← Legal

Data Processing Addendum

This Data Processing Addendum (the “DPA”) forms part of the Andy Labs Master Services Agreement, Version 3.0, dated September 4, 2026 (the “Agreement”) between Andy Labs LLC, a Wyoming limited liability company (“Andy Labs”, “we”, “us”) and the customer that signs an Order Form referencing the Agreement (“Customer”, “you”). It governs the processing of Personal Data by Andy Labs on Customer’s behalf. Capitalized terms not defined here have the meaning given in the Agreement.


1. DEFINITIONS

1.1 “Personal Data” means information about an identified or identifiable individual that Andy Labs processes on Customer’s behalf under the Agreement.

1.2 “Controller” means the party that determines the purposes and means of processing Personal Data. Where applicable law uses a different term for the same role, including “business” or “organization”, that term applies.

1.3 “Processor” means the party that processes Personal Data on behalf of the Controller. Where applicable law uses a different term for the same role, including “service provider”, that term applies.

1.4 “Data Subject” means the individual to whom Personal Data relates.

1.5 “Processing” means any operation performed on Personal Data, including collection, storage, retrieval, use, transmission, disclosure, and deletion.

1.6 “Subprocessor” means a third party engaged by Andy Labs that processes Personal Data on Customer’s behalf in the course of Andy Labs performing the Services.

1.7 “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Personal Data on the Instance.

1.8 “Data Protection Law” means the privacy and data protection laws that apply to a party’s processing under the Agreement, including applicable United States federal and state privacy laws, the Personal Information Protection and Electronic Documents Act (Canada) and applicable provincial privacy legislation where the Customer is Canadian or processes the data of individuals in Canada, and the EU and UK General Data Protection Regulation where applicable.


2. ROLES OF THE PARTIES

2.1 Customer is the Controller. Customer determines what data Andy Labs is instructed to process in performing the Services, for what purposes, and for how long. Customer is the Controller of all Personal Data processed under the Agreement.

2.2 Andy Labs is the Processor. Andy Labs processes Personal Data only as a Processor, acting on Customer’s documented instructions.

2.3 Customer’s responsibilities as Controller. Customer is responsible for the lawfulness of the processing it instructs, for having a valid legal basis and any required consent, permit, or authorization, for the accuracy of the Personal Data it connects, for giving the notices Data Subjects are entitled to, for responding to Data Subject requests, and for determining whether the Services and the security measures in Section 6 are appropriate for the Personal Data Customer chooses to connect. Customer warrants that it is entitled to transfer the Personal Data to Andy Labs for processing under this DPA.

2.4 Documented instructions. Customer’s instructions are the Agreement, the Order Form, this DPA, and the operational instructions Customer gives through the interfaces Andy Labs operates in performing the Services. Andy Labs will process Personal Data only on those instructions, and will not process it for its own purposes, will not sell it, will not share it for cross-context behavioural advertising, and will not retain, use, or disclose it outside the direct business relationship with Customer. If Andy Labs is required by law to process Personal Data other than on Customer’s instructions, it will tell Customer before doing so unless the law forbids that notice.

2.5 Unlawful instruction. If Andy Labs reasonably believes an instruction from Customer violates Data Protection Law, Andy Labs will tell Customer and may suspend performance of that instruction until it is resolved.

2.6 Personnel. Andy Labs will ensure that anyone it authorizes to process Personal Data is bound by a duty of confidentiality and is granted access only to the extent needed to perform the Services.


3. CATEGORIES OF DATA AND DATA SUBJECTS

3.1 Subject matter and duration. The subject matter of the processing is Andy Labs’ performance of the Services. The duration is the term of the Agreement, plus the exit period in Section 9.

3.2 Nature and purpose of processing. Andy Labs operates a dedicated single-tenant virtual machine, which it procures in its own name and controls, that reads data from the Customer Systems Customer connects, stores a persistent memory database derived from that data, transmits relevant portions of it to a Model Provider for inference, and produces Output for Customer’s business use. Processing includes collection, storage, structuring, retrieval, use, transmission to Subprocessors, and deletion.

3.3 Categories of Data Subjects. These will typically include Customer’s employees and contractors, Customer’s customers, clients, and prospects, Customer’s suppliers and vendors, and any individual named in the correspondence, records, and documents held in the Customer Systems Customer connects.

