Data processing addendum
Our Article 28 processing terms, including the Standard Contractual Clauses, our security measures and the current subprocessor list.
01Scope and application
This Data Processing Addendum (“DPA”) forms part of the agreement between OneCloud, LLC, a limited liability company registered in the State of Florida, United States (“Processor”, “we”) and the customer identified in the applicable order form (“Controller”, “you”) for the provision of the Services (the “Agreement”).
It applies where we process personal data on your behalf in the course of providing the Services, and it reflects the requirements of Article 28 of the EU General Data Protection Regulation, the UK GDPR, and applicable US state privacy laws.
Where this DPA conflicts with the Terms of Service, this DPA prevails for matters concerning the processing of personal data. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
02Definitions
- Applicable Data Protection Law — the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, Swiss FADP, the California Consumer Privacy Act as amended by the CPRA, and any other privacy law applicable to the processing.
- Controller, Processor, Data Subject, Personal Data, Processing, Supervisory Authority — as defined in the GDPR, and their equivalents (including business and service provider) under US state law.
- Customer Personal Data — personal data contained within Customer Content or otherwise processed by us on your behalf under the Agreement.
- Standard Contractual Clauses (“SCCs”) — the clauses annexed to Commission Implementing Decision (EU) 2021/914.
- UK Addendum — the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
03Roles and instructions
You are the Controller and we are the Processor in respect of Customer Personal Data. You are responsible for the lawfulness of the data you submit, for having a lawful basis, and for providing any notices and obtaining any consents required from data subjects.
We will process Customer Personal Data only on your documented instructions, which comprise the Agreement, this DPA, your configuration of the Services, and any further written instruction you give. We will tell you if, in our opinion, an instruction infringes Applicable Data Protection Law, and we may suspend that processing until it is resolved.
If we are required by law to process beyond your instructions, we will inform you before doing so unless that law prohibits it on important grounds of public interest.
No training, no secondary use. We do not use Customer Personal Data to train, fine-tune or improve any machine-learning model, we do not sell or share it, and we do not use it for our own purposes, including advertising or profiling.
04Confidentiality of personnel
We ensure that anyone authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality, is subject to least-privilege access, and receives training appropriate to their role. Access to customer content is time-bound, purpose-limited and logged.
05Security measures
We implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to data subjects.
We may update those measures over time provided the level of protection is not reduced.
06Subprocessors
You give general authorisation for us to engage subprocessors. The current list is at Annex III.
- We impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
- We will give at least 30 days’ notice before adding or replacing a subprocessor. To receive those notices, email [email protected].
- You may object on reasonable data-protection grounds within that notice period. We will work with you in good faith to offer an alternative; if none is available, you may terminate the affected part of the Services and receive a refund of prepaid unused fees.
- Where you deploy the Services in your own infrastructure or bring your own model provider keys, that provider is not our subprocessor — the relationship is directly between you and them.
07Assistance with data subject rights
The Services give you tools to search, export, correct and delete records directly, which is normally the fastest route to responding to a data subject.
Where a data subject contacts us directly about Customer Personal Data, we will not respond substantively but will refer them to you without undue delay. Taking into account the nature of the processing, we will provide reasonable assistance with your obligations under Chapter III of the GDPR, by appropriate technical and organisational measures, insofar as possible.
08Personal data breach
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of that at once, we will provide it in phases without undue further delay. We will assist you with your own notification obligations to supervisory authorities and data subjects.
09Data protection impact assessments
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority. For AI-specific assessments we can also supply architecture detail, retrieval traces and model-routing configuration to support your analysis.
10Deletion and return
On termination or expiry of the Agreement, you may export Customer Personal Data using the Services for 30 days.
After that period we will delete Customer Personal Data from production systems within 30 days, and from encrypted backups within a further 90 days as those backups age out on their normal rotation, unless storage is required by law. On written request we will certify deletion.
11Audits
We will make available the information necessary to demonstrate compliance with Article 28 GDPR, including our security documentation, completed questionnaires and any third-party attestation reports we hold.
Where that is not sufficient, you may audit us once in any twelve-month period on at least 30 days’ written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. You bear your own costs; we bear ours unless the audit reveals material non-compliance. A supervisory authority may audit in accordance with its statutory powers at any time.
12International transfers
We are established in the United States. Where you transfer Customer Personal Data from the EEA, UK or Switzerland to us, or where we transfer it onward, the following apply:
- EEA transfers — the SCCs are incorporated into this DPA by reference, with Module Two (Controller to Processor) applying between you and us, and Module Three where you act as a processor for your own customer. Annex I is populated by Annex I below, Annex II by Annex II, and the optional docking clause applies. The governing law is that of Ireland and the forum is the Irish courts, save where a different EU member state law is mandatory.
- UK transfers — the UK Addendum applies to the SCCs, with the UK as the governing jurisdiction.
- Swiss transfers — the SCCs apply with references to the GDPR read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
- Supplementary measures — encryption in transit and at rest, tenant isolation, access logging, a policy of challenging overbroad government requests, and publishing what we lawfully can about them.
- Alternatives — you may avoid transfers altogether by selecting a regional deployment or running the Services in your own infrastructure.
13US state privacy law
Where the CCPA/CPRA applies, we act as a service provider and you as the business. We are prohibited from, and will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than performing the Services specified in the Agreement; retain, use or disclose it outside the direct business relationship with you; or combine it with personal information from another source except as the CCPA permits.
We will notify you if we determine we can no longer meet these obligations. Equivalent terms apply under comparable state laws including those of Virginia, Colorado, Connecticut, Utah, Texas and Florida.
