Data processing agreement

For business customers. Your agents' work is opened only inside sealed chips. We never see it, and you can check this yourself. If it holds personal data, like your customers' names, the law still calls this processing on your behalf. So this agreement is here, as the law requires.

Last updated 2 October 2026

The short version

Contents
  1. 1. Parties and how this agreement applies
  2. 2. What we process, and why
  3. 3. Your instructions
  4. 4. Your duties
  5. 5. People who handle the data
  6. 6. Security
  7. 7. Our partners (sub-processors)
  8. 8. Data outside the EU
  9. 9. Helping you
  10. 10. Data breaches
  11. 11. End of the service
  12. 12. Audits
  13. 13. Records
  14. 14. Liability
  15. 15. Duration
  16. Annex 1. Details of the processing
  17. Annex 2. Security measures
  18. Annex 3. Sub-processors

1. Parties and how this agreement applies

1.1. This agreement is between you, the business customer named at checkout, and COMPANY_LEGAL_NAME (SIREN), COMPANY_ADDRESS. You are the controller: the one who decides why and how personal data is used. We are the processor: the one who handles personal data only on the controller's behalf. Your content is opened only inside sealed chips, and we never see it (Annex 2). The law still counts this as processing (GDPR Art. 4(2)), so we take on a processor's duties in full. This agreement is part of our Terms of service and applies from the moment you accept them. Nothing extra needs to be signed.

1.2. It applies whenever your content, as defined in the Terms, contains personal data. If you are yourself a processor for someone else, we are your sub-processor, and you confirm your controller has authorized our use.

1.3. If this agreement and the Terms differ on personal data, this agreement wins.

1.4. Private buyers. This agreement does not apply if you buy as a private person for your own use. We then handle your content as controller, as our privacy notice explains.

1.5. Words used here have the meaning given in the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"). "Personal data breach" means a security incident that leads to personal data being lost, destroyed, changed, disclosed or accessed without authorization.

2. What we process, and why

The subject, duration, nature and purpose of the processing, and the types of data and people concerned, are in Annex 1.

3. Your instructions

3.1. We process your personal data only on your documented instructions. Your instructions are: these Terms and this agreement, and the requests you or your users send through your keys. Using the service as designed is an instruction.

3.2. We may process it otherwise only if EU or French law requires it. If so, we tell you first, unless that law forbids it.

3.3. If we think an instruction breaks data protection law, we tell you, and we may refuse to follow it.

3.4. Never trained on. We do not use your personal data, or any of your content, to train, test or improve any AI model, for our own purposes, or for anyone else.

4. Your duties

4.1. You are responsible for having a legal basis to send us the data, for telling the people concerned, and for the accuracy of what you send.

4.2. Sensitive data. Special categories of data (health, religion, biometrics and others under GDPR Art. 9) and data about criminal offences need extra care. If you send them, you confirm you have checked that our measures in Annex 2 are enough for your use, including any impact assessment you need (GDPR Art. 35). Do not send us health data that French law requires a certified health data host to handle (article L1111-8 of the French public health code). We are not certified for that.

5. People who handle the data

Everyone who works for us and could access personal data is bound to secrecy, by contract or by law, and gets only the access their job needs. Today that is the founder only. Our staff never see your content: they have no way into the sealed chips where it is opened, and outside them it is only ever encrypted (Annex 2).

6. Security

We take the technical and organizational measures in Annex 2, as GDPR Article 32 requires. We may improve them, but we will not make them weaker overall.

7. Our partners (sub-processors)

7.1. You give us general permission to use the sub-processors listed in Annex 3.

7.2. We tell you at least 30 days before we add or replace a sub-processor that handles your content, by email to your billing email and on this page. You may object in that time for a reasonable data protection reason. If we can't resolve it, you may end the contract before the change, and we pay back the unused part of your current month and any credit left.

7.3. Each sub-processor is bound by a written contract with data protection duties at least as strict as these. We stay fully responsible to you for their work (GDPR Art. 28(4)).

8. Data outside the EU

8.1. Your content, and any other personal data we handle for you, is processed and kept only in the European Union. We do not send it outside the EU.

8.2. Every sub-processor in Annex 3 is a company based in the EU, and none belongs to a group based outside the EU. Their servers are in the EU. The providers they use to hold our data meet the same rule.

8.3. If an authority outside the EU asks us for your data, we do not hand it over unless EU or French law, or an international agreement, requires it (GDPR Art. 48). We tell you first, unless that law forbids it.

8.4. To change any of this, we would have to change this agreement, with at least 30 days' notice. You could then end the contract before the change applies, as in section 7.2.

