> For the complete documentation index, see [llms.txt](https://docs.console.zenlayer.com/zenlayer-legal/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.console.zenlayer.com/zenlayer-legal/specific-product-terms/ai-gateway-data-processing-addendum.md).

# AI Gateway Data Processing Agreement

Last updated: August 12, 2026

Version 1.0 | Effective Date: \[August 12, 2026]

This Data Processing Agreement ("DPA") is between Zenlayer Inc., a company incorporated in Delaware with its principal business address at 21700 Copley Drive Suite 350, Diamond Bar, CA 91765, United States ("Company," "we," "us," or "our"), and the entity or person accepting these terms ("Customer").

This DPA forms part of and is incorporated into the AI Gateway Service Agreement or Online Terms (including but not limited to AI GATEWAY SERVICE TERMS as applicable) between the parties (the "Agreement"). Capitalized terms not defined in this DPA have the meanings given in the Agreement. In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the subject matter herein.

This DPA applies to Customer Personal Data processed by the Company in connection with the Services.

## How to Use This DPA

This DPA governs the Company's processing of Customer Personal Data in connection with two distinct service types. Please refer to the guidance below to identify which sections are relevant to your use of the Services:

* API Routing Services (Type A) only: Sections 1, 2.1, 2.2, 14, 15, and 16 are relevant to your use. Sections 3 through 13 have limited or no application to Type A Services, as the Company does not store or retain Input or Output content and processes only limited technical metadata (such as token counts, timestamps, IP, request ID, and model identifiers) as an independent data controller for its own billing and operational purposes. If you use Type A Services exclusively, you are not required to review Sections 3 through 13 in full.
* Dedicated Inference Services (Type B) only: All Sections apply in full to your use of the Services.
* Both service types: All Sections apply, with the Company's obligations varying by service type as indicated throughout this DPA. The applicable service type for each model is designated on the Platform at the point of model selection. Where a model is operated directly by the Company, Type B Services apply. Where a model is routed to a third-party Model Provider, Type A Services apply.

## Section 1. Definitions

In this DPA, the following terms have the following meanings:

"Applicable Data Protection Laws" means all privacy, data protection and data security laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including as applicable: the EU GDPR; the UK GDPR; the Swiss Federal Act on Data Protection (revFADP); the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA); and other applicable US state privacy laws, in each case as amended from time to time.

"Controller" means the natural or legal person which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

"Customer Personal Data" means any Personal Data Processed by the Company or its Sub-Processors on behalf of Customer in the course of providing the Services under the Agreement.

"Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates.

"Data Subject Request" means the exercise by a Data Subject of its rights under Applicable Data Protection Laws in respect of Customer Personal Data.

"EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

"Model Provider" means the independent third-party entity that owns, operates, and provides access to an AI model accessible through the Services.

"Personal Data" means "personal data," "personal information," "personally identifiable information," or equivalent term as defined under Applicable Data Protection Laws.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in the Company's possession, custody or control.

"Personnel" means, in relation to a party, that party's employees, agents, consultants, contractors, and other staff.

"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

"Processor" means the natural or legal person that Processes Personal Data on behalf of a Controller.

"Restricted Transfer" means: (i) in the context of the EU GDPR, any transfer of Customer Personal Data from the EEA to a country or territory outside the EEA that does not benefit from an adequacy decision of the European Commission; and (ii) in the context of the UK GDPR, any transfer of Customer Personal Data from the UK to a country or territory outside the UK that does not benefit from adequacy regulations under section 17A of the Data Protection Act 2018.

"SCCs" means the standard contractual clauses approved by the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021.

"Sub-Processor" means any third party appointed by or on behalf of the Company to Process Customer Personal Data.

"Type A Services" means Services where the Company routes API requests to third-party Model Providers, as designated on the Platform at the point of model selection.

"Type B Services" means Services where the Company operates AI inference infrastructure directly on its own hardware, as designated on the Platform at the point of model selection.

"UK GDPR" means the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended.

"UK Transfer Addendum" means the template Addendum B.1.0 issued by the UK Information Commissioner's Office and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of the Mandatory Clauses.

## Section 2. Scope and Roles

### 2.1 General

This DPA applies to Customer Personal Data Processed by the Company in connection with the Services. This DPA does not apply to Personal Data for which the Company is an independent Controller, such as account registration data and billing metadata processed for the Company's own operational purposes, which are governed by the Company's Privacy Policy.

