Data Processing Addendum

Effective date: April 22, 2026

1. Introduction and scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Totally Private AI ("TPAI," "Processor," "we") and the customer subscribing to the Service ("Customer," "Controller," "you"). This DPA applies to the extent that TPAI processes Personal Data on behalf of the Customer in the course of providing the Totally Private AI Pro service.

Enterprise customers: if your Master Services Agreement includes data processing terms, those terms govern instead of this DPA. Where the MSA is silent on a topic addressed here, this DPA applies as a supplement.

This DPA is entered into as of the date you accept the Agreement or begin using the Service, whichever is earlier.


2. Definitions

Terms not defined here have the meaning given in the Agreement or in applicable Data Protection Laws.

"Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the UK GDPR, the California Consumer Privacy Act (as amended by the CPRA), and any other applicable privacy or data protection legislation.

"Personal Data" means any information relating to an identified or identifiable natural person that TPAI processes on behalf of the Customer in connection with the Service.

"Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, encryption, pseudonymization, and deletion.

"Sub-processor" means any third party engaged by TPAI to process Personal Data on behalf of the Customer.

"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed by TPAI.


3. Processing details

3.1 Roles

The Customer is the Controller. TPAI is the Processor. TPAI processes Personal Data only on behalf of and under the documented instructions of the Customer.

3.2 Subject matter and purpose

TPAI processes Personal Data to provide the Totally Private AI service: an air-gapped AI inference platform with per-user encryption, no public internet egress from the AI environment, and pseudonymized user identity within the platform. Processing includes receiving prompts, generating AI model responses via AWS Bedrock, encrypting and storing conversation data, and collecting operational metadata for platform monitoring and billing.

3.3 Types of Personal Data

  • Account data: email address (pseudonymized before entering the air-gapped environment), Stripe customer identifier, subscription status.
  • User content: prompts, AI model responses, and any files uploaded through the Service. Content is encrypted with a per-user key within the air-gapped boundary.
  • Operational metadata: request timestamps, model identifiers, token counts, error codes. Does not include prompt or response content.
  • Connection data (Pro): VPN connection timestamps, connection duration, IP addresses in infrastructure logs.

3.4 Categories of data subjects

Authorized users of the Customer's Totally Private AI subscription. For individual Pro subscribers, the data subject is the subscriber themselves.

3.5 Duration

Processing continues for the duration of the Agreement. Post-termination processing is limited to data retention and deletion as described in Section 10.


4. Customer instructions

TPAI processes Personal Data only in accordance with the Customer's documented instructions. The Agreement (including this DPA) constitutes the Customer's complete initial instructions. Additional instructions require mutual written agreement. If TPAI believes an instruction violates Data Protection Laws, it will promptly notify the Customer.


5. Confidentiality

TPAI ensures that all personnel authorized to process Personal Data are bound by appropriate confidentiality obligations (contractual or statutory). Access to Personal Data is limited to personnel who require it to perform their duties in connection with the Service.


6. Security measures

TPAI implements and maintains technical and organizational measures appropriate to the risk, including:

  • Air-gapped architecture: the AI environment has no internet gateway, no NAT gateway, and no route to the public internet. All cloud service communication occurs over private endpoints.
  • Per-user encryption: each user's data is encrypted with a unique data encryption key managed in AWS KMS within the deployment boundary. Access to keys is restricted and audited.
  • Pseudonymization: user email addresses are pseudonymized using a hardware-backed cryptographic function before entering the air-gapped environment.
  • Access controls: TPAI does not access user content under normal operations. Infrastructure access is limited to platform maintenance and does not provide access to encrypted user data.
  • Logging and monitoring: operational logs (access, authentication, administrative actions) are maintained within the boundary. No third-party analytics, telemetry, or SIEM services receive platform data.
  • No model training: neither TPAI nor the model provider (AWS Bedrock) uses customer data for model training, per AWS Bedrock service terms.

A detailed description of the architecture and security controls is available under NDA as part of TPAI's security review process. Contact security@totallyprivate.ai to request a review.


7. Sub-processors

7.1 Current sub-processors

The Customer authorizes TPAI to engage the following sub-processors:

Sub-processor Purpose Data processed Location
Amazon Web Services (Bedrock) AI model inference via private endpoints within the air-gapped environment Prompts and responses (transient, not retained by AWS for training) Same AWS region as Pro deployment
Stripe, Inc. Payment processing and subscription management Email address, payment card details, billing address United States

7.2 Changes to sub-processors

TPAI will notify the Customer at least 30 days before engaging a new sub-processor or materially changing the scope of an existing sub-processor's processing. Notification will be sent by email to the address associated with the Customer's account and posted to the Privacy Policy.

If the Customer objects to a new sub-processor on reasonable data protection grounds, the Customer may notify TPAI within 15 days of the notification. TPAI will work with the Customer to find a commercially reasonable solution. If no resolution is reached, the Customer may terminate the Agreement without penalty.

7.3 Sub-processor obligations

TPAI imposes data protection obligations on each sub-processor that are no less protective than those in this DPA. TPAI remains fully liable to the Customer for the performance of each sub-processor's obligations.


