DATA PROTECTION

Data Processing Addendum

Baseline data-processing terms for customer personal data processed through Clyvel.

Last updated September 2, 2026

1. Roles and scope

When a customer submits personal data to Clyvel for processing on the customer's behalf, the customer acts as controller or business and Clyvel acts as processor or service provider, as those concepts apply under relevant data-protection law. Clyvel processes that data only to provide and secure the service, on documented customer instructions and as otherwise required by law.

2. Processing details

  • Subject matter: operation of an AI gateway and related observability, cost, reliability, governance and support services.
  • Duration: for the term of the customer's use of the service plus any limited retention required for security, backup, legal or contractual purposes.
  • Data subjects: customer users, end users, personnel, contractors and other individuals whose data the customer submits.
  • Data categories: account information, identifiers, prompts, responses, application metadata, request telemetry, diagnostics and other customer-controlled content.
  • Purpose: routing, processing, monitoring, securing, supporting and improving service reliability within the customer's instructions.

3. Confidentiality and security

Clyvel will use reasonable technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Personnel or contractors with access to customer personal data should be bound by confidentiality obligations appropriate to their role.

4. Subprocessors

Clyvel may use subprocessors to provide infrastructure, authentication, email, billing and other service functions. Clyvel will maintain a current list on the Subprocessors page and should contractually require subprocessors to protect customer personal data consistently with their role in the service.

5. Data-subject requests

Taking into account the nature of the processing, Clyvel will provide reasonable assistance to customers responding to valid requests from data subjects when the relevant information cannot reasonably be handled by the customer through product controls.

6. Security incidents

Clyvel will notify affected customers without undue delay after confirming a security incident involving customer personal data where notification is required by applicable law or contract. Notice should include available information reasonably necessary for the customer to evaluate the incident and meet its own legal obligations.

7. Deletion and return

On termination or a valid customer request, Clyvel will delete or return customer personal data within a reasonable period, subject to technical backup cycles and retention required by law, security or legitimate dispute resolution. Any retained data remains protected under the applicable confidentiality and security obligations.

8. International transfers

Where cross-border transfer safeguards are legally required, the parties should use an appropriate transfer mechanism, which may include approved standard contractual clauses or another valid mechanism applicable to the relevant jurisdictions.

9. Audit information

Clyvel will make reasonably available information necessary to demonstrate compliance with these processor obligations, subject to confidentiality, security and proportionality restrictions. On-site audits are not automatically included and may require a separate written arrangement.