Data Processing Addendum
Abliteration AI, Inc.
Effective October 8, 2026
This Data Processing Addendum ("DPA") supplements and forms part of the agreement, order form, or terms governing Customer's use of the Services (the "Agreement") between the customer identified in the Agreement ("Customer") and Abliteration AI, Inc. ("Company"). This DPA applies when Company Processes Customer Personal Data on Customer's behalf in providing the Services. Capitalized terms not defined here have the meanings given in the Agreement.
This DPA becomes effective on the date it is incorporated into the Agreement, accepted through a Company-provided acceptance mechanism, or signed by both parties, whichever occurs first (the "Effective Date").
Definitions
Applicable Data Protection Law. Means the privacy, data protection, and data security laws applicable to Company's Processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, and applicable comprehensive U.S. state privacy laws.
Customer Personal Data. Means Personal Data Processed by Company on behalf of Customer to provide the Services. It excludes Company Account Data and Company Usage Data to the extent Company Processes those data as an independent Controller for account administration, billing, security, fraud prevention, service improvement using data that does not include Customer Content, legal compliance, or other purposes described in the Agreement.
Company Account Data. Means business contact, account, authentication, subscription, and billing information relating to Customer's relationship with Company.
Company Usage Data. Means service, security, audit, diagnostic, and operational metadata generated from use of the Services, excluding Customer Content except where content is lawfully retained for a specific feature, security purpose, or legal obligation described in the Agreement.
Controller, Processor, Process, Processing, Personal Data, Personal Data Breach, and Data Subject. Have the meanings assigned to them under Applicable Data Protection Law.
Services. Means the products and services described in the Agreement.
Subprocessor. Means a third party engaged by Company to Process Customer Personal Data on behalf of Customer in connection with the Services.
Scope, Roles, and Instructions
Roles. Customer is the Controller or a Processor acting on behalf of another Controller, and Company is the Processor or Subprocessor, as applicable, with respect to Customer Personal Data. Each party will comply with its obligations under Applicable Data Protection Law.
Documented Instructions. The Agreement, this DPA, Customer's use and configuration of the Services, and other written instructions accepted by Company constitute Customer's documented instructions. Company will Process Customer Personal Data only on those instructions, including with respect to international transfers, unless Applicable Data Protection Law requires otherwise. Where legally permitted, Company will inform Customer before Processing required by law.
Processing Details. The subject matter, nature, purpose, duration, categories of Personal Data, and Data Subjects are described in Exhibit A.
Unlawful Instructions. Company will inform Customer if, in Company's reasonable opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected Processing until the parties resolve the issue.
Company Obligations
Confidentiality. Company will ensure that persons authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and access it only as necessary to perform their duties.
Data Subject Requests. Taking into account the nature of the Processing, Company will provide reasonable assistance through available product functionality or other appropriate measures to help Customer respond to requests from Data Subjects. If Company receives a request relating to Customer Personal Data, Company may direct the requester to Customer and will not respond on Customer's behalf unless authorized by Customer or required by law.
Regulatory Assistance. Taking into account the nature of the Processing and information available to Company, Company will provide reasonable assistance with Customer's obligations concerning security, Personal Data Breaches, data protection impact assessments, and prior consultation with a supervisory authority, in each case to the extent required by Applicable Data Protection Law.
Government Requests. Unless legally prohibited, Company will notify Customer of a legally binding demand for Customer Personal Data and will direct the requesting authority to Customer where reasonably practicable. Company will not voluntarily provide Customer Personal Data to a government authority except as authorized by Customer or required by law.
Security
Security Program. Company will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures in Exhibit C describe Company's current security controls and may be updated so long as the overall level of protection is not materially reduced.
Shared Responsibility. Customer is responsible for securely configuring and using the Services, protecting credentials and API keys, managing its users and permissions, and ensuring that Customer's systems and instructions are appropriate for the Personal Data it submits.
Subprocessors
General Authorization. Customer generally authorizes Company to engage Subprocessors to provide the Services. Company's current Subprocessor information is available through the Abliteration Trust Center.
Changes. Company will provide notice of a new Subprocessor that will Process Customer Personal Data at least thirty (30) days before that Subprocessor begins Processing, using the Trust Center, in-product notice, email, or another reasonable method. Customer is responsible for subscribing to available Trust Center notifications.
