Download as plain textTo attach to your compliance documentation, or to sign if your organisation requires it.
1. Subject matter and roles
You, the customer, are the controller of any personal data you include in your requests. We process it solely to provide the service, on your instructions — which are the requests you send us through the API.
2. What we process, and for how long
The content of your requests and responses is processed in memory for the duration of the request and is not stored: zero on disk, in logs, or in backups. Two exceptions, both documented: the response cache, in memory for up to an hour, which you can switch off entirely with Confidential Mode; and content you supply to us on purpose for an audit of your own traffic, which is encrypted at rest under a key held separately, never used for training, and erased on your instruction or with your account. For each call we keep metadata with no content: model, token counts, latency and cost.
3. Subprocessors
To provide the service we rely on an inference provider in the European Union, which processes your prompts with no retention and no training; a payment provider; a transactional email provider; and an infrastructure provider. The current list, with what each one sees, is on the privacy architecture page. We will tell you before adding a new subprocessor, and you may object.
4. Security
Encryption in transit with TLS 1.3 as a minimum. Data and backups encrypted at rest. Restricted, authenticated access. No access logs, and application logs carry only errors and security events with the IP passed through a hash with a daily salt.
5. International transfers
Processing takes place in the European Union. Should a transfer outside the European Economic Area ever become necessary, it would be made with the safeguards the GDPR requires and announced beforehand.
6. Assistance and breach notification
We will help with your users' rights requests and with your impact assessments as far as it depends on us. If a security breach affects you, we will tell you without undue delay and with what we know at that point.
7. Return and deletion
When the contract ends, or whenever you ask, we delete the personal data we process on your behalf. Accounting records are kept for six years as the law requires, detached from identity.
8. Audit
You may ask us for the reasonable information you need to demonstrate compliance with this agreement, including security documentation and the subprocessor list.