Effective date: June 17, 2026
This Data Processing Agreement (this "DPA") forms part of, and is incorporated into, the Terms of Use or other written or clicked-through agreement between Vault Garden Oy ("Infersec", "we", "us", "our", or "Processor") and the entity that has accepted it ("Customer", "you", or "Controller") governing your use of the Infersec platform and related services (the "Agreement"). Capitalised terms used but not defined in this DPA have the meanings given to them in the Agreement.
This DPA applies where Infersec processes Personal Data on behalf of Customer in the provision of the Services. The parties agree to comply with this DPA with effect from the Effective Date.
1. Definitions
- "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where control means the direct or indirect ownership of more than fifty percent (50%) of the voting interests of the subject entity.
- "Applicable Data Protection Laws" means all privacy and data protection laws and regulations applicable to a party's processing of Personal Data under the Agreement, as amended, superseded, or replaced from time to time, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the "GDPR"), the United Kingdom General Data Protection Regulation and Data Protection Act 2018 (the "UK GDPR"), the Swiss Federal Act on Data Protection (the "revFADP"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA").
- "Console Data" means message content, tool-call arguments and results, and related configuration that Customer intentionally submits to the Console chat playground for testing or evaluation purposes. Console Data is Customer Data.
- "Contact Data" means the Personal Data that Infersec processes as a controller, such as account-holder identity, billing contact details, and correspondence with Infersec personnel.
- "Controller" means the entity that, alone or jointly with others, determines the purposes and means of the processing of Personal Data, and includes equivalent terms under Applicable Data Protection Laws (such as "business" under the CCPA).
- "Customer Data" means the Personal Data processed by Infersec on behalf of Customer in the provision of the Services, including account-user identity, Customer's usage metadata, API credentials, Console Data, and billing-related data tied to Customer's account.
- "Data Subject" means an identified or identifiable natural person to whom Personal Data relates, and includes equivalent terms under Applicable Data Protection Laws (such as "consumer" under the CCPA).
- "EEA" means the European Economic Area.
- "Personal Data" means any information relating to a Data Subject that is processed as a result of the Agreement, and includes equivalent terms under Applicable Data Protection Laws (such as "personal information" under the CCPA).
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, combination, restriction, erasure, or destruction.
- "Processor" means the entity that processes Personal Data on behalf of the Controller, and includes equivalent terms under Applicable Data Protection Laws (such as "service provider" under the CCPA).
- "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data. Security Incidents do not include unsuccessful attempts that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, or similar network attacks.
- "Service-Generated Data" means usage and technical metadata generated through the provision of the Services (such as aggregated token counts and reliability metrics), to the extent such data constitutes Personal Data.
- "Services" means the Infersec platform and related services made available to Customer under the Agreement.
- "Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Implementing Decision (EU) 2021/914, as updated or replaced from time to time.
- "Sub-processor" means any third party (including an Affiliate of Infersec) authorised by Infersec to process Customer Data in order to provide the Services.
2. General; Term; Termination
- This DPA forms part of the Agreement. Where this DPA conflicts with the Agreement, this DPA prevails with respect to the processing of Personal Data.
- Any liability arising under this DPA is subject to the limitations of liability in the Agreement.
- This DPA takes effect on the Effective Date and remains in force until Infersec has deleted or returned all Customer Data in accordance with Section 11, or as otherwise required by Applicable Data Protection Laws.
3. Relationship of the Parties
- Infersec as Processor. With regard to Customer Data, Customer acts as a Controller (or as a Processor instructing Infersec) and Infersec acts as a Processor. Infersec processes Customer Data only on behalf of, and in accordance with, Customer's documented instructions as described in Section 5.
- Infersec as Controller. With regard to Contact Data and any Service-Generated Data that Infersec processes as a controller, Infersec determines the purposes and means of that processing in accordance with its Privacy Policy and Applicable Data Protection Laws. Schedule 1 does not apply to data Infersec processes as a controller.
- Customer as Controller. Customer is responsible for the accuracy, quality, and legality of Customer Data and the means by which Customer acquired it.
4. Compliance with Laws
Each party complies with its respective obligations under Applicable Data Protection Laws in connection with its processing of Personal Data under the Agreement.
5. Role and Scope of Processing; Customer Instructions
- Customer responsibilities. Customer is responsible for obtaining and maintaining all consents, providing all notices, and establishing a valid legal basis necessary for Infersec to lawfully process Customer Data for the purposes contemplated by the Agreement. Customer warrants that it has complied, and will continue to comply, with all Applicable Data Protection Laws applicable to its collection and provision of Customer Data.