### 2.2 Type A Services — API Routing

Under Type A Services, the Company acts as a routing intermediary that transmits Customer's Inputs to third-party Model Providers on Customer's instruction and returns the resulting Outputs. With respect to Customer Personal Data processed under Type A Services:

* When Customer submits Inputs to the Company for routing to Model Providers, the Company acts as a Processor on behalf of Customer. The Company processes Customer Inputs solely for the purpose of routing them to the appropriate Model Provider on Customer's instruction.
* Model Providers are not Sub-Processors of the Company. The Company is not responsible for Model Providers' data handling practices, security, or compliance with applicable data protection laws. Customer is responsible for reviewing each Model Provider's own terms of service and privacy policy before submitting data, and for ensuring it has a lawful basis for its use of the applicable Model Provider's services.
* The Company processes only limited request metadata (such as model identifier, token counts, request ID, request latency, response status codes, timestamps, and IP address) for billing, security, and operational purposes, acting as an independent data controller with respect to such metadata. The Company does not store, retain, or log the content of Inputs or Outputs. Sections 3 through 13 of this DPA apply to Type A Services only to the extent the Company processes Customer Personal Data as a Data Processor. Where the transmission of Inputs from Customer to the Company constitutes a Restricted Transfer under Applicable Data Protection Laws, the transfer mechanisms in Section 11 (International Data Transfers) apply. The limited metadata processing described above is governed by the Company's Privacy Policy.

### 2.3 Type B Services — Self-Hosted Inference (Company as Processor)

Under Type B Services, the Company operates AI inference infrastructure directly on its own hardware. With respect to Customer Personal Data processed under Type B Services:

* The Company acts as a data Processor on behalf of Customer as Controller (or as a Sub-Processor on behalf of Customer acting as a Processor), and Sections 3 through 13 of this DPA apply in full.
* The Company processes Customer Personal Data solely for the purpose of providing the Services in accordance with Customer's documented instructions.
* The Company does not persistently store Inputs or Outputs beyond what is necessary to process each request and return the Output to Customer. The Company does not use Customer Personal Data to train, fine-tune, or improve any AI model without Customer's prior written consent.
* Where applicable law at the inference deployment location requires the Company to retain certain data for compliance purposes (including content safety monitoring, audit logging, or other regulatory requirements), the Company shall: (i) retain only the minimum data required by applicable law; (ii) notify Customer promptly upon becoming aware of such requirement; (iii) process such retained data solely for the purpose of complying with applicable law; and (iv) delete such data as soon as legally permissible.
* Where required by applicable law at the inference deployment location, the Company may implement content filtering or output restrictions. The Company shall notify Customer of any such filtering requirements that may materially affect the Services.

### 2.4 Mixed Services

Where Customer uses both Type A and Type B Services, Sections 3 through 13 apply to the extent the Company processes Customer Personal Data as a Processor under Type B Services. The metadata processing under Type A Services remains governed by the Company's Privacy Policy.

## Section 3. Processing Instructions

The Company shall Process Customer Personal Data only: (a) in accordance with Customer's documented instructions as set out in the Agreement and this DPA; and (b) as required by Applicable Data Protection Laws, in which case the Company shall inform Customer in advance of such requirement, unless prohibited from doing so by applicable law.

The Agreement and this DPA constitute Customer's complete and final documented instructions to the Company regarding the Processing of Customer Personal Data. Any additional instructions from Customer shall be binding on the Company only if agreed in writing by both parties.

If the Company reasonably considers that any instruction from Customer would infringe Applicable Data Protection Laws, the Company shall promptly notify Customer accordingly.

## Section 4. Details of Processing

The details of the Company's Processing of Customer Personal Data are set out in Annex 1 (Data Processing Details) to this DPA.

## Section 5. Security

### 5.1 Security Measures

The Company shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data, as described in Annex 2 (Security Measures) to this DPA. The Company may update the Security Measures from time to time, provided that such updates do not materially decrease the overall level of security afforded to Customer Personal Data.

### 5.2 Personnel

The Company shall take commercially reasonable steps to ensure the reliability of its Personnel who Process Customer Personal Data and shall ensure that all such Personnel are subject to appropriate obligations of confidentiality.

