Draft — not legal advice, and not in force
This document has not been reviewed by counsel and has no effective date. It is published here for internal review only and is excluded from search indexing.
Data Processing Addendum
This addendum forms part of the Terms of Use between Diaphora Inc. ("Processor") and the customer ("Controller") and applies where Diaphora processes personal data on the Controller's behalf through the hosted platform.
Draft — not yet in force. This document has not been reviewed by counsel and carries no effective date. Do not rely on it. A DPA is a contract that enterprise buyers and their counsel will read closely; this needs review before it is offered to anyone.
[NEEDS INPUT: decide the execution mechanism. Options: (a) click-through acceptance during signup, (b) a countersigned PDF on request, (c) auto-incorporated by reference into the Terms of Use. Enterprise buyers usually expect (b) or a negotiated version.]
1. Roles
The Controller determines the purposes and means of processing. Diaphora processes personal data only on documented instructions from the Controller.
This split matches the Privacy Policy: Customer Content — plans, session inputs and outputs, results history, Vault credentials, and data retrieved from connected systems — is processed by Diaphora as a processor. Account and billing data is processed by Diaphora as a controller and falls outside this addendum.
2. Scope of processing (Annex I)
Subject matter. Provision of the Diaphora hosted automation platform.
Duration. The term of the Controller's subscription, plus the retention and deletion periods in section 9.
Nature and purpose. Hosting, executing, storing, transmitting and backing up Customer Content so that the Controller's automations run, and retaining results history for the period the Controller's subscription plan provides.
Categories of data subjects. Determined by the Controller. Typically: the Controller's own personnel with platform access, and any individuals whose data appears in systems the Controller's plans connect to — which may include the Controller's customers, employees, suppliers or end users.
Categories of personal data. Determined by the Controller. Typically:
- Identifiers and contact details of workspace members.
- Any personal data contained in plan definitions, prompts, session inputs and outputs.
- Any personal data returned by connected systems — databases, MCP servers, file servers, APIs — and held in results history.
- Credentials stored in the Vault, to the extent they identify an individual.
Special category data. The platform is not designed for special category data under GDPR Art. 9, nor for data subject to sector-specific regimes such as HIPAA, PCI-DSS or FedRAMP. The Controller must not process such data through the platform unless a separate written agreement expressly permits it. [NEEDS INPUT: if you intend to sell into healthcare, financial services or government, this restriction blocks those deals and you will need a BAA and the corresponding controls.]
3. Instructions
Diaphora processes personal data only on the Controller's documented instructions, which comprise this addendum, the Terms of Use, and the Controller's configuration and use of the platform. Diaphora will tell the Controller if an instruction appears to infringe applicable data protection law, and may suspend processing where required by law — informing the Controller unless legally prohibited.
Diaphora does not train models on Customer Content, and does not use it for any purpose other than providing the platform.
4. Confidentiality
Diaphora ensures that personnel authorised to process personal data are bound by confidentiality obligations and receive appropriate data protection training. Access is granted on a least-privilege, need-to-know basis, and is logged.
5. Security measures (Annex II)
Diaphora implements appropriate technical and organisational measures, including:
- Encryption of personal data in transit (TLS) and at rest.
- Vault credential protection — credentials are encrypted with keys held separately from the encrypted material, decrypted only at execution time for the session that needs them, never rendered in plaintext after saving, never written to logs or results history, and not readable by Diaphora staff.
- Access control — least-privilege, unique accounts, multi-factor authentication for administrative access, and SSO/SAML for Enterprise customers.
- Logging and monitoring, including exportable audit logs for Enterprise customers.
- Segregation of customer workspaces.
- Backup and recovery procedures.
- Secure development, change management and vulnerability management.
- Personnel screening and confidentiality obligations.
[NEEDS INPUT: this annex must describe what is actually implemented today. Every measure listed here becomes a contractual commitment that an enterprise security review will test. Delete anything not yet true.]
[NEEDS INPUT: certifications — SOC 2 Type II, ISO 27001, penetration-test cadence. State only what is actually held or contracted.]
6. Sub-processing
The Controller gives general authorisation for Diaphora to engage sub-processors. The current list is published at /legal/subprocessors.
Diaphora will:
- Give at least 30 days' notice before adding or replacing a sub-processor, by email to the workspace billing contact and by updating that page.
- Impose data protection obligations on each sub-processor no less protective than this addendum.
- Remain fully liable to the Controller for its sub-processors' performance.
