Data protection
Data Processing Addendum
Effective September 30, 2026 · Last updated September 30, 2026
Data protection
Effective September 30, 2026 · Last updated September 30, 2026
This Data Processing Addendum (DPA) forms part of the Cedros Terms of Service or other agreement that incorporates it (Agreement) between Cedros LLC, a Wyoming limited liability company (Cedros), and the customer identified by the applicable account or order (Customer). It applies when Cedros processes Personal Data on Customer's behalf to provide the Services (Customer Personal Data). It takes effect when Customer accepts an Agreement incorporating this DPA. Separate signatures or a separate completed form are not required for these standard terms. A separately negotiated DPA governs instead where it expressly replaces these terms.
Cedros's privacy contact is [email protected]. Legal notices may also be sent to Cedros LLC, Attn: Privacy, 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, United States. Customer's legal identity and contact information are those in its account or applicable order; its designated privacy contact is the contact it supplies for that purpose or, otherwise, its account administrator. Customer's selected Services, authorized configuration, and documented instructions determine the processing described in Schedule A.
Customer acts as controller/business or, where it processes for another controller, as a processor authorized to appoint Cedros as a subprocessor. Cedros acts as processor/service provider/contractor for Customer Personal Data. Cedros's independent processing of its own account administration, billing, and legally permitted platform-security information is governed separately by its Privacy Policy; this distinction does not permit repurposing Customer Personal Data.
Applicable Data Protection Law means privacy and data-protection law applicable to the relevant processing, including the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws where they apply. Personal Data, processing, controller, processor, personal data breach, business, service provider, and contractor have their applicable statutory meanings. A Subprocessor is a third party Cedros engages to process Customer Personal Data on Customer's behalf.
This DPA controls over conflicting general terms concerning Customer Personal Data. Mandatory law and any applicable executed international-transfer clauses control to the extent of a conflict. No general content license, product-improvement clause, assignment clause, or later policy update permits sale of user information or expands Customer's processing instructions. A change to this DPA requires the parties' documented agreement, except a subprocessor change made under Section 6.
Cedros will process Customer Personal Data only to provide the agreed Services in accordance with this DPA, Schedule A, Customer's authorized configuration and requests, and other documented instructions. If law requires different processing, Cedros will inform Customer before processing unless that law prohibits notice. Cedros will promptly inform Customer if it believes an instruction infringes Applicable Data Protection Law and may suspend only the affected processing pending resolution.
Customer will establish a lawful basis, provide required notices, obtain required permissions, protect its credentials, and issue lawful instructions. Special-category, child-related, health, or other regulated data requires express agreement on suitability and safeguards before submission. Customer's obligations do not excuse Cedros from its own obligations.
Cedros will never sell user information, including Customer Personal Data, Customer Content, AI Inputs or Outputs, and aggregated, deidentified, anonymized, or inferred information derived from users. Cedros will not rent, trade, or license that information for monetary or other valuable consideration. Necessary processing by contracted service providers to deliver Services, Customer-directed disclosure, and lawful compulsory disclosure do not authorize sale.
Cedros will not share Customer Personal Data for cross-context behavioral advertising, use it for its own targeted advertising, or use it to train generalized Cedros models without Customer's separate, affirmative authorization for the identified training purpose. Cedros will not authorize a managed AI provider to use private Customer Content or Customer Personal Data for its own advertising or generalized model training without that separate authorization. Authorization cannot permit a sale or override third-party rights or Applicable Data Protection Law.
Cedros must select provider contracts and settings consistent with these restrictions before sending Customer Personal Data. AI inference, temporary feature context, security review, and abuse monitoring must remain limited to the applicable service purpose and lawful terms. No-training is not a representation of zero retention. Customer-selected BYOK services are governed by Customer's own provider relationship, but Cedros remains responsible for its own handling and disclosure of the data.
Cedros will restrict access to authorized personnel with a service need who are subject to confidentiality obligations or an appropriate statutory duty. Cedros will implement and maintain technical and organizational measures appropriate to the nature, scope, context, purpose, and risk of processing, including the requirements in Schedule B. Cedros will not materially reduce the overall protection of Customer Personal Data during the agreed processing.
Cedros will document the applicable controls, review access and security risks, and provide reasonably necessary evidence to Customer under Section 10. Security measures are appropriate to the agreed processing. No certification, regional residency guarantee, or zero-retention service is represented unless expressly included in a separate written agreement.
