Legal
Data Processing Addendum
Last updated October 1, 2026
This Data Processing Addendum (the DPA) forms part of the Terms of Service between Zurelay LLC (Zurelay) and the customer that accepted them (Customer) (together, the Agreement). It applies when Zurelay processes Customer Personal Data on Customer's behalf. It takes effect when Customer accepts the Terms; no signature is required. Customers who need a countersigned copy can request one at support@zurelay.com. Capitalized terms not defined here have the meanings given in the Terms.
1. Definitions
- Applicable Data Protection Law means all laws that apply to the processing of Customer Personal Data under the Agreement, which may include the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection and United States state privacy laws such as the California Consumer Privacy Act.
- Customer Personal Data means personal data contained in Customer Content that Zurelay processes on Customer's behalf to provide the Services.
- Subprocessor means a third party engaged by Zurelay that processes Customer Personal Data, including Infrastructure Providers.
- Personal Data Breach means a breach of security in systems controlled by Zurelay leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- SCCs means the standard contractual clauses approved by the European Commission in Decision (EU) 2021/914.
- Controller, processor, data subject, personal data, processing, business and service provider have the meanings given in Applicable Data Protection Law.
2. Roles and scope
For Customer Personal Data, Customer is the controller (or a processor acting for its own customers) and Zurelay is a processor (or subprocessor). This DPA does not apply to personal data Zurelay processes as an independent controller, such as account, billing, support, security and website data, which our Privacy Policy covers.
3. Customer's instructions
3.1 Instructions. Zurelay will process Customer Personal Data only to provide, secure and support the Services in accordance with the Agreement, this DPA and Customer's use and configuration of the Services, which together are Customer's complete documented instructions, and as required by law. Where the law requires processing beyond those instructions, Zurelay will tell Customer first unless the law prohibits it.
3.2 Routing is an instruction. Customer instructs Zurelay to send Customer Content to Infrastructure Providers chosen by Zurelay, and to retry, reroute and fail over requests among them, as needed to generate Outputs.
3.3 Infringing instructions. Zurelay will tell Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Zurelay is not required to carry out legal reviews of Customer's instructions.
4. Customer's obligations
Customer is responsible for having a lawful basis for, and giving all notices and obtaining all consents needed for, the processing of Customer Personal Data under the Agreement. Customer will not send Restricted Data, including special categories of personal data and personal data of children, unless the parties have signed a separate written agreement that allows it. Customer is responsible for limiting the personal data it includes in Inputs to what its use of the Services requires, and for deciding whether the Services, including processing by Infrastructure Providers under their own terms as described in Section 7, are appropriate for its data.
5. Confidentiality
Zurelay will ensure that the people it authorizes to process Customer Personal Data are bound by appropriate obligations of confidentiality and access it only as needed to provide the Services.
6. Security
Zurelay will implement and maintain the technical and organizational measures described in Annex II, which are designed to protect Customer Personal Data in systems Zurelay controls. Zurelay may update these measures as long as the overall level of protection is not materially reduced.
7. Subprocessors
7.1 General authorization. Customer gives Zurelay general authorization to engage Subprocessors in the following categories: (a) hosting, database, storage and networking providers; (b) payment, email and support providers, to the extent they process Customer Personal Data; and (c) Infrastructure Providers that serve Models, which may include Model Developers, cloud platforms and independent providers of model capacity.
7.2 Confidential list. The identities of Zurelay's Infrastructure Providers are confidential commercial information. Zurelay will give Customer a list of its current Subprocessors on written request, subject to Customer's confidentiality obligations under the Agreement.
7.3 Changes. To keep the Services available, Zurelay may add, remove and replace Infrastructure Providers at any time. Zurelay will notify Customer of any new category of Subprocessor by updating this DPA. If Customer objects on reasonable data protection grounds, the parties will discuss the objection in good faith; if it cannot be resolved, Customer's sole remedy is to stop using the affected Services and terminate the Agreement.
7.4 Subprocessor terms. Where Zurelay can negotiate a Subprocessor's terms, it will require data protection obligations that are, in substance, no less protective than those in this DPA, to the extent relevant to the services the Subprocessor provides. Some Infrastructure Providers make their services available only on their standard terms. Customer acknowledges that, for those providers, their standard terms govern their processing of Customer Content and that Zurelay may not be able to obtain additional commitments from them.
7.5 Responsibility. Zurelay remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law, subject to the limitations of liability in the Agreement.
8. Data subject requests
Taking into account the nature of the processing, Zurelay will give Customer reasonable assistance in responding to requests from data subjects to exercise their rights. If Zurelay receives such a request about Customer Personal Data, it will refer the requester to Customer where it can identify Customer, and will not respond itself except to confirm the referral or as required by law. Customer will pay Zurelay's reasonable costs for assistance beyond what the Services make available.
9. Personal Data Breaches
Zurelay will notify Customer without undue delay after becoming aware of a Personal Data Breach and will provide the information reasonably available to it that Customer needs to meet its own notification obligations. Zurelay will take reasonable steps to contain and investigate the breach. Notification is not an acknowledgment of fault or liability. Customer is responsible for notifying regulators and data subjects where required. If an Infrastructure Provider notifies Zurelay of a security incident affecting Customer Personal Data, Zurelay will pass on the relevant information it receives.
