Skip to content
sundr
Results How it works Guarantee Pricing Docs Writing Free audit

Draft for counsel review — not yet offered for signature.

Data Processing Addendum

Draft of 9 October 2026. Text in [brackets] is for counsel to decide.

This Data Processing Addendum ("DPA") forms part of the agreement between [Customer legal name] ("Customer") and [Sundr legal entity name and address] ("Sundr") for the Services (the "Agreement"). [Counsel: the Agreement is currently the Terms; decide whether a signed order form is also needed.]

1. Definitions

  • "Applicable Data Protection Law" means the data protection laws that apply to the processing under this DPA, including [the GDPR, the UK GDPR, the Swiss FADP and the CCPA, as amended].
  • "Customer Data" means logs Customer uploads for an audit, requests Customer sends through the proxy, and anything Sundr stores from them.
  • "Customer Personal Data" means personal data in Customer Data that Sundr processes for Customer under the Agreement.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • "Services" means the Savings Audit, the Sundr proxy and the dashboard.
  • "Subprocessor" means a third party Sundr engages to process Customer Personal Data.
  • "SCCs" means the standard contractual clauses approved by the European Commission in Decision (EU) 2021/914, and, where relevant, the UK International Data Transfer Addendum and the Swiss amendments.
  • Terms such as "controller", "processor", "data subject" and "processing" have the meanings given in Applicable Data Protection Law.

2. Roles and scope

  1. Customer is the controller of Customer Personal Data, or a processor acting for its own controller. Sundr is Customer's processor, or subprocessor.
  2. Annex 1 describes the processing.
  3. Customer is responsible for having a lawful basis to send Customer Data to Sundr. Customer will not send special categories of personal data, health data or payment card data unless the parties agree in writing.
  4. This DPA does not cover data Sundr handles as a controller, such as account contact details. The privacy notice covers that data.

3. Processing instructions

  1. Sundr processes Customer Personal Data only on Customer's documented instructions. The Agreement, this DPA, and Customer's use of the Services (uploading logs, routing calls, changing a task's state) are Customer's instructions.
  2. Sundr will tell Customer if it believes an instruction breaks Applicable Data Protection Law.
  3. Sundr will not sell Customer Personal Data or use it for any purpose outside the Agreement. Sundr will not use it to train shared or general-purpose models. Models fitted on Customer Data are used only to provide the Services to Customer.
  4. If law requires Sundr to process Customer Personal Data in another way, Sundr will tell Customer first, unless the law forbids it.
  5. [Counsel: decide whether to add CCPA service-provider terms.]

4. Confidentiality

Sundr will make sure that anyone it authorises to process Customer Personal Data is bound by a duty of confidentiality. Sundr limits access to the people who need it to provide the Services.

5. Security

Sundr will implement the technical and organisational measures in Annex 2. Sundr may change them over time, as long as the overall level of protection does not decrease.

6. Subprocessors

  1. Customer authorises Sundr to use the Subprocessors listed at sundr.ai/subprocessors.
  2. Sundr will email Customer at least [30] days before adding or replacing a Subprocessor. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may end the affected Services [and receive a refund of any prepaid fees for them].
  3. Sundr will bind each Subprocessor to data protection terms [no less protective than / substantially similar to] this DPA. Sundr remains responsible for its Subprocessors' performance [to the extent required by Applicable Data Protection Law].
  4. The LLM provider Customer calls through the proxy, using Customer's own API key, is not a Subprocessor. It processes data under Customer's own agreement with it.

7. International transfers

  1. Sundr processes Customer Personal Data in the United States. Subprocessors process it in the locations listed at sundr.ai/subprocessors.
  2. For transfers of personal data from the EEA, the UK or Switzerland to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference: [Module Two (controller to processor) and/or Module Three (processor to processor)].
  3. [Counsel: choose the SCC options (Clause 7 docking, Clause 9 subprocessor option, Clause 11 redress, Clause 13 supervisory authority, Clauses 17 and 18 governing law and courts), complete the UK and Swiss terms, and decide whether Sundr will self-certify under the EU-U.S. Data Privacy Framework.]

8. Data subject requests and assistance

  1. If a data subject asks Sundr to exercise a right over Customer Personal Data, Sundr will tell Customer [within [5] business days]. Sundr will not respond to the request itself, except to refer the data subject to Customer, unless Customer authorises it.
  2. Sundr will help Customer respond to such requests, for example by finding and deleting stored calls that contain a data subject's information. [Counsel: decide whether help beyond the normal Services is chargeable.]
  3. Sundr will give reasonable help with data protection impact assessments and prior consultations with supervisory authorities that relate to the Services, using the information Sundr has.

