1. Roles and scope
When a customer submits personal data to Clyvel for processing on the customer's behalf, the customer acts as controller or business and Clyvel acts as processor or service provider, as those concepts apply under relevant data-protection law. Clyvel processes that data only to provide and secure the service, on documented customer instructions and as otherwise required by law.
2. Processing details
- Subject matter: operation of an AI gateway and related observability, cost, reliability, governance and support services.
- Duration: for the term of the customer's use of the service plus any limited retention required for security, backup, legal or contractual purposes.
- Data subjects: customer users, end users, personnel, contractors and other individuals whose data the customer submits.
- Data categories: account information, identifiers, prompts, responses, application metadata, request telemetry, diagnostics and other customer-controlled content.
- Purpose: routing, processing, monitoring, securing, supporting and improving service reliability within the customer's instructions.
3. Confidentiality and security
Clyvel will use reasonable technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Personnel or contractors with access to customer personal data should be bound by confidentiality obligations appropriate to their role.
4. Subprocessors
Clyvel may use subprocessors to provide infrastructure, authentication, email, billing and other service functions. Clyvel will maintain a current list on the Subprocessors page and should contractually require subprocessors to protect customer personal data consistently with their role in the service.
5. Data-subject requests
Taking into account the nature of the processing, Clyvel will provide reasonable assistance to customers responding to valid requests from data subjects when the relevant information cannot reasonably be handled by the customer through product controls.
6. Security incidents
Clyvel will notify affected customers without undue delay after confirming a security incident involving customer personal data where notification is required by applicable law or contract. Notice should include available information reasonably necessary for the customer to evaluate the incident and meet its own legal obligations.
7. Deletion and return
On termination or a valid customer request, Clyvel will delete or return customer personal data within a reasonable period, subject to technical backup cycles and retention required by law, security or legitimate dispute resolution. Any retained data remains protected under the applicable confidentiality and security obligations.
8. International transfers
Where cross-border transfer safeguards are legally required, the parties should use an appropriate transfer mechanism, which may include approved standard contractual clauses or another valid mechanism applicable to the relevant jurisdictions.
9. Audit information
Clyvel will make reasonably available information necessary to demonstrate compliance with these processor obligations, subject to confidentiality, security and proportionality restrictions. On-site audits are not automatically included and may require a separate written arrangement.