- Customer instructions. Infersec processes Customer Data only on Customer's documented and lawful instructions, including the instructions necessary to provide the Services. By entering into the Agreement, Customer instructs Infersec to process Customer Data (a) to perform Infersec's obligations under the Agreement; (b) to comply with Applicable Data Protection Laws to which Infersec is subject; and (c) to establish, exercise, or defend legal claims. Where Infersec becomes aware that an instruction infringes Applicable Data Protection Laws, Infersec will inform Customer without undue delay.
- No sale; no training. Infersec does not sell or share Customer Data, and does not retain, use, or disclose Customer Data for any purpose other than providing the Services or as otherwise permitted by this DPA. Infersec does not use Customer Data (including prompts, completions, and tool-call payloads) for model training, fine-tuning, or any other machine-learning purpose.
- Inference data is not persisted. Prompt content, completions, and tool-call payloads processed through the public inference path are processed in memory only, for the duration of the active request, and are discarded immediately on completion. Such data is never written to disk, logged, or stored in any database. Tool-call payloads relayed through server-side tool interception (such as MCP interception) are processed in plain text in memory for the duration of the request and discarded on completion.
- Shared responsibility for Customer-controlled infrastructure. Customer acknowledges that the Conduit agent, the local AI engines it proxies (such as vLLM or llama.cpp), and any MCP server endpoints Customer configures are owned and controlled by Customer, and that Infersec does not operate, access, or control them. Customer is solely responsible for the security, configuration, and legal compliance of that infrastructure and for any Personal Data processed on it.
- Console Data. Customer intentionally submits Console Data to the Console chat playground. Infersec processes Console Data as Customer Data, subject to the retention and deletion terms of this DPA.
6. Sub-processing
- General authorisation; back-to-back terms; liability. Customer authorises Infersec to engage Sub-processors to process Customer Data in order to provide the Services. Infersec enters into a written agreement with each Sub-processor imposing data-protection obligations substantially similar to those in this DPA. Infersec remains liable for compliance with this DPA and for any act or omission of a Sub-processor that causes Infersec to breach this DPA.
- List of Sub-processors. The current list of Sub-processors, including their functions and processing locations, is set out in the Annex to this DPA. Infersec updates the Annex when a new Sub-processor is engaged or an existing one is removed.
- Notice and objection. Infersec will notify Customer of the addition or replacement of a Sub-processor by updating the Annex and, where Customer has requested notice in writing, by informing Customer at the contact details associated with its account. If Customer has a reasonable, documented objection on data-protection grounds, Customer may notify Infersec in writing within ten (10) calendar days of the notice. The parties will discuss the objection in good faith. If the parties cannot resolve it, Customer's sole and exclusive remedy is to terminate the Agreement (or the affected portion of the Services) without penalty by providing written notice, and Customer will remain liable for fees accrued up to the date of termination.
7. Security
- Security Measures. Infersec implements and maintains the technical and organisational measures described in Schedule 2 (the "Security Measures") to protect Customer Data from Security Incidents and to preserve its confidentiality, integrity, availability, and resilience. Infersec may update the Security Measures from time to time, provided that the updates do not materially reduce the level of protection compared to the Effective Date.
- Customer responsibility. Customer is responsible for reviewing the Security Measures and making an independent determination as to whether the Services meet Customer's requirements and legal obligations. Customer is responsible for securing its authentication credentials, API keys, systems, and devices, and for the configuration choices it makes within the Services.
- Security Incident notification. On becoming aware of a confirmed Security Incident, Infersec will notify Customer without undue delay and will provide reasonable information about the Security Incident and the measures Infersec has taken or proposes to take to mitigate its effects, to the extent such information is available. Infersec's notification is not an acknowledgement of fault or liability. Customer is solely responsible for complying with any Security Incident notification obligations it has toward Data Subjects, regulators, or third parties.
8. Audits and Reviews of Compliance
- Independent assurance. Where Infersec has obtained independent third-party assurance reports (such as SOC 2 Type II or ISO/IEC 27001) relevant to the Security Measures, Infersec will, on Customer's written request at reasonable intervals and subject to reasonable confidentiality obligations, make available a copy of the most recent report or a suitable summary.
- Customer audits. To the extent required by Applicable Data Protection Laws, Customer may audit Infersec's compliance with this DPA, provided that: (a) Customer gives Infersec reasonable prior written notice; (b) the audit is conducted no more than once per calendar year except where triggered by a Security Incident or a binding instruction from a competent regulator; (c) the audit is conducted at Customer's expense, during normal business hours, in a manner that does not disrupt Infersec's operations; and (d) Customer complies with Infersec's reasonable security and confidentiality requirements. Infersec will reasonably cooperate with such an audit.