### 5.3 Customer Responsibilities

Customer is responsible for: (a) making appropriate use of the Services to maintain security appropriate to the risk in respect of Customer Personal Data; (b) securing Customer's account credentials, systems and devices used to access the Services; (c) ensuring the lawfulness of Customer's instructions to the Company; and (d) backing up Customer Personal Data, as the Company does not persistently store the content of Inputs or Outputs beyond what is necessary to process each request and cannot recover such data on Customer's behalf.

## Section 6. Sub-Processors

### 6.1 General Authorization

For the avoidance of doubt, Model Providers are not Sub-Processors of the Company. As described in Section 2.2, the Company's processing of Customer Personal Data under Type A Services is limited to real-time transmission to Model Providers on Customer's instruction. Model Providers are not engaged by the Company to process Customer Personal Data on the Company's behalf, and each Model Provider is independently responsible for its own compliance with applicable data protection laws with respect to any processing occurring within its own infrastructure.

This Section 6.1 applies to Type B Services only. Customer hereby generally authorizes the Company to appoint Sub-Processors in accordance with this Section 6. The Company's current Sub-Processors, including their names, functions and locations, are set out in Annex 3 to this DPA. Customer authorizes the Company's engagement of the Sub-Processors listed in Annex 3 as of the date Customer accepts the Agreement.

### 6.2 Notification of Changes

The Company shall give Customer at least 10 business days' prior written notice of the appointment of any new Sub-Processor or replacement of any existing Sub-Processor, by updating the Sub-Processor List. Customer is solely responsible for monitoring updates to Annex 3, which the Company will update in accordance with this Section 6.2. If, within 10 business days of the update to the Sub-Processor List, Customer notifies the Company in writing of any objection to the proposed appointment or replacement (based on reasonable grounds evidencing that the use of the proposed Sub-Processor would cause Customer to be in material and unavoidable breach of Applicable Data Protection Laws), the Company shall: (a) use reasonable efforts to make available a commercially reasonable change in the provision of the Services to avoid use of the objected-to Sub-Processor; or (b) if such a change is not commercially feasible within 30 days, or if Customer declines to bear any incremental cost associated with such change, either party may terminate the relevant portion of the Services upon written notice, without penalty.

### 6.3 Sub-Processor Obligations

The Company shall: (a) enter into a written agreement with each Sub-Processor imposing data protection obligations no less protective than those set out in this DPA; and (b) remain liable to Customer for the acts and omissions of Sub-Processors to the same extent the Company would be liable if it had performed the relevant processing directly.

## Section 7. Data Subject Rights

The Company shall, taking into account the nature of the Processing and the information available to the Company, provide Customer with such reasonable assistance as may be technically feasible to assist Customer in fulfilling its obligations to respond to Data Subject Requests under Applicable Data Protection Laws. If the Company receives a Data Subject Request directly, the Company shall: (a) promptly notify Customer; and (b) not respond to the Data Subject Request other than to advise the Data Subject to submit the request to Customer, except as required by Applicable Data Protection Laws. Except to the extent prohibited by Applicable Data Protection Laws, Customer shall reimburse the Company for any reasonable costs incurred in providing assistance under this Section 7, beyond self-service features included as part of the Services, at the Company's then-current professional services rates.

## Section 8. Data Protection Impact Assessments and Prior Consultation

To the extent required by Applicable Data Protection Laws, the Company shall, taking into account the nature of the Processing and the information available to it, provide reasonable cooperation and assistance to Customer in connection with: (a) any data protection impact assessment that Customer is required to conduct; and (b) any prior consultation with a Supervisory Authority in relation to high-risk Processing. Customer shall reimburse the Company for any reasonable costs incurred in providing such assistance, except where any non-compliance by the Company necessitated such assistance.

## Section 9. Audits and Compliance

### 9.1 Information and Certification

The Company shall make available to Customer, upon reasonable written request, information necessary to demonstrate the Company's compliance with this DPA. In the first instance, the Company may satisfy this obligation by providing relevant internal compliance documentation, third-party audit reports, certifications or attestations (if any), acceptance of which for this purpose shall not be unreasonably withheld by Customer.

