Data Processing Agreement
Version Number: [2026V1] | Last Updated: [2026.07]
This Data Processing Agreement ("DPA") is between Zenlayer Inc., a company incorporated in Delaware with its principal business address at 21700 Copley Drive Suite 350, Diamond Bar, CA 91765, United States ("Company," "we," "us," or "our"), and the entity or person accepting these terms ("Customer").
This DPA forms part of and is incorporated into the AI Router Terms of Service available at https://www.tkex.ai/legal/terms (the "Agreement"). Capitalized terms not defined in this DPA have the meanings given in the Agreement. In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the subject matter herein.
This DPA automatically applies where required by Applicable Data Protection Laws upon Customer's acceptance of the Agreement.
Section 1. Definitions
In this DPA, the following terms have the following meanings:
-
"Applicable Data Protection Laws" means all privacy, data protection and data security laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including as applicable: the EU GDPR; the UK GDPR; the Swiss Federal Act on Data Protection (revFADP); the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA); and other applicable US state privacy laws, in each case as amended from time to time.
-
"Controller" means the natural or legal person which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
-
"Customer Personal Data" means any Personal Data Processed by the Company or its Sub-Processors on behalf of Customer in the course of providing the Services under the Agreement.
-
"Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates.
-
"Data Subject Request" means the exercise by a Data Subject of its rights under Applicable Data Protection Laws in respect of Customer Personal Data.
-
"EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
-
"UK GDPR" means the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.
-
"Personal Data" means "personal data," "personal information," "personally identifiable information," or equivalent term as defined under Applicable Data Protection Laws.
-
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in the Company's possession, custody or control. Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful login attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.
-
"Personnel" means, in relation to a party, that party's employees, agents, consultants, contractors, and other staff.
-
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
-
"Processor" means the natural or legal person that Processes Personal Data on behalf of a Controller.
-
"Restricted Transfer" means: (i) in the context of the EU GDPR, any transfer of Customer Personal Data from the EEA to a country or territory outside the EEA that does not benefit from an adequacy decision of the European Commission; and (ii) in the context of the UK GDPR, any transfer of Customer Personal Data from the UK to a country or territory outside the UK that does not benefit from adequacy regulations under section 17A of the Data Protection Act 2018.
-
"SCCs" means the standard contractual clauses approved by the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021.
-
"Services" has the meaning given in the Agreement.
-
"Sub-Processor" means any third party appointed by or on behalf of the Company to Process Customer Personal Data.
-
"Sub-Processor List" means the list of Sub-Processors set out in Annex 3 to this DPA, as updated from time to time in accordance with Section 6.2.
-
"Supervisory Authority" means: (i) in the context of the EU GDPR, a supervisory authority as defined in Article 4(21) of the EU GDPR; and (ii) in the context of the UK GDPR, the UK Information Commissioner's Office (or its successor).
-
"UK Transfer Addendum" means the template Addendum B.1.0 issued by the UK Information Commissioner's Office and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of the Mandatory Clauses.
Section 2. Scope and Roles
2.1 Scope
This DPA applies to Customer Personal Data which the Company Processes as a Processor on behalf of Customer as Controller (or as a Sub-Processor on behalf of Customer acting as a Processor), solely to the extent required by Applicable Data Protection Laws. This DPA does not apply to Personal Data for which the Company is an independent Controller, such as account registration data and billing data processed for the Company's own business purposes, which are addressed in the Privacy Policy.
2.2 Roles
As between the parties and for the purposes of Applicable Data Protection Laws:
-
Customer is the Controller (or Processor, where Customer itself acts as a Processor on behalf of a third party) of Customer Personal Data.
-
The Company is the Processor of Customer Personal Data, Processing it only on behalf of and in accordance with Customer's documented instructions.
2.3 AI Router Architecture — Limited Processing
Customer acknowledges the following characteristics of the Service, which define the nature and scope of the Company's Processing of Customer Personal Data:
-
No prompt storage: the Company does not store, retain, log, or persist the content of any Input (prompts, instructions, or other content submitted to the Service) or any Output (AI model responses). Inputs and Outputs are transmitted in real time to the applicable Model Provider and are discarded by the Company upon completion of each transmission.
