Data Processing Agreement
Last updated: 1 August 2026 · Version: 2026-08-01.4
This Data Processing Agreement ("DPA") forms part of the agreement between the customer entity accepting it ("Customer") and Relixr Ltd ("Relixr") for the Relixr Services. If a signed enterprise agreement conflicts with this DPA, the signed agreement controls. A downloadable standard form is available at /trust/dpa.pdf.
1. Roles
Customer is the controller (or equivalent) of Customer Personal Data contained in prompts, completions, and other customer content submitted via the API. Relixr is the processor (or equivalent) for processing that content to provide the Services as instructed by Customer.
For Relixr account administration, authentication, billing, and Relixr's own product security and abuse-prevention data, Relixr acts as an independent controller as described in the Privacy Policy. That controller processing is outside the scope of this DPA except where the parties expressly agree otherwise.
2. Customer's instructions
Relixr will process Customer Personal Data only to provide the Services, in accordance with Customer's documented configuration (including routing, logging, retention, and guardrails) and Relixr's published security practices, unless required to do otherwise by applicable law (in which case Relixr will notify Customer unless legally prohibited).
3. Security
Relixr implements appropriate technical and organizational measures to protect Customer Personal Data, including encryption in transit, access controls, workspace isolation, hashed API credentials, and controls described at /trust and /security. Customer is responsible for configuring logging and retention settings appropriate to its use case.
4. Subprocessors
Customer authorizes Relixr to engage subprocessors as needed to provide the Services (including infrastructure, payment, and model-provider partners). Relixr will impose data-protection obligations on subprocessors no less protective than those in this DPA. A current list is available on request via the Trust Center access form at /trust/request. Relixr will provide notice of material subprocessor changes by email or in-product notice where legally required. Customer may object to a new subprocessor on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may stop using the affected Services.
5. International transfers
Where Relixr transfers Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, Relixr will ensure appropriate safeguards, including Standard Contractual Clauses (and UK transfer addenda where applicable), unless another lawful transfer mechanism applies.
6. Assistance
Taking into account the nature of processing, Relixr will reasonably assist Customer with data-subject requests, security incidents affecting Customer Personal Data, and Customer's obligations under applicable data-protection law, subject to technical feasibility and verification of Customer's authority.
7. Breach notification
Relixr will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data processed under this DPA, and will provide information reasonably available to help Customer meet its notification obligations.
8. Deletion and return
Upon termination of the Services or Customer's written request, Relixr will delete or return Customer Personal Data in Relixr-controlled logs and stores subject to Customer's logging and retention settings, except data Relixr must retain as an independent controller (for example billing records) or under legal hold.
9. Audits
Upon reasonable written request no more than once per twelve months (unless required by a supervisory authority or following a confirmed breach), Relixr will provide written information reasonably necessary to demonstrate compliance with this DPA. On-site audits require mutual agreement on scope, timing, and confidentiality, and may be subject to reasonable fees where they exceed standard evidence packages.
10. Contact
security@relixr.com
Download: /trust/dpa.pdf
Latest data processing agreement: /trust/dpa