### 9.2 Audits

Where Customer can provide documentary evidence that third-party certifications are insufficient to demonstrate the Company's compliance with this DPA, and subject to Applicable Data Protection Laws specifically requiring it, Customer or its authorized designee may conduct an audit of the Company's compliance with its obligations under this DPA, limited to records and documentation relating to the Processing of Customer Personal Data, subject to the following conditions:

* Customer shall give the Company at least 30 days' prior written notice of any audit, unless a shorter period is required under Applicable Data Protection Laws.
* Customer shall submit a detailed proposed audit plan in advance. The parties will work cooperatively to agree on a final audit plan.
* Audits shall be conducted during normal business hours, no more than once per calendar year (except where required by a Supervisory Authority), and in a manner that minimizes disruption to the Company's operations.
* Customer shall ensure that any auditor: (i) executes a non-disclosure agreement with the Company on terms acceptable to the Company (acting reasonably) prior to the audit; and (ii) has been approved in advance by the Company (acting reasonably). The Company may reject any proposed auditor who is a competitor of the Company or whose engagement would compromise the confidentiality or security of data belonging to other customers of the Company.
* Customer shall bear all costs of any audit, including the Company's reasonable costs of cooperating with and facilitating the audit, unless the audit reveals material non-compliance by the Company with this DPA, in which case the Company shall bear its own costs.

## Section 10. Personal Data Breach

### 10.1 Notification

The Company shall notify Customer without undue delay upon confirming a Personal Data Breach affecting Customer Personal Data. Such notification shall, to the extent then known and available to the Company, include: (a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected; (b) the likely consequences of the Personal Data Breach; and (c) measures taken or proposed to be taken to address the Personal Data Breach. The Company may provide this information in phases as it becomes available. Notification of or response to a Personal Data Breach by the Company shall not constitute an acknowledgement of fault or liability.

### 10.2 Cooperation

The Company shall provide Customer with reasonable cooperation and assistance as may be necessary for Customer to comply with its obligations to notify relevant Supervisory Authorities and affected Data Subjects under Applicable Data Protection Laws. The Company shall not notify any Supervisory Authority or Data Subject directly on Customer's behalf without Customer's prior written consent, except as required by Applicable Data Protection Laws.

### 10.3 Customer's Responsibility

As between the parties, Customer is solely responsible for complying with applicable breach notification laws and fulfilling any third-party notification obligations related to any Personal Data Breach. The obligations in Sections 10.1 and 10.2 do not apply to any Personal Data Breach caused by Customer's actions or omissions.

### 10.4 Customer Notification Consultation

If Customer determines that a Personal Data Breach affecting Customer Personal Data must be notified to any Supervisory Authority, other governmental authority, Data Subject, or the public under Applicable Data Protection Laws, and such notice directly or indirectly refers to or identifies the Company, Customer agrees, to the extent permitted by applicable law, to: (a) notify the Company in advance of issuing such notice; and (b) in good faith, consult with the Company and consider any reasonable clarifications or corrections the Company may recommend to any such notice, to the extent they relate to the Company's involvement in or relevance to the Personal Data Breach and are consistent with applicable law. This obligation does not restrict Customer's ability to comply with any mandatory notification deadlines under Applicable Data Protection Laws.

## Section 11. International Data Transfers

This Section applies where the processing of Customer Personal Data under this DPA involves a Restricted Transfer. The applicable transfer mechanism depends on the service type and the jurisdiction of the Customer, as set out below.

### 11.1 General

For Type A Services, to the extent that Customer's use of the Services involves a Restricted Transfer of Customer Personal Data from Customer to the Company, the transfer mechanisms set out in Sections 11.2 and 11.3 apply. The Company's processing under Type A Services is limited to real-time transmission of Inputs to Model Providers and retention of limited metadata; no Input or Output content is stored by the Company. The onward transmission of Inputs from the Company to Model Providers is made on Customer's documented instruction. Customer is responsible for reviewing each Model Provider's terms of service and data handling practices before submitting Personal Data, and for ensuring that its use of any Model Provider's services complies with Applicable Data Protection Laws.

For Type B Services, all transfers of Customer Personal Data to the inference deployment location are subject to the mechanisms set out in this Section. The Company shall process Customer Personal Data at the inference deployment location(s) set out in Schedule 4 (Deployment Locations) to this DPA. The Company shall notify Customer at least 30 days in advance of any material change to deployment location(s), and Customer may object to such change on reasonable data protection grounds. The Company shall implement appropriate transfer mechanisms for both the inbound transfer of Customer Personal Data to the inference location and the outbound return of Outputs to Customer, in compliance with Applicable Data Protection Laws.