-
Metadata only: the Company retains only limited request metadata for billing, security, and operational purposes. Such metadata may include, for example, model identifier, Provider routed to, token counts, request latency, response status codes, timestamps, and IP address. This metadata does not include the content of Inputs or Outputs.
-
Pass-through transmission and Model Provider role: to the extent Customer Personal Data is contained within Inputs, the Company's Processing is limited to real-time transmission to the applicable Model Provider on Customer's instruction, as necessary to perform the Service. Model Providers are not Sub-Processors of the Company. The Company is not responsible for Model Providers' data handling practices, security, or compliance with applicable data protection laws. Customer's use of any Model Provider's services is additionally subject to that Model Provider's own terms of service and privacy policy, which Customer is responsible for reviewing.
Section 3. Processing Instructions
The Company shall Process Customer Personal Data only: (a) in accordance with Customer's documented instructions as set out in the Agreement and this DPA; and (b) as required by Applicable Data Protection Laws, in which case the Company shall inform Customer in advance of such requirement, unless prohibited from doing so by applicable law.
The Agreement and this DPA constitute Customer's complete and final documented instructions to the Company regarding the Processing of Customer Personal Data. Any additional instructions from Customer shall be binding on the Company only if agreed in writing by both parties.
If the Company reasonably considers that any instruction from Customer would infringe Applicable Data Protection Laws, the Company shall promptly notify Customer accordingly.
Section 4. Details of Processing
The details of the Company's Processing of Customer Personal Data are set out in Annex 1 (Data Processing Details) to this DPA.
Section 5. Security
5.1 Security Measures
The Company shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data, as described in Annex 2 (Security Measures) to this DPA. The Company may update the Security Measures from time to time, provided that such updates do not materially decrease the overall level of security afforded to Customer Personal Data.
5.2 Personnel
The Company shall take commercially reasonable steps to ensure the reliability of its Personnel who Process Customer Personal Data and shall ensure that all such Personnel are subject to appropriate obligations of confidentiality.
5.3 Customer Responsibilities
Customer is responsible for: (a) making appropriate use of the Services to maintain security appropriate to the risk in respect of Customer Personal Data; (b) securing Customer's account credentials, systems and devices used to access the Services; (c) ensuring the lawfulness of Customer's instructions to the Company; and (d) backing up Customer Personal Data, as the Company does not store the content of Inputs or Outputs and cannot recover such data on Customer's behalf.
Section 6. Sub-Processors
6.1 General Authorization
For the avoidance of doubt, Model Providers are not Sub-Processors of the Company. As described in Section 2.3, the Company's processing of Customer Personal Data is limited to real-time transmission to Model Providers on Customer's instruction. Model Providers are not engaged by the Company to process Customer Personal Data on the Company's behalf, and each Model Provider is independently responsible for its own compliance with applicable data protection laws with respect to any processing occurring within its own infrastructure.
Customer hereby generally authorizes the Company to appoint Sub-Processors in accordance with this Section 6. The Company's current Sub-Processors, including their names, functions and locations, are set out in Annex 3 to this DPA. Customer authorizes the Company's engagement of the Sub-Processors listed in Annex 3 as of the date Customer accepts the Agreement.
6.2 Notification of Changes
The Company shall give Customer at least 10 business days' prior written notice of the appointment of any new Sub-Processor or replacement of any existing Sub-Processor, by updating the Sub-Processor List. Customer is solely responsible for monitoring updates to Annex 3, which the Company will update in accordance with this Section 6.2. If, within 10 business days of the update to the Sub-Processor List, Customer notifies the Company in writing of any objection to the proposed appointment or replacement (based on reasonable grounds evidencing that the use of the proposed Sub-Processor would cause Customer to be in material and unavoidable breach of Applicable Data Protection Laws), the Company shall: (a) use reasonable efforts to make available a commercially reasonable change in the provision of the Services to avoid use of the objected-to Sub-Processor; or (b) if such a change is not commercially feasible within 30 days, or if Customer declines to bear any incremental cost associated with such change, either party may terminate the relevant portion of the Services upon written notice, without penalty.