9. Helping you

9.1. People's rights. If someone asks us directly to see, fix or delete their data in your content, we pass the request to you and do not answer it ourselves. Because your content is wiped within an hour and never kept, we usually hold nothing to give or delete. We help you with any request as far as we reasonably can.

9.2. Other duties. We give you the information you reasonably need for your security, impact assessments and consultations with authorities (GDPR Art. 32 to 36), including this agreement and its annexes.

10. Data breaches

10.1. If we become aware of a personal data breach affecting your data, we tell you without undue delay, and in any case within 48 hours, at your billing email. Please also send a security contact to PRIVACY_EMAIL if you want notices to go there too.

10.2. We tell you what we know: what happened, the data and people likely concerned, the likely effects, and what we are doing about it. If we don't know everything yet, we tell you in steps.

10.3. We take reasonable steps to stop the breach and limit harm. We do not notify authorities or the people concerned on your behalf unless you ask us to, since that duty is yours as controller.

11. End of the service

11.1. Your content is wiped automatically within an hour after a key goes quiet (Annex 1), so at the end of the contract there is no content left to return or delete. The request logs, which hold no content, are deleted after 7 days at most.

11.2. Account and billing records are not your content. We handle them as controller, under our privacy notice.

12. Audits

12.1. We make available the information needed to show we meet this agreement and GDPR Article 28, starting with this agreement, its annexes, and the public checks for agents and for Laya, with the published source and fingerprint of the software that runs in the sealed chips.

12.2. You may audit us once a year, or after a personal data breach, with 30 days' notice. You may do it yourself or use an independent auditor bound to secrecy. Audits take place during business hours, and must not harm our other customers or our security. You pay for the audit, unless it finds a serious breach by us.

13. Records

We keep a record of the processing we do for our customers, as GDPR Article 30(2) requires.

14. Liability

Each party's liability under this agreement follows the Terms, including the limits there, as far as the GDPR allows. Nothing here limits anyone's liability toward the people whose data it is.

15. Duration

This agreement lasts as long as we process personal data for you under the Terms, and ends after that. Sections 3.4, 10 and 11 apply even after it ends.

Annex 1. Details of the processing

SubjectRunning AI models on the content you send through your keys (agents, Spot and Laya), and sending back the answers
DurationEach request: while it runs. Paused conversations: at most one hour after the key goes quiet (5 to 60 minutes depending on size; the clock restarts while the key is busy; may be wiped sooner to make room). The agreement: as long as the Terms
Nature of processingReceiving over an encrypted connection that ends inside the sealed chips; splitting text into tokens (the small pieces a model works with); making short fingerprints of text pieces in memory, so a paused conversation can continue without being sent again; running the model; keeping paused conversations in memory; sending the answer; wiping
PurposeOnly to provide the service to you
People concernedWhoever appears in your content, as you decide: for example your staff, your customers, your contacts
Types of personal dataWhatever you put in your content: for example names, contact details, messages, documents, source code with author names. Special categories only if you send them (section 4.2)
WhereIn memory, inside sealed chips, on servers in the EU: agents in AGENTS_COUNTRY (Verda), Laya in LAYA_LOCATION (LAYA_HOST_PROVIDER)
What is never doneWriting content to disk or to logs; training or improving models with it; selling or sharing it; opening it outside the sealed chips
What is kept about each requestA technical log line with no content and no account: time, request id, model, sizes, status. Deleted after 7 days at most

Annex 2. Security measures

Sealed processing (agents and Spot)

On the way

Content in memory only

Access

Checking it yourself

Limits of the seal

Payments

Logs

Database

People and process

Annex 3. Sub-processors

All of them are companies based in the EU, none belongs to a group based outside the EU, and their servers are in the EU (section 8).

Partners that may handle your content:

PartnerWhat they doYour contentWhere
VERDA_LEGAL_ENTITY (Verda)Rents us the sealed servers that run agentsIn memory only, inside sealed chips that Verda can't see intoAGENTS_COUNTRY, EU
LAYA_HOST_PROVIDERRents us the sealed server that runs LayaText sent to Laya, in memory only, inside a sealed chip that the host can't see intoLAYA_LOCATION, EU

Partners that never receive your content, listed so you have the full picture. They handle account and billing data, for which we are the controller (see our privacy notice):

PartnerWhat they doWhere
PAYMENT_PROVIDERPayments and invoicesPAYMENT_LOCATION, EU
HOSTING_PROVIDERHosts the website and account pageHOSTING_LOCATION, EU
DATABASE_PROVIDERDatabaseDATABASE_LOCATION, EU
EMAIL_PROVIDEROur emailEMAIL_LOCATION, EU