Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the Terms of Service (the "Agreement") between Routero Intelligence Pte. Ltd. ("Provider") and the customer entity that has accepted the Agreement ("Customer"). It governs the processing of Personal Data by Provider on Customer's behalf when Customer uses the Routero AI service (the "Service").
In case of conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Personal Data.
1. Definitions
Applicable Data Protection Law — the EU GDPR, the UK GDPR, the UK Data Protection Act 2018, the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), Singapore's PDPA, and any other privacy or data-protection law applicable to a processing activity under this DPA.
Personal Data, Controller, Processor, Sub-processor, Data Subject, Processing — meanings under the EU GDPR (or equivalent under other Applicable Data Protection Law).
Customer Personal Data — Personal Data contained in Customer Content or otherwise processed by Provider on Customer's behalf in connection with the Service.
2. Roles
In connection with Customer Personal Data, Customer is the Controller and Provider is the Processor.
Where Customer's end users are themselves the controllers of Personal Data they submit through Customer (e.g., where Customer offers an end-user-facing application), Customer must ensure its agreements with those end-user controllers permit processing through the Service in accordance with this DPA.
In all events, Customer represents and warrants that it has a lawful basis under Applicable Data Protection Law for the processing it instructs Provider to carry out.
3. Subject matter and details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Routero AI Gateway service: routing inference requests to upstream LLM providers, providing administrative APIs, and storing usage records. |
| Duration | The term of the Agreement plus the post-termination period set out in §11. |
| Nature and purpose | Forwarding prompts to upstream LLM providers; returning responses; persisting account, usage, and audit data; sending operational alerts. |
| Categories of Data Subjects | Customer's authorized users (admins, developers, internal staff); end users of Customer's downstream application(s) where Customer uses the Service to power user-facing features; any individual whose data is included in a prompt submitted by Customer. |
| Categories of Personal Data | Identifiers (email, user_id, sso_user_id, end_user, requester IP); authentication artifacts (hashed passwords, salts, hashed API keys); usage metadata (timestamps, costs, tokens); the content of prompts and responses (which may include any category of Personal Data Customer chooses to submit, including special categories — see §4); team/organization membership; audit-log artifacts. |
| Special categories | Submission of special categories (Article 9 GDPR) is at Customer's discretion. Customer must ensure a lawful basis exists for any such processing. Provider does not classify, separate, or apply heightened protection to special-category data submitted in prompts; Customer should treat the storage layer accordingly. |
4. Customer instructions
Provider processes Customer Personal Data only on documented instructions from Customer, which include:
- The Agreement and this DPA;
- The configuration choices Customer makes in the Service (provider selection, key permissions, rate limits, caching toggles, retention setup, content-moderation hooks if Customer enables them);
- Lawful written instructions from Customer's authorized representative.
Provider will inform Customer if, in Provider's opinion, an instruction infringes Applicable Data Protection Law.
5. Sub-processors
Customer authorizes Provider to engage Sub-processors to process Customer Personal Data, subject to:
- Maintaining a current Sub-processor list (see the Subprocessors page);
- Imposing on each Sub-processor data protection obligations no less protective than those in this DPA;
- Remaining responsible for each Sub-processor's compliance with this DPA;
- Giving Customer at least 10 days prior notice of any new Subprocessor (Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection in good faith, Customer may terminate the affected portion of the Service).
Important: upstream LLM providers (OpenAI, Anthropic, Google, AWS Bedrock, Azure OpenAI, etc.) act as Sub-processors of inference traffic. Their data-handling and training-on-data practices are governed by their own contracts. Customer is responsible for confirming each upstream provider's training-on-data position with respect to Customer's traffic and exercising any available opt-outs (e.g., OpenAI's "do not use my data for training" toggle, Anthropic's enterprise terms).
6. International transfers
Customer acknowledges that Customer Personal Data may be transferred across borders when the Service forwards Customer Content to upstream model providers selected, enabled, configured, credentialed, or routed to by Customer.
Where Provider transfers Customer Personal Data from Singapore to a recipient outside Singapore through Provider’s own infrastructure Sub-processors or other recipients engaged by Provider, Provider will take appropriate steps required under Singapore’s PDPA to ensure comparable protection.