3.4 Categories of Personal Data. These will typically include:

  1. contact and identity data, including name, job title, employer, email address, telephone number, and postal address.

  2. communications content and metadata, including the body, subject lines, headers, attachments, timestamps, and participant lists of email and chat messages.

  3. calendar and scheduling data, including meeting titles, times, locations, and attendees.

  4. commercial and transactional data, including customer records, invoices, payment status, amounts, and accounting entries, but not payment card data.

  5. business documents and files stored in the connected systems.

  6. website and analytics data, including aggregated and pseudonymous usage measurements.

3.5 Excluded Data. Customer will not connect protected or personal health information, payment card data, or special category personal data as those are defined in the Order Form, except under a written addendum signed by both parties. Andy Labs does not design or perform the Services for that data and does not accept it absent such an addendum.


4. SINGLE-TENANT ISOLATION

4.1 Dedicated Instance. Andy Labs performs the Services for each customer on a dedicated virtual machine that Andy Labs provisions, operates, and controls. Customer’s Personal Data is stored on the Instance allocated to Customer and is not stored on the Instance of any other customer.

4.2 No pooling. Andy Labs does not pool, aggregate, combine, or cross-reference Customer’s Personal Data with the data of any other customer, and does not use Customer’s Personal Data to answer another customer’s query or to serve another customer in any way.

4.3 Separate Credentials. Each Instance holds its own Credentials, its own memory database, and its own configuration. Credentials are not shared between Instances.


5. CONFIDENTIALITY AND USE RESTRICTIONS

Personal Data is Customer’s Confidential Information under Section 9 of the Agreement. Andy Labs will not disclose it to a third party except to a Subprocessor listed in Section 7, to the extent required by law under Section 9.4 of the Agreement, or with Customer’s written instruction.


6. SECURITY MEASURES

6.1 Measures in place. Andy Labs maintains the following technical and organizational measures. This list is stated accurately and completely. Andy Labs makes no security representation beyond it.

  1. Dedicated single-tenant virtual machine. The Instance runs on a virtual machine dedicated to Customer, with no other customer tenant on it. Andy Labs procures that machine in its own name and provisions, administers, and controls it, as set out in Section 2.7 of the Agreement.

  2. Unprivileged service account. Andy Labs Technology runs on the Instance under an unprivileged operating system account with no administrative rights on the machine, under a service sandbox that prevents privilege escalation, restricts writes to the system directories, and restricts access to home directories.

  3. Host firewall, default deny. Each Instance runs a host firewall configured to deny inbound traffic by default, allowing only the specific ports required to perform the Services.

  4. TLS 1.3 in transit. Traffic between the Instance and Customer, and between the Instance and third party services including Model Providers and Customer Systems, is encrypted using TLS version 1.3.

  5. Vault-encrypted secrets at rest. Credentials, API keys, and other secrets used to provision and operate the Instance are stored encrypted in an encrypted secrets vault in Andy Labs’ deployment repository, and are not stored in plain text in source control.

  6. No model training on Customer data. Andy Labs does not use Customer Data or Personal Data to train, fine-tune, or otherwise improve any machine learning model, and contracts with its Model Providers on terms that do not permit them to do so.

  7. Access control, and Andy Labs’ exclusive administrative control. Administrative and root access to the Instance is held exclusively by Andy Labs and is limited to Andy Labs personnel who need it to perform and support the Services, using key-based authentication. Customer has no operating system account, no shell access, no root or administrative credential, no hypervisor or console access, and no ability to alter the system configuration of the Instance or to add or remove system-level components. Customer interacts with the Services only through the application-level interface that Andy Labs operates. The Instance remains in Andy Labs’ possession and under Andy Labs’ exclusive administrative control at all times, as set out in Section 2.7 of the Agreement.

6.2 What Andy Labs does not claim. Customer is entitled to an honest description of the security posture, and Andy Labs states plainly that as of the date of this DPA it does not provide, and does not represent that it provides, any of the following:

  1. application-level encryption of Customer Data at rest on the Instance beyond the secrets encryption described in Section 6.1(e).

  2. SOC 2, ISO 27001, HIPAA, PCI DSS, or any other third party security certification, attestation, or audit report.

  3. offsite or geographically redundant backups of Customer Data.