10. Assistance and audits
10.1 Assistance. Taking into account the nature of the processing and the information available to it, Zurelay will give Customer reasonable assistance with data protection impact assessments and prior consultations with regulators where Applicable Data Protection Law requires them, at Customer's cost where the assistance is more than minimal.
10.2 Information. On written request, no more than once in any 12-month period, Zurelay will provide written answers to a reasonable security and privacy questionnaire and other information reasonably necessary to demonstrate compliance with this DPA.
10.3 Audits. If Applicable Data Protection Law requires an audit beyond that information, Customer may conduct one, at its own cost, no more than once in any 12-month period, on at least 30 days' written notice, during normal business hours, under appropriate confidentiality obligations and by an auditor that does not compete with Zurelay. Audits will not give access to other customers' data, to Infrastructure Providers' systems or to the identities of Infrastructure Providers beyond what the law requires.
11. Retention and deletion
Zurelay does not store the content of chat and text requests after serving them. Generated images and videos, their prompts and reference images, and error details from failed attempts are deleted after 30 days. Within 90 days after the Agreement ends, Zurelay will delete any remaining Customer Personal Data in systems it controls, except copies it must keep by law and copies in backups, which are deleted on their normal schedule. Customer Personal Data processed by Infrastructure Providers is retained according to their own terms.
12. International transfers
12.1 Authorization. Customer authorizes Zurelay and its Subprocessors to transfer and process Customer Personal Data in the United States and in other countries where they operate.
12.2 European transfers. To the extent Customer Personal Data is subject to the GDPR and is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA as follows: Module Two applies where Customer is a controller and Module Three where Customer is a processor; the optional docking clause in Clause 7 applies; in Clause 9, Option 2 applies, with the notice described in Section 7.3; the optional wording in Clause 11 does not apply; in Clause 17, the SCCs are governed by the laws of Ireland; and in Clause 18, the courts of Ireland have jurisdiction. Annexes I and II of this DPA complete the corresponding annexes of the SCCs.
12.3 United Kingdom and Switzerland. For personal data subject to the UK GDPR, the SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner. For personal data subject to Swiss law, the SCCs apply with references adapted to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
12.4 Precedence. If the SCCs conflict with this DPA, the SCCs prevail to the extent of the conflict.
13. United States state privacy laws
To the extent United States state privacy laws apply, Zurelay is Customer's service provider or processor for Customer Personal Data. Zurelay will not sell or share Customer Personal Data; will not retain, use or disclose it for any purpose other than the business purposes set out in the Agreement or outside the direct business relationship between Zurelay and Customer; and will not combine it with personal data from other sources except as those laws permit. Zurelay will comply with the applicable obligations of those laws, will notify Customer if it can no longer meet them, and grants Customer the right to take reasonable steps to stop and remediate unauthorized use of Customer Personal Data.
14. General
This DPA prevails over the Terms on the protection of Customer Personal Data. Otherwise, the Terms apply, including their limitations of liability, governing law and dispute resolution, except where Applicable Data Protection Law or the SCCs require otherwise. Zurelay may update this DPA to reflect changes in law, in the Services or in its Subprocessors, and will notify Customer of material changes. This DPA ends when the Agreement ends, except for obligations that by their nature continue.
Annex I: Details of processing
| Item | Details |
|---|---|
| Data exporter | Customer, as identified in its account. Activities: use of the Services. |
| Data importer | Zurelay LLC, support@zurelay.com. Activities: providing the Services. |
| Data subjects | Individuals whose personal data Customer includes in Customer Content, which may include Customer's personnel, customers, end users and other people. |
| Categories of personal data | Any personal data Customer chooses to include in prompts, files, images and other Inputs, and in the resulting Outputs. |
| Sensitive data | None. Customer must not send special categories of personal data or other Restricted Data. |
| Nature and purpose | Receiving requests, routing them to Infrastructure Providers, returning Outputs, storing generated files for download, metering and billing, preventing abuse and providing support. |
| Frequency and duration | Continuous while Customer uses the Services, for the term of the Agreement and the deletion period in Section 11. |
| Retention | As described in Section 11. |
| Subprocessors | The categories in Section 7.1, which process Customer Personal Data to provide the Services for the same duration. |
| Competent supervisory authority | The authority of the EU member state where Customer is established or, where Customer has a representative under Article 27 of the GDPR, where that representative is established. |
Annex II: Technical and organizational measures
- Encryption: TLS for data in transit to and from the Services; encryption at rest provided by Zurelay's hosting providers.
- Credentials: API keys stored only as one-way hashes; sign-in with one-time codes; workspace roles controlling who can manage keys and billing.
- Access control: access to production systems and data limited to personnel who need it.
- Data minimization: chat and text content processed in memory and not stored; generated files, their prompts and error details deleted after 30 days; customer end-user identifiers removed from requests before they are sent to Infrastructure Providers.
- Monitoring: continuous monitoring of the availability and behavior of the Services and of Infrastructure Providers, with incidents recorded and investigated.
- Resilience: automatic retry and failover across Infrastructure Providers.
- Incident response: investigation, containment and customer notification of Personal Data Breaches as described in Section 9.
- Vendor oversight: review of Subprocessors' services and terms before use, and removal of those that do not meet Zurelay's requirements.
Questions about this document?
Zurelay LLC answers legal and privacy questions by email.