6.3 Company Obligations Regarding Sub-Processors
The Company shall: (a) enter into a written agreement with each Sub-Processor imposing data protection obligations no less protective than those set out in this DPA; and (b) remain liable to Customer for the acts and omissions of Sub-Processors to the same extent the Company would be liable if it had performed the relevant processing directly.
Section 7. Data Subject Rights
The Company shall, taking into account the nature of the Processing and the information available to the Company, provide Customer with such reasonable assistance as may be technically feasible to assist Customer in fulfilling its obligations to respond to Data Subject Requests under Applicable Data Protection Laws. If the Company receives a Data Subject Request directly, the Company shall: (a) promptly notify Customer; and (b) not respond to the Data Subject Request other than to advise the Data Subject to submit the request to Customer, except as required by Applicable Data Protection Laws. Except to the extent prohibited by Applicable Data Protection Laws, Customer shall reimburse the Company for any reasonable costs incurred in providing assistance under this Section 7, beyond self-service features included as part of the Services, at the Company's then-current professional services rates.
Section 8. Data Protection Impact Assessments and Prior Consultation
To the extent required by Applicable Data Protection Laws, the Company shall, taking into account the nature of the Processing and the information available to it, provide reasonable cooperation and assistance to Customer in connection with: (a) any data protection impact assessment that Customer is required to conduct; and (b) any prior consultation with a Supervisory Authority in relation to high-risk Processing. Customer shall reimburse the Company for any reasonable costs incurred in providing such assistance, except where any non-compliance by the Company necessitated such assistance.
Section 9. Audits and Compliance
9.1 Information and Certification
The Company shall make available to Customer, upon reasonable written request, information necessary to demonstrate the Company's compliance with this DPA. In the first instance, the Company may satisfy this obligation by providing relevant third-party audit reports, certifications or attestations (if any), acceptance of which for this purpose shall not be unreasonably withheld by Customer.
9.2 Audits
Where Customer can provide documentary evidence that third-party certifications are insufficient to demonstrate the Company's compliance with this DPA, and subject to Applicable Data Protection Laws specifically requiring it, Customer or its authorized designee may conduct an audit of the Company's compliance with its obligations under this DPA, limited to records and documentation relating to the Processing of Customer Personal Data, subject to the following conditions:
-
Customer shall give the Company at least 30 days' prior written notice of any audit, unless a shorter period is required under Applicable Data Protection Laws.
-
Customer shall submit a detailed proposed audit plan in advance. The parties will work cooperatively to agree on a final audit plan.
-
Audits shall be conducted during normal business hours, no more than once per calendar year (except where required by a Supervisory Authority), and in a manner that minimizes disruption to the Company's operations.
-
Customer shall ensure that any auditor: (i) executes a non-disclosure agreement with the Company on terms acceptable to the Company (acting reasonably) prior to the audit; and (ii) has been approved in advance by the Company (acting reasonably). The Company may reject any proposed auditor whom it has not approved in advance (acting reasonably), including any auditor who is a competitor of the Company or whose engagement would compromise the confidentiality or security of data belonging to other customers of the Company or the availability of the Company's services to such other customers.
-
Customer shall bear all costs of any audit, including the Company's reasonable costs of cooperating with and facilitating the audit, unless the audit reveals material non-compliance by the Company with this DPA, in which case the Company shall bear its own costs. Customer shall use its best efforts, and shall ensure that each of its mandated auditors uses its best efforts, to avoid causing any destruction, damage, injury or disruption to the Company's premises, equipment, Personnel, data, and business during any audit, including any interference with the confidentiality or security of data belonging to other customers of the Company or the availability of the Company's services to such other customers.
Section 10. Personal Data Breach
10.1 Notification
The Company shall notify Customer without undue delay upon confirming a Personal Data Breach affecting Customer Personal Data. Such notification shall, to the extent then known and available to the Company, include: (a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected; (b) the likely consequences of the Personal Data Breach; and (c) measures taken or proposed to be taken to address the Personal Data Breach. The Company may provide this information in phases as it becomes available. Notification of or response to a Personal Data Breach by the Company shall not constitute an acknowledgement of fault or liability.