### 11.2 EU SCCs

In respect of any Restricted Transfer of Customer Personal Data from Customer to the Company that is subject to the EU GDPR, the parties hereby enter into and agree to comply with the SCCs, which are incorporated by reference into this DPA, as follows:

* Module Two (Controller to Processor) applies where Customer is a Controller of Customer Personal Data.
* Module Three (Processor to Processor) applies where Customer is itself a Processor of Customer Personal Data.
* In Clause 7 (Docking Clause): the optional docking clause does not apply.
* In Clause 9 (Use of Sub-Processors): Option 2 (General Written Authorization) applies. The minimum time period for prior notice of Sub-Processor changes is as set out in Section 6.2 of this DPA.
* In Clause 11 (Redress): the optional language does not apply.
* In Clause 17 (Governing Law): Option 1 applies; the SCCs are governed by the laws of Ireland.
* In Clause 18(b) (Choice of Forum): disputes shall be resolved before the courts of Ireland.
* Annex I to the SCCs is deemed populated with the information in Annex 1 to this DPA.
* Annex II to the SCCs is deemed populated with the information in Annex 2 to this DPA.

### 11.3 UK Transfer Addendum

In respect of any Restricted Transfer of Customer Personal Data from Customer to the Company that is subject to the UK GDPR, the SCCs as described in Section 11.2 apply as varied by the UK Transfer Addendum as follows:

* Tables 1, 2 and 3 of the UK Transfer Addendum are deemed populated with the relevant information from the SCCs populated in accordance with Section 11.2 and Annex 1 to this DPA.
* In Table 4 of the UK Transfer Addendum, "Importer" is deemed selected.
* The start date of the UK Transfer Addendum is the date Customer accepts the Agreement.
* The Parties agree that Part 2 (Mandatory Clauses) of the UK Transfer Addendum is incorporated into and forms part of this DPA.

### 11.4 Deployment Location Laws

For Type B Services, the Company shall comply with the data protection laws applicable at the inference deployment location set out in Schedule 4 to this DPA. Where such laws require specific contractual safeguards or transfer mechanisms for the processing of Customer Personal Data at such location or for onward transfers from such location, the Company shall implement appropriate measures and notify Customer accordingly. Where the inference deployment location is subject to an adequacy decision under Applicable Data Protection Laws, such adequacy decision shall constitute the applicable transfer mechanism. Where no adequacy decision applies, the Company shall implement the Standard Contractual Clauses or such other transfer mechanism as required by Applicable Data Protection Laws for the applicable jurisdiction.

#### 11.4.1 Japan APPI Compliance (Type B Services Deployed in Japan)

For Type B Services deployed in Japan, the Company shall comply with Japan's Act on the Protection of Personal Information (APPI). In particular:

(a) The Company's processing shall comply with APPI's basic principles and personal information protection standards;

(b) All security measures set out in Section 5 and Annex 2 shall apply and shall be implemented consistently with APPI Article 20 requirements;

(c) Data Subject requests shall be handled in accordance with Section 7, within 30 days as required by APPI;

(d) Breach notification shall occur within 24 hours as required by APPI Article 27;

(e) Sub-Processors shall be bound by written agreements imposing APPI-compliant data protection obligations;

(f) Retention and deletion shall follow Section 12, consistent with APPI's retention principles;

(g) All audit and compliance verification requirements in Section 9 shall apply to APPI compliance;

(h) Any transfer of Customer Personal Data from Japan to other jurisdictions shall comply with APPI Articles 40-44 and shall require appropriate transfer mechanisms (SCCs, customer consent, or adequacy determination).

### 11.5 Alternative Transfer Mechanisms

If the Company adopts an alternative lawful transfer mechanism under Applicable Data Protection Laws (including, if applicable, certification under the EU-US Data Privacy Framework or UK Extension thereto), such mechanism shall apply instead of or in addition to the SCCs. The parties shall cooperate in good faith to implement any new or replacement transfer mechanism required by changes in Applicable Data Protection Laws.