Where Customer selects, enables, configures, provides credentials for, or routes traffic to an upstream model provider, Customer is responsible for reviewing the relevant provider terms, privacy policy, data-processing terms, data-residency options, retention practices, training-on-data practices, and cross-border transfer mechanisms.
Where Customer Personal Data is transferred internationally and applicable data protection law requires a transfer mechanism, the parties will use an applicable lawful transfer mechanism, which may include adequacy decisions, Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, Swiss adaptations, certifications, contractual protections, or other mechanisms permitted by applicable law.
7. Confidentiality
Provider shall ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
8. Security
Provider implements and maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. Current measures are described in the Security Overview. Provider may update those measures provided that the level of protection is not reduced.
9. Personal data breach notification
If Provider becomes aware of a Personal Data Breach affecting Customer Personal Data, Provider will:
- Notify Customer without undue delay after it has credible grounds to believe that such breach has occurred and, where feasible, within seventy-two (72) hours. Customer remains responsible for assessing whether the breach is notifiable and for notifying regulators or affected individuals, except to the extent Applicable Data Protection Law imposes such obligation directly on Provider;
- Provide such information as Customer reasonably requires to comply with its own notification obligations (nature of the breach, categories and approximate number of data subjects, likely consequences, measures taken or proposed);
- Cooperate with Customer's investigation.
10. Data subject requests
Provider will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligations to respond to data subject requests.
The Service does not currently expose automated subject-access endpoints. Where Customer needs to extract Customer Personal Data for a request, Customer may export from the management UI/API or contact privacy@routero.ai for assistance.
11. Deletion and return on termination
Upon termination of the Agreement, Provider will, at Customer's choice:
- Delete all Customer Personal Data (including spend logs containing prompts/responses) within 30 days, or
- Return Customer Personal Data to Customer in a structured, commonly-used, machine-readable format and then delete it, unless retention is required by Applicable Data Protection Law or by an order of a competent authority.
12. Audits
On reasonable prior written notice and not more than once per year (except where a Personal Data Breach has occurred or where required by a regulator), Provider will make available to Customer the information necessary to demonstrate compliance with this DPA, including:
- The latest available SOC 2, ISO 27001, or equivalent third-party audit report, where Provider holds one;
- Responses to a reasonable security questionnaire;
- For Customers with regulatory obligations that require it, on-site or remote audit access on reasonable terms (Customer bears its own audit costs; Provider may charge for Provider-time at standard professional-services rates).
13. Customer's controller obligations
Customer represents and warrants that:
- It has a lawful basis under Applicable Data Protection Law for each category of processing instructed;
- It has made all required disclosures and obtained all required consents from data subjects;
- It will not submit content to the Service that violates Applicable Data Protection Law or this DPA;
- It will exercise (or instruct end-user controllers to exercise) any training-on-data opt-outs available from upstream LLM providers where such opt-outs are required by Customer's risk posture or by Customer's own contracts.
14. CCPA/CPRA terms
To the extent Provider processes Personal Information of California residents on Customer's behalf:
- Provider is a "Service Provider" / "Contractor" as defined under the CCPA/CPRA;
- Provider will not sell or share Personal Information for cross-context behavioural advertising;
- Provider will not retain, use, or disclose Personal Information outside the direct business relationship between Provider and Customer or for any purpose other than the business purposes specified in the Agreement;
- Provider will not combine Personal Information received from Customer with Personal Information received from another source or collected from Provider's own interaction with the data subject, except as permitted by 11 CCR §7050(b);
- Provider certifies that it understands these restrictions and will comply with them.
15. General
- Severability. If any provision of this DPA is held to be invalid, the remainder remains in effect.
- Order of precedence. Annexes referenced in this DPA form part of it.
- Survival. Sections that by their nature should survive termination (including §9, §10, §11, §12) survive.
16. Annexes
Annex A — Technical and Organizational Measures: as described in the Security Overview, which is incorporated into this DPA by reference and may be updated from time to time provided the level of protection is not reduced.
Annex C — Subprocessor list: see the Subprocessors page.
Where EU, UK, Swiss, or other applicable data protection law requires specific transfer terms, annexes, transfer details, or technical and organisational measures to be completed, the parties will execute or incorporate the applicable transfer documentation, including Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, Swiss adaptations, or other lawful transfer mechanisms as required.