Data protection

Data Processing Addendum

Terms for Elektric's processing of Customer Personal Data on behalf of business customers.

Version 1.0
Last updated: September 4, 2026

1. Scope and roles

This DPA forms part of the agreement where Elektric processes personal data in Customer Content ("Customer Personal Data") for Customer. Customer is controller/business and Elektric processor/service provider, except where each independently processes account, billing, security, legal, or administration data. Data-protection terms have their applicable-law meanings.

2. Instructions and restrictions

Elektric will process Customer Personal Data only on documented instructions in the agreement, feature settings, and API requests; to provide, secure, support, and administer the Service; or as legally required, with notice unless prohibited. Elektric will inform Customer if it believes an instruction violates Data Protection Law. Customer is responsible for lawful instructions, notices, consents, minimization, accuracy, and configuration.

For applicable U.S. state law, Elektric will not sell/share Customer Personal Data; use or disclose it outside specified business purposes; combine it with other-source data except as legally permitted to provide the Service; or use it outside the direct business relationship. Elektric will provide required protection, notify Customer if it can no longer comply, and permit reasonable remediation steps.

3. Confidentiality and security

Elektric will bind authorized personnel to confidentiality and apply Schedule 2 measures. Customer is responsible for credential security, least privilege, end-user security, lawful minimization, and determining whether the Service suits its risk and regulatory requirements.

4. Subprocessors

Customer generally authorizes subprocessors on the Subprocessor List. Elektric will impose appropriate data-protection duties and remain responsible for its DPA obligations. Elektric will provide advance notice and an opportunity to object on documented data-protection grounds.

5. Assistance

Taking account of processing and available information, Elektric will reasonably assist with data-subject requests, security duties, breach notifications, impact assessments, prior consultations, and legally required risk assessments. Customer reimburses reasonable costs where permitted and not caused by Elektric breach.

6. Security incidents

Elektric will notify Customer without undue delay after confirming accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data ("Security Incident"). Notice will include reasonably available information needed for Customer obligations. Elektric will investigate, mitigate, and update. Unsuccessful attempts that do not compromise data are not Security Incidents.

7. Deletion and return

Customer may use controls to delete Conversations, Memory, Knowledge, files, and accounts. At termination/request, Elektric will delete or return Customer Personal Data unless law requires retention, subject to technical limits, backups, security records, and Privacy Policy behavior. Selected financial records may be pseudonymized and retained for seven years after account deletion.

8. Audits

Elektric will provide information reasonably necessary to demonstrate compliance. No more than annually, unless law or a material Security Incident requires more, Customer may request a reasonable remote audit by an independent confidential auditor, without disrupting service or exposing another customer's data. Customer bears reasonable cost unless material Elektric noncompliance is found.

9. International transfers

Parties will use a lawful mechanism where required. For EEA restricted transfers to Elektric in a non-adequate country, the applicable 2021 EU SCCs are intended to apply using Module 2, or Module 3 where Customer is a processor, once properly completed. UK transfers are intended to use the UK Addendum or IDTA as applicable.

10. Schedule 1 — Processing

Subject/purpose: provider-neutral AI inference, routing, context, media/file processing, support, security, usage controls, and related infrastructure requested by Customer. Duration: agreement term plus feature/legal retention. Activities: receipt, transmission, hosting, organization, retrieval, inference, transformation, generation, indexing, logging, support, security review, deletion, and return.

Data subjects: Customer personnel, Authorized Users, application end users, customers, prospects, contractors, and others whose data Customer submits. Data: identifiers; account/contact data; prompts, messages and Outputs; Conversation, Memory, Knowledge, files, images/audio/video/documents and tool results; usage, network, routing, security, and billing metadata. Frequency: as initiated by Customer. Sensitive data is not required; Customer must not submit it without legal authority and confirmed safeguards.

11. Schedule 2 — Measures

  • Cloudflare edge infrastructure and TLS for HTTPS endpoints.
  • Project API keys stored as hashes and shown once; separate dashboard sessions and machine credentials.
  • OAuth-token application encryption configuration and hashed magic-link tokens.
  • Project roles, membership authorization, and scoped data queries.
  • Server-side provider/payment credentials in Cloudflare secrets.
  • Payload, rate, concurrency, spend, job, file, health, and capacity controls.
  • File type/size/signature checks, private no-store delivery, one-hour default expiry, and asynchronous deletion.
  • SSRF protections including scheme, address, redirect, byte, page, and time limits.
  • Structured telemetry/monitoring and scheduled 90-day raw-telemetry deletion.
  • Stripe-hosted card entry; no full card details stored by Elektric.
  • Account purge and pseudonymization of selected retained financial records.

No SOC 2, ISO 27001, HIPAA, PCI, or other certification is represented.

12. Priority and liability

This DPA controls conflicts concerning Customer Personal Data; mandatory SCC terms control conflicts with this DPA. DPA liability is subject to the agreement's liability terms unless expressly agreed otherwise.