### 11.6 Operational Clarifications for SCCs

In relation to any SCCs entered into pursuant to Section 11.2, the parties agree to the following operational clarifications:

* Clause 8.3 (Transparency): When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer shall not provide or otherwise make available, and shall take appropriate steps to protect, the Company's trade secrets, confidential information, and other commercially sensitive information.
* Clause 8.4 (Accuracy): For Type B Services, the Company processes Customer Personal Data solely on Customer's instructions and is not in a position to independently assess the accuracy or currency of Customer Personal Data contained in Inputs. The obligation under Clause 8.4 applies only to Customer Personal Data of which the Company becomes aware in the course of providing the Services.
* Clause 8.5 / 16(d) (Deletion certification): Certification of deletion of Customer Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Customer's written request.
* Clause 8.6(d) (Personal Data Breach notification): The notification obligations under Clause 8.6(d) of the SCCs shall be subject to the conditions and procedures set out in Section 10 of this DPA.
* Clause 8.8 (Onward transfers): Any approval by Customer of the Company's appointment of a Sub-Processor constitutes Customer's documented instruction to effect disclosures and onward transfers to such Sub-Processor as required under Clause 8.8 of the SCCs. Onward transfers to Model Providers under Type A Services are made on Customer's instruction as necessary to perform the Services and do not constitute disclosures to Sub-Processors.
* Clause 8.9 (Audits): The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to the conditions set out in Section 9.2 of this DPA.
* Clause 14 (Transfer Impact Assessment): Customer, as data exporter, is solely responsible for conducting any transfer impact assessment required in connection with the transfer of Customer Personal Data to the Company pursuant to these SCCs. The Company shall, upon Customer's reasonable written request, provide information about the legal framework applicable to the Company as a data importer in the United States to assist Customer in conducting such assessment.
* Clause 15.1(a) (Data Subject notifications): Except to the extent prohibited by applicable law, Customer shall be solely responsible for making any notifications to relevant Data Subjects if and as required.
* Clause 16 (Termination): The obligations of the Company upon termination or expiry of the SCCs, including with respect to the return or deletion of Customer Personal Data, shall be governed by Section 12 of this DPA.

## Section 12. Return and Deletion of Customer Personal Data

Upon expiration or termination of the Agreement, or upon Customer's written request, the Company shall: (a) securely delete or return all Customer Personal Data in the Company's possession or control, to the extent technically feasible; and (b) certify such deletion in writing upon Customer's written request. To the extent that deletion of any Customer Personal Data contained in backups maintained by or on behalf of the Company is not technically feasible within the requested timeframe, the Company shall: (i) securely delete such Customer Personal Data at the next scheduled backup deletion or overwrite cycle; and (ii) pending such deletion, put such Customer Personal Data beyond use and ensure it is not actively Processed for any purpose.

For Type B Services, the Company does not persistently store the content of Inputs or Outputs beyond what is necessary to process each request. Accordingly, no Input or Output content is subject to return or deletion upon termination, except where applicable law at the inference deployment location requires retention of certain data, in which case such data shall be retained only for the legally required period, processed only for legal compliance purposes, and deleted as soon as legally permissible, and shall not be subject to return to Customer.

The Company may retain Customer Personal Data where required by Applicable Data Protection Laws or other applicable law (including applicable tax, accounting, and financial record-keeping requirements), provided that the Company shall maintain the confidentiality of all such data and Process it only to the extent and for as long as required by such applicable law.

## Section 13. US State Privacy Laws

To the extent Applicable Data Protection Laws include US state privacy laws (including the CCPA/CPRA), the following additional terms apply:

* The Company is a "service provider" (as defined under the CCPA) with respect to Customer Personal Data.
* Customer discloses Customer Personal Data to the Company solely for the limited and specified business purpose of providing the Services.
* The Company shall not: (i) sell or share Customer Personal Data; (ii) retain, use, or disclose Customer Personal Data for any purpose other than providing the Services or as permitted by applicable US state privacy laws; (iii) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (iv) combine Customer Personal Data with personal information received from or on behalf of any other person, except as necessary to provide the Services.
* The Company shall notify Customer in writing if it determines it can no longer meet its obligations under applicable US state privacy laws.
* The Company hereby certifies that it understands and will comply with its obligations under this Section 13.
* De-identification. To the extent required by State Privacy Laws, and to the extent the Company creates de-identified data from Customer Personal Data (which, given the Company's current data minimization architecture — under Type A Services the Company does not store Input or Output content, and under Type B Services the Company does not persistently store Input or Output content beyond what is necessary to process each request —is not anticipated in the ordinary course of providing the Services), the Company shall: (a) adopt reasonable measures to prevent such de-identified data from being used to infer information about, or otherwise being linked to, any individual; (b) maintain and use such data in de-identified form; and (c) contractually obligate any recipients to comply with the same requirements. This Section will apply to the extent the Company's data processing practices evolve to include de-identification of Customer Personal Data.