9. Impact Assessments and Consultations
Infersec will provide reasonable cooperation to Customer, to the extent Infersec has access to the relevant information, in connection with Customer's data-protection impact assessments and prior consultations with supervisory authorities required under Applicable Data Protection Laws, taking into account the nature of the processing and the information available to Infersec.
10. Data Subject Requests
- Self-service. Customer is primarily responsible for responding to requests from Data Subjects exercising their rights under Applicable Data Protection Laws. To the extent Customer cannot reasonably fulfil a request using the self-service functionality of the Services, Infersec will, on Customer's written request, provide reasonable assistance at Customer's expense.
- Direct requests. If Infersec receives a request from a Data Subject concerning Customer Data, Infersec will advise the Data Subject to submit the request to Customer and will not respond directly except to confirm receipt and redirect the request, or as required by Applicable Data Protection Laws.
11. Return or Deletion of Customer Data
- During the term. Customer may export or delete Customer Data through the functionality of the Services at any time while the Agreement is in effect.
- On termination. On termination or expiration of the Agreement, Customer instructs Infersec to delete all Customer Data within thirty (30) days, except to the extent Infersec is required by law to retain it. Personal Data retained under this exception remains subject to this DPA for the duration of the retention period.
12. International Provisions
- Location of processing. Infersec processes Customer Data exclusively within the EEA, on infrastructure operated by Scaleway in the Netherlands. Of the Sub-processors listed in the Annex, only Scaleway processes Customer Data, and it does so within the EEA. The remaining Sub-processors do not process Customer Data: HuggingFace syncs only public model-catalog metadata; Tailscale carries only operational VPN metadata; and Plausible processes only marketing-website analytics. Stripe processes payment data under its own agreements and its own data-transfer mechanisms; Infersec does not receive or store full card details and transfers to Stripe only the minimal identifiers required to initiate a payment or issue an invoice.
- Customer responsibility. Customer acknowledges that the public Services are accessible globally and that Customer is responsible for compliance with any cross-border transfer obligations applicable to Customer's own transfer of Personal Data into the Services.
- Standard Contractual Clauses. To the extent that the processing of Customer Data ever requires a transfer mechanism to lawfully transfer Personal Data to a country outside the EEA, the Standard Contractual Clauses are deemed incorporated into this DPA by reference and apply as described in Schedule 3.
- Jurisdiction-specific terms. The additional terms in Schedule 4 apply where Customer Data is subject to the Applicable Data Protection Laws of the jurisdictions listed there.
Schedule 1: Subject Matter and Details of Processing
This Schedule 1 sets out the details required by Article 28(3) of the GDPR.
- Nature and purpose. Infersec processes Customer Data as necessary to provide the Services, including operating Customer's account, routing and metering inference requests, recording aggregated usage for billing, maintaining API credentials, and supporting the Console chat playground. Infersec does not sell Customer Data and does not use it for model training.
- Activities. Collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure by transmission, and deletion of Customer Data, as further described in this DPA.
- Duration. For the term of the Agreement, plus the deletion period in Section 11, except where a longer retention is required by law.
- Categories of Data Subjects. Customer's authorised users, and the end users, contacts, and other individuals whose Personal Data is included in Customer Data, to the extent Customer submits such Personal Data to the Services.
- Categories of Personal Data. Account-user identity (name, email address); authentication data (password hashes, API-key hashes); account and billing-related data (company name, billing country, VAT identifier, payment transaction records maintained for accounting); aggregated and per-request usage metrics (token counts, request counts, latency, success rates); machine metadata relating to Customer's connected inference sources; and Console Data (message content and tool-call arguments and results submitted to the Console chat playground). Full payment card details are never received or stored by Infersec; they are handled by Stripe.
- Sensitive data. Customer must not submit special categories of personal data (as defined in Article 9 of the GDPR), or equivalent sensitive data under other Applicable Data Protection Laws, to the Services. If Customer does so, it does so at its own risk and Infersec has no liability for the consequences.
Schedule 2: Technical and Organisational Measures
Infersec maintains the following measures, which are appropriate to the nature, scope, context, and purposes of the processing and the risks it presents.
- Hosting and network isolation. Customer Data is processed and stored on managed infrastructure operated by Scaleway in the Netherlands (Amsterdam region) within the EEA. The primary MySQL database and the Redis cluster are isolated on a Scaleway private network and are not directly reachable from the public internet. The Overseer background service runs on a private, non-publicly-exposed container. Operational access to the private network is mediated through a bastion instance over an encrypted mesh VPN (Tailscale).