8. Data subject rights

TPAI will assist the Customer in responding to requests from data subjects exercising their rights under Data Protection Laws (access, rectification, erasure, portability, restriction, objection). TPAI will promptly notify the Customer if it receives a request directly from a data subject, unless prohibited by law from doing so.

Because the TPAI architecture pseudonymizes user identity and encrypts content per-user, many data subject rights are satisfied by the architecture itself. TPAI will provide reasonable technical assistance to enable the Customer to fulfill its obligations.


9. Security incident notification

TPAI will notify the Customer without undue delay (and in any event within 72 hours of becoming aware) of any Security Incident affecting Personal Data processed under this DPA. Notification will include, to the extent known:

  • The nature of the incident, including the categories and approximate number of data subjects and records affected.
  • The likely consequences of the incident.
  • The measures taken or proposed to address the incident and mitigate its effects.
  • The name and contact details of a point of contact for further information.

TPAI will cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of the incident. TPAI will not notify any third party (including supervisory authorities or data subjects) on behalf of the Customer unless the Customer requests it in writing or TPAI is legally required to do so.


10. Data retention and deletion

On termination or expiration of the Agreement, TPAI will, at the Customer's choice, return or delete all Personal Data within 30 days, except where retention is required by applicable law. Because user content is encrypted with a per-user key, deletion of the key renders the content irrecoverable.

Default retention windows for the Pro tier: usage metadata is retained for up to 90 days; VPN connection logs and infrastructure logs are retained for up to 30 days; audit trail logs are retained for up to 30 days. These defaults may be adjusted for security or compliance requirements.

Stripe retains billing data in accordance with its own retention policies and applicable financial regulations.


11. International data transfers

The Pro environment operates in a single AWS region. TPAI does not transfer user content across regional boundaries. The current hosting region is published on the Security page (or contact privacy@totallyprivate.ai).

Where Personal Data is transferred outside the European Economic Area, the United Kingdom, or Switzerland to a country not covered by an adequacy decision, TPAI relies on appropriate safeguards as required by Data Protection Laws, including Standard Contractual Clauses (EU Commission decision 2021/914) where applicable. The Customer may request a copy of the applicable transfer mechanism by contacting privacy@totallyprivate.ai.

Stripe's processing of billing data involves transfer to the United States. Stripe is certified under the EU-US Data Privacy Framework.


12. Audit rights

TPAI will make available to the Customer, on request, information necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR. This includes, where applicable, the results of third-party audits or certifications (such as SOC 2 Type II reports, ISO 27001 certificates, or penetration test summaries).

The Customer (or a qualified third-party auditor appointed by the Customer) may conduct an audit of TPAI's processing activities under this DPA, subject to the following conditions:

  • The Customer provides at least 30 days written notice.
  • Audits are conducted during normal business hours and no more than once per 12-month period, unless required by a supervisory authority or following a Security Incident.
  • The auditor executes a confidentiality agreement acceptable to TPAI before accessing any proprietary or security-sensitive information.
  • The audit scope is limited to TPAI's processing of the Customer's Personal Data and does not extend to other customers' data or to proprietary architecture detail beyond what is necessary to verify compliance.

TPAI will cooperate with the audit and provide reasonable access to relevant records, systems, and personnel. If an audit reveals a material non-compliance, TPAI will remediate the issue at its own expense within a reasonable timeframe.


13. Data protection impact assessments

TPAI will provide reasonable assistance to the Customer in conducting data protection impact assessments and prior consultations with supervisory authorities, to the extent required under Data Protection Laws and to the extent the assessment relates to TPAI's processing of Personal Data.


14. Term and termination

This DPA takes effect on the date the Customer accepts the Agreement and remains in effect for as long as TPAI processes Personal Data on behalf of the Customer. Termination of the Agreement automatically terminates this DPA, subject to TPAI's obligations under Section 10 (data retention and deletion).


15. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement. This DPA does not limit either party's liability for breaches of Data Protection Laws to the extent such limitation is prohibited by applicable law.


16. Conflict

In the event of any conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict with respect to the processing of Personal Data. In all other respects, the Agreement governs.


17. Contact

For questions about this DPA or TPAI's data processing practices:

Totally Private AI
Email: privacy@totallyprivate.ai
Security: totallyprivate.ai/security


Annex I: Standard Contractual Clauses (EU)

Where the Customer is established in the European Economic Area, the United Kingdom, or Switzerland, and Personal Data is transferred to TPAI in a country not covered by an adequacy decision, the parties agree that the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914, "SCCs") are incorporated by reference into this DPA. The parties agree to Module 2 (Controller to Processor).

