PrivedgePrivedge · Docs
Privedge Privedge
Data Processing Addendum
Version 1.0 · June 8, 2026
Confidential

Data Processing Addendum

Pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR)

Data Controller
(hereinafter "Controller")
Data Processor
Privedge
[email protected] · privedge.io
(hereinafter "Processor")

Preamble: The Controller uses the Privedge AI inference proxy to detect and anonymize PII in AI prompts before transmission to third-party LLM providers. This Addendum governs the Processor's handling of personal data on behalf of the Controller pursuant to GDPR Art. 28.

Subject matter and nature of processing

The Processor provides an AI inference proxy that: (a) receives prompts from the Controller's systems, (b) detects and replaces personally identifiable information with synthetic tokens, (c) forwards anonymized prompts to designated AI providers, (d) reverses tokenization on responses, and (e) returns de-anonymized responses to the Controller.

Personal data is processed exclusively in memory during the request lifecycle. No prompt content is written to persistent storage.

Categories of data subjects and personal data

Data subjects

End users of the Controller's AI-enabled products and services whose prompts are routed through the Processor.

Categories of personal data

  • Names, identifiers, and contact details (detected and tokenized)
  • Health-related information (PHI), where applicable
  • Financial identifiers (IBAN, card numbers), where applicable
  • National identification numbers (SSN, DNI/NIF), where applicable
  • Any other PII present in user-submitted prompts

The Processor processes audit metadata on a persistent basis: timestamp, pii_types detected (not values), routed_to, latency_ms. This metadata does not identify individuals.

Purposes and legal basis

Processing is carried out solely for the purpose of providing the Privedge anonymization service as described in Clause 1. The Processor acts only on documented instructions from the Controller. No processing for the Processor's own purposes occurs.

Sub-processors

The Processor engages the following sub-processors. The Controller hereby grants general authorization for these sub-processors:

  • Cloudflare, Inc. — Edge compute runtime (Workers). Processing location: distributed globally, EU region for EU customers. Certifications: SOC 2 Type II, ISO 27001, HIPAA-eligible.
  • Cloudflare, Inc. — Audit log storage (R2). Enterprise tier only. No prompt content stored.

The Processor shall notify the Controller of any intended addition or replacement of sub-processors at least 30 days in advance. The Controller may object in writing within 14 days of such notification.

International data transfers

The Processor engages Cloudflare, Inc. (United States) as a sub-processor. Transfers of personal data to Cloudflare are governed by Standard Contractual Clauses (SCCs) adopted pursuant to GDPR Art. 46(2)(c), as incorporated in Cloudflare's Data Processing Addendum (cloudflare.com/cloudflare-customer-dpa). For EU customers, the Processor configures edge routing to prioritize EEA Points of Presence.

No other international transfers of personal data occur in connection with the Privedge service.

Data retention and deletion

  • Prompt content: Zero retention. Processed in-memory, never written to storage.
  • Token maps: Destroyed upon request completion (V8 isolate teardown).
  • Audit metadata (Pro): 30 days from creation date.
  • Audit metadata (Enterprise): As specified in the main service agreement.
  • Deletion on termination: All retained data deleted within 30 days of contract end.

Technical and organisational security measures

  • All data in transit encrypted with TLS 1.3
  • Each request processed in an isolated V8 sandbox (Cloudflare Workers) — zero shared state between requests
  • Audit logs encrypted at rest with AES-256 (Cloudflare R2)
  • Access controls: principle of least privilege; no Privedge personnel access to prompt content
  • Processor infrastructure certified: SOC 2 Type II, ISO 27001, HIPAA-eligible (via Cloudflare)
  • Incident response: breach notification to Controller within 24 hours of discovery

Data subject rights

The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability) insofar as technically feasible. Given that prompt content is not stored, most erasure requests are satisfied by architecture. The Processor shall forward any requests received directly from data subjects to the Controller within 5 business days.

Breach notification

The Processor shall notify the Controller without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach. Notification shall include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

Audit rights

The Controller may request reasonable information to verify compliance with this Addendum. The Processor shall make available all information necessary to demonstrate compliance and shall allow for and contribute to audits, including inspections, subject to reasonable advance notice and confidentiality obligations.

Termination and return of data

Upon termination of the main service agreement, the Processor shall delete all retained data within 30 days and provide written confirmation. Self-hosted deployments retain no data on the Processor's systems; this clause applies to cloud-mode customers only.

Relationship to main agreement

This Addendum forms part of and is incorporated into the Privedge Terms of Service available at privedge.io/terms (the "Agreement"). In the event of any conflict between this Addendum and the Agreement with respect to the subject matter hereof, this Addendum shall prevail. Capitalized terms not defined herein have the meaning given in the Agreement.

Data Controller
Data Processor — Privedge
PrivedgePrivedge DPA v1.0 · June 8, 2026 · [email protected]