Legal

Data Processing Agreement

Version2026-07-30Effective30 July 2026

Summary

For customers whose personal data we process on their behalf, principally personal data contained in the datasets, models, and agent traffic they bring to the platform. This is a contract intended to be executed by both parties, not a click-through; enterprise procurement teams will normally want it signed alongside a Master Services Agreement.

This summary is for readability only. The full text below is what applies.

Status of this document

This is a DRAFT for review by counsel. It is published here so customers can see our position in advance, but it is intended to be executed as a signed agreement alongside a Master Services Agreement, not accepted by ticking a box.

To request an executable copy, contact hello@origina.cloud.

1. Definitions

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in applicable data protection law (including the GDPR where it applies). "Customer Personal Data" means personal data we process on the customer's behalf under this agreement.

"Subprocessor" means a third party engaged by us to process Customer Personal Data. "Applicable Data Protection Law" means the data protection and privacy laws that apply to the processing.

2. Roles and scope

Where a customer uploads or licenses data containing personal data, or routes traffic through an agent, the customer is the Controller and Origina is the Processor, acting only on the customer's documented instructions.

For personal data about the customer's own users of the Origina platform (names, emails, logins), Origina is the Controller and its Privacy Policy applies, not this agreement.

This agreement applies to our processing of Customer Personal Data and prevails over any conflicting term about data protection in the general Terms of Service.

3. Customer instructions

We will process Customer Personal Data only on the customer's documented instructions, including as to international transfers, unless required to do otherwise by law, in which case we will inform the customer first, unless the law forbids it.

The customer's instructions are this agreement, the customer's use of the platform's features, and any further written instructions the parties agree. The customer is responsible for the lawfulness of the instructions and of the data it provides.

We will inform the customer if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law.

4. Nature, purpose, and duration

Nature and purpose of processing: storage, integrity verification and checksums, security scanning, access control, metering, delivery of licensed assets, and proxying of agent calls, all to provide the platform.

Duration: for the term of the customer's use of the platform, plus any period genuinely required by law.

5. Categories of data and data subjects

The categories of personal data and of data subjects depend on what the customer chooses to upload or process and are therefore determined by the customer.

6. Our obligations as processor

Process Customer Personal Data only as set out in this agreement and on documented instructions.

Ensure that personnel authorised to process Customer Personal Data are bound by an obligation of confidentiality.

Implement and maintain the technical and organisational security measures described in Section 8.

Respect the conditions in Section 9 for engaging Subprocessors.

Assist the customer, so far as reasonably possible given the nature of the processing and the information available to us, with responding to data subject requests and with the customer's obligations on security, breach notification, and data protection impact assessments.

At the customer's choice, delete or return Customer Personal Data at the end of the relationship, except where retention is required by law.

Make available the information reasonably necessary to demonstrate compliance with this agreement.

7. Confidentiality

We keep Customer Personal Data confidential and limit access to personnel who need it to provide the platform, each bound by confidentiality obligations, and we do not use it for any purpose other than providing the service.

8. Security measures

We maintain measures appropriate to the risk, including: encryption of credentials at rest and of data in transit; authenticated, membership-verified access to organization data; hashing of passwords and API-key secrets; append-only audit logging of security-relevant events; rate limiting on sensitive endpoints; and validation of user-supplied URLs to reduce server-side request forgery.

We review these measures over time and may update them, provided the level of protection is not materially reduced.

9. Subprocessors

The customer gives general authorisation for us to engage Subprocessors to process Customer Personal Data, provided each is bound by data-protection obligations no less protective than those in this agreement, and we remain responsible for their performance.

We will inform the customer of intended changes to Subprocessors and give the customer a reasonable opportunity to object on reasonable data-protection grounds.

10. Assistance and data subject requests

If we receive a request from a data subject relating to Customer Personal Data, we will not respond directly (except to confirm the request should be directed to the customer) and will forward it to the customer without undue delay.

We will provide reasonable assistance to enable the customer to respond to such requests and to meet its own obligations, taking into account the nature of the processing and the information available to us.

11. Personal data breach notification

We will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information reasonably available to us at the time, and will provide further information as it becomes available.

We will take reasonable steps to mitigate and, where appropriate, to remediate the breach. This notification is not an acknowledgement of fault or liability.

12. International transfers

Our infrastructure is currently hosted in the European Union. We will not transfer Customer Personal Data to a third country except on the customer's instructions or as necessary to provide the platform, and only with an appropriate transfer mechanism in place.

13. Audits

We will make available information reasonably necessary to demonstrate compliance with this agreement and will allow for and contribute to audits, including inspections, conducted by the customer or an auditor it mandates.

Audits are subject to reasonable prior notice, confidentiality, and reasonable limits on frequency and scope so as not to disrupt the platform or compromise the security of other customers.

14. Return or deletion of data

On termination of the platform relationship, and at the customer's choice, we will return or delete Customer Personal Data, and delete existing copies, except to the extent retention is required by law, in which case we will keep it only for as long, and only for the purpose, that the law requires.

15. Liability and precedence

This agreement forms part of, and is subject to, the Master Services Agreement or Terms of Service between the parties, including their limitations of liability.

Questions about this document? Contact hello@origina.cloud

Back to top ↑