Data Processing Addendum
Last updated: 13 July 2026
This Data Processing Addendum ("DPA") forms part of and is subject to the SafeRouter Terms of Service (the "Terms") between the Customer and Sumplus, a company organized in the British Virgin Islands ("Sumplus", operating the "SafeRouter" service). This DPA governs the processing of Personal Data by Sumplus on behalf of the Customer in connection with the Service. Capitalized terms not defined in this DPA have the meanings given in the Terms. To execute this DPA, contact support@sumplus.xyz.
1. Roles of the Parties
For the purposes of this DPA, the Customer acts as the data controller and Sumplus, operating SafeRouter, acts as the data processor with respect to Personal Data processed on the Customer's behalf. Each party will comply with its respective obligations under applicable data protection law.
2. Subject Matter and Duration
The subject matter of the processing is the provision of the Service as described in the Terms. Processing continues for the duration of the Customer's use of the Service and until deletion or return of Personal Data in accordance with Section 9, subject to the append-only nature of the transparency log described in Section 5 and in the Privacy Policy.
3. Nature and Purpose of Processing
Sumplus processes Personal Data for the purpose of providing, operating, securing, metering, and supporting the Service, including routing Customer requests to Upstream Providers, returning outputs, computing costs and managing Credits, authenticating accounts, and generating and anchoring the append-only transparency log. The nature of the processing includes receipt, transmission, routing, computation of metadata and hashes, storage of account and usage metadata, and related operations.
4. Categories of Data Subjects and Personal Data
Categories of data subjects: the Customer's authorized users and account holders, and, to the extent included by the Customer within prompts, individuals whose Personal Data the Customer submits to the Service.
Categories of Personal Data:
- account data, including email address, OAuth identifier, and cryptocurrency wallet address;
- usage metadata, including timestamps, model name, token or unit counts, computed cost, Upstream Provider, and latency;
- payment metadata related to Credit top-ups, handled by the payment processor; and
- transient prompt and completion content needed to route a request, which may contain Personal Data determined by the Customer.
5. Processor Obligations
Sumplus will:
- (a) Documented instructions. Process Personal Data only on the Customer's documented instructions, including as set out in the Terms, this DPA, and the Customer's configuration and use of the Service, unless required to act otherwise by applicable law, in which case Sumplus will inform the Customer unless legally prohibited.
- (b) Confidentiality of personnel. Ensure that persons authorized to process Personal Data are bound by appropriate obligations of confidentiality.
- (c) Security measures. Implement appropriate technical and organizational measures, including hardware Trusted Execution Environment isolation (AMD SEV-SNP) with remote attestation, hashing of call records, argon2 password hashing, Secure session cookies, and encryption of data in transit. The transparency log records only hashes and call metadata and does not record the plaintext content of prompts or completions.
- (d) Sub-processors. Engage sub-processors as described in Section 6, and provide notice of intended changes to sub-processors so that the Customer has the opportunity to object.
- (e) Assistance with data-subject requests. Taking into account the nature of the processing, provide reasonable assistance to the Customer in responding to requests from data subjects to exercise their rights, including access, deletion, and export of account data.
- (f) Breach notification. Notify the Customer without undue delay after becoming aware of a Personal Data breach affecting the Customer's Personal Data, and provide reasonably available information to assist the Customer in meeting its obligations.
- (g) Deletion or return. Upon termination of the Service, delete or return Personal Data processed on the Customer's behalf in accordance with Section 9, subject to retention required by applicable law and to the append-only transparency log records, which consist of hashes and call metadata and by design cannot be altered or removed.
- (h) Demonstrating compliance. Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA.
6. Sub-Processors
The Customer authorizes Sumplus to engage the following categories of sub-processors, described by role:
- third-party AI model providers, which fulfill inference requests (Upstream Providers);
- a cloud hosting provider located in the United States (AWS, region us-east-2);
- a cryptocurrency payment processor, which handles Credit top-ups; and
- a transactional email provider, which delivers transactional email.
Sumplus will impose data protection obligations on its sub-processors that are consistent with this DPA and will remain responsible for the performance of its sub-processors' obligations. Sumplus will provide notice of any intended addition or replacement of a sub-processor, and the Customer may object on reasonable data protection grounds by contacting support@sumplus.xyz.
7. International Transfers
Sumplus is organized in the British Virgin Islands and hosts the Service with a cloud provider located in the United States. Upstream Providers and other sub-processors may process Personal Data in various jurisdictions. The parties will ensure that any transfer of Personal Data is subject to appropriate safeguards as required by applicable data protection law.
8. Data-Subject Requests
Where Sumplus receives a request from a data subject relating to Personal Data processed on the Customer's behalf, Sumplus will, to the extent legally permitted, direct the data subject to the Customer and provide reasonable assistance to the Customer in responding, taking into account the nature of the processing.
9. Deletion or Return on Termination
Upon expiry or termination of the Service, and at the Customer's choice, Sumplus will delete or return the Personal Data processed on the Customer's behalf, and will delete existing copies unless retention is required by applicable law. This obligation does not apply to hashed records and anchored roots in the append-only transparency log, which do not contain plaintext content and by design cannot be altered or removed.
10. Relationship to the Terms of Service
This DPA supplements the Terms and is limited by them. In the event of a conflict between this DPA and the Terms with respect to the processing of Personal Data, this DPA controls. Except as expressly modified by this DPA, the Terms remain in full force and effect, including the provisions on warranty disclaimer, limitation of liability, and governing law. This DPA is governed by the laws of the British Virgin Islands, consistent with the Terms.
11. Contact and Execution
For execution of this DPA and for all notices under it, contact support@sumplus.xyz.