Objections. Customer may object in writing during the notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If no commercially reasonable resolution is available, Customer may stop using the affected portion of the Services and terminate that affected portion as permitted by the Agreement. Any refund or fee consequence is governed by the Agreement.
Flow Down and Responsibility. Company will impose data-protection obligations on each Subprocessor that are no less protective, in all material respects, than the obligations applicable to Company under this DPA. Company remains responsible for its Subprocessors' performance of those obligations to the extent required by Applicable Data Protection Law and subject to the Agreement.
Personal Data Breaches
Notice. Company will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Information and Cooperation. As information becomes reasonably available, Company will provide details sufficient for Customer to meet applicable notification obligations and will take reasonable steps to contain, investigate, mitigate, and remediate the Personal Data Breach. A notice is not an admission of fault or liability.
Return and Deletion
Customer Instructions. During the term, Customer may use Service functionality made available for that purpose to access, export, or delete Customer Personal Data. Upon expiration or termination of the Agreement, Company will, at Customer's choice and subject to the Agreement, return or delete Customer Personal Data and existing copies.
Permitted Retention. Company may retain Customer Personal Data only to the extent required or permitted by applicable law or reasonably necessary for billing, fraud prevention, security, tax, audit, dispute, or compliance purposes. Any retained Customer Personal Data will remain protected under this DPA, be restricted from unrelated use, and be deleted when the applicable retention need ends.
Backups. Customer Personal Data remaining in backups or other recovery systems will be protected from active use and deleted or overwritten through Company's documented backup lifecycle, unless a longer period is required by law.
International Transfers
Transfer Mechanisms. Company may Process Customer Personal Data in the United States and other locations where Company or its authorized Subprocessors operate. Where Applicable Data Protection Law requires a transfer mechanism, Company will use an adequacy decision, the Standard Contractual Clauses, the UK Addendum, or another valid safeguard.
European Economic Area. For restricted transfers subject to the EU GDPR, the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated by reference. Module Two applies when Customer is a Controller and Company is a Processor. Module Three applies when Customer is a Processor and Company is a Subprocessor. The EU SCCs are completed as described in Exhibit B.
United Kingdom. For restricted transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 ("UK Addendum") is incorporated by reference and completed as described in Exhibit B.
Switzerland. For restricted transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with references to the EU GDPR interpreted to include the Swiss Federal Act on Data Protection, the competent authority being the Swiss Federal Data Protection and Information Commissioner for transfers governed by Swiss law, and the term "Member State" not limiting Swiss Data Subjects from enforcing rights in Switzerland.
Conflict. The EU SCCs or UK Addendum prevail over this DPA to the extent of a conflict concerning a restricted transfer.
United States Privacy Requirements
Service Provider and Processor. To the extent applicable, Company acts as Customer's service provider, contractor, or processor under U.S. comprehensive privacy laws. The parties acknowledge that Customer does not sell Customer Personal Data to Company.
Restrictions. Company will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship with Customer, or combine it with Personal Data received from other sources, except as directed by Customer or otherwise permitted by applicable law to provide the Services, maintain security and integrity, prevent fraud, comply with law, or perform another business purpose specified in the Agreement or Exhibit A.
Compliance. Company will notify Customer if it determines that it can no longer meet applicable U.S. privacy-law obligations. Upon reasonable notice that Company is Processing Customer Personal Data in violation of those obligations, the parties will work in good faith to stop and remediate the unauthorized Processing.
Compliance Information and Audits
Information. Upon reasonable written request and subject to appropriate confidentiality protections, Company will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, security summaries, certifications, or independent assessment materials then available through the Trust Center.
Audit. If the information made available is insufficient to satisfy a requirement of Applicable Data Protection Law, Customer may request an audit no more than once in any twelve-month period, unless a Personal Data Breach or supervisory authority requires otherwise. Audits must be conducted during normal business hours, on reasonable advance notice, by an independent auditor bound by confidentiality, at Customer's expense, and without unreasonable disruption or access to other customers' information. The parties will agree in advance on scope, timing, and security safeguards.
Customer Responsibilities and Regulated Data
Lawful Data. Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for providing all required notices and obtaining all necessary rights, consents, and lawful bases for Company to Process it under this DPA.