- Encryption in transit. Data in transit between Customer (or its end users) and the public Services is protected using TLS. Internal payloads exchanged between application instances over Redis are protected using authenticated encryption (AES-256-GCM) with keys derived through argon2id.
- Encryption at rest. Data at rest benefits from the managed encryption capabilities of the underlying Scaleway database, object storage, and container platform services. Database backups are managed by the infrastructure provider.
- Access control and authentication. User passwords are hashed using argon2id. Access to the Console requires authenticated sessions backed by signed cookies and a Redis-backed session store. API access requires hashed API keys scoped to roles. Infrastructure secrets (database credentials, signing keys, payment-provider keys) are stored in the Scaleway secret store and injected at runtime; they are not committed to source control.
- Least-privilege and change management. Administrative access is granted on a least-privilege basis over the mesh VPN. Changes to the production environment are made through a managed deployment pipeline. Application logs are reviewed as part of normal operations.
- Data minimisation on the inference path. Prompt content, completions, and tool-call payloads processed through the public inference path are handled in memory only and are not persisted, logged, or written to any database.
- No secondary use of Customer Data. Customer Data is not used for model training, fine-tuning, or any machine-learning purpose.
- Retention and deletion. Personal Data is retained only as long as necessary for the purposes described in this DPA. Account records follow the soft-delete pattern and are removed in line with the Privacy Policy and Section 11 of this DPA. Aggregated usage metrics are pruned on a schedule (hourly aggregates are removed after seven (7) days, daily aggregates after one (1) year). Website early-access entries, where their IP is captured, store only a salted hash of the IP address, not the raw address, and are hard-deleted on expiry.
- Reliability and recovery. The infrastructure provider supplies managed database backups and multi-zone resilience. Application availability is monitored, and incidents are triaged through the normal operations process.
- Personnel. Access to production systems is restricted to authorised personnel. Personnel are bound by confidentiality obligations.
- Vulnerability management. Dependencies are kept current through the normal build and deployment process. Security issues identified through review or reported externally are triaged and remediated according to severity.
- Sub-processor controls. Each Sub-processor is bound by written terms requiring it to protect Customer Data to a standard substantially similar to this DPA and to support Infersec's obligations under this DPA.
Schedule 3: Cross-Border Transfer Mechanism
- Current posture. As of the Effective Date, Infersec processes Customer Data exclusively within the EEA. Scaleway, the only Sub-processor that processes Customer Data, also operates within the EEA. No Customer Data is transferred to a country outside the EEA. Accordingly, the Standard Contractual Clauses are not currently triggered for the transfer of Customer Data.
- Deemed incorporation. To the extent that a transfer mechanism becomes necessary for the lawful transfer of Customer Data to a country outside the EEA, the Standard Contractual Clauses (Module Two: controller-to-processor, or Module Three: processor-to-processor, as applicable) are deemed incorporated into this DPA by reference and apply automatically, without further action by either party, as follows:
- In Clause 7, the optional docking clause applies.
- In Clause 9, Option 2 applies, and the prior-notice period for Sub-processor changes is as set out in Section 6 of this DPA.
- In Clause 11, the optional language applies.
- In Clause 17 (Option 1), the Standard Contractual Clauses are governed by the laws of Finland.
- In Clause 18(b), disputes are resolved before the courts of Finland.
- Annex I, Part A: the data exporter is Customer; the data importer is Vault Garden Oy (Y-tunnus 3431968-5, Näkinkaari 4 A, 02320 Espoo, Finland; contact: infersec@vault.garden). The roles of the parties are as described in Section 3.
- Annex I, Part B: the details of the processing are as described in Schedule 1; the transfer is on a continuous basis for the duration of the Agreement.
- Annex I, Part C: the competent supervisory authority is the Finnish Data Protection Ombudsman, or, where another authority has primary jurisdiction under the GDPR, that authority.
- Annex II is Schedule 2 of this DPA.
- Conflict. Where the Standard Contractual Clauses and this DPA conflict, the Standard Contractual Clauses prevail with respect to the transfer they govern.
- UK and Swiss transfers. With respect to transfers subject to the UK GDPR, the UK International Data Transfer Addendum (the "UK IDTA") is deemed incorporated into this DPA and extends the Standard Contractual Clauses. With respect to transfers subject to the revFADP, the Standard Contractual Clauses apply with the Swiss-adaptation terms set out in Schedule 4.
