Data Processing Agreement (DPA)
Last updated: July 25, 2026 · Effective for all LogionOS service agreements
1. Parties
This Data Processing Agreement ("DPA") is entered into between:
- Data Controller ("Customer"): The entity that has signed a LogionOS service agreement.
- Data Processor ("LogionOS"): LogionOS, Inc., a Delaware corporation.
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person processed through the Service.
- Processing: Any operation performed on Personal Data, including collection, storage, analysis, and deletion.
- Sub-processor: A third party engaged by LogionOS to process Personal Data on behalf of the Customer.
3. Scope of Processing
LogionOS processes data solely for the purpose of providing AI compliance checking services.
| Category | Details |
|---|---|
| Subject Matter | AI compliance checking, PII detection, audit trail generation |
| Duration | For the term of the Service Agreement plus 30 days |
| Nature & Purpose | Real-time regulatory compliance analysis of AI model inputs/outputs |
| Types of Personal Data | AI prompts/responses that may contain PII (names, emails, identifiers) |
| Categories of Data Subjects | End users of Customer's AI-powered applications |
4. Customer Obligations
- Ensure lawful basis for processing Personal Data through the Service.
- Provide transparent privacy notices to data subjects.
- Not intentionally submit prohibited categories of sensitive data unless covered by a specific addendum.
5. LogionOS Obligations
- Process Personal Data only on documented instructions from the Customer.
- Ensure all personnel with access are bound by confidentiality obligations.
- Implement and maintain appropriate technical and organizational security measures (see Section 7).
- Assist the Customer with data subject requests (access, rectification, erasure, portability).
- Delete or return all Personal Data upon termination, at Customer's election.
- Make available all information necessary to demonstrate compliance and allow audits.
6. Sub-processors
LogionOS may use the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Render | API hosting and compute | United States |
| Vercel | Dashboard hosting (CDN) | Global (US-based) |
| OpenAI / Anthropic | LLM Judge (Deep Path only) | United States |
| Resend | Transactional email delivery | United States |
Customer will be notified 30 days before any new sub-processor is engaged. Customer may object in writing within 14 days.
7. Security Measures
- Encryption in transit (TLS 1.2+) and Fernet authenticated encryption (AES-128-CBC with HMAC-SHA256) for stored keys.
- API key authentication with SHA-256 hashing — raw keys never stored.
- Per-key IP allowlisting available.
- Rate limiting with standard HTTP headers.
- Hash-chained audit trails with SHA-256 chain verification.
- PII detection and masking at the application layer.
- Security headers (HSTS, X-Content-Type-Options, X-Frame-Options).
- Role-based access control (RBAC) with four permission levels.
8. Data Breach Notification
LogionOS will notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach. Notification will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
9. International Transfers
If Personal Data is transferred outside the EEA, LogionOS will ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as adopted by the European Commission (2021/914).
10. Data Retention & Deletion
- Audit logs: retained for the duration of the agreement.
- AI check data: retained for 90 days, then auto-purged (configurable).
- Upon termination: all Customer data deleted within 30 days, with certification upon request.
11. Legacy Creator Risk Layer (discontinued) — Historical Processing Addendum
The Legacy Creator Risk Layer is discontinued and is not a currently offered service. This section survives solely to document historical processing obligations for customers that used the former Team tier or higher.
11.1 Historical Scope of Processing
When authorized users ran historical /v1/creator-check calls through the Chrome extension or Dashboard, LogionOS processed the following Personal Data on the Customer's instructions:
- Authenticated user identifier, including email address and Clerk user ID.
- Team membership records linking users to the Customer's team.
- A hash of the check payload, not raw text by default, plus action_type, target_venues, fired rule IDs, safety_status, and timing metadata.
- Hash-chained session receipt entries and usage counters for users and teams.
11.2 Historical Shared Workspace Processing
Team customers authorized session receipts and usage counters to be visible to authorized members of the same team, subject to Dashboard role-based access controls and the Customer's instructions.
11.3 Historical Stripe & Clerk Subprocessors
The following subprocessors supported historical Creator Risk Layer processing in addition to Section 6:
- Stripe, Inc. — subscription billing, billing portal, and webhook delivery; processed billing contact details and payment-method metadata in the United States.
- Clerk, Inc. — Dashboard identity and authentication; processed email addresses and session metadata in the United States.
Applicable data processing agreements and transfer safeguards, including Standard Contractual Clauses where required, governed those historical transfers.
11.4 Historical Product Boundary
Historical processing supported risk signals and workflow guidance only. LogionOS did not make legal determinations, and customers remained responsible for published content and compliance decisions based on service outputs.
11.5 Receipt Export & Deletion
Customers could export session receipts or receipt bundles. Upon a valid Customer request or termination of the historical subscription, LogionOS was required to delete Creator Risk Layer receipts, usage counters, and telemetry within 30 days. Certification of deletion remains available on written request where applicable.
12. Governing Law
This DPA is governed by the laws of the State of Delaware, USA, except where mandatory data protection laws require otherwise (e.g., GDPR).
To execute this DPA, contact us at legal@logionos.com with your company name and service agreement reference number.