Last updated: July 15, 2026

Data Processing Agreement

Last updated: July 15, 2026

This Data Processing Agreement ("DPA") is entered into between the Customer identified on the applicable Order Form or dashboard account ("Customer," "Controller," "you") and ValGuard.ai ("ValGuard," "Processor," "we," "us"), and supplements and forms part of the Terms of Service ("Terms"). This DPA applies to the extent ValGuard processes Personal Data on Customer's behalf in the course of providing the ValGuard AI Security & Governance Gateway (the "Service"). Capitalized terms used but not defined in this DPA have the meanings given in the Terms or in Section 1 below. In the event of a conflict between this DPA and the Terms with respect to the processing of Personal Data, this DPA controls; in all other respects, the Terms control.

Enterprise customers may request a countersigned, order-form-referenced version of this DPA (including a completed signature block) by contacting legal@valguard.neteos.eu. Absent a countersigned version, this published DPA applies automatically to all Customers for whom ValGuard processes Personal Data, consistent with Article 28 GDPR.

1. Definitions

  • "GDPR" means Regulation (EU) 2016/679 (the General Data Protection Regulation), as it forms part of UK law by virtue of the European Union (Withdrawal) Act 2018 ("UK GDPR"), and equivalent data protection laws in the jurisdictions where Customer or its end users are located.
  • "Personal Data," "Processing," "Controller," "Processor," "Data Subject," "Personal Data Breach," and "Supervisory Authority" have the meanings given in the GDPR, applied to this DPA regardless of whether Customer or a Data Subject is located in the EEA/UK.
  • "Customer Personal Data" means Personal Data that ValGuard processes on Customer's behalf as a Processor (or Sub-processor) in connection with the Service, as further described in Annex 1. It does not include ValGuard Account Data (defined below).
  • "ValGuard Account Data" means Personal Data that ValGuard collects and processes as an independent Controller for its own business purposes — such as the name, email, and role of Customer's authorized dashboard users, billing contact details, and support communications — as described in the Privacy Policy.
  • "Sub-processor" means any third party ValGuard engages to process Customer Personal Data in order to provide the Service, as listed in Annex 2.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), and, where applicable, the UK International Data Transfer Addendum issued by the UK Information Commissioner's Office.
  • "Payload Logging" means the Customer-configurable Agent setting (log level) that, when enabled, causes Prompt and Output content to be persisted for the retention period Customer selects, as described in Section 3.2 of the Terms and Annex 1 of this DPA.

2. Scope, roles, and relationship to other documents

2.1 Processor relationship. Where Customer Personal Data constitutes Personal Data, Customer acts as Controller (or, where Customer itself processes Personal Data on behalf of a third-party controller, as a Processor instructing a Sub-processor), and ValGuard acts as Processor (or Sub-processor, as applicable) with respect to that Customer Personal Data, in each case only to the extent ValGuard processes such data in providing the Service.

2.2 Separate controller relationship for ValGuard Account Data. Independently of the Processor relationship described above, ValGuard acts as an independent Controller (or, for California residents, a "business" under the CCPA/CPRA) with respect to ValGuard Account Data — for example, dashboard user account and authentication records, billing and invoicing records, and support tickets — because ValGuard determines the purposes and means of that processing for its own account administration, billing, security, and legal-compliance purposes. That processing is governed by the Privacy Policy, not by this DPA. This distinction matters primarily for CCPA-style frameworks that define "business," "service provider," and "third party" by reference to who determines the purpose of processing; it does not narrow ValGuard's obligations as Processor under Section 3 below with respect to Customer Personal Data.

2.3 No payload storage by default. As described in Section 3.2 of the Terms, ValGuard validates Prompts (ingress) and Outputs (egress) in memory by default and does not persist that content unless Customer explicitly enables Payload Logging for an Agent. This DPA applies to Customer Personal Data regardless of whether Payload Logging is enabled, because metadata about validation activity (timestamps, token counts, cost, validator pass/fail results, and, where applicable, redacted validator messages) may itself constitute Personal Data (for example, where it is linked to an identifiable end user via request or session identifiers). Annex 1 describes both scenarios.