Special Categories. No special-category Personal Data under Article 9 of the EU GDPR, criminal-conviction data, or protected health information ("PHI") is intended to be Processed through the ordinary Services. If such data is included incidentally or unexpectedly, it remains Customer Personal Data protected under this DPA, and Customer remains responsible for satisfying any additional legal requirements applicable to that data.
PHI. Customer may submit PHI only after the parties execute a Business Associate Agreement and Company confirms in writing that the applicable Service and configuration are eligible for PHI Processing. Execution of this DPA alone does not authorize PHI Processing or make every Service feature HIPAA eligible.
General
Order of Precedence. If this DPA conflicts with the Agreement regarding the Processing of Customer Personal Data, this DPA controls. The Agreement otherwise remains in effect, including its limitations of liability, exclusions, governing law, and dispute terms, except where the EU SCCs or UK Addendum require otherwise.
Affiliates. Customer enters into this DPA for itself and, where required by Applicable Data Protection Law, its permitted Affiliates that use the Services under the Agreement. Customer remains the single point of contact and is responsible for coordinating its Affiliates' instructions.
Changes. Company may update this DPA to reflect changes in law, the Services, or security practices, provided the update does not materially reduce protections for Customer Personal Data during an active Order Form without Customer's agreement, unless the change is required by law.
Notices. Privacy and data-protection notices to Company may be sent to [email protected] with the subject line "Privacy" or by the notice method in the Agreement.
Exhibit A — Details of Processing
| Subject matter | Providing, securing, supporting, and administering the Services described in the Agreement. |
|---|---|
| Nature and purpose | Receiving, transmitting, structuring, accessing, using, generating, routing, securing, monitoring, troubleshooting, and deleting Customer Personal Data as necessary to provide the Services on Customer’s instructions; authenticate users and API clients; administer organizations, projects, permissions, usage, and billing; deliver model inference and customer-enabled tools; provide support; prevent abuse and fraud; maintain reliability; and comply with law. |
| Duration | For the term of the Agreement and the period reasonably necessary afterward to complete return, deletion, security, billing, tax, audit, dispute, and legal obligations, subject to Section 7. |
| Frequency | Continuous or intermittent, depending on Customer’s use of the Services. |
| Categories of Data Subjects | Customer users, administrators, employees, contractors, customers, end users, business contacts, and other individuals whose Personal Data Customer or its users include in Customer Content or customer-enabled tool requests. |
| Categories of Customer Personal Data | Business contact and account identifiers; organization and membership information; authentication and authorization metadata; API-client and project identifiers; network, device, IP-address, user-agent, request, security, audit, and diagnostic metadata; support communications; usage and subscription information; and Customer Content, prompts, messages, tool inputs, URLs, uploaded content, and generated outputs to the extent they contain Personal Data. Payment-card data is processed by Company’s payment provider rather than stored as full card data by Company. |
| Special-category data and PHI | Not intended under the ordinary Services. If included incidentally or unexpectedly, it remains protected as Customer Personal Data. PHI may be submitted only under a separate executed Business Associate Agreement and through a Service and configuration Company has confirmed in writing as eligible. |
| Core inference content | Processed to generate and deliver Customer-requested outputs. The particular providers, regions, retention behavior, and optional storage features depend on the Service and configuration described in the Agreement, documentation, or Order Form. |
| Optional web search and fetch | When Customer enables or invokes a web-search or fetch feature, the relevant query, URL, and associated request data may be sent to an authorized search or retrieval provider to perform Customer’s instruction. |
| Subprocessor transfers | Authorized Subprocessors Process Customer Personal Data only as necessary to provide their contracted portion of the Services and for the duration required to do so, subject to Section 5. |
Exhibit B — International Transfer Details
Parties.
| Data exporter | The Customer identified in the Agreement. Address and contact information are stated in the Agreement or applicable Order Form. |
|---|---|
| Exporter role | Controller or Processor, as applicable. |
| Data importer | Abliteration AI, Inc. |
| Importer address | 425 Page Mill Rd., Palo Alto, CA 94306, United States |
| Importer contact | [email protected], subject line Privacy |
| Importer role | Processor or Subprocessor, as applicable. |
| Activities | As described in the Agreement, this DPA, and Exhibit A. |
| Signature | The parties’ acceptance of the Agreement or this DPA constitutes signature of the incorporated transfer clauses. |
EU Standard Contractual Clauses.