Customer gives general written authorization for Cedros to engage subprocessors to perform the limited service functions described in Schedule C. Cedros will identify the subprocessors relevant to Customer's Services, their function, and relevant processing-location and transfer information on request. The provider information in Schedule C describes the configured services identified there; Customer-selected integrations remain subject to Customer's own instructions and provider relationship.
For additions or replacements after execution, Cedros will give at least 30 days' prior written notice to Customer's designated privacy contact. Customer may object on reasonable data-protection grounds during that period. The parties will seek a reasonable alternative. Cedros will not send affected Customer Personal Data to the disputed new subprocessor while the objection remains unresolved. If no workable alternative exists, either party may end the affected Service and Cedros will refund unused prepaid fees for that Service.
Cedros will impose written obligations on each subprocessor that provide the protection required by this DPA and applicable law. Cedros remains responsible for its subprocessors' performance of those obligations. These requirements apply to provider-routing changes that introduce a new subprocessor; technical fallback functionality does not waive them.
Taking account of the nature of processing and information available to it, Cedros will assist Customer with legally required access, correction, deletion, portability, restriction, objection, opt-out, and other individual-rights requests. Cedros will promptly forward a request concerning Customer Personal Data to Customer unless prohibited by law, and will not independently determine the response except on Customer's instructions or as required by law.
Cedros will provide reasonable assistance with security obligations, data-protection impact assessments, prior regulatory consultation, and regulator inquiries where required. Customer must supply the information needed to identify affected data without unnecessary disclosure. Any agreed assistance fees must be reasonable, disclosed in advance, and must not prevent or delay assistance that applicable law requires; Cedros will not charge Customer to remedy Cedros's own breach.
Cedros will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. An initial notice may be supplemented as information becomes available and will not be delayed merely because an investigation is incomplete.
To the extent known, notices will describe the nature of the breach, affected categories and approximate numbers of individuals and records, likely consequences, measures taken or proposed, and a contact for follow-up. Cedros will investigate, contain, mitigate, preserve appropriate evidence, and cooperate with Customer's legally required notifications. Notice is not an admission of fault. Cedros will not notify Customer's affected individuals on Customer's behalf without instructions unless required by law.
Cedros will not make a restricted international transfer of Customer Personal Data unless a lawful transfer mechanism and necessary supplementary measures apply. Cedros and Customer will identify the relevant countries, entities, transfer roles, and applicable mechanism in the transfer documentation before the affected transfer. Where required, they must execute the appropriate EU Standard Contractual Clauses, UK Addendum or IDTA, or other approved instrument and complete its annexes and required assessments.
This DPA is not itself the European Commission's Standard Contractual Clauses or a UK transfer instrument. Merely linking to a provider's policy, selecting a foreign provider, or accepting this DPA does not complete a required transfer arrangement. If a lawful mechanism is unavailable or ceases to apply, Cedros will suspend the affected restricted transfer and work with Customer on a lawful alternative.
Cedros will review compulsory demands for Customer Personal Data, limit disclosure to what is lawfully required, and notify Customer before disclosure where legally permitted. Cedros will seek to redirect requests to Customer and challenge unlawful or disproportionate demands where reasonably appropriate and legally permitted.
Cedros will make available information necessary to demonstrate compliance with its processor obligations and permit and contribute to audits and inspections by Customer or its qualified independent auditor. The parties may use relevant reports and questionnaires first where sufficient, without removing a legally required inspection right. Audits will use reasonable notice, confidentiality safeguards, and measures to protect other customers and service security; urgent incidents, credible noncompliance, or regulator requirements may justify shorter notice.
At the end of the processing relationship, Cedros will, at Customer's choice, return or delete Customer Personal Data and delete existing copies unless law requires retention. Customer may give the instruction through [email protected] or an agreed account process. Cedros will provide an available reasonable export method and explain format, scope, timing, and any genuine technical limitation. Cedros will not use an unsupported export format as a reason to disregard a mandatory return right.
Cedros will carry out valid instructions without undue delay and within applicable legal or agreed deadlines. A record category with no automatic age-based expiry remains subject to deletion instructions and necessity review. Where law requires retention, Cedros will identify the requirement where legally permitted, retain only the necessary information, restrict its use and access, and delete it when the requirement ends.
Where deletion from isolated encrypted backups cannot reasonably occur immediately, those copies will remain protected and unavailable for ordinary use until overwritten or deleted under the applicable backup rotation and lawful-retention process. Cedros will reapply valid deletion instructions if a backup is restored before ordinary processing resumes. Backup selection and storage limitations do not authorize indefinite retention without a lawful basis. Cedros will confirm completion or explain remaining restricted copies and their retention basis on request.
