Data Processing Agreement (DPA)
This Data Processing Agreement (this "Agreement" or "DPA") is entered into between COGNIS AI PTE. LTD. (the "Company", the "Processor") and the customer that accepts the Company's Terms of Service (the "Customer" or the "Controller"). This Agreement is incorporated into, and forms part of, the Company's Terms of Service by reference.
1. Definitions
In this Agreement, the following terms have the meanings set out below:
- "Personal Data" means any information relating to an identified or identifiable natural person (a "Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier (such as a name, identification number, location data or online identifier) or to one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
- "Processor" means the natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
- "Sub-processor" means any third-party processor engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Breach" means a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
- "Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under this Agreement, including without limitation the EU General Data Protection Regulation (GDPR) and the data protection laws of the relevant jurisdictions.
2. Scope and Roles
This Agreement applies where the Company processes Personal Data on behalf of the Customer. The roles of the parties are as follows:
- Controller (Customer): the Customer determines the purposes and means of the Processing of Personal Data, including which data is sent to the Company's API and for which business purposes.
- Processor (Company): the Company processes and transmits the relevant data solely on the Customer's instructions for the purpose of providing API routing and aggregation services, and does not determine the purposes of the Processing itself.
3. Details of Processing
Details of the Personal Data processed by the Company on behalf of the Customer are as follows:
| Item | Details |
|---|---|
| Nature of Processing | Transmission, routing, formatting and return of data via API |
| Purpose of Processing | Provision of large language model API aggregation and routing services to the Customer |
| Categories of Personal Data | Input submitted by the Customer through the API (which may contain Personal Data of end users); account identifiers; API usage metadata |
| Categories of Data Subjects | The Customer's end users; the Customer's employees or authorised users |
| Duration of Processing | The term of the Agreement, unless the Customer instructs otherwise in writing |
4. Obligations of the Company
As Processor, the Company undertakes to:
- process Personal Data only on the Customer's documented instructions, including those set out in this Agreement and the Terms of Service; where Processing is required by law, the Company will inform the Customer of that legal requirement before Processing, unless prohibited from doing so by law;
- ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Applicable Data Protection Law;
- comply with the conditions set out in Clause 6 of this Agreement for engaging Sub-processors;
- assist the Customer, so far as reasonably practicable and taking into account the nature of the Processing, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests to exercise Data Subject rights;
- assist the Customer in ensuring compliance with its obligations under Applicable Data Protection Law relating to security, Data Breach notification, data protection impact assessments and prior consultation;
- at the Customer's election, delete or return all Personal Data on termination of the Service and delete existing copies, unless storage of that Personal Data is required by applicable law;
- make available to the Customer all information necessary to demonstrate compliance with its obligations under this Agreement, and allow for and contribute to audits and inspections conducted by the Customer or an auditor mandated by the Customer.
5. Security Measures
The Company maintains technical and organisational security measures appropriate to the risk of the Processing and the nature of the Personal Data, including without limitation:
- Transport layer security: all API communications are encrypted using TLS 1.2 or above, ensuring that data cannot be intercepted or tampered with in transit;
- Access control: strict access controls are applied to systems storing Personal Data, following the principle of least privilege, with access granted only to necessary personnel;
- Container isolation: containerisation is used to isolate the processing of different tenants' data and prevent cross-contamination;
- Encryption at rest: sensitive credentials and Personal Data are stored encrypted at rest using industry-standard encryption algorithms;
- Security monitoring: systems are subject to continuous security monitoring so that anomalous access or security incidents are detected and responded to promptly;
- Regular audits: security measures are internally audited and assessed on a regular basis for continuous improvement.
6. Sub-processors
6.1 Authorisation to engage Sub-processors
The Customer authorises the Company to engage Sub-processors to assist in providing the Service. Before engaging any Sub-processor to process Personal Data, the Company will enter into a written contract with that Sub-processor imposing data protection obligations substantially the same as those imposed on the Company under this Agreement.