9. Personal Data Breaches

  1. Sundr will notify Customer by email without undue delay, and no later than 72 hours after becoming aware of a Personal Data Breach.
  2. The notice will include what Sundr knows at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Sundr may provide the information in stages.
  3. Sundr will take reasonable steps to contain the breach and limit its effects. A notice under this section is not an admission of fault.

10. Deletion and return

  1. While the Agreement is in force, Sundr deletes Customer Data on the schedule in Annex 2.
  2. When the Agreement ends, or when Customer asks in writing, Sundr will delete Customer Personal Data within [30] days. This does not apply to data in volume snapshots, which expire on their own schedule (currently [5] days), or to data that law requires Sundr to keep.
  3. Before deletion, Customer may ask Sundr to return [task certificates and stored call logs] in a common machine-readable format. [Counsel and Sundr: decide what "return" covers.]
  4. On request, Sundr will confirm deletion in writing.

11. Audits

  1. Sundr will make available the information reasonably needed to show that it complies with this DPA. This includes this DPA, the security page, and answers to reasonable security questionnaires [no more than once a year].
  2. Sundr does not yet have a third-party audit report such as SOC 2. If that information does not reasonably meet Customer's obligations, Customer may audit Sundr's compliance [through an independent auditor bound by confidentiality, at Customer's cost, on [30] days' written notice, no more than once in any 12 months, during business hours, and without access to other customers' data].
  3. Once Sundr has a current third-party audit report, it may provide that report instead of an audit under 11.2, unless a supervisory authority requires otherwise.

12. Liability

Each party's liability arising out of or in connection with this DPA, including the SCCs to the extent the law allows, is subject to the limitations and exclusions of liability in the Agreement. [Counsel: the current Terms have no limitation of liability. Add one to the Terms, or state the cap here.]

13. Term and precedence

  1. This DPA applies for as long as Sundr processes Customer Personal Data.
  2. If this DPA conflicts with the Agreement on a data protection matter, this DPA wins. If the SCCs conflict with this DPA or the Agreement, the SCCs win.
  3. This DPA is governed by [the law that governs the Agreement].

Annex 1: Description of processing

  • Subject matter: providing the Services.
  • Duration: the term of the Agreement, plus the deletion periods in section 10.
  • Nature and purpose: running Savings Audits on uploaded logs; forwarding LLM requests through the proxy; storing judgment calls; fitting and certifying per-task decision models; answering judgment calls within the certified error budget; checking live error; sending service email.
  • Types of personal data: any personal data Customer includes in uploaded logs and LLM requests, as decided by Customer [for example names, contact details and message contents]; email addresses of Customer's users of the Services.
  • Special categories: none intended. See section 2.3.
  • Data subjects: people whose data appears in Customer's LLM inputs, such as Customer's end users; Customer's staff who use the Services.
  • Frequency: once per audit; continuously while Customer routes calls through the proxy.
  • Retention: see Annex 2 and section 10.

Annex 2: Security measures

These are the measures in place on the date of this draft. The security page has more detail, including what is not in place yet.

  • Encryption in transit: TLS from clients to Cloudflare, and from Cloudflare to the Fly.io origin with certificate checks ("Full (strict)"). HTTPS for all calls to Subprocessors and to Customer's LLM provider.
  • Encryption at rest: uploaded logs are encrypted by the app with Fernet, using a key stored as a Fly.io secret. The Fly.io volume that holds all stored data is encrypted at rest.
  • Access control: production access is limited to Sundr's founder, through the Fly.io and Cloudflare accounts. Accounts with production access must use two-factor authentication.
  • Authentication: workspace keys are made from 32 random bytes and stored only as SHA-256 hashes. Dashboard sessions use HMAC-signed cookies that are HttpOnly, SameSite=Strict and HTTPS-only, and expire after 30 days.
  • Key handling: Customer's LLM provider keys are forwarded with each request and are never stored or logged. Sundr's own secrets are stored as Fly.io secrets, not in source code.
  • Separation: each workspace's tasks, calls and models are linked to that workspace. The dashboard and the control API return only the authenticated workspace's data.
  • Data minimisation: proxy requests without a task header, and streaming requests, are forwarded without their content being stored.
  • Retention: uploaded logs are deleted when the report is written, or within 2 days if the audit is never confirmed. Reports are deleted after 30 days. Proxy call logs are deleted after 30 days.
  • Availability: one Fly.io machine in Ashburn, Virginia, with Fly.io's daily volume snapshots. There is no failover yet.

Annex 3: Subprocessors

The Subprocessors listed at sundr.ai/subprocessors on [the date this DPA is signed].

Questions about this draft: [email protected].

sundr

Uploaded logs are encrypted at rest and deleted as soon as your report is ready. Reports are deleted after 30 days.

Docs Writing Agent setup Dashboard Privacy Terms Security Subprocessors [email protected]