## Section 14. Customer's Responsibilities

Customer represents, warrants and undertakes that:

* Customer shall comply with its obligations under Applicable Data Protection Laws in its Processing of Customer Personal Data and in issuing instructions to the Company.
* Customer has a valid legal basis for the Processing of Customer Personal Data by the Company under the Agreement and this DPA.
* All Data Subjects have been provided with all required notices and, where required, have given all necessary consents, in each case relating to the Company's Processing of Customer Personal Data.
* Customer's instructions to the Company shall at all times be lawful and shall not cause the Company to violate Applicable Data Protection Laws.
* Customer is solely responsible for the accuracy, quality and lawfulness of Customer Personal Data provided to the Company.
* Customer shall not submit to the Services any Special Categories of Personal Data (as defined under Article 9 of the EU GDPR) without first ensuring that appropriate safeguards are in place and notifying the Company accordingly.

## Section 15. Liability

The aggregate liability of each party under or in connection with this DPA, whether in contract, tort (including negligence) or otherwise, shall be subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this Section 15 limits any person's liability to Data Subjects under the third-party beneficiary provisions of the SCCs, where applicable.

## Section 16. Miscellaneous

Amendments. Where changes to this DPA are required to comply with mandatory requirements of Applicable Data Protection Laws (including to implement a new lawful transfer mechanism), the Company may make such amendments unilaterally by providing Customer with at least 15 days' prior written notice, and Customer's continued use of the Services after the effective date of such amendment constitutes acceptance. For all other amendments to this DPA, the Company may post an updated version of this DPA on its website and notify Customer through the Platform, by email, or by other reasonable means. Customer's affirmative acceptance (including by checking an acceptance box upon a subsequent login to the Platform), shall constitute the Customer's agreement to the updated DPA. Such affirmative acceptance, together with the associated records and timestamps maintained by the Company, shall constitute written agreement between the parties for the purposes of this DPA. If any such update has a material adverse effect on Customer, Customer may terminate the affected Services by written notice within thirty (30) days of the notice of update.

Survival. The following Sections will survive termination or expiration of this DPA: Sections 1 (to the extent necessary to interpret surviving provisions), 5, 7, 10, 11, 12, 13, 15, and 16.

Prevail. In the event of conflict: (a) this DPA prevails over the Agreement with respect to the Processing of Customer Personal Data; (b) the SCCs prevail over this DPA with respect to the Restricted Transfer to which they apply; and (c) the UK Transfer Addendum prevails over this DPA with respect to UK Restricted Transfers to which it applies.

Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall continue in full force.

Governing Law. This DPA is governed by the laws of the State of California, without regard to conflict of law principles, except to the extent otherwise required by the SCCs or UK Transfer Addendum.

Entire Agreement. This DPA, together with the Agreement, constitutes the entire agreement between the parties with respect to the Processing of Customer Personal Data and supersedes all prior agreements on this subject.

This DPA is incorporated into the Agreement. For online engagements, Customer accepts this DPA by accepting the AI GATEWAY SERVICE TERMS, and no signature is required.

## Annex 1. Data Processing Details

**Table 1: Processing Overview**

|                       | Type A Services                                                                                                                  | Type B Services                                                                                                                  |
| --------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| Zenlayer's Role       | Independent Controller (metadata only)                                                                                           | Processor on behalf of Customer                                                                                                  |
| Nature of Processing  | Real-time routing; no Input/Output storage                                                                                       | Direct AI inference on Zenlayer controlled hardware                                                                              |
| Subject Matter        | Routing of API requests to Model Providers                                                                                       | AI inference on Customer's Inputs                                                                                                |
| Duration              | Term of the Agreement                                                                                                            | Term of the Agreement                                                                                                            |
| Deployment Location   | United States, Singapore, Japan, German.                                                                                         | Per Schedule 4                                                                                                                   |
| Data Subjects         | Customer's employees, contractors and end users whose Personal Data may appear incidentally in request metadata                  | Any individuals whose Personal Data is contained in Customer's Inputs, including employees, contractors, customers and end users |
| Supervisory Authority | For EU transfers: the Supervisory Authority of the EEA Member State where Customer is established. For UK transfers: the UK ICO. | For EU transfers: the Supervisory Authority of the EEA Member State where Customer is established. For UK transfers: the UK ICO. |

