Data Processing Addendum | Diaphora | Diaphora

Data Processing Addendum

This addendum forms part of the Terms of Use between Diaphora Inc. ("Processor") and the customer ("Controller") and applies where Diaphora processes personal data on the Controller's behalf through the hosted platform.

Draft — not yet in force. This document has not been reviewed by counsel and carries no effective date. Do not rely on it. A DPA is a contract that enterprise buyers and their counsel will read closely; this needs review before it is offered to anyone.

[NEEDS INPUT: decide the execution mechanism. Options: (a) click-through acceptance during signup, (b) a countersigned PDF on request, (c) auto-incorporated by reference into the Terms of Use. Enterprise buyers usually expect (b) or a negotiated version.]

1. Roles

The Controller determines the purposes and means of processing. Diaphora processes personal data only on documented instructions from the Controller.

This split matches the Privacy Policy: Customer Content — blueprints, session inputs and outputs, results history, Vault credentials, and data retrieved from connected systems — is processed by Diaphora as a processor. Account and billing data is processed by Diaphora as a controller and falls outside this addendum.

2. Scope of processing (Annex I)

Subject matter. Provision of the Diaphora hosted automation platform.

Duration. The term of the Controller's subscription, plus the retention and deletion periods in section 9.

Nature and purpose. Hosting, executing, storing, transmitting and backing up Customer Content so that the Controller's automations run, and retaining results history for the period the Controller's subscription plan provides.

Categories of data subjects. Determined by the Controller. Typically: the Controller's own personnel with platform access, and any individuals whose data appears in systems the Controller's blueprints connect to — which may include the Controller's customers, employees, suppliers or end users.

Categories of personal data. Determined by the Controller. Typically:

Special category data. The platform is not designed for special category data under GDPR Art. 9, nor for data subject to sector-specific regimes such as HIPAA, PCI-DSS or FedRAMP. The Controller must not process such data through the platform unless a separate written agreement expressly permits it. [NEEDS INPUT: if you intend to sell into healthcare, financial services or government, this restriction blocks those deals and you will need a BAA and the corresponding controls.]

3. Instructions

Diaphora processes personal data only on the Controller's documented instructions, which comprise this addendum, the Terms of Use, and the Controller's configuration and use of the platform. Diaphora will tell the Controller if an instruction appears to infringe applicable data protection law, and may suspend processing where required by law — informing the Controller unless legally prohibited.

Diaphora does not train models on Customer Content, and does not use it for any purpose other than providing the platform.

4. Confidentiality

Diaphora ensures that personnel authorised to process personal data are bound by confidentiality obligations and receive appropriate data protection training. Access is granted on a least-privilege, need-to-know basis, and is logged.

5. Security measures (Annex II)

Diaphora implements appropriate technical and organisational measures, including:

[NEEDS INPUT: this annex must describe what is actually implemented today. Every measure listed here becomes a contractual commitment that an enterprise security review will test. Delete anything not yet true.]

[NEEDS INPUT: certifications — SOC 2 Type II, ISO 27001, penetration-test cadence. State only what is actually held or contracted.]

6. Sub-processing

The Controller gives general authorisation for Diaphora to engage sub-processors. The current list is published at /legal/subprocessors.

Diaphora will:

The Controller may object on reasonable data-protection grounds within the notice period. The parties will work in good faith to resolve it; if they cannot, the Controller may terminate the affected part of the subscription without penalty and receive a pro-rata refund of prepaid fees.

LLM providers are not sub-processors. Where the Controller supplies its own model API keys, the Controller's blueprints call those providers under the Controller's own account and contract. Diaphora does not engage them, does not contract with them for the Controller's processing, and is not responsible for their handling of data sent under the Controller's credentials. The Controller is responsible for its own agreements with those providers, including their training and retention settings.

7. Data subject requests

Taking account of the nature of the processing, Diaphora will assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to data subject requests.

Where Diaphora receives a request directly from a data subject relating to Customer Content, it will not respond substantively but will refer the request to the Controller without undue delay.

The platform provides self-service access, export and deletion for Customer Content, which the Controller can use to satisfy most requests without contacting Diaphora.

8. Personal data breaches

Diaphora will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's personal data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point.

Diaphora will assist the Controller in meeting its own breach notification obligations to supervisory authorities and data subjects.

9. Deletion and return

Results history is deleted automatically at the end of the retention period for the Controller's subscription plan, as set out in the Privacy Policy and on the pricing page:

Subscription plan Results history retained
Free 30 days
Starter 1 year
Team 2 years
Enterprise Unlimited, or as specified in the order form

Downgrading shortens the window, and history beyond the new window becomes eligible for deletion. The Controller should export before downgrading.

On termination, the Controller has 30 days to export Customer Content through the platform. After that Diaphora deletes it, including from backups within [NEEDS INPUT: backup cycle, e.g. 35 days], except where retention is required by law. On written request within the export window, Diaphora will provide the Controller with a copy in a structured, commonly used, machine-readable format.

10. Audits

Diaphora will make available information reasonably necessary to demonstrate compliance with this addendum, and will allow for and contribute to audits conducted by the Controller or an auditor it mandates.

Diaphora may satisfy this by providing current third-party audit reports or certifications. Where those are insufficient for the Controller's regulatory obligations, on-site or remote audits may be conducted no more than once per year (unless required by a supervisory authority or following a breach), on at least 30 days' notice, during business hours, subject to confidentiality, and without unreasonably disrupting operations. Each party bears its own costs.

11. International transfers

Diaphora is US-based. Where personal data is transferred out of the EEA, the UK or Switzerland, the parties incorporate:

Diaphora will conduct transfer impact assessments where required and will challenge disproportionate government access requests where lawful.

12. California (CCPA/CPRA)

Where the Controller is a "business" and Diaphora a "service provider" as CCPA/CPRA defines them, Diaphora:

The Controller may take reasonable steps to ensure Diaphora uses personal information consistently with these obligations, and Diaphora will notify the Controller if it determines it can no longer meet them.

13. Liability and precedence

Each party's liability under this addendum is subject to the limitations in the Terms of Use, except where applicable data protection law prohibits limitation.

Order of precedence: where a conflict arises, the Standard Contractual Clauses prevail over this addendum, this addendum prevails over the Terms of Use, and a negotiated Enterprise order form prevails over all of them to the extent it says so expressly.

Contact

Diaphora Inc. [NEEDS INPUT: registered Delaware address] hello@diaphora.ai

[NEEDS INPUT: whether a DPO is appointed — required under GDPR Art. 37 only in specific cases — and any EU/UK Art. 27 representative.]