Where Cedros receives Personal Information as a service provider or contractor under the CCPA or equivalent applicable law, the limited and specified business purposes are the service operations recorded in Schedule A. Cedros will not sell or share that information; retain, use, or disclose it for a commercial purpose outside those purposes; or retain, use, or disclose it outside the direct business relationship with Customer, except as expressly permitted by applicable law.
Cedros will not combine the information with Personal Information received from another person or collected from its own interaction with an individual except where applicable law expressly permits it for the specified business purposes. Cedros certifies that it understands these restrictions and will comply with them.
Cedros will comply with applicable obligations and provide the level of privacy protection required by applicable law. Customer may take reasonable and appropriate steps to verify consistent use and, upon notice, stop and remediate unauthorized use. Cedros will notify Customer if it determines that it can no longer meet these obligations and cooperate in reasonable remediation. Cedros will provide legally required assistance and bind subcontractors to the applicable restrictions.
This DPA continues while Cedros processes Customer Personal Data, including permitted retained copies. Confidentiality, use restrictions, no-sale obligations, return/deletion requirements, and legally required cooperation survive for as long as relevant information remains under Cedros's control.
The Agreement's governing-law, dispute, and liability provisions apply subject to this DPA, mandatory law, and any controlling transfer instrument. Nothing limits an individual's statutory rights, a regulator's powers, or liability that cannot lawfully be limited. Nothing makes Customer responsible for Cedros's own violation of this DPA.
This schedule identifies the processing covered by this DPA. The particular operations are limited to the Services Customer selects and the instructions it issues. Optional features do not authorize unrelated processing or disclosure to every configured provider.
Hosting and operating Customer Sites; storing and retrieving Customer-provided records; fulfilling authorized API requests; delivering customer-requested communications; executing configured workflows and AI inference; providing support, security, backup and recovery, and necessary usage accounting for the agreed Services. Purposes exclude sale, cross-context advertising, and unauthorized generalized model training.
Collection or receipt, organization, storage, retrieval, transmission to authorized recipients, display, hosting, transformation, inference, export, restriction, and deletion. Processing is continuous for hosting/storage and otherwise occurs as instructed through selected features. Public disclosure occurs only for content Customer intentionally publishes. Customer's configuration, feature selection, account permissions, and documented requests specify the frequency and scope.
Depending on the selected Services: Customer's personnel and authorized users; website visitors; customers and prospective customers; suppliers; and people whose information Customer lawfully includes in its records. Categories may include identifiers and contact details; account and role information; transaction, order, and booking details; form submissions and correspondence; technical, device, IP-address, usage, and security information; uploaded content; and AI inputs, outputs, and connected-service context.
Only categories necessary for Customer's selected operations are authorized. Government identifiers, special-category health/biometric data, payment-card data outside supported payment flows, children's data requiring special safeguards, and other specially regulated information are excluded unless separately agreed with suitable controls and any required agreement.
Processing lasts for the agreed service term and the necessary return/deletion period, subject to documented lawful retention. Customer controls the retention settings exposed for its deployment and may issue return/deletion instructions under Section 11. Where no specific window is agreed or configured, Cedros will retain Customer Personal Data only as necessary for the documented service purpose or a lawful retention obligation, subject to valid deletion instructions. The Privacy Policy describes dated settings for the Cedros-operated site; those settings do not override a Customer's valid instructions or an applicable contractual or legal requirement.
Customer's designated administrators may provide instructions within their authority. Material changes to purpose, data categories, regulated uses, providers, or restricted-transfer arrangements must be documented before the changed processing. Cedros will send privacy, breach, subprocessor, and transfer notices to Customer's designated privacy contact or account administrator. Cedros's contact is [email protected].
Customer's account or order identifies its legal name, service relationship, administrators, and contact details. Customer's selection and use of the Services, permitted data submissions, and documented instructions specify the operations and data categories within this schedule. If Customer acts for another controller, Customer represents that it is authorized to appoint Cedros for that processing. Any additional regional, industry, residency, or transfer requirement must be supported by the applicable Service and lawful arrangement before Customer uses it for that purpose.
Cedros will maintain the following safeguards appropriate to the agreed processing and its risks. These are contractual security obligations, not a certification, an uptime guarantee, or a representation that every customer configuration uses every available control. A separately agreed security schedule may specify additional measures.