10.2 Cooperation
The Company shall provide Customer with reasonable cooperation and assistance as may be necessary for Customer to comply with its obligations to notify relevant Supervisory Authorities and affected Data Subjects under Applicable Data Protection Laws. The Company shall not notify any Supervisory Authority or Data Subject directly on Customer's behalf without Customer's prior written consent, except as required by Applicable Data Protection Laws.
10.3 Customer's Responsibility
As between the parties, Customer is solely responsible for complying with applicable breach notification laws and fulfilling any third-party notification obligations related to any Personal Data Breach. The obligations in Sections 10.1 and 10.2 do not apply to any Personal Data Breach caused by Customer's actions or omissions.
10.4 Customer Notification Consultation
If Customer determines that a Personal Data Breach affecting Customer Personal Data must be notified to any Supervisory Authority, other governmental authority, Data Subject, or the public under Applicable Data Protection Laws, and such notice directly or indirectly refers to or identifies the Company, Customer agrees, to the extent permitted by applicable law, to: (a) notify the Company in advance of issuing such notice; and (b) in good faith, consult with the Company and consider any reasonable clarifications or corrections the Company may recommend to any such notice, to the extent they relate to the Company's involvement in or relevance to the Personal Data Breach and are consistent with applicable law. This obligation does not restrict Customer's ability to comply with any mandatory notification deadlines under Applicable Data Protection Laws.
Section 11. International Data Transfers
11.1 General
Customer acknowledges that the Company's infrastructure is based in the United States and that Processing of Customer Personal Data may involve Restricted Transfers. The Company shall only effect Restricted Transfers in compliance with Applicable Data Protection Laws and shall establish an appropriate legal transfer mechanism for each Restricted Transfer.
11.2 EU SCCs
In respect of any Restricted Transfer of Customer Personal Data from Customer to the Company that is subject to the EU GDPR, the parties hereby enter into and agree to comply with the SCCs, which are incorporated by reference into this DPA, as follows:
-
Module Two (Controller to Processor) applies to any Restricted Transfer in respect of which Customer is a Controller of Customer Personal Data.
-
Module Three (Processor to Processor) applies to any Restricted Transfer in respect of which Customer is itself a Processor of Customer Personal Data.
-
In Clause 7 (Docking Clause): the optional docking clause does not apply.
-
In Clause 9 (Use of Sub-Processors): Option 2 (General Written Authorization) applies. The minimum time period for prior notice of Sub-Processor changes is as set out in Section 6.2 of this DPA.
-
In Clause 11 (Redress): the optional language does not apply.
-
In Clause 17 (Governing Law): Option 1 applies; the SCCs are governed by the laws of Ireland.
-
In Clause 18(b) (Choice of Forum): disputes shall be resolved before the courts of Ireland.
-
Annex I to the SCCs is deemed populated with the information set out in Annex 1 to this DPA.
-
Annex II to the SCCs is deemed populated with the information set out in Annex 2 to this DPA.
11.3 UK Transfer Addendum
In respect of any Restricted Transfer of Customer Personal Data from Customer to the Company that is subject to the UK GDPR, the SCCs as described in Section 11.2 apply as varied by the UK Transfer Addendum as follows:
-
Tables 1, 2 and 3 of the UK Transfer Addendum are deemed populated with the relevant information from the SCCs populated in accordance with Section 11.2 and Annex 1 to this DPA.
-
In Table 4 of the UK Transfer Addendum, "Importer" is deemed selected.
-
The start date of the UK Transfer Addendum is the date Customer accepts the Agreement.
-
The Parties agree that Part 2 (Mandatory Clauses) of the UK Transfer Addendum is incorporated into and forms part of this DPA.
11.4 Alternative Transfer Mechanisms
If the Company adopts an alternative lawful transfer mechanism under Applicable Data Protection Laws (including, if applicable, certification under the EU-US Data Privacy Framework or UK Extension thereto), such mechanism shall apply instead of or in addition to the SCCs. The parties shall cooperate in good faith to implement any new or replacement transfer mechanism required by changes in Applicable Data Protection Laws.