  4. 24 hours a day, 7 days a week security monitoring, a security operations centre, or intrusion detection with continuous human review.

  5. third party penetration testing or vulnerability assessment of the Instance or of Andy Labs Technology.

6.3 Customer’s decision. Customer acknowledges the disclosures in Section 6.2 and is responsible for deciding whether the measures in Section 6.1 are appropriate for the Personal Data Customer chooses to connect, given the nature of that data and the risk to Data Subjects. Customer should not connect data whose loss or disclosure would cause serious harm to a Data Subject.

6.4 Changes to measures. Andy Labs may change the measures in Section 6.1 provided the overall level of security is not materially reduced. Andy Labs will update this DPA when it adds a control, and will not claim a control it has not implemented.

6.5 Customer-side security. Customer is responsible for the security of the Customer Systems, for the scope and lifecycle of the Credentials it supplies, and for revoking them when appropriate.


7. SUBPROCESSORS

7.1 Authorization. Customer authorizes Andy Labs to engage the Subprocessors listed below.

Subprocessor Role Processing location What it processes
Anthropic PBC Large language model inference United States The prompt content sent for inference, which may include Personal Data drawn from Customer Systems and from the Instance memory
OpenRouter, Inc. Large language model inference routing, used as an alternative or fallback to Anthropic United States The prompt content sent for inference, which may include Personal Data drawn from Customer Systems and from the Instance memory
The Constant Company, LLC (Vultr) Compute and hosting of the dedicated virtual machine Region selected for the Instance and recorded in the Order Form or provisioning record All data stored on the Instance, at the infrastructure layer
Cloudflare, Inc. DNS resolution for the Instance hostname, and hosting of the Andy Labs marketing site Global anycast network DNS query metadata. Cloudflare does not process the content of Customer Data

7.2 Which inference provider is used. Andy Labs uses Anthropic, OpenRouter, or both, depending on the model selected for the Instance. Where Customer supplies its own provider key, inference runs through the provider Customer’s key belongs to, under Customer’s own agreement with that provider.

7.3 Subprocessor obligations. Andy Labs will impose on each Subprocessor data protection obligations no less protective than those in this DPA, to the extent applicable to the service that Subprocessor performs, and remains fully liable to Customer for each Subprocessor’s performance of those obligations.

7.4 Changes. Andy Labs will give Customer at least thirty days written notice before adding or replacing a Subprocessor. Customer may object on reasonable data protection grounds within that thirty day period, in which case the parties will discuss a resolution in good faith. If they cannot resolve it, Customer may terminate the affected Order Form on written notice without further liability other than fees accrued to the date of termination. Andy Labs may replace a Subprocessor with less than thirty days notice where an urgent security or continuity need requires it, and will notify Customer as soon as practicable with the reason.

7.5 Customer Systems are not Subprocessors. Customer’s own accounts with Microsoft, Google, Stripe, Intuit, and any other provider of Customer Systems are Customer’s systems, held under Customer’s own contracts with those providers, and operated for Customer’s own purposes. Andy Labs accesses them only under Credentials Customer grants and only to perform the Services. Those providers are not Andy Labs’ Subprocessors, Andy Labs is not responsible for their processing, their security, their availability, or their compliance, and Customer’s relationship with each of them is governed by Customer’s own agreement with that provider. Customer may revoke Andy Labs’ access to any of them at any time.


8. CROSS-BORDER TRANSFERS

8.1 Inference goes to the United States. Customer should understand this clearly. Regardless of the region in which the Instance is hosted, the content sent for model inference is transmitted to and processed on infrastructure located in the United States, because Andy Labs’ Model Providers operate there. Choosing a Canadian or European hosting region for the virtual machine does not keep the inference content in that region. If data residency in a specific country is a legal requirement for Customer, the Services in their current form do not meet that requirement for the content that goes to inference, and Customer should not connect data subject to that requirement.

8.2 Hosting region. The virtual machine is hosted in the region recorded in the Order Form or the provisioning record. Data at rest on the Instance stays in that region.

8.3 Transfer mechanism. Where a transfer of Personal Data out of a jurisdiction requires a legal transfer mechanism, the parties will put the applicable mechanism in place, including the European Commission’s Standard Contractual Clauses and the UK Addendum where relevant, and those clauses are incorporated by reference on the parties’ agreement to complete them. Andy Labs will provide reasonable assistance with a transfer impact assessment on request.