Schedule 4: Jurisdiction-Specific Terms
This Schedule 4 applies in addition to the body of this DPA where Customer Data is subject to the Applicable Data Protection Laws of the relevant jurisdiction.
4.1 Finland and the EEA
- This DPA is governed by the laws of Finland, and the courts of Finland have exclusive jurisdiction over any disputes arising under or in connection with it, consistent with the governing-law provision of the Agreement.
- When engaging a Sub-processor, Infersec imposes written terms on the Sub-processor that meet the requirements of Article 28(3) and (4) of the GDPR, including sufficient guarantees to implement appropriate technical and organisational measures.
- Nothing in this DPA requires Infersec to act on instructions that infringe the GDPR.
- Regulatory fines. Each party remains responsible for any administrative fines issued against it under Article 83 of the GDPR as a result of its own breach of the GDPR, and nothing in this DPA or the Agreement is to be read as one party indemnifying the other against such fines.
4.2 United Kingdom
- Applicable Data Protection Laws includes the UK GDPR and the Data Protection Act 2018.
- For transfers of Customer Data subject to the UK GDPR, the UK IDTA applies as described in Section 3 of Schedule 3.
- The competent supervisory authority for transfers governed by the UK IDTA is the Information Commissioner's Office.
- References to the GDPR in this DPA are read as including the UK GDPR, with "EU" or "Member State" read as including the United Kingdom where the context permits.
4.3 Switzerland
- Applicable Data Protection Laws includes the revFADP.
- References to "GDPR" are read as including the revFADP, and references to "Data Subject", "Personal Data", "Controller", and "Processor" include their equivalents under the revFADP.
- With respect to transfers subject to the revFADP, the Standard Contractual Clauses apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner, including that: (a) they are not subject to the exemption for pure domestic transfers; (b) Swiss law may be chosen as the governing law where a Swiss authority is the competent supervisory authority; and (c) the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers from Switzerland that are not subject to the jurisdiction of another EEA or UK authority.
- The term "Data Subject" includes legal persons until the entry into force of the revised Swiss Data Protection Act provisions concerning legal persons.
4.4 California
- Applicable Data Protection Laws includes the CCPA.
- The terms "business", "commercial purpose", "service provider", "sell", "share", and "personal information" have the meanings given to them in the CCPA.
- With respect to Customer Data that Infersec processes as a Processor under Section 3.1 of this DPA:
- Infersec is a service provider under the CCPA, and Customer is the business.
- Infersec will not (a) sell or share Customer Data; (b) retain, use, or disclose Customer Data for any purpose other than providing the Services, including for a commercial purpose other than providing the Services; or (c) retain, use, or disclose Customer Data outside the direct business relationship between the parties.
- Infersec will not combine Customer Data with personal information that Infersec receives from or on behalf of another person, except as permitted by the CCPA.
- Infersec certifies that it understands the restrictions in this Section 4.4 and will comply with them.
- Customer gives Infersec written notice of its right to monitor Infersec's compliance with the CCPA, and the audit terms in Section 8 apply to such monitoring.
- To the extent Infersec processes personal information as a Controller under Section 3.2 of this DPA, Infersec acts as a business under the CCPA and processes such data in accordance with its Privacy Policy and the CCPA.
Annex: Sub-processors
The following third parties provide services that support the provision of the Services, as of the Effective Date. Only Scaleway processes Customer Data; the others are listed for transparency and do not process Customer Data, as described in the Function column. Locations are within the EEA unless otherwise stated.
| Sub-processor | Function | Location |
|---|---|---|
| Scaleway | Infrastructure hosting (managed database, Redis, object storage, serverless containers, container registry); transactional email delivery | Netherlands (EU) |
| Stripe | Payment processing, invoicing, and tax/VAT validation. Card data is received and stored by Stripe; Infersec does not receive or store full card details | Locations determined by Stripe's agreements with Customer |
| HuggingFace | Optional synchronisation of public model-catalog metadata only. No Customer Data is transferred to HuggingFace | Determined by HuggingFace |
| Tailscale | Encrypted mesh VPN used solely for operational (bastion) access to the private network. No Customer Data is transferred to or stored by Tailscale | Infrastructure provider (no Customer Data) |
| Plausible | Optional, privacy-focused analytics for the public marketing website only. No Customer Data is processed | Determined by Plausible |
Infersec will update this Annex when a Sub-processor is added, replaced, or removed.
Contact
For questions about this DPA, contact us at:
Vault Garden Oy (Y-tunnus 3431968-5) Näkinkaari 4 A, 02320 Espoo, Finland Email: infersec@vault.garden