**Table 2: Data Categories, Purposes and Retention Periods**

| Data Category         | Applicable To | Specific Content                                                                                           | Purpose                               | Legal Basis                             | Retention Period                                                                |
| --------------------- | ------------- | ---------------------------------------------------------------------------------------------------------- | ------------------------------------- | --------------------------------------- | ------------------------------------------------------------------------------- |
| Request metadata      | Type A + B    | Token counts, request ID, model identifier, Provider routed to, response status codes, latency, timestamps | Billing, operational monitoring       | Legitimate interests                    | Zero persistent storage — discarded immediately upon completion of each request |
| IP address            | Type A + B    | Request source IP address                                                                                  | Security, geo-restriction enforcement | Legitimate interests                    | 6 months                                                                        |
| Account data          | Type A + B    | Email address, company name, account settings, API key identifiers                                         | Account management                    | Performance of contract                 | 6 months                                                                        |
| Payment records       | Type A + B    | Transaction IDs, amounts, payment method type (card details by Stripe only)                                | Billing                               | Legal obligation                        | 3 years (tax/accounting requirements)                                           |
| Input content         | Type B only   | Any Personal Data in Customer's prompts, instructions or other content submitted to the Services           | Provision of inference Services       | Performance of contract                 | Zero persistent storage — discarded immediately upon completion of each request |
| Output content        | Type B only   | Any Personal Data in model-generated responses                                                             | Provision of inference Services       | Performance of contract                 | Zero persistent storage — discarded immediately upon completion of each request |
| Inference logs        | Type B only   | Request-level operational logs (if any)                                                                    | Debugging, performance monitoring     | Legitimate interests                    | 6 months                                                                        |
| Security / audit logs | Type B only   | Access logs, security event logs                                                                           | Security compliance                   | Legal obligation / Legitimate interests | 6 months                                                                        |
| Legally required data | Type B only   | Data required by applicable law at inference deployment location                                           | Legal compliance                      | Legal obligation                        | As required by applicable law; deleted as soon as legally permissible           |

Note: Type A Services — Zenlayer does not collect or process the content of Inputs or Outputs. The metadata categories above are processed by Zenlayer as an independent data controller and are governed by the Company's Privacy Policy.

## Annex 2. Security Measures

The Company implements and maintains the following technical and organizational security measures with respect to Customer Personal Data. The Company may update these measures from time to time, provided that such updates do not materially decrease the overall level of security.

Physical Access Controls: Technical and organizational measures to prevent unauthorized physical access to data processing systems, including: restricted security areas; access authorization systems; locked facilities; CCTV and alarm systems; and securing decentralized equipment.

Logical Access Controls: Technical and organizational measures to prevent unauthorized logical access, including: user authentication and identity management; password policies; automatic session locking and timeout; and monitoring of unauthorized access attempts.

Data Access Controls: Technical and organizational measures to ensure authorized persons access only data within their access rights, including: role-based access controls; least-privilege principles; monitoring and logging of data access; and data deletion and change management procedures.

Transmission Security: Technical and organizational measures to protect Personal Data during transmission, including: encryption of data in transit using industry-standard protocols (TLS 1.2 or higher); secure API communications; and logging of data transmissions.

Availability Controls: Technical and organizational measures to protect Personal Data against accidental loss or destruction, including: backup procedures; redundant systems and failover capabilities; anti-virus and firewall systems; and disaster recovery planning.

Organizational Measures: Organizational measures supporting data security, including: confidentiality obligations for all personnel with access to Customer Personal Data; regular security training; security incident response procedures; and vendor security assessment processes for Sub-Processors.

## Annex 3. Sub-Processor List

| Sub-Processor Company Name | Purpose  | Location      | Details | Created at      |
| -------------------------- | -------- | ------------- | ------- | --------------- |
| Stripe                     | Payments | United States | /       | August 12, 2026 |

This Annex will be updated prior to the engagement of any new Sub-Processor in accordance with Section 6.2.

For Type A Services, Model Providers are not Sub-Processors. They operate independently and are not engaged by the Company to process Customer Personal Data on the Company's behalf.

## Schedule 4. Deployment Locations

This Schedule sets out the current deployment locations. The Company shall update this Schedule and provide Customer with at least 30 days' prior written notice of any material change to the deployment locations listed below. Customer may object to any such change on reasonable data protection grounds within 10 business days of receiving such notice.

| Service Type                 | Deployment Location                      |
| ---------------------------- | ---------------------------------------- |
| Type A (API Routing)         | United States, Singapore, Japan, German. |
| Type B (Dedicated Inference) | United States, Singapore, Japan.         |
