Data processing agreement

Standard terms for personal data processed through the gateway
v1.0 · 9 Sep 2026
How to execute this. This is our standard DPA. If it works for you, email team@gain.ventures naming your organization and the version above, and we will countersign and return a PDF. If your own DPA must govern instead, send it: we will review rather than insist on ours. Not yet reviewed by counsel on our side.

This agreement supplements the terms of service between Ga^3in Ventures LLC ("Processor") and the customer organization named on execution ("Controller"), and governs personal data that the Controller submits to the OpenGa^3in gateway. Where it conflicts with the terms of service on the handling of personal data, this agreement prevails.

01Roles

The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller's documented instructions, of which use of the service is itself an instruction, unless required otherwise by law, in which case the Processor notifies the Controller first unless that notice is legally prohibited.

02What is actually processed

The nature of this service materially limits the processing, and the limitation is technical rather than merely contractual:

Subject matterRouting of model inference requests to third party providers
DurationThe term of the service relationship, plus the retention period below
Nature and purposeTransmission, metering, billing and abuse prevention
Personal data in promptsTransmitted, never stored. Prompt and completion content passes through memory to the selected provider and is not written to any Processor system
Personal data retainedAccount contact details: name, work email, organization. Request metadata: timestamp, model, token counts, cost, key hash, organization id
Not collectedIP addresses of the Controller or its end users; prompt or output content; special category data, unless the Controller submits it inside a prompt, which is transmitted and not retained
Data subjectsThe Controller's personnel who hold portal accounts; any individuals referenced within the Controller's prompts

03Confidentiality and security

Personnel authorised to process personal data are bound by confidentiality. The Processor maintains measures appropriate to the risk, including: TLS encryption in transit for all traffic; encryption at rest for stored records; AES-256-GCM encryption of provider credentials with the decryption key held separately; API keys stored only as hashes; per organization isolation enforced server side; access to production limited to the Processor's principals; and continuous monitoring of the gateway with alerting on failure.

The Processor does not hold SOC 2 or ISO 27001 certification and does not represent that it does.

04Sub-processors

The Controller grants general authorisation for the sub-processors below. The Processor gives at least 30 days' notice by email to organization owners before adding or replacing one, during which the Controller may object and, if the objection cannot be resolved, terminate the affected service without penalty.

Sub-processorPurposeLocation
AnthropicModel inference (default)United States
DeepSeekModel inference, opt in only, off unless the Controller calls a CN labelled modelChina
Fly.ioGateway compute and usage databaseUnited States
NetlifyPortal hosting and API edgeUnited States
ClerkAuthentication and session managementUnited States
StripePayment processingUnited States
AirtableAccount and billing recordsUnited States

Model providers act as independent controllers or processors under their own terms for the content the Controller sends them. On written request the Processor will disable any listed provider for the Controller's organization.

05International transfers

Processing takes place in the United States. Where the Controller is established in the EEA, the United Kingdom or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), incorporated by reference and completed with the details in sections 02 and 04, together with the UK International Data Transfer Addendum where applicable. Traffic that the Controller directs to a CN labelled model is transferred to China at the Controller's instruction; the Controller is responsible for assessing that transfer, and may have the route disabled entirely.

06Assisting the Controller

07Audit

On reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, the Processor makes available the information necessary to demonstrate compliance with this agreement. That includes a live walkthrough of the request record for the Controller's own traffic, demonstrating that payload fields are empty. On site audits are by agreement and at the Controller's cost.

08Retention and deletion

Request metadata is retained for 12 months and then deleted. Account and billing records are retained as long as required for tax and accounting purposes. On termination or on written request the Processor deletes the Controller's personal data within 30 days, except records it must keep by law, and confirms deletion in writing.

09Liability and precedence

Liability under this agreement is subject to the limitations in the terms of service. This agreement takes effect on execution by both parties and remains in force while the Processor processes personal data for the Controller.

10Execution

Processor

Ga^3in Ventures LLC

Signature, name, title, date
Controller

Customer organization

Signature, name, title, date

OpenGa^3in data processing agreement v1.0 · 9 September 2026 · see also data handling and terms.