11.5 Operational Clarifications for SCCs
In relation to any SCCs entered into pursuant to Section 11.2, the parties agree to the following operational clarifications:
-
Clause 8.3 (Transparency): When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer shall not provide or otherwise make available, and shall take appropriate steps to protect, the Company's trade secrets, confidential information, and other commercially sensitive information.
-
Clause 8.4 (Accuracy): Given the Company's pass-through architecture, the Company does not access or review the content of Inputs or Outputs and is therefore not in a position to assess the accuracy or currency of Customer Personal Data contained therein. The obligation under Clause 8.4 applies only to Customer Personal Data of which the Company becomes aware in the course of providing the Services.
-
Clause 8.5 / 16(d) (Deletion certification): Certification of deletion of Customer Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Customer's written request.
-
Clause 8.6(d) (Personal Data Breach notification): The notification obligations under Clause 8.6(d) of the SCCs shall be subject to the conditions and procedures set out in Section 10 of this DPA.
-
Clause 8.8 (Onward transfers): Any approval by Customer of the Company's appointment of a Sub-Processor constitutes Customer's documented instruction to effect disclosures and onward transfers to such Sub-Processor as required under Clause 8.8 of the SCCs. Onward transfers to Model Providers are made on Customer's instruction as necessary to perform the Service and do not constitute disclosures to Sub-Processors.
-
Clause 8.9 (Audits): The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to the conditions set out in Section 9.2 of this DPA.
-
Module Three, Clause 10(a) (Third-party controllers): For the purposes of Clause 10(a) of Module Three of the SCCs, Customer acknowledges that there are no circumstances in which it would be appropriate for the Company to notify any third-party Controller of a Data Subject Request, and that any such notification shall be the sole responsibility of Customer.
-
Clause 14 (Transfer Impact Assessment): Customer, as data exporter, is solely responsible for conducting any transfer impact assessment required in connection with the transfer of Customer Personal Data to the Company pursuant to these SCCs. The Company shall, upon Customer's reasonable written request, provide information about the legal framework applicable to the Company as a data importer in the United States to assist Customer in conducting such assessment, to the extent such information is available to the Company and its disclosure is not restricted by applicable law. The Company's provision of such information shall not constitute a warranty or representation that the transfer meets the requirements of applicable data protection law.
-
Clause 15.1(a) (Data Subject notifications): For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law, Customer shall be solely responsible for making any notifications to relevant Data Subjects if and as required.
-
Clause 16 (Termination): The obligations of the Company upon termination or expiry of the SCCs, including with respect to the return or deletion of Customer Personal Data, shall be governed by Section 12 of this DPA. Given the Company's no-storage architecture as described in Section 2.3, prompt and output content is not retained by the Company and is therefore not subject to return or deletion upon termination.
Section 12. Return and Deletion of Customer Personal Data
Upon expiration or termination of the Agreement, or upon Customer's written request, the Company shall, to the extent technically feasible and subject to the Company's no-storage architecture described in Section 2.3: (a) delete or return all Customer Personal Data in the Company's possession or control; and (b) certify such deletion in writing upon Customer's request. To the extent that deletion of any Customer Personal Data contained in backups maintained by or on behalf of the Company is not technically feasible within the requested timeframe, the Company shall: (i) securely delete such Customer Personal Data at the next scheduled backup deletion or overwrite cycle in accordance with the Company's standard backup retention policies; and (ii) pending such deletion, put such Customer Personal Data beyond use and ensure it is not actively Processed for any purpose.
Notwithstanding the foregoing, the Company may retain Customer Personal Data where required by Applicable Data Protection Laws or other applicable law (including applicable tax, accounting, and financial record-keeping requirements), provided that the Company shall maintain the confidentiality of all such data and Process it only to the extent and for as long as required by such applicable law.
Given the Company's no-storage architecture, the Company does not store the content of Inputs or Outputs and therefore no prompt content is subject to return or deletion upon termination.