The Controller may object on reasonable data-protection grounds within the notice period. The parties will work in good faith to resolve it; if they cannot, the Controller may terminate the affected part of the subscription without penalty and receive a pro-rata refund of prepaid fees.
LLM providers are not sub-processors. Where the Controller supplies its own model API keys, the Controller's plans call those providers under the Controller's own account and contract. Diaphora does not engage them, does not contract with them for the Controller's processing, and is not responsible for their handling of data sent under the Controller's credentials. The Controller is responsible for its own agreements with those providers, including their training and retention settings.
7. Data subject requests
Taking account of the nature of the processing, Diaphora will assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to data subject requests.
Where Diaphora receives a request directly from a data subject relating to Customer Content, it will not respond substantively but will refer the request to the Controller without undue delay.
The platform provides self-service access, export and deletion for Customer Content, which the Controller can use to satisfy most requests without contacting Diaphora.
8. Personal data breaches
Diaphora will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's personal data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point.
Diaphora will assist the Controller in meeting its own breach notification obligations to supervisory authorities and data subjects.
9. Deletion and return
Results history is deleted automatically at the end of the retention period for the Controller's subscription plan, as set out in the Privacy Policy and on the pricing page:
| Subscription plan | Results history retained |
|---|---|
| Free | 30 days |
| Starter | 1 year |
| Team | 2 years |
| Enterprise | Unlimited, or as specified in the order form |
Downgrading shortens the window, and history beyond the new window becomes eligible for deletion. The Controller should export before downgrading.
On termination, the Controller has 30 days to export Customer Content through the platform. After that Diaphora deletes it, including from backups within [NEEDS INPUT: backup cycle, e.g. 35 days], except where retention is required by law. On written request within the export window, Diaphora will provide the Controller with a copy in a structured, commonly used, machine-readable format.
10. Audits
Diaphora will make available information reasonably necessary to demonstrate compliance with this addendum, and will allow for and contribute to audits conducted by the Controller or an auditor it mandates.
Diaphora may satisfy this by providing current third-party audit reports or certifications. Where those are insufficient for the Controller's regulatory obligations, on-site or remote audits may be conducted no more than once per year (unless required by a supervisory authority or following a breach), on at least 30 days' notice, during business hours, subject to confidentiality, and without unreasonably disrupting operations. Each party bears its own costs.
11. International transfers
Diaphora is US-based. Where personal data is transferred out of the EEA, the UK or Switzerland, the parties incorporate:
- The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) where the Controller is a controller, and Module Three (processor to processor) where the Controller is itself a processor. Clause 7 (docking) applies; Clause 9 option 2 (general authorisation, 30 days' notice) applies; Clause 11's independent dispute resolution option does not apply; Clause 17 governing law and Clause 18 forum are [NEEDS INPUT: EU member state, commonly Ireland or the Netherlands]. Annexes I and II are populated by sections 2 and 5 of this addendum, and Annex III by the sub-processor page.
- The UK International Data Transfer Addendum to the EU SCCs, with Tables 1–4 populated from the same sections.
- For Switzerland, the SCCs with references to GDPR read as references to the Swiss FADP and the FDPIC as supervisory authority.
Diaphora will conduct transfer impact assessments where required and will challenge disproportionate government access requests where lawful.
12. California (CCPA/CPRA)
Where the Controller is a "business" and Diaphora a "service provider" as CCPA/CPRA defines them, Diaphora:
- Processes personal information only to provide the platform under the Terms of Use.
- Does not sell or share personal information, as those terms are defined.
- Does not retain, use or disclose it outside the direct business relationship or for any purpose other than the services.
- Does not combine it with personal information from other sources, except as permitted for a service provider.
- Certifies that it understands and will comply with these restrictions.
The Controller may take reasonable steps to ensure Diaphora uses personal information consistently with these obligations, and Diaphora will notify the Controller if it determines it can no longer meet them.
13. Liability and precedence
Each party's liability under this addendum is subject to the limitations in the Terms of Use, except where applicable data protection law prohibits limitation.
Order of precedence: where a conflict arises, the Standard Contractual Clauses prevail over this addendum, this addendum prevails over the Terms of Use, and a negotiated Enterprise order form prevails over all of them to the extent it says so expressly.
Contact
Diaphora Inc. [NEEDS INPUT: registered Delaware address] hello@diaphora.ai
[NEEDS INPUT: whether a DPO is appointed — required under GDPR Art. 37 only in specific cases — and any EU/UK Art. 27 representative.]
Processor terms for customers subject to GDPR, UK GDPR or CCPA — processing scope, security measures, sub-processing, breach notification, transfers and audits.