Last updated: 13 June 2026

Data Processing Agreement (DPA)

This Data Processing Agreement (this "Agreement" or "DPA") is entered into between COGNIS AI PTE. LTD. (the "Company", the "Processor") and the customer that accepts the Company's Terms of Service (the "Customer" or the "Controller"). This Agreement is incorporated into, and forms part of, the Company's Terms of Service by reference.

This Agreement applies to customers who enter into the Terms of Service on behalf of an organisation, or who use the Service for commercial or for-profit purposes. If you use the Service in a personal capacity, the processing of your data is governed by the Company's Privacy Policy.

1. Definitions

In this Agreement, the following terms have the meanings set out below:

2. Scope and Roles

This Agreement applies where the Company processes Personal Data on behalf of the Customer. The roles of the parties are as follows:

3. Details of Processing

Details of the Personal Data processed by the Company on behalf of the Customer are as follows:

Item Details
Nature of Processing Transmission, routing, formatting and return of data via API
Purpose of Processing Provision of large language model API aggregation and routing services to the Customer
Categories of Personal Data Input submitted by the Customer through the API (which may contain Personal Data of end users); account identifiers; API usage metadata
Categories of Data Subjects The Customer's end users; the Customer's employees or authorised users
Duration of Processing The term of the Agreement, unless the Customer instructs otherwise in writing

4. Obligations of the Company

As Processor, the Company undertakes to:

5. Security Measures

The Company maintains technical and organisational security measures appropriate to the risk of the Processing and the nature of the Personal Data, including without limitation:

6. Sub-processors

6.1 Authorisation to engage Sub-processors

The Customer authorises the Company to engage Sub-processors to assist in providing the Service. Before engaging any Sub-processor to process Personal Data, the Company will enter into a written contract with that Sub-processor imposing data protection obligations substantially the same as those imposed on the Company under this Agreement.

6.2 Current Sub-processors

Because the platform provides intelligent routing and aggregation services, we must forward encrypted API payloads to the upstream large language model interfaces specified by the Customer in its requests. We work only with compliant vendors holding mainstream international security certifications (such as ISO 27001 and SOC 2 Type II). A list of currently active Sub-processors is available on request through the official customer support channel.

6.3 Notice of changes to Sub-processors

The Company will notify the Customer in writing (including by email) of any intended change to its Sub-processors (including the addition or replacement of a Sub-processor) at least thirty (30) days before that change takes effect, giving the Customer the opportunity to object before the change comes into force. If the Customer reasonably objects to a proposed change, the parties will negotiate a solution in good faith.

7. Data Breach Notification

In the event of a Data Breach, the Company will:

8. Data Subject Rights

The Company will, so far as reasonably practicable and by appropriate technical and organisational measures, assist the Customer in fulfilling its obligation to respond to requests from Data Subjects exercising the following rights:

9. Data Retention and Deletion

9.1 Retention period

The Company will retain the Customer's Personal Data only for as long as necessary to provide the Service, or as required by applicable law. By default (where prompt logging is not enabled), the Company does not store input or output content after an API call has been completed.

9.2 Deletion and return

On termination of the service relationship, or at the Customer's written request, the Company will within a reasonable period (not exceeding thirty (30) days):

Where applicable law requires the continued storage of certain Personal Data, the Company will inform the Customer and will take steps to isolate that data from other data and carry out no further Processing of it.

10. Data Localisation and Cross-Border Transfers

The Company processes Personal Data primarily within the Republic of Singapore. Where Personal Data must be transferred to another jurisdiction, the Company will ensure that the transfer complies with Applicable Data Protection Law, including without limitation by:

11. Audit Rights

The Company will make available to the Customer all information necessary to demonstrate compliance with its obligations under this Agreement. On reasonable prior notice (of not less than thirty (30) days) and no more than once per year, the Customer may, itself or through an independent third-party auditor, audit the manner in which the Company processes the Customer's Personal Data, and the Company will cooperate with such an audit. The cost of the audit is borne by the Customer, and the auditor must be bound by obligations of confidentiality.

12. Precedence

In the event of any conflict between this Agreement and the Terms of Service or any other agreement between the Company and the Customer, this Agreement prevails to the extent the conflict concerns the protection of Personal Data.

13. Governing Law

This Agreement is governed by the laws of the Republic of Singapore. The parties agree that any dispute arising out of this Agreement shall be submitted to the courts of Singapore or to the Singapore International Arbitration Centre (SIAC).

14. Term

This Agreement takes effect on the date the Customer accepts the Company's Terms of Service and continues until the service relationship is terminated. The Company's obligations to delete or return Personal Data survive termination of this Agreement until they have been performed.