2.4 Sub-processor relationship for LLM Providers. Where Customer connects to an LLM Provider using its own credentials (BYOK) or via Provider Vault, ValGuard routes Prompts to that LLM Provider strictly on Customer's instruction and using Customer's chosen credentials. As stated in the Subprocessors page and Section 7.4 of the Terms, ValGuard does not consider Customer-configured LLM Providers to be its own Sub-processors, because Customer — not ValGuard — selects, contracts with, and instructs each LLM Provider, and controls whether and when to route traffic to it. Customer is responsible for its own controller-processor or controller-controller relationship with each LLM Provider it configures, including executing that provider's own data processing terms where Customer Personal Data will be sent to it.

3. Processing of Customer Personal Data

3.1 Details of processing. The subject matter, duration, nature and purpose of processing, categories of Data Subjects, and categories of Customer Personal Data are described in Annex 1 to this DPA.

3.2 Processing only on instructions. ValGuard will process Customer Personal Data only on documented instructions from Customer, including those given via: (a) Customer's configuration of Agents, Guardrails, log levels, and retention settings in the dashboard; (b) Customer's use of the API and SDKs; (c) this DPA and the Terms; and (d) any applicable Order Form — unless required to do otherwise by applicable law, in which case ValGuard will, to the extent legally permitted, inform Customer of that legal requirement before processing. ValGuard will promptly notify Customer if, in its opinion, an instruction infringes the GDPR or another applicable data protection law.

3.3 Scope limitation. ValGuard will not process Customer Personal Data for any purpose other than providing, securing, supporting, and billing for the Service, and will not sell Customer Personal Data or use it to build profiles for advertising purposes.

4. Confidentiality of personnel

ValGuard ensures that any person it authorizes to process Customer Personal Data (including employees, contractors, and personnel of any Sub-processor) is subject to a binding written or statutory duty of confidentiality and receives appropriate training on the handling of Personal Data, and that access to Customer Personal Data is limited to personnel who need it to perform their job function in providing the Service.

5. Security of processing (Article 32 GDPR)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects, ValGuard implements appropriate technical and organizational measures, including those described in Annex 3, which currently include:

5.1 In-memory-first payload handling. By default, Prompt and Output content is processed transiently, in memory, to apply Guardrail validation, and is not written to persistent storage; persistence only occurs where Customer explicitly enables Payload Logging for an Agent, and then only for the retention period Customer configures (capped by Plan, as described in Annex 1).

5.2 Encryption of Provider Vault credentials. Upstream LLM Provider API keys and other credentials that Customer stores in Provider Vault are encrypted at rest using AES-256-GCM authenticated encryption with per-secret nonces, and are transmitted only over encrypted (TLS) connections; ValGuard never returns decrypted credential values through the dashboard or API — only non-secret metadata (provider, label, and dates) is ever exposed.

5.3 Access controls and least privilege. Access to Customer Personal Data, Provider Vault secrets, and platform administration functions is restricted through role-based access control (RBAC) — Customer's own organization roles (owner, admin, member) gate sensitive actions such as Provider Vault management, billing, and data-erasure requests, and ValGuard's own internal administrative access to production systems is limited to authorized personnel on a least-privilege basis and is logged.

5.4 Encryption in transit. All network traffic to and from the Service, including the validation proxy, dashboard, and APIs, is encrypted in transit using TLS.

5.5 Logging, monitoring, and audit trails. Administrative and governance-relevant actions (such as Provider Vault changes and access-control changes) are recorded in an audit log. Service telemetry is monitored for availability and security anomalies.

5.6 Vulnerability management and incident response. ValGuard maintains a vulnerability disclosure process (see /.well-known/security.txt) and documented incident-response procedures covering triage, containment, remediation, and communication.