Section 13. US State Privacy Laws
To the extent Applicable Data Protection Laws include US state privacy laws (including the CCPA/CPRA), the following additional terms apply:
-
The Company is a "service provider" (as defined under the CCPA) with respect to Customer Personal Data.
-
Customer discloses Customer Personal Data to the Company solely for the limited and specified business purpose of providing the Services.
-
The Company shall not: (i) sell or share Customer Personal Data; (ii) retain, use, or disclose Customer Personal Data for any purpose other than providing the Services or as permitted by applicable US state privacy laws; (iii) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (iv) combine Customer Personal Data with personal information received from or on behalf of any other person, except as necessary to provide the Services.
-
The Company shall notify Customer in writing if it determines it can no longer meet its obligations under applicable US state privacy laws.
-
Customer has the right, upon such notice, to take reasonable steps to stop and remediate unauthorized use of Customer Personal Data.
-
The Company hereby certifies that it understands and will comply with its obligations under this Section 13.
-
De-identification. To the extent required by State Privacy Laws, and to the extent the Company creates de-identified data from Customer Personal Data (which, given the Company's current no-storage architecture, is not anticipated in the ordinary course of providing the Services), the Company shall: (a) adopt reasonable measures to prevent such de-identified data from being used to infer information about, or otherwise being linked to, any individual; (b) maintain and use such data in de-identified form; and (c) contractually obligate any recipients to comply with the same requirements. This Section will apply to the extent the Company's data processing practices evolve to include de-identification of Customer Personal Data.
Section 14. Customer's Responsibilities
Customer represents, warrants and undertakes that:
-
Customer shall comply with its obligations under Applicable Data Protection Laws in its Processing of Customer Personal Data and in issuing instructions to the Company.
-
Customer has a valid legal basis for the Processing of Customer Personal Data by the Company under the Agreement and this DPA.
-
All Data Subjects have been provided with all required notices and, where required, have given all necessary consents, in each case relating to the Company's Processing of Customer Personal Data.
-
Customer's instructions to the Company shall at all times be lawful and shall not cause the Company to violate Applicable Data Protection Laws.
-
Customer is solely responsible for the accuracy, quality and lawfulness of Customer Personal Data provided to the Company.
Section 15. Liability
The aggregate liability of each party under or in connection with this DPA, whether in contract, tort (including negligence) or otherwise, shall be subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this Section 15 limits any person's liability to Data Subjects under the third-party beneficiary provisions of the SCCs, where applicable.
Section 16. Miscellaneous
-
Amendments. Where changes to this DPA are required to comply with mandatory requirements of Applicable Data Protection Laws (including to implement a new lawful transfer mechanism), the Company may make such amendments unilaterally by providing Customer with at least 15 days' prior written notice, and Customer's continued use of the Services after the effective date of such amendment constitutes acceptance. For all other amendments to this DPA, the parties shall act in good faith to agree on any variations that are commercially reasonable and necessary to address changes in Applicable Data Protection Laws. No such non-mandatory amendment shall be binding unless agreed in writing by both parties.
-
The following Sections will survive termination or expiration of this DPA: Sections 1 (to the extent necessary to interpret surviving provisions), 5, 7, 10, 11, 12, 13, 15, and 16.
-
Prevail. In the event of conflict: (a) this DPA prevails over the Agreement with respect to the Processing of Customer Personal Data; (b) the SCCs prevail over this DPA with respect to the Restricted Transfer to which they apply; and (c) the UK Transfer Addendum prevails over this DPA with respect to UK Restricted Transfers to which it applies.
-
Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall continue in full force.
-
Governing Law. This DPA is governed by the laws of the State of California, without regard to conflict of law principles, except to the extent otherwise required by the SCCs or UK Transfer Addendum.
-
Entire Agreement. This DPA, together with the Agreement, constitutes the entire agreement between the parties with respect to the Processing of Customer Personal Data and supersedes all prior agreements on this subject.
