This Data Processing Agreement ("DPA") forms part of the agreement between VaultAPI ("Processor", "VaultAPI") and the customer ("Controller", "you") for use of the Service. It governs Processor's processing of Personal Data on Controller's behalf.
1. Definitions
“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, and “Subprocessor” have the meanings in applicable data protection law, including GDPR, UK GDPR, India DPDP Act, and CCPA.
2. Roles & scope
Controller is the controller and VaultAPI is the processor for Customer Personal Data processed to provide the Service. VaultAPI will process only on documented instructions from Controller, including configuration in the Service, except where required by law.
3. Details of processing
- Subject matter: provision of the VaultAPI AI-gateway Service.
- Duration: the term of the Agreement plus the deletion/return period.
- Purpose: routing requests to selected LLM providers; token/cost tooling; observability; and billing.
- Data subjects: Controller's authorized users and individuals whose personal data appears in Controller requests.
- Data categories: account identifiers, technical and usage metadata, personal data included in request content, and encrypted provider credentials.
4. Processor obligations
VaultAPI will process only on Controller instructions; ensure authorized persons are bound by confidentiality; implement appropriate technical and organizational measures; respect the requirements for subprocessors; assist with data-subject requests, security, DPIA, and breach obligations; delete or return Personal Data at the end of services; and make available information necessary to demonstrate compliance.
5. Subprocessors
Controller provides general authorization for VaultAPI to engage subprocessors, including cloud database providers, Redis cache providers, and payment processors (Stripe and Razorpay). LLM providers selected by Controller receive request data through Controller's BYOK credentials under Controller's own arrangements. VaultAPI will give 30 days' notice of new subprocessors; Controller may object on reasonable data-protection grounds.
6. Security
Measures include envelope encryption (AES-GCM) of stored provider keys; hashed passwords and rotating, reuse-detecting refresh tokens; encryption in transit; role-based access control and tenant isolation; audit logging; rate limiting; and secrets held in a secrets manager.
7. International transfers
Where processing involves transfers subject to applicable law, the parties will rely on a valid transfer mechanism, such as Standard Contractual Clauses or an applicable equivalent.
8. Data-subject requests, breaches & audits
- Data-subject requests: VaultAPI will promptly notify Controller of requests it receives and assist Controller in responding.
- Personal data breach: VaultAPI will notify Controller without undue delay after becoming aware, with available details.
- Audits: VaultAPI will provide reasonable compliance information and, subject to confidentiality and reasonable advance notice terms, allow audits.
9. Deletion & return
On termination, VaultAPI will, at Controller's choice, delete or return Customer Personal Data within 30 days unless retention is legally required. Loss of the master key renders encrypted BYOK keys unrecoverable; deletion of provider keys is effectively irreversible.
10. Liability & precedence
Liability under this DPA is subject to the limitations in the Agreement. In a conflict on data-protection matters, this DPA controls.
11. Contact & inquiries
For any DPA or data processing questions, contact VaultAPI at vaultapi.support@gmail.com.