Trust

v2026-08-01.4 · immutable link · sha256:7ab038d86fad

Data Processing Agreement

Last updated: 1 August 2026 · Version: 2026-08-01.4

This Data Processing Agreement ("DPA") forms part of the agreement between the customer entity accepting it ("Customer") and Relixr Ltd ("Relixr") for the Relixr Services. If a signed enterprise agreement conflicts with this DPA, the signed agreement controls. A downloadable standard form is available at /trust/dpa.pdf.

1. Roles

Customer is the controller (or equivalent) of Customer Personal Data contained in prompts, completions, and other customer content submitted via the API. Relixr is the processor (or equivalent) for processing that content to provide the Services as instructed by Customer.

For Relixr account administration, authentication, billing, and Relixr's own product security and abuse-prevention data, Relixr acts as an independent controller as described in the Privacy Policy. That controller processing is outside the scope of this DPA except where the parties expressly agree otherwise.

2. Customer's instructions

Relixr will process Customer Personal Data only to provide the Services, in accordance with Customer's documented configuration (including routing, logging, retention, and guardrails) and Relixr's published security practices, unless required to do otherwise by applicable law (in which case Relixr will notify Customer unless legally prohibited).

3. Security

Relixr implements appropriate technical and organizational measures to protect Customer Personal Data, including encryption in transit, access controls, workspace isolation, hashed API credentials, and controls described at /trust and /security. Customer is responsible for configuring logging and retention settings appropriate to its use case.

4. Subprocessors

Customer authorizes Relixr to engage subprocessors as needed to provide the Services (including infrastructure, payment, and model-provider partners). Relixr will impose data-protection obligations on subprocessors no less protective than those in this DPA. A current list is available on request via the Trust Center access form at /trust/request. Relixr will provide notice of material subprocessor changes by email or in-product notice where legally required. Customer may object to a new subprocessor on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may stop using the affected Services.

5. International transfers

Where Relixr transfers Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, Relixr will ensure appropriate safeguards, including Standard Contractual Clauses (and UK transfer addenda where applicable), unless another lawful transfer mechanism applies.

6. Assistance

Taking into account the nature of processing, Relixr will reasonably assist Customer with data-subject requests, security incidents affecting Customer Personal Data, and Customer's obligations under applicable data-protection law, subject to technical feasibility and verification of Customer's authority.

7. Breach notification

Relixr will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data processed under this DPA, and will provide information reasonably available to help Customer meet its notification obligations.

8. Deletion and return

Upon termination of the Services or Customer's written request, Relixr will delete or return Customer Personal Data in Relixr-controlled logs and stores subject to Customer's logging and retention settings, except data Relixr must retain as an independent controller (for example billing records) or under legal hold.

9. Audits

Upon reasonable written request no more than once per twelve months (unless required by a supervisory authority or following a confirmed breach), Relixr will provide written information reasonably necessary to demonstrate compliance with this DPA. On-site audits require mutual agreement on scope, timing, and confidentiality, and may be subject to reasonable fees where they exceed standard evidence packages.

10. Contact

security@relixr.com

Download: /trust/dpa.pdf

Latest data processing agreement: /trust/dpa