Legal

Data Processing Agreement

Last updated:

This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or Terms of Service between Enclavia and its enterprise clients. It governs the processing of personal data on behalf of our clients in compliance with global data protection laws (e.g., GDPR, CCPA).

ON THIS PAGE

1. Definitions

"Personal Data", "Data Controller", "Data Processor", and "Processing" shall have the same meanings as defined in applicable data protection laws. Enclavia acts as the Data Processor, while the Client acts as the Data Controller.

2. Data Processing Obligations

Enclavia will only process Personal Data in accordance with the Client's documented instructions. We will not use or process Personal Data for any purpose other than providing the Services, nor will we use Client data to train our foundational models.

3. Security Measures

We implement and maintain technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include AES-256 encryption at rest, TLS 1.3 in transit, and continuous vulnerability scanning.

4. Sub-processors

The Client grants Enclavia general authorization to engage sub-processors. We will enter into written agreements with all sub-processors imposing data protection terms that require the sub-processor to protect the Personal Data to the standard required by applicable data protection laws.