LEGAL

Data Processing Addendum

The Data Processing Addendum governing ModelLane's processing of personal data on behalf of enterprise customers.

1. Scope

This Data Processing Addendum (“DPA”) supplements the agreement between you (the “Customer”) and Neuromorph Systems, LLC dba Galadriel Labs (“ModelLane”) to the extent ModelLane processes personal data on your behalf in providing the Service. This DPA is incorporated into and forms part of that agreement. If an enterprise agreement contains a separately negotiated DPA, that DPA controls.

2. Definitions

Capitalized terms not defined here have the meaning given in the agreement or in applicable data protection law. “Personal Data,” “Controller,” “Processor,” “Data Subject,” “Subprocessor,” and “Supervisory Authority” have the meanings given in the General Data Protection Regulation (GDPR) and other applicable law.

3. Roles

The parties acknowledge that, as between them, the Customer acts as Controller (or Processor on behalf of its own controllers) of Customer personal data, and ModelLane acts as a Processor, processing that data solely to provide the Service and on the Customer’s documented instructions. The Customer’s use of the Service constitutes its instruction to process personal data for that purpose.

4. Processing details

  • Subject matter: the provision of the ModelLane inference routing Service.
  • Nature and purpose: routing inference requests, enforcing routing policies, and providing observability, support, and billing.
  • Duration: for the term of the agreement, subject to the retention terms in the Privacy Policy.
  • Categories of data subjects: the Customer’s users and any individuals whose data appears in the content the Customer routes.
  • Types of personal data: account and billing data and any personal data contained in routed content, as determined by the Customer.

5. Subprocessors

ModelLane may engage subprocessors to provide the Service. Current subprocessors are listed in the Trust Center. ModelLane will provide notice of new subprocessors and allow the Customer to object where required by law. All subprocessors are bound by written terms requiring data protection standards at least as protective as this DPA.

6. Security measures

ModelLane implements appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, and audit logging, as further described in the Security page and Trust Center.

7. Data subject requests and breach notification

ModelLane will provide reasonable assistance to the Customer in responding to data subject requests and will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, to the extent required by law.

8. International transfers

Personal data is processed in the United States and where ModelLane’s subprocessors operate. Where required, transfers are governed by the European Commission’s Standard Contractual Clauses or another valid transfer mechanism, as set out in the agreement.

9. Retention and deletion

ModelLane processes personal data only as long as necessary to provide the Service, after which it is deleted or returned as described in the Privacy Policy and the agreement.

10. Audit

ModelLane will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable security reviews. Enterprise customers may receive additional audit rights under their agreement.

11. Term

This DPA remains in effect for the term of the agreement and continues until all personal data has been deleted or returned.

12. Contact

To execute a signed DPA or discuss enterprise data processing terms, contact legal@modellane.app.