Limit access by role and service need; authenticate authorized users; protect privileged credentials and API keys; promptly remove access when no longer needed; maintain appropriate access records; and apply confidentiality obligations to personnel with access. Use available stronger authentication for privileged access where appropriate to risk.
Use encrypted transport for supported service interfaces. Protect storage and infrastructure through access controls appropriate to the data. Encrypt database/vault backup artifacts and safeguard recovery material separately from ordinary public content. Restrict access to provider credentials and secrets; rotate compromised credentials. Do not represent all stored content as end-to-end encrypted.
Enforce account and tenant access boundaries, including exports, background jobs, extensions, and agent tools. Minimize the data sent to optional providers and apply granted permissions. Maintain documented retention, deletion, and backup-rotation instructions, including deletion handling after restoration.
Maintain backups appropriate to the agreed deployment, restrict recovery operations, and periodically evaluate restoration and continuity arrangements. Define the scope of backup coverage and exclusions. No recovery-point, recovery-time, uptime, or lossless-recovery guarantee is implied unless separately agreed.
Maintain proportionate operational and security logs, investigate suspected unauthorized access, address vulnerabilities according to risk, manage supported dependencies, and apply an incident-response process. Avoid placing unnecessary Personal Data or secrets in logs. Limit retention of diagnostic material to the necessary purpose.
Evaluate providers for their function, data access, contract, security measures, retention, training use, and transfer requirements. Keep evidence of applicable terms and settings. Review material changes before routing Customer Personal Data through a new provider. Document testing and corrective actions; make appropriate compliance evidence available under Section 10.
Customer configures its users, permissions, integrations, lawful data collection, and workflows; protects its endpoints and credentials; and maintains independent copies of critical information where appropriate. Cedros remains responsible for its own controls and the processing it undertakes under this DPA.
The Service providers & subprocessors page provides current configured-service disclosures, provider reference links, location information, and the channel for customer-specific information and notice contacts. It includes infrastructure, delivery, and payment services such as DigitalOcean hosting, Hetzner, Cloudflare, and Stripe where used, in addition to the functions below. The actual processing role and providers depend on the selected Services. Publication of this information does not replace the authorization, notice, objection, or transfer safeguards required by this DPA.
Cedros uses providers for infrastructure, storage, communications, AI, search, and other service functions. A provider processes Customer Personal Data only where relevant to the Services selected and only under the applicable authorization, instructions, and contractual restrictions. Cedros remains responsible for its subprocessor obligations under Section 6.
| Configured service | Function and relevant information |
|---|---|
| DigitalOcean Spaces | Media and encrypted-backup storage. Configured storage region: sfo3, United States. |
| Amazon Web Services - SES | Email delivery, message content and delivery metadata. Configured delivery region: us-east-2, United States. |
| OpenAI / Anthropic / Google Gemini / xAI | AI model services: requested inputs, relevant context, outputs and request metadata. |
| OpenRouter | AI routing and inference through the provider selected for the request. Both router and downstream provider may process relevant inputs and metadata. |
| ElevenLabs | Voice functionality: text or audio submitted to the feature and request metadata. |
| Exa | Search for requested features: queries and information included in those queries. |
| Ahrefs | Backlink and search-performance analysis: relevant domains, URLs and related analysis information. |
These are configured service brands for the Cedros-operated site as of the date above. The provider set for a Customer deployment depends on its selected Services and integrations. Brand names identify the services, not every affiliate or downstream legal entity. Where a service acts as a subprocessor, Cedros's obligations apply to the actual engaged entity and relevant onward processing.
Customer may obtain the current information applicable to its Services, including the relevant contracting entity, function, countries of processing, and applicable transfer safeguards, by contacting [email protected]. Cedros will provide the information necessary to administer Customer's subprocessor authorization. Additional or replacement subprocessors are subject to the notice and objection process in Section 6.
A listed storage region does not guarantee that every Service, support function, or AI provider processes information exclusively in that region. Regional processing, zero retention, and restricted-transfer support apply only where available and expressly agreed. Cedros must use the lawful mechanism and safeguards required by Section 9 before a restricted transfer. This DPA does not itself constitute EU Standard Contractual Clauses or a UK transfer instrument.
The Cedros Privacy Policy describes Cedros's own data handling and its permanent no-sale commitment. The Beta Service Level Agreement sets the service-level terms during beta and does not reduce the data-protection obligations in this DPA.
Related documents: Terms of Service, Privacy Policy, and Beta Service Level Agreement.