| Applicable modules | Module Two for Controller-to-Processor transfers; Module Three for Processor-to-Subprocessor transfers. |
|---|---|
| Clause 7 | The optional docking clause does not apply. |
| Clause 9 | Option 2, general written authorization, applies. The notice period is thirty (30) days as stated in Section 5. |
| Clause 11 | The optional redress language does not apply. |
| Clause 13 | The competent supervisory authority is determined under Clause 13 based on the Data Exporter and the applicable law. |
| Clause 17 | Option 1 applies. The EU SCCs are governed by the law of Ireland. |
| Clause 18 | The courts of Ireland have jurisdiction. |
| Annex I | The parties and transfer details appear in Exhibit A and Exhibit B. |
| Annex II | The technical and organizational measures appear in Exhibit C. |
| Annex III | Current Subprocessor information is available through the Abliteration Trust Center. |
UK Addendum.
| Start date | The Effective Date of this DPA. |
|---|---|
| Parties and contacts | As stated in B1 above. |
| Selected SCCs | The EU SCCs and modules identified in B2 above. |
| Appendix information | Exhibit A, Exhibit B, and Exhibit C of this DPA. |
| Ending the UK Addendum if approved terms change | Importer and Exporter may end the UK Addendum as permitted by the mandatory clauses. |
| Mandatory clauses | The mandatory clauses of the ICO’s International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 in force 21 March 2022, as revised or replaced, are incorporated by reference. |
Exhibit C — Technical and Organizational Measures
Company maintains a risk-based security program appropriate to the nature and scope of the Services. The following measures describe the current control categories without representing that every measure applies identically to every Service component.
| Access control | Role-based and least-privilege access; unique accounts; multifactor authentication for privileged systems where supported; access approval, review, and removal procedures; and controlled service identities. |
|---|---|
| Authentication and secrets | Secure authentication, protected API keys and credentials, managed secret storage, credential rotation, and restrictions on administrative and production access. |
| Encryption | Industry-standard encrypted transport, including TLS 1.2 or higher where supported, and provider-managed encryption at rest for production data stores and storage systems. |
| Network and infrastructure security | Cloud network segmentation, firewalls and access controls, edge protection, restricted administrative paths, secure configuration baselines, and monitoring of in-scope infrastructure. |
| Logging and monitoring | Security, authentication, administrative, application, infrastructure, and operational events are logged and monitored according to risk, with alerting and incident escalation for material events. |
| Secure development and change management | Version control, peer review or documented approved exceptions, automated checks, dependency and secret scanning, controlled deployment workflows, testing, change records, and separation of production and test environments. |
| Vulnerability management | Risk-based vulnerability identification, dependency monitoring, remediation tracking, infrastructure review, and periodic penetration testing or equivalent independent testing appropriate to the Services. |
| Resilience and recovery | Managed cloud resilience, backup and recovery controls for authoritative stored data, monitoring, incident response, business continuity and disaster-recovery procedures, and periodic testing appropriate to service criticality. |
| Data minimization and retention | Collection and retention are limited according to service purpose, customer configuration, legal obligations, and documented retention practices. Customer Content is not used for unrelated purposes. Deletion and disposal procedures apply to production systems, backups, logs, and third-party providers according to their respective lifecycles. |
| Personnel security | Confidentiality obligations, security awareness training, least-privilege access, and documented onboarding and offboarding controls for personnel with access to Company systems or Customer Personal Data. |
| Vendor management | Risk-based review of material service providers; contractual privacy and security obligations; access and data minimization; and periodic reassessment of critical vendors and Subprocessors. |
| Incident response | Documented identification, containment, investigation, remediation, recovery, communication, and post-incident review procedures, including the Personal Data Breach obligations in Section 6. |
| Physical security | Physical and environmental safeguards are provided primarily by the cloud and data-center providers used to deliver the Services. Company personnel work from controlled endpoints subject to Company security requirements. |
| Assurance | Company maintains compliance evidence and makes current assurance status and relevant security materials available through its Trust Center. This DPA does not claim a certification or audit report that has not been completed and issued. |