DeepAPI
TermsPrivacyDPA

Data Processing Addendum

Last updated: August 20, 2026

This addendum is part of the Terms of Service. It covers how DeepAPI processes personal data when you use the service. There is no separate click-through or signature. If you need a signed copy, email us.

1. This addendum

This Data Processing Addendum ("DPA") is incorporated into the Terms of Service by reference. It is a contract between you and DADA INDUSTRIES sp. z o.o. ("DeepAPI", "we", "us"). It applies when we process personal data in connection with the service.

2. Roles

We act in two roles, depending on the data.

  • Processor. For customer request content — the inputs your agents send and the results we return — you are the controller (or processor acting for your own customers) and we are the processor. We process that data on your behalf.
  • Controller. For account and billing data — sign-in details, workspace membership, usage metadata, and the credit ledger — we are the controller. That processing is described in the Privacy Policy.

3. Instructions

When we act as your processor, we process personal data only on your documented instructions. Those instructions are these terms, this DPA, the API requests you send, and the uses described in the Privacy Policy (including, during early access, debugging and product improvement). We will not process that data for other purposes except as the law requires. If a legal requirement stops us from following an instruction, we will tell you unless the law forbids it.

4. Security

We maintain appropriate technical and organizational measures to protect personal data, including access controls, encryption in transit, logging, and least-privilege access for personnel. No measure is perfect. You remain responsible for how you use the service and for the data you send.

5. Personal data breaches

If we become aware of a personal data breach that affects data we process for you, we will notify you without undue delay. We will give you the information we reasonably have so you can meet your own notification duties. We do not commit to a fixed number of hours.

6. Subprocessors

You authorize us to use subprocessors in these categories:

  • Cloud hosting and infrastructure (application serving, database, authentication).
  • Public web data collection.
  • Email sending and inbox infrastructure.
  • AI model providers for research and generation.
  • Address lookup for checkout.

A current list of the specific subprocessors is available on request at support@deepapi.co. We may update our providers as the service evolves.

7. Deletion

Email support@deepapi.co with a written request to delete customer request content. We will delete that content within 30 days, except for data we must keep for accounting, security, or legal reasons (including the billing ledger). Deletion is done by hand. We do not automatically delete request content when an account is closed.

8. International transfers

DeepAPI's core infrastructure (API and database) runs in Europe (Germany and Switzerland). Some providers we use are outside the EU. Where we transfer personal data to those providers, we rely on the European Commission's standard contractual clauses.

9. Assistance with data-subject requests

Taking into account the nature of the processing, we will give you reasonable assistance with requests from people whose personal data we process for you. Contact support@deepapi.co.

10. Confidentiality

People who process personal data for us are bound to keep it confidential. They may access it only as needed to provide the service.

11. Survival

This DPA lasts for as long as we process personal data under it. It survives termination of the Terms while we still hold that data.

12. Contact

Questions about this DPA: support@deepapi.co. See also our Terms of Service and Privacy Policy.

© 2026 DeepAPI
TermsPrivacyDPA