5.7 Data minimization by design. Default request-level logging captures operational metadata (status, latency, token counts, cost, validator outcomes) rather than raw content, and validator messages are redacted unless Payload Logging is enabled, reducing the volume of Personal Data retained in the ordinary course.

6. Sub-processors

6.1 General authorization. Customer provides ValGuard general written authorization to engage Sub-processors to provide the Service, subject to the requirements of this Section 6.

6.2 Current list. ValGuard's current Sub-processors are listed in Annex 2 and published at /legal/subprocessors.

6.3 Flow-down obligations. ValGuard enters into a written agreement with each Sub-processor imposing data protection obligations materially no less protective of Customer Personal Data than those set out in this DPA, including with respect to confidentiality, security, and (where the Sub-processor is located outside the EEA/UK) an appropriate international transfer mechanism such as the SCCs. ValGuard remains liable to Customer for a Sub-processor's performance of its data-protection obligations to the same extent ValGuard would be liable if performing the services directly.

6.4 Notice of new Sub-processors. Enterprise customers receive advance notice of at least thirty (30) days before ValGuard adds a new Sub-processor that will process Customer Personal Data, as described on the Subprocessors page. If Customer reasonably objects to a new Sub-processor on data-protection grounds within that notice period, the parties will work together in good faith to address the objection, which may include ValGuard not applying the new Sub-processor to Customer's account or, if no resolution is reached, Customer terminating the affected part of the Service without penalty.

6.5 LLM Providers excluded. As described in Section 2.4, LLM Providers that Customer itself selects and configures (via BYOK or Provider Vault) are not ValGuard Sub-processors and are not listed in Annex 2.

7. Assistance with Data Subject rights

Taking into account the nature of the processing, ValGuard will provide Customer with reasonable technical and organizational assistance (including, where applicable, self-service tooling in the dashboard) to enable Customer to respond to requests from Data Subjects to exercise their rights under applicable data protection law (including access, rectification, erasure, restriction, portability, and objection). If ValGuard receives a request directly from a Data Subject that relates to Customer Personal Data, ValGuard will, where legally permitted, promptly inform Customer and will not respond to the request itself except to confirm receipt and redirect the Data Subject to Customer, unless required by law.

8. Assistance with DPIAs and Articles 32–36 compliance

ValGuard will provide Customer with reasonable information about ValGuard's processing and security measures — including this DPA and its Annexes, the Security page, and, on request, additional documentation under NDA — to assist Customer in complying with its own obligations under Articles 32 to 36 of the GDPR, including data protection impact assessments (DPIAs) and, where required, prior consultation with a Supervisory Authority.

9. Personal data breach notification

ValGuard will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware, after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, so that Customer can meet its own notification obligations under Article 33 GDPR (or equivalent law) where applicable. That notice will describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. ValGuard will provide reasonably requested follow-up information as it becomes available and will cooperate with Customer's investigation and any required regulatory or Data Subject notifications.

10. International data transfers

Where ValGuard or a Sub-processor processes Customer Personal Data outside the country or region in which it originated (including transfers out of the EEA/UK to the United States or another third country), ValGuard relies on an appropriate transfer mechanism, which may include: (a) the Standard Contractual Clauses, which are hereby incorporated by reference and deemed executed between Customer (as data exporter) and ValGuard or the relevant Sub-processor (as data importer) to the extent required by applicable law, with the parties' details, transfer descriptions, and technical/organizational measures for that purpose set out in Annexes 1 through 3 of this DPA; (b) an adequacy decision covering the destination country; or (c) another lawful transfer mechanism recognized under applicable data protection law. On request, ValGuard will provide Customer with a copy of the executed transfer mechanism applicable to a given transfer.

11. Audits

On reasonable prior written notice (at least thirty (30) days, except where a shorter period is required by a Supervisory Authority or necessary to investigate a suspected Personal Data Breach), and no more than once per twelve (12) month period unless otherwise required by a Supervisory Authority, ValGuard will make available to Customer information reasonably necessary to demonstrate compliance with this DPA — including this DPA, applicable security documentation, and, for Enterprise customers, reasonable access to relevant audit reports, certifications, or a scoped audit conducted by Customer or an independent third-party auditor bound by confidentiality, subject to reasonable scheduling, scope, and confidentiality restrictions, and at Customer's expense unless the audit reveals a material non-compliance caused by ValGuard.

