, we will delete or return Customer Content from active systems within a commercially reasonable period, except data retained as required by law or isolated backups pending expiry.
12. Audits
Upon reasonable written notice, we will provide information necessary to demonstrate compliance, including third-party security reports where available, subject to confidentiality.
13. Contact
privacy@qwythos.ai · dpo@qwythos.ai