Data processing agreement
This agreement supplements the terms of service between Ga^3in Ventures LLC ("Processor") and the customer organization named on execution ("Controller"), and governs personal data that the Controller submits to the OpenGa^3in gateway. Where it conflicts with the terms of service on the handling of personal data, this agreement prevails.
01Roles
The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller's documented instructions, of which use of the service is itself an instruction, unless required otherwise by law, in which case the Processor notifies the Controller first unless that notice is legally prohibited.
02What is actually processed
The nature of this service materially limits the processing, and the limitation is technical rather than merely contractual:
| Subject matter | Routing of model inference requests to third party providers |
| Duration | The term of the service relationship, plus the retention period below |
| Nature and purpose | Transmission, metering, billing and abuse prevention |
| Personal data in prompts | Transmitted, never stored. Prompt and completion content passes through memory to the selected provider and is not written to any Processor system |
| Personal data retained | Account contact details: name, work email, organization. Request metadata: timestamp, model, token counts, cost, key hash, organization id |
| Not collected | IP addresses of the Controller or its end users; prompt or output content; special category data, unless the Controller submits it inside a prompt, which is transmitted and not retained |
| Data subjects | The Controller's personnel who hold portal accounts; any individuals referenced within the Controller's prompts |
03Confidentiality and security
Personnel authorised to process personal data are bound by confidentiality. The Processor maintains measures appropriate to the risk, including: TLS encryption in transit for all traffic; encryption at rest for stored records; AES-256-GCM encryption of provider credentials with the decryption key held separately; API keys stored only as hashes; per organization isolation enforced server side; access to production limited to the Processor's principals; and continuous monitoring of the gateway with alerting on failure.
The Processor does not hold SOC 2 or ISO 27001 certification and does not represent that it does.
04Sub-processors
The Controller grants general authorisation for the sub-processors below. The Processor gives at least 30 days' notice by email to organization owners before adding or replacing one, during which the Controller may object and, if the objection cannot be resolved, terminate the affected service without penalty.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic | Model inference (default) | United States |
| DeepSeek | Model inference, opt in only, off unless the Controller calls a CN labelled model | China |
| Fly.io | Gateway compute and usage database | United States |
| Netlify | Portal hosting and API edge | United States |
| Clerk | Authentication and session management | United States |
| Stripe | Payment processing | United States |
| Airtable | Account and billing records | United States |
Model providers act as independent controllers or processors under their own terms for the content the Controller sends them. On written request the Processor will disable any listed provider for the Controller's organization.
05International transfers
Processing takes place in the United States. Where the Controller is established in the EEA, the United Kingdom or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), incorporated by reference and completed with the details in sections 02 and 04, together with the UK International Data Transfer Addendum where applicable. Traffic that the Controller directs to a CN labelled model is transferred to China at the Controller's instruction; the Controller is responsible for assessing that transfer, and may have the route disabled entirely.
06Assisting the Controller
- Data subject requests. Because prompts are not retained, the Processor cannot locate personal data inside them. For retained account and metadata records the Processor assists with access, correction, deletion, restriction and portability requests within 10 business days of a written request.
- Breach notification. The Processor notifies the Controller without undue delay and within 72 hours of becoming aware of a personal data breach affecting the Controller's data, with the facts known at the time and updates as the picture develops.
- Impact assessments. The Processor provides the information reasonably required for the Controller's data protection impact assessments and prior consultations.
07Audit
On reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, the Processor makes available the information necessary to demonstrate compliance with this agreement. That includes a live walkthrough of the request record for the Controller's own traffic, demonstrating that payload fields are empty. On site audits are by agreement and at the Controller's cost.
08Retention and deletion
Request metadata is retained for 12 months and then deleted. Account and billing records are retained as long as required for tax and accounting purposes. On termination or on written request the Processor deletes the Controller's personal data within 30 days, except records it must keep by law, and confirms deletion in writing.
09Liability and precedence
Liability under this agreement is subject to the limitations in the terms of service. This agreement takes effect on execution by both parties and remains in force while the Processor processes personal data for the Controller.
10Execution
Ga^3in Ventures LLC
Customer organization