12. Return or deletion of Customer Personal Data

Upon termination or expiration of the Terms, or earlier at Customer's written request, ValGuard will, at Customer's election, delete or return all Customer Personal Data then in ValGuard's possession, except to the extent applicable law requires ValGuard to retain some or all of it, in which case ValGuard will continue to protect that data in accordance with this DPA for as long as it is retained. Where Payload Logging was not enabled, this obligation is in practice limited to metadata and redacted validator records, since raw Prompt/Output content was never persisted. Deletion of expired data in the ordinary course (absent a specific deletion request) otherwise follows the retention periods described in Annex 1 and ValGuard's automated retention-purge process.

13. Intellectual property

As between the parties, Customer retains all right, title, and interest in its Prompts, Outputs, and Customer Data, and ValGuard retains all right, title, and interest in the Service, including the validation proxy, Guardrail/validator catalog, and dashboard. This DPA does not grant either party any additional intellectual property rights beyond those in Section 8 (Intellectual property) of the Terms, which governs in full and is incorporated by reference.

14. Warranty disclaimer and limitation of liability

14.1 Disclaimer. Except as expressly stated in this DPA or a signed Order Form, the Service is provided on an "as is" and "as available" basis as described in Section 10 of the Terms, which is incorporated by reference. Without limiting that disclaimer, ValGuard is not responsible for, and expressly disclaims liability arising from: (a) unintended agentic loops, runaway orchestration, or excessive fan-out or retry/reask behavior resulting from Customer's own Agent, Playbook, or orchestration configuration; (b) cost overruns or billing disputes arising from Customer's use of, or agreements with, any third-party LLM Provider; and (c) security breaches, data loss, or unauthorized access occurring on Customer's own infrastructure, endpoints, accounts, or systems, including custom or self-hosted model endpoints Customer connects via Provider Vault or BYOK.

14.2 Limitation of liability. ANY LIABILITY ARISING OUT OF OR RELATED TO THIS DPA IS SUBJECT TO THE LIMITATIONS AND EXCLUSIONS OF LIABILITY SET OUT IN SECTION 11 (LIMITATION OF LIABILITY) OF THE TERMS, WHICH APPLY TO THIS DPA AS IF SET OUT IN FULL, INCLUDING THE AGGREGATE CAP ON EACH PARTY'S LIABILITY EQUAL TO THE TOTAL FEES ACTUALLY PAID BY CUSTOMER TO VALGUARD IN THE SIX (6) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. NOTHING IN THIS DPA OR THE TERMS LIMITS OR EXCLUDES EITHER PARTY'S LIABILITY THAT CANNOT LAWFULLY BE LIMITED OR EXCLUDED UNDER THE GDPR OR OTHER MANDATORY APPLICABLE LAW.

15. Term and order of precedence

This DPA takes effect on the date Customer first agrees to the Terms (or the effective date of the applicable Order Form) and remains in effect for as long as ValGuard processes Customer Personal Data under the Terms. If any provision of this DPA conflicts with the SCCs incorporated under Section 10, the SCCs prevail to the extent of the conflict with respect to the transfers they govern.

16. Governing law and jurisdiction

This DPA is governed by the same governing law and dispute-resolution provisions as the Terms (Section 15 of the Terms — the laws of the Republic of Poland and, as applicable, European Union law, without regard to conflict-of-laws principles, subject to the EU/EEA/UK consumer-protection carve-out and the Order Form precedence rule described there), except that, to the extent the SCCs apply to a given transfer of Customer Personal Data, the governing law and forum specified in the SCCs govern that transfer.