14Liability and term
Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Applicable Data Protection Law does not permit such limitation, and except as the SCCs otherwise provide in respect of data subject claims.
This DPA takes effect on the effective date of the Agreement and continues for as long as we process Customer Personal Data. Provisions that by their nature should survive do so.
15Annex I — details of processing
A. Parties
- Data exporter / Controller — the customer identified in the order form, at the contact details on its account. Role: Controller (or Processor, where acting for its own customer).
- Data importer / Processor — OneCloud, LLC, a limited liability company registered in the State of Florida, United States. Contact: [email protected]. Activities: provision of the ERAG and Stratum platforms and related consulting services. Role: Processor.
B. Description of processing
| Item | Detail |
|---|---|
| Categories of data subjects | The customer’s employees, contractors and other authorised users; individuals referred to within documents, records, communications or source code that the customer submits; the customer’s own clients, suppliers and counterparties where they appear in that content. |
| Categories of personal data | Identity and contact data (names, work emails, roles); authentication identifiers; usage and audit records; and any personal data contained within documents, files, messages, transcripts, database records or source code that the customer chooses to submit. |
| Special category data | Not requested and not required. The customer controls what it submits; if special category or criminal-offence data is submitted, it is processed under the same measures, and the customer is responsible for having an Article 9 or 10 condition. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Nature of processing | Collection, storage, organisation, structuring, indexing, retrieval, analysis, generation of derived output, transmission to selected model providers for inference, erasure and destruction. |
| Purpose | Providing the Services: retrieval and question answering with citations, agent and workflow automation, codebase analysis, migration planning, test generation and code transformation, plus support and security. |
| Retention | For the term of the Agreement plus the deletion periods in section 10. |
| Subprocessor processing | As set out in Annex III, for the duration of the relevant subprocessor engagement. |
C. Competent supervisory authority
The supervisory authority of the EEA member state in which the data exporter is established, or where the exporter is not established in the EEA, the authority of the member state in which its Article 27 representative is established. For UK transfers, the Information Commissioner’s Office.
16Annex II — technical and organisational measures
The measures below apply to our hosted Services. Where you self-host, you implement the equivalent controls in your own environment. Full detail is on our security page.
| Measure | Implementation |
|---|---|
| Pseudonymisation and encryption | TLS 1.2+ in transit; AES-256 or equivalent at rest for documents, indexes and backups; secrets encrypted with authenticated symmetric encryption and never returned unmasked. |
| Confidentiality and integrity | Logical tenant isolation; per-document access control evaluated inside vector and keyword queries rather than post-filtered; integrity checks on ingestion and storage. |
| Availability and resilience | Encrypted backups with scheduled restore testing; monitoring and alerting; documented recovery objectives. |
| Access control | SSO via OIDC and SAML 2.0; SCIM provisioning and de-provisioning; TOTP MFA and step-up re-authentication; role-based permissions; session revocation; least privilege and periodic access review for our own personnel. |
| Identification of the data subject in a transmission | Per-query traces and a complete audit trail, exportable to the customer’s SIEM. |
| Secure development | Peer review on every change; automated tests in CI; dependency, container, static and secret scanning; infrastructure as code. |
| Sandboxing | Generated tests and code execute in an isolated sandbox with no access to production systems or customer networks. |
| AI-specific controls | Retrieved content treated as untrusted data rather than instructions; capability-scoped API keys; confirmation steps before actions with side effects; content moderation; grounding checks and abstention; no training on customer data. |
| Incident management | Documented and exercised response plan; 72-hour breach notification to the controller; written post-incident review with tracked corrective actions. |
| Governance | Security and privacy training at onboarding and annually; confidentiality obligations in all personnel contracts; joiner, mover and leaver processes; subprocessor due diligence and contractual flow-down. |
| Data minimisation and retention | Customer-configurable retention policies, right-to-be-forgotten workflows, PII detection and redaction, and deletion propagated to indexes and backups. |
17Annex III — subprocessors
The following subprocessors may process Customer Personal Data in connection with the hosted Services. We give 30 days’ notice before any addition or replacement.
| Subprocessor | Purpose | Location | Applies when |
|---|---|---|---|
| Cloud infrastructure provider | Hosting, compute, storage and backup for the hosted Services | Customer-selected region | Hosted deployments only |
| Resend | Transactional email, including contact-form delivery and service notifications | United States | Always |
| Anthropic | Model inference for routed workloads | United States | Hosted models, where routed to this provider |
| OpenAI | Model inference for routed workloads | United States | Hosted models, where routed to this provider |
| Microsoft Azure OpenAI | Model inference for routed workloads | Customer-selected region | Hosted models, where routed to this provider |
| Amazon Web Services (Bedrock) | Model inference for routed workloads | Customer-selected region | Hosted models, where routed to this provider |
| Google Cloud (Vertex AI) | Model inference for routed workloads | Customer-selected region | Hosted models, where routed to this provider |
| Payment processor | Billing, invoicing and card processing | United States / EU | Paid plans |
Model providers process content only where you use OneCloud-hosted models and only for the workloads routed to them. Bring your own keys, pin routing to a single provider, or run local models on vLLM or Ollama, and the corresponding entries no longer apply to you.
18Signature and contact
This DPA is incorporated into the Agreement by reference and requires no separate signature. Where your procurement process requires a counter-signed copy, request one from [email protected] and we will return it.
OneCloud, LLC, a limited liability company registered in the State of Florida, United States
Privacy: [email protected]
Security: [email protected]
Legal: [email protected]