6.2 Current Sub-processors
Because the platform provides intelligent routing and aggregation services, we must forward encrypted API payloads to the upstream large language model interfaces specified by the Customer in its requests. We work only with compliant vendors holding mainstream international security certifications (such as ISO 27001 and SOC 2 Type II). A list of currently active Sub-processors is available on request through the official customer support channel.
6.3 Notice of changes to Sub-processors
The Company will notify the Customer in writing (including by email) of any intended change to its Sub-processors (including the addition or replacement of a Sub-processor) at least thirty (30) days before that change takes effect, giving the Customer the opportunity to object before the change comes into force. If the Customer reasonably objects to a proposed change, the parties will negotiate a solution in good faith.
7. Data Breach Notification
In the event of a Data Breach, the Company will:
- notify the Customer in writing without undue delay and in any event within seventy-two (72) hours of becoming aware of the Data Breach;
- provide the following information in the notification, to the extent available: a description of the nature of the Data Breach; the categories and approximate number of Data Subjects affected; the categories and approximate number of Personal Data records affected; a description of the likely consequences of the Data Breach; and the measures taken or proposed to be taken by the Company to address it;
- where it is not possible to provide all of the information at once, provide it in phases;
- assist the Customer, so far as reasonably practicable, in fulfilling its obligations to report the Data Breach to the relevant supervisory authorities and Data Subjects.
8. Data Subject Rights
The Company will, so far as reasonably practicable and by appropriate technical and organisational measures, assist the Customer in fulfilling its obligation to respond to requests from Data Subjects exercising the following rights:
- the right of access (to obtain a copy of their Personal Data);
- the right to rectification (to have inaccurate Personal Data corrected);
- the right to erasure (to have Personal Data deleted in certain circumstances);
- the right to restriction of Processing (in certain circumstances);
- the right to data portability (to receive Personal Data in a structured, commonly used format);
- the right to object (to Processing in certain circumstances).
9. Data Retention and Deletion
9.1 Retention period
The Company will retain the Customer's Personal Data only for as long as necessary to provide the Service, or as required by applicable law. By default (where prompt logging is not enabled), the Company does not store input or output content after an API call has been completed.
9.2 Deletion and return
On termination of the service relationship, or at the Customer's written request, the Company will within a reasonable period (not exceeding thirty (30) days):
- permanently delete the Customer's Personal Data and all copies of it; or
- return the Personal Data to the Customer in a commonly used format of the Customer's choosing, and then delete it.
Where applicable law requires the continued storage of certain Personal Data, the Company will inform the Customer and will take steps to isolate that data from other data and carry out no further Processing of it.
10. Data Localisation and Cross-Border Transfers
The Company processes Personal Data primarily within the Republic of Singapore. Where Personal Data must be transferred to another jurisdiction, the Company will ensure that the transfer complies with Applicable Data Protection Law, including without limitation by:
- relying on Standard Contractual Clauses (SCCs) approved by the European Commission;
- relying on an adequacy decision;
- adopting another recognised lawful transfer mechanism.
11. Audit Rights
The Company will make available to the Customer all information necessary to demonstrate compliance with its obligations under this Agreement. On reasonable prior notice (of not less than thirty (30) days) and no more than once per year, the Customer may, itself or through an independent third-party auditor, audit the manner in which the Company processes the Customer's Personal Data, and the Company will cooperate with such an audit. The cost of the audit is borne by the Customer, and the auditor must be bound by obligations of confidentiality.
12. Precedence
In the event of any conflict between this Agreement and the Terms of Service or any other agreement between the Company and the Customer, this Agreement prevails to the extent the conflict concerns the protection of Personal Data.
13. Governing Law
This Agreement is governed by the laws of the Republic of Singapore. The parties agree that any dispute arising out of this Agreement shall be submitted to the courts of Singapore or to the Singapore International Arbitration Centre (SIAC).
14. Term
This Agreement takes effect on the date the Customer accepts the Company's Terms of Service and continues until the service relationship is terminated. The Company's obligations to delete or return Personal Data survive termination of this Agreement until they have been performed.