17. Contact

Questions about this DPA, or requests for a countersigned version, can be sent to:


Annex 1 — Details of Processing

ItemDescription
Subject matterValGuard's provision of the AI Security & Governance Gateway — ingress/egress Guardrail validation, cost and usage monitoring, and observability — for LLM API traffic Customer routes through the Service.
DurationFor as long as Customer maintains an active account or Plan under the Terms, plus (a) any post-termination period reasonably required to complete deletion or return of Customer Personal Data under Section 12, and (b) any period Customer Personal Data must be retained by applicable law.
Nature of processingAutomated, in-memory validation of Prompts and Outputs against Customer-configured Guardrails; computation of usage/cost/telemetry metadata; where Customer enables Payload Logging, storage and later deletion of Prompt/Output content and associated metadata; routing of Prompts to Customer-selected LLM Providers on Customer's instruction; encrypted storage of upstream provider credentials in Provider Vault (where used); and provision of dashboard analytics and audit logs.
Purpose of processingTo provide, secure, monitor, support, and bill for the Service, including detecting and blocking non-compliant, unsafe, or malformed traffic; enforcing budgets and rate limits; and giving Customer observability into its own AI traffic.
Categories of Data SubjectsCustomer's authorized personnel and dashboard users; and, only to the extent Customer's own applications route such data through the Service, Customer's end users or other individuals whose Personal Data appears within Prompts or Outputs.
Categories of Customer Personal Data(a) Always processed (metadata, in-memory or minimized by default): account and organization identifiers, request/response timestamps, provider and model identifiers, status codes, latency, token counts, cost, Guardrail/validator pass-fail outcomes, and — unless Payload Logging is enabled — redacted validator messages with content masked. (b) Only where Customer enables Payload Logging for an Agent: the content of Prompts and Outputs routed through that Agent, which may include any category of Personal Data (including, if Customer chooses to route it, special categories of Personal Data) that Customer's own systems or end users submit — Customer is solely responsible for determining whether its use case permits doing so and for configuring Guardrails appropriate to that data.
RetentionDefault (Payload Logging disabled): Prompt/Output content is never written to persistent storage. Where Payload Logging is enabled, content and related validation detail are retained for the period Customer configures, capped by Plan: 7 days (Free, Developer), 30 days (Growth), 90 days (Production), 365 days (Enterprise), and are purged by an automated daily retention job thereafter. Request-level metadata (excluding raw content) may be retained longer for billing, security, and aggregate analytics purposes, consistent with the Privacy Policy.

Annex 2 — Sub-processors

Sub-processorPurposeLocation
Amazon Web Services, Inc.Cloud infrastructure for the ValGuard.ai platform — application hosting, database and log storage, transactional email delivery, and monitoring.United States (with regional data-residency options for Enterprise customers)
Stripe, Inc.Payment processing and subscription billing.United States

The current list is also published at /legal/subprocessors and is updated in accordance with Section 6.4 of this DPA. LLM Providers that Customer itself configures (via BYOK or Provider Vault) are Customer's own service providers, not ValGuard Sub-processors, as described in Section 2.4 and 6.5.

Annex 3 — Technical and Organizational Measures

  • Confidentiality: personnel confidentiality obligations; role-based access control (RBAC) limiting access to Customer Personal Data and Provider Vault secrets to authorized roles; least-privilege administrative access to production systems.
  • Integrity and availability: encryption in transit (TLS) for all API, dashboard, and proxy traffic; AES-256-GCM encryption at rest for Provider Vault credentials; automated backups and monitoring of production infrastructure; documented incident-response procedures.
  • Data minimization and storage limitation: in-memory-only validation by default with no payload persistence; redaction of validator messages unless Payload Logging is explicitly enabled; automated, plan-tiered retention purge job for logged content.
  • Ability to restore availability: infrastructure hosted on redundant cloud infrastructure (see Annex 2) with monitoring and incident-response procedures to restore access and availability following an incident.
  • Testing and assurance: ongoing vulnerability management and a published coordinated-disclosure process (/.well-known/security.txt); audit logging of governance-relevant administrative actions (e.g., Provider Vault and access-control changes).