1. Parties and roles
This Addendum forms part of the Terms of Service between the Customer (“Controller”) and Vantafold (“Processor”). Where the Customer is itself a processor for its own customers, Vantafold acts as a subprocessor and this Addendum applies accordingly.
It takes effect on the date the Customer accepts the Terms of Service or executes an order form, whichever is earlier.
2. Subject matter and duration
The subject matter is the provision of the Vantafold inference and orchestration platform. Processing continues for the term of the agreement and for the deletion period described below.
3. Nature and purpose
Vantafold processes personal data only to:
- Receive, validate, and route requests to the model selected by policy.
- Return responses, usage counts, and cost data to the Controller.
- Record traces and telemetry for the retention period of the Controller's plan.
- Provide support, security monitoring, and abuse prevention.
- Comply with legal obligations.
4. Categories of data and data subjects
The categories depend on what the Controller sends through the API and are determined by the Controller, not by Vantafold.
| Category | Examples | Data subjects |
|---|---|---|
| Account data | Name, work email, company, billing contact | Controller's personnel |
| Request content | Prompts, completions, tool arguments | Whoever the Controller's application serves |
| Usage metadata | Token counts, latency, model routed to, cost | Controller's personnel and end users |
| Technical data | IP address, user agent, API key identifier | Controller's personnel and systems |
The Controller must not send special categories of personal data under Article 9 GDPR unless it has enabled zero-retention mode and has a lawful basis for doing so.
5. Processor obligations
Vantafold will:
- Process personal data only on the Controller's documented instructions, including the instructions expressed through product configuration such as region pinning and retention.
- Ensure personnel with access are bound by confidentiality obligations.
- Implement the technical and organisational measures described in the security page.
- Notify the Controller without undue delay, and in any case within 72 hours, of a personal data breach affecting its data.
- Assist the Controller with data-subject requests, impact assessments, and consultations with supervisory authorities.
- Delete or return personal data at the Controller's choice on termination.
6. Subprocessors
The Controller grants general authorisation for Vantafold to engage the subprocessors listed on the subprocessors page. Vantafold gives at least 30 days' notice before adding or replacing a subprocessor.
The Controller may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, the Controller may terminate the affected service without penalty for the remainder of the term.
7. International transfers
Transfers of personal data out of the EEA, Switzerland, or the UK rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two or Module Three as applicable, together with the UK International Data Transfer Addendum.
Where the Controller has enabled data residency, personal data does not leave the selected region and no transfer occurs.
8. Security measures
Vantafold maintains the measures described on the security page, including encryption in transit and at rest, least-privilege access with mandatory multi-factor authentication, tenant isolation, centralised logging, tested backups, and an annual third-party penetration test.
Measures may be updated provided the level of protection is not reduced.
9. Audit
Vantafold will make available the information necessary to demonstrate compliance, including its current SOC 2 Type II report and penetration test summary under NDA.
Where those are insufficient for a Controller's regulatory obligations, the Controller may conduct an audit no more than once per year, on 30 days' notice, during business hours, at its own cost, and subject to confidentiality.
10. Return and deletion
On termination, Vantafold deletes personal data within 30 days unless the Controller requests return first, or law requires retention. Backups are purged on their normal rotation, within 90 days.
Zero-retention mode means request content is never written to persistent storage and there is nothing to delete.
11. Liability
Each party's liability under this Addendum is subject to the limitations in the Terms of Service. Nothing here limits a data subject's rights under applicable data protection law.
Questions about this document? Write to legal@vantafold.ai, or see the contact page for our registered entities.