Skip to content

Legal

Data Processing Agreement

A summary of the structure and key terms of our DPA under Art. 28 GDPR. The full agreement is provided on request and signed with your order.

Draft

Draft — this document requires professional legal review before publication and is not yet binding.

Last updated:

Overview

When you send personal data to our AI services, you typically act as controller and Lirux [Legal Entity TBD] acts as processor. Our Data Processing Agreement ("DPA") sets out the terms required by Art. 28(3) GDPR. This page summarises its structure so your data protection officer can review it before requesting the full text.

Background on processing locations, roles and transfer safeguards is available on our Data processing page.

1. Subject matter and duration

The DPA covers the processing of personal data contained in Customer Data in connection with the services described in your order (Managed AI API, Private AI Node, Mac Cloud and related support). It applies for the term of the main agreement and for as long as we process personal data on your behalf afterwards.

2. Nature and purpose of processing

  • Receiving requests through the API gateway and processing prompts and inputs with the models you have selected;
  • Returning generated output, embeddings or transcriptions to you;
  • Logging request metadata for billing, rate limiting, security and operations;
  • Storing content only where you have enabled content logging or storage, for the retention period configured;
  • Providing support at your request.

Customer Data is not used to train models.

3. Categories of data and data subjects

Categories of personal data

  • Personal data contained in prompts, files, audio and generated output, as determined by the customer;
  • Request metadata, such as timestamps, API key identifiers, IP addresses and usage figures;
  • Contact details of the customer's authorised users.

Special categories of personal data (Art. 9 GDPR) may only be processed if expressly agreed in advance.

Categories of data subjects

  • The customer's employees and authorised users;
  • The customer's own customers, end users and other individuals whose data the customer submits.

4. Processor obligations

  • Process personal data only on documented instructions from the customer, including with regard to transfers;
  • Ensure that persons authorised to process the data are bound by confidentiality;
  • Implement the technical and organisational measures described in the Annex (Art. 32 GDPR);
  • Inform the customer if an instruction, in our opinion, infringes data protection law;
  • Notify the customer of personal data breaches without undue delay after becoming aware of them, with the information required under Art. 33(3) GDPR as it becomes available;
  • Make available the information necessary to demonstrate compliance with Art. 28 GDPR.

5. Sub-processors

A list of sub-processors is provided with the DPA. The customer gives general authorisation to engage sub-processors, subject to the following: we inform the customer of intended additions or replacements in advance, the customer may object on reasonable data protection grounds, and every sub-processor is bound by data protection obligations equivalent to those in the DPA. Notice period for changes: [X days — to be determined].

6. International transfers and SCCs

Our compute infrastructure is currently located in Georgia, which is outside the European Economic Area. Where personal data is transferred from the EEA to a third country, the DPA incorporates the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) in the applicable module, or relies on another transfer mechanism under Chapter V GDPR where available.

We provide information to support the customer's transfer impact assessment, including a description of the processing, the measures in the Annex and relevant information about the destination country as far as known to us. The applicable SCC module depends on the contracting setup and is specified in the DPA. Customers remain responsible for determining the appropriate legal basis for their workloads.

7. Technical and organisational measures (Annex outline)

The Annex to the DPA describes our measures in detail. It is structured as follows:

  • Encryption: TLS for all API traffic in transit; encryption of data at rest [scope to be specified].
  • Access control: administrative access limited to named engineers, key-based authentication, least privilege, logging of administrative access.
  • Network security: private inter-node network, API gateway with authentication and rate limits, IP allowlisting and VPN options for dedicated deployments.
  • Tenant separation: dedicated hardware for Private AI Nodes; per-customer authentication and request isolation on shared services.
  • Availability and resilience: monitoring and alerting, configuration backups, high-availability architecture options.
  • Data minimisation and retention: configurable content logging and retention on dedicated deployments; defaults defined in the DPA.
  • Physical security: restricted physical access to hardware (details under NDA).
  • Incident management: detection, response and customer notification process.
  • Review: regular review and evaluation of the effectiveness of these measures.

8. Assistance

Taking into account the nature of the processing, we assist the customer with appropriate technical and organisational measures in responding to data subject requests (Chapter III GDPR), and with security, breach notification, data protection impact assessments and prior consultation (Art. 32–36 GDPR), using the information available to us. [cost allocation for assistance to be determined]

9. Deletion and return

At the end of the provision of services, we delete or return all personal data processed on the customer's behalf, at the customer's choice, and delete existing copies unless Union or Member State law requires storage. Content that is not stored (because content logging is disabled) is not retained beyond the processing of the request. Deletion timeline: [X days after termination — to be determined].

10. Audits

We make available the information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the customer or an auditor mandated by the customer. Audits are generally carried out first by way of written information and documentation; on-site audits are arranged with reasonable notice, during business hours, without disproportionate disruption and subject to confidentiality. We do not currently hold third-party certifications that could replace an audit.

Request the full DPA

The full DPA, the Annex of technical and organisational measures and the list of sub-processors are provided on request and as part of your order.

Request the full DPA

Or write to [email protected].