Data Processing Addendum

Effective date: [Effective date]

This is a template DPA published for review during private preview. It is not executed by default. For an executed DPA, contact hello@jouledns.com.

1. Roles

For personal data contained in API request and response content, the customer is the controller and JouleCloud (operated by [Legal entity name]) is the processor. JouleCloud is an independent controller of account and billing data it needs to run the service.

2. Scope and purpose of processing

JouleCloud processes prompts, completions, and usage metadata solely to provide the service: routing requests to GPUs, producing responses, metering usage, enforcing budgets and rate limits, and preventing abuse. No processing for training or advertising.

3. Subprocessors

The subprocessors listed in the Privacy Policy are engaged under terms no less protective than this addendum. We will update the published list before adding a subprocessor that touches customer request content.

4. Security

Technical and organizational measures are described on the Security page: TLS in transit, server-side secret handling, org-scoped keys, and per-organization limits.

5. Breach notification

JouleCloud will notify the customer without undue delay, and in any case within [Notification window, e.g. 72 hours], after becoming aware of a personal data breach affecting customer data.

6. Deletion

On termination of the service relationship, JouleCloud deletes customer request logs and organization data within the retention windows stated in the Privacy Policy, except where retention is required for billing integrity or by law.

7. International transfers

No specific international transfer mechanism is claimed during the private preview: [Transfer mechanism if applicable].

8. Governing law

This addendum is governed by the laws of [Jurisdiction], and is subordinate to the Terms of Service.