Annex 1. Data Processing Details
| Field | Details |
|---|---|
| Data exporter (Customer) | The entity or person who accepts the Agreement and this DPA. |
| Data importer (Company) | Zenlayer Inc., 21700 Copley Drive Suite 350, Diamond Bar, CA 91765, United States. Contact for data protection: [privacy@zenlayer.com]. |
| Role of Customer | Controller (or Processor, where Customer itself acts as a Processor on behalf of a third party). |
| Role of Company | Processor. |
| Processing Details | Description |
|---|---|
| Categories of Data Subjects | Data Subjects may include any individuals whose Personal Data is contained within Inputs submitted by Customer through the Service, including Customer's employees, contractors, end users, or other individuals whose data Customer causes the Company to process. |
| Categories of Personal Data | Any categories of Personal Data contained within Inputs submitted by Customer through the Service. The Company does not prescribe or control what Personal Data Customer submits. Common categories may include: identifiers (names, email addresses, user IDs); professional information; communications content; and other data included in prompts by Customer. |
| Sensitive Data | Customer may submit special categories of Personal Data (as defined in Article 9 of the EU GDPR) within Inputs at Customer's sole discretion. The Company does not recommend submitting sensitive data given the pass-through nature of the Service. Where sensitive data is submitted, Customer confirms that the technical and organizational measures described in Annex 2 are appropriate for such data. |
| Processing location | United States (routing infrastructure, as updated at https://www.tkex.ai). Model Provider locations vary by model selected and are outside the Company's control. |
| Nature of Processing | Real-time pass-through transmission of Inputs to Model Providers and return of Outputs to Customer. No storage, retention, or further processing of Input or Output content by the Company beyond the transmission itself. |
| Purpose of Processing | To provide the Services as described in the Agreement: routing Customer's API requests to the lowest-cost qualified Model Provider and returning the resulting Outputs. |
| Duration of Processing | For the duration of the Agreement, or until Customer requests deletion of Customer Personal Data, subject to the Company's legal retention obligations. |
| Frequency of Transfer | Continuous — as initiated by Customer through its use of the Services. |
| Sub-Processors | As listed in the Annex 3. |
| Competent Supervisory Authority | For EU Restricted Transfers: the Supervisory Authority of the EEA Member State in which Customer is established, or where Customer is not established in the EEA, the Supervisory Authority of the EEA Member State in which Customer's EU GDPR representative is based. For UK Restricted Transfers: the UK Information Commissioner's Office. |
Annex 2. Security Measures
The Company implements and maintains the following technical and organizational security measures with respect to Customer Personal Data. The Company may update these measures from time to time, provided that such updates do not materially decrease the overall level of security.
Physical Access Controls
Technical and organizational measures to prevent unauthorized physical access to data processing systems, including: establishing restricted security areas; access authorization systems (card readers, key management); locked facilities and door controls; CCTV and alarm systems; security personnel; and securing decentralized equipment.
Logical Access Controls
Technical and organizational measures to prevent unauthorized logical access, including: user authentication and identity management; password policies (complexity requirements, minimum length, mandatory rotation); automatic session locking and timeout; monitoring of unauthorized access attempts; and encryption of data at rest.
Data Access Controls
Technical and organizational measures to ensure that authorized persons access only Personal Data within their access rights, including: role-based access controls; least-privilege principles; monitoring and logging of data access; disciplinary procedures for unauthorized access; and data deletion and change management procedures.
Transmission Security
Technical and organizational measures to protect Personal Data during transmission, including: encryption of data in transit using industry-standard protocols (TLS 1.2 or higher); secure API communications; and logging of data transmissions.
Availability Controls
Technical and organizational measures to protect Personal Data against accidental loss or destruction, including: backup procedures; redundant systems and failover capabilities; uninterruptible power supply; anti-virus and firewall systems; and disaster recovery planning.
Organizational Measures
Organizational measures to support data security, including: confidentiality obligations for all personnel with access to Customer Personal Data; regular security training and awareness; security incident response procedures; and vendor security assessment processes for Sub-Processors.
Annex 3. Sub-Processor List
As of the Effective Date, the Company does not engage any Sub-Processors to process Customer Personal Data in connection with the Services. This Annex will be updated prior to the engagement of any new Sub-Processor in accordance with Section 6.2.