Data Processing Agreement (DPA)

Last updated: July 25, 2026 · Effective for all LogionOS service agreements

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

2. Definitions

3. Scope of Processing

LogionOS processes data solely for the purpose of providing AI compliance checking services.

CategoryDetails
Subject MatterAI compliance checking, PII detection, audit trail generation
DurationFor the term of the Service Agreement plus 30 days
Nature & PurposeReal-time regulatory compliance analysis of AI model inputs/outputs
Types of Personal DataAI prompts/responses that may contain PII (names, emails, identifiers)
Categories of Data SubjectsEnd users of Customer's AI-powered applications

4. Customer Obligations

5. LogionOS Obligations

6. Sub-processors

LogionOS may use the following sub-processors:

Sub-processorPurposeLocation
RenderAPI hosting and computeUnited States
VercelDashboard hosting (CDN)Global (US-based)
OpenAI / AnthropicLLM Judge (Deep Path only)United States
ResendTransactional email deliveryUnited States

Customer will be notified 30 days before any new sub-processor is engaged. Customer may object in writing within 14 days.

7. Security Measures

8. Data Breach Notification

LogionOS will notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach. Notification will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

9. International Transfers

If Personal Data is transferred outside the EEA, LogionOS will ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as adopted by the European Commission (2021/914).

10. Data Retention & Deletion

11. Legacy Creator Risk Layer (discontinued) — Historical Processing Addendum

The Legacy Creator Risk Layer is discontinued and is not a currently offered service. This section survives solely to document historical processing obligations for customers that used the former Team tier or higher.

11.1 Historical Scope of Processing

When authorized users ran historical /v1/creator-check calls through the Chrome extension or Dashboard, LogionOS processed the following Personal Data on the Customer's instructions:

11.2 Historical Shared Workspace Processing

Team customers authorized session receipts and usage counters to be visible to authorized members of the same team, subject to Dashboard role-based access controls and the Customer's instructions.

11.3 Historical Stripe & Clerk Subprocessors

The following subprocessors supported historical Creator Risk Layer processing in addition to Section 6:

Applicable data processing agreements and transfer safeguards, including Standard Contractual Clauses where required, governed those historical transfers.

11.4 Historical Product Boundary

Historical processing supported risk signals and workflow guidance only. LogionOS did not make legal determinations, and customers remained responsible for published content and compliance decisions based on service outputs.

11.5 Receipt Export & Deletion

Customers could export session receipts or receipt bundles. Upon a valid Customer request or termination of the historical subscription, LogionOS was required to delete Creator Risk Layer receipts, usage counters, and telemetry within 30 days. Certification of deletion remains available on written request where applicable.

12. Governing Law

This DPA is governed by the laws of the State of Delaware, USA, except where mandatory data protection laws require otherwise (e.g., GDPR).

To execute this DPA, contact us at legal@logionos.com with your company name and service agreement reference number.