Legal · last updated 2026-06-30
Data Processing Addendum
This Data Processing Addendum (DPA) applies when AegisRail processes Customer Personal Data on behalf of a customer, unless a separately signed data processing agreement applies. It forms part of the Terms of Service.
Practical template pending legal review. Not legal advice.
Scope And Roles
This DPA applies where AegisRail, operated by Eastbase Studio, processes personal data contained in Customer Data ("Customer Personal Data") on behalf of the customer ("Customer") in the course of providing the Service.
For Customer Personal Data, the Customer is the controller (or business) and AegisRail is the processor (or service provider). AegisRail processes Customer Personal Data only as described here and in the Terms and Privacy Policy.
Subject Matter And Duration
The subject matter of the processing is the provision of the AegisRail AI TrustOps Service. The duration is the term of the Customer’s use of the Service, plus the period needed to delete or return Customer Personal Data afterward.
Nature And Purpose Of Processing
AegisRail processes Customer Personal Data to provide AI observability, evaluation, governance, incident, evidence, notification, billing, support, security, and reliability features, and to operate the Service in line with the Customer’s instructions.
Categories Of Data Subjects
Data subjects include the Customer’s authorized users and administrators, and any individuals whose data the Customer chooses to include in the telemetry, evaluation, evidence, or operational metadata it submits to the Service.
Categories Of Personal Data
Personal data may include account and contact identifiers, workspace membership and roles, billing identifiers, audit and usage metadata, and any personal data the Customer includes in submitted content.
AegisRail is designed to avoid raw prompt and completion storage by default. The Customer controls what it submits and should not include special-category or otherwise sensitive personal data unless approved retention, redaction, access controls, and disclosure processes are in place.
Processing Instructions
AegisRail processes Customer Personal Data only on the Customer’s documented instructions, which include the Terms, this DPA, and the Customer’s configuration and use of the Service, unless required to act otherwise by applicable law.
If AegisRail believes an instruction infringes applicable data protection law, it will inform the Customer.
Confidentiality
AegisRail ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only as needed to provide and support the Service.
Security Measures
AegisRail maintains technical and organizational measures appropriate to the risk, including organization-scoped access controls, role-based permissions, hashed API key storage, encryption of outbound integration secrets, an append-only audit log, a tamper-evident proof chain, production security headers, and monitored operational jobs.
Operational logs and error events are designed to exclude secrets, raw request bodies, raw prompts, raw completions, and payment details.
Subprocessors
The Customer provides a general authorization for AegisRail to engage subprocessors to provide the Service. The current subprocessors and their roles are published on the Subprocessors page, and AegisRail imposes data protection obligations on them consistent with this DPA.
AegisRail will make a reasonable effort to give notice of new subprocessors that process Customer Personal Data so the Customer can review them.
International Transfers
AegisRail and its subprocessors may process Customer Personal Data in countries other than the Customer’s, including the United States. Where required, AegisRail relies on appropriate safeguards for international transfers, such as standard contractual clauses or an equivalent mechanism.
Data Subject Requests
Taking into account the nature of the processing, AegisRail will assist the Customer, by appropriate technical and organizational measures and insofar as possible, to respond to requests from data subjects exercising their rights.
If AegisRail receives a request directly from a data subject regarding Customer Personal Data, it will direct that person to the Customer rather than respond on the Customer’s behalf.
Personal Data Breach
AegisRail will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations.
Deletion Or Return
On termination of the Service, and at the Customer’s choice, AegisRail will delete or return Customer Personal Data, subject to retention required by law and to backups that age out on their normal cycle.
The Customer may also request deletion or export of workspace data during the term through support or available product workflows.
Audits And Compliance Information
AegisRail will make available to the Customer the information and documentation reasonably necessary to demonstrate compliance with this DPA. The Customer’s audit rights are satisfied in the first instance by reviewing this documentation.
Where documentation is not sufficient, a live inspection or deeper audit requires reasonable prior notice, mutually agreed scope and timing, and appropriate confidentiality protections, and must not compromise the security, availability, or data of other customers.
Liability And Order Of Precedence
This DPA is incorporated into and subject to the Terms, including the limitation of liability. In case of conflict regarding the processing of Customer Personal Data, the order of precedence is: a separately signed data processing agreement, then this DPA, then the Terms and Privacy Policy.
Contact
Data protection questions and requests under this DPA can be sent to support@eastbase.studio.