For the purposes of the SCCs:

  • The data exporter is the Customer (Controller).
  • The data importer is Totally Private AI (Processor).
  • The competent supervisory authority is the supervisory authority of the EU Member State in which the data exporter is established, or where the data exporter is not established in the EU, the supervisory authority of the Member State in which the data exporter's EU representative is established.
  • Clause 7 (Docking clause): the parties agree that additional entities may accede to the SCCs as a data exporter or data importer with the written agreement of all existing parties.
  • Clause 9 (Use of sub-processors): the parties select Option 2 (general written authorization). The data importer has the data exporter's general authorization for the engagement of sub-processors listed in Section 7 of this DPA. The data importer will notify the data exporter of any intended changes to that list in accordance with Section 7.2.
  • Clause 11 (Redress): the optional language is not adopted.
  • Clause 17 (Governing law): the SCCs are governed by the law of the EU Member State in which the data exporter is established. Where the data exporter is not established in an EU Member State, the laws of Ireland apply.
  • Clause 18 (Choice of forum and jurisdiction): disputes are resolved before the courts of the EU Member State in which the data exporter is established. Where the data exporter is not established in an EU Member State, the courts of Ireland have jurisdiction.

Annex I.A: List of parties

Data exporter:

NameThe Customer, as identified in the Agreement
RoleController
ContactAs provided in the Customer's account registration
ActivitiesUse of the Totally Private AI service for AI-assisted professional work

Data importer:

NameTotally Private AI
RoleProcessor
AddressNew York, NY, United States
Contactprivacy@totallyprivate.ai
ActivitiesProviding air-gapped AI infrastructure with per-user encryption and no public internet egress from the AI environment

Annex I.B: Description of transfer

Categories of data subjectsAuthorized users of the Customer's Totally Private AI subscription
Categories of Personal DataEmail address (pseudonymized before entering the air-gapped environment), prompts and AI model responses (encrypted per-user), operational metadata (timestamps, model identifiers, token counts), VPN connection timestamps and IP addresses
Sensitive dataThe Service does not require submission of sensitive or special category data. If the Customer chooses to include such data in prompts, it is encrypted per-user within the air-gapped boundary under the same protections as all other user content
Frequency of transferContinuous, each time an authorized user accesses the Service
Nature of processingReceiving and encrypting prompts, generating AI model responses via AWS Bedrock over private endpoints, storing encrypted conversation data, collecting operational metadata for monitoring and billing
Purpose of transferProvision of the Totally Private AI service as described in the Agreement
Retention periodUser content: duration of subscription plus 30 days. Usage metadata: up to 90 days. VPN and infrastructure logs: up to 30 days. Audit trail logs: up to 30 days

Annex I.C: Competent supervisory authority

The competent supervisory authority is determined in accordance with Clause 13 of the SCCs. Where the data exporter is established in the EU, it is the supervisory authority of the Member State in which the data exporter is established. Where the data exporter is not established in the EU, the Irish Data Protection Commission (DPC) acts as competent supervisory authority.


Annex II: Technical and organizational measures

The data importer implements the following technical and organizational measures to protect Personal Data. These measures are described in further detail on the TPAI Security page and are available for review under NDA as part of TPAI's security review process.

Encryption

All user content is encrypted at rest using a unique data encryption key per user, managed in AWS KMS within the deployment boundary. Data is encrypted in transit using TLS 1.2 or higher. VPN connections use certificate-based mutual authentication issued from a private certificate authority.

Network isolation

The AI environment has no internet gateway, no NAT gateway, and no route to the public internet. All cloud service communication occurs over private endpoints on the provider backbone. The deployment boundary enforces network-level, service-level, routing, and organizational controls.

Access controls

TPAI does not access user content under normal operations. Infrastructure access is limited to platform maintenance and does not provide access to encrypted user data. All administrative access is logged and auditable.

Pseudonymization

User email addresses are pseudonymized using a hardware-backed cryptographic function before entering the air-gapped environment. The pseudonym, not the email address, is the identifier used within the platform.

Sub-processor controls

AWS Bedrock processes inference within the deployment boundary over private endpoints and does not use customer data for model training (per AWS Bedrock service terms). Stripe processes billing data in its own environment under its own security program; TPAI does not store payment card data.

Incident response

TPAI maintains incident response procedures and will notify the data exporter within 72 hours of becoming aware of a Security Incident, as described in Section 9 of this DPA.

Data minimization

TPAI collects and processes only the minimum Personal Data necessary to provide the Service. Operational metadata does not include prompt or response content. No third-party analytics, telemetry, SIEM, or advertising services receive platform data.


Annex III: List of sub-processors

Sub-processor Purpose Data processed Location
Amazon Web Services (Bedrock) AI model inference via private endpoints within the air-gapped environment Prompts and responses (transient, processed within deployment boundary, not retained for training) Same AWS region as Pro deployment
Stripe, Inc. Payment processing and subscription management Email address, payment card details, billing address United States (certified under EU-US Data Privacy Framework)

UK and Swiss addendum

Where the Customer is subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs (issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018) is incorporated by reference. The information required by Table 1 through Table 4 of the UK Addendum is as set out in the Annexes above.

Where the Customer is subject to the Swiss Federal Act on Data Protection (FADP), the SCCs apply with the modifications required by Swiss law, including that the Swiss Federal Data Protection and Information Commissioner (FDPIC) acts as competent supervisory authority, and references to the GDPR are read as references to the FADP where applicable.