This Data Processing Addendum ("DPA") forms part of the Terms of Service between FEYA, s.r.o., Pekná cesta 19, 831 52 Bratislava-Rača, Slovak Republic, IČO 47 887 541 ("Processor", "Heabsy") and the customer ("Controller", "you"). It applies where you process personal data through the Heabsy Platform. If you require a signed copy for your records, contact [email protected].
1. Roles and scope
For content you submit to the inference API (prompts) and the resulting completions, you act as controller and Heabsy acts as processor. For the website and account data described in the Privacy Policy, Heabsy is an independent controller and this DPA does not apply.
2. Subject matter, duration, nature and purpose
Subject matter & purpose: providing AI model inference requested by you through the Service. Nature: transmission and in-memory processing of prompts to generate completions. Duration: for the term of the Terms and, for each request, only for the time needed to serve it. For models served on Heabsy infrastructure, Heabsy does not persist prompt or completion content; for models fulfilled by third-party inference providers, content is transmitted to that provider and handled under its own policy (see §5–§6 and the Privacy Policy).
3. Types of data and categories of data subjects
Determined and controlled by you through what you choose to send. This may include any personal data contained in your prompts and relating to any data subjects you include. You must not send special-category data (GDPR Art. 9), government identifiers, or data of children unless you have a lawful basis and have informed us in writing; the Service is not designed for such data.
4. Processor obligations
- Instructions. Heabsy processes the content only on your documented instructions — including with regard to any transfer of personal data to a third country or international organisation — which comprise the Terms, this DPA, and your use of the Service, unless required by EU or Member-State law (in which case Heabsy informs you unless the law prohibits it). Heabsy will inform you if, in its opinion, an instruction infringes the GDPR.
- Confidentiality. Personnel authorised to process the content are bound by confidentiality.
- Security (Art. 32). Heabsy maintains appropriate technical and organisational measures — TLS in transit, authentication and least-privilege access, in-memory-only handling of content on inference nodes with no durable storage of content, encrypted backups of metadata, and an incident-response process.
- Data-subject requests (Art. 12–23). Taking into account the nature of the processing, Heabsy assists you by appropriate measures to respond to data-subject requests; because content is not retained, Heabsy generally holds no content to retrieve.
- Assistance (Art. 32–36). Heabsy assists you with security, breach notification, and data-protection impact assessments, taking into account the information available to it.
- Breach notification. Heabsy notifies you without undue delay after becoming aware of a personal-data breach affecting your content.
- Deletion / return. On termination, Heabsy deletes or returns personal data as you choose; as content is not persisted, this concerns account and usage metadata, subject to legal retention.
- Audit (Art. 28(3)(h)). Heabsy makes available the information necessary to demonstrate compliance and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice and subject to confidentiality.
5. Sub-processors
You give general authorisation for Heabsy to engage sub-processors, including EEA GPU compute providers (including GPU-marketplace hosts) that provide the compute on which inference runs, and — for models marked as third-party-fulfilled — third-party inference providers. Heabsy imposes data-protection obligations on sub-processors substantially equivalent to those in this DPA. Where a compute-infrastructure sub-processor does not enter into such terms, Heabsy engages it only under compensating technical and organisational measures — in particular in-memory-only processing of content with no durable storage — and remains fully liable to you for that sub-processor's performance of its data-protection obligations. Heabsy maintains a list of sub-processors (available on request; see the Privacy Policy, §7) and gives you reasonable advance notice of any intended addition or replacement, so that you may object on reasonable data-protection grounds.
6. International transfers
Inference on Heabsy-served models is provisioned within the EEA. Where a sub-processor is outside the EEA (for third-party-fulfilled models or ancillary services), transfers rely on an adequacy decision, the EU-US Data Privacy Framework, or Standard Contractual Clauses with a transfer-impact assessment. The Standard Contractual Clauses are incorporated by reference where they apply.
7. Liability and precedence
The limitations and exclusions of liability in the Terms apply to this DPA. In case of conflict on the processing of personal data, this DPA prevails over the Terms. This DPA is governed by the same law as the Terms.
8. Contact
FEYA, s.r.o., Pekná cesta 19, 831 52 Bratislava-Rača, Slovak Republic. Data protection: [email protected]; legal: [email protected].