8.4 Government access requests. If Andy Labs receives a legally binding request from a public authority for Personal Data, it will notify Customer before disclosing unless the law forbids that notice, will disclose only the minimum required, and will challenge a request that is unlawful on its face.

8.5 Where Andy Labs itself sits. Andy Labs is a Wyoming limited liability company established in the United States, and it is subject to United States legal process, including a request or order of the kind described in Section 8.4. That is true whatever hosting region Customer selects for the Instance. Andy Labs is not established in Canada, the European Union, or the United Kingdom, and has not appointed a representative in any of them. Where a transfer mechanism is needed under Section 8.3, Customer is the exporter and Andy Labs is the importer. Andy Labs personnel who administer the Instance may access it from outside the United States, including from Israel, which is the subject of a European Commission adequacy decision. Customer is responsible for deciding whether this arrangement is acceptable for the Personal Data it chooses to connect.


9. RETENTION AND DELETION

9.1 During the term. Andy Labs retains Personal Data on the Instance for as long as the Agreement is in force, because the persistent memory database on the Instance is part of how Andy Labs performs the Services. Customer may instruct Andy Labs to delete specific Personal Data at any time, and Andy Labs will do so within thirty days of the instruction.

9.2 On termination. The exit process in Section 11.6 of the Agreement applies. Customer Data, including Personal Data, is available for export for thirty days after termination. The Instance and all backups and snapshots of it are destroyed within sixty days after termination. Andy Labs will provide a signed certificate of deletion on Customer’s written request made within ninety days after termination.

9.3 Legal retention. Andy Labs may retain Personal Data to the extent required by law. Data retained under this exception remains subject to this DPA and to Section 9 of the Agreement for as long as it is held, and is used for no purpose other than the legal requirement.

9.4 Data Subject deletion requests. If a Data Subject asks Andy Labs to delete Personal Data, Andy Labs will refer the request to Customer and will act only on Customer’s instruction.


10. DATA SUBJECT RIGHTS AND ASSISTANCE

10.1 Requests. Customer is responsible for responding to Data Subject requests to access, correct, delete, restrict, port, or object to the processing of Personal Data. If Andy Labs receives such a request directly, it will promptly refer it to Customer and will not respond substantively except to confirm the referral, unless legally required to respond.

10.2 Assistance. Taking into account the nature of the processing, Andy Labs will provide reasonable assistance to Customer in responding to Data Subject requests, in carrying out a data protection impact assessment, and in consulting a supervisory authority. Where the assistance sought goes beyond what is reasonable in scope or frequency, Andy Labs will quote the additional assistance in writing in advance and will provide it, at Customer’s cost, once Customer accepts the quote in writing.


11. SECURITY INCIDENTS

Andy Labs will notify Customer of a Security Incident without undue delay and in any event within seventy-two (72) hours of becoming aware of it, in accordance with Section 8.4 of the Agreement. The notice will describe what is known at the time, including the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the containment and remediation steps taken or planned. Andy Labs will provide further information as it becomes available and will cooperate reasonably with Customer’s investigation and with any notification Customer must make. Customer is responsible for determining whether the incident requires notification to a supervisory authority or to a Data Subject, and for making that notification.


12. AUDIT

12.1 Scope of audit rights. Customer’s audit right under this DPA is limited to the following. Once per calendar year, Customer may send Andy Labs a written security and privacy questionnaire covering the measures in Section 6 and the obligations in this DPA. Andy Labs will answer it accurately and completely within thirty days.

12.2 What is not included. The audit right does not include an on-site inspection, access to the Instance’s infrastructure layer, access to Andy Labs’ internal systems, access to another customer’s environment, penetration testing, vulnerability scanning of Andy Labs’ systems, or an audit of a Subprocessor. Andy Labs does not hold a third party audit report and will not represent that it does.

12.3 Additional audits. If Data Protection Law requires an audit beyond Section 12.1, or if a supervisory authority requires one, the parties will discuss in good faith how to satisfy it, and Customer will bear the reasonable cost of Andy Labs’ cooperation.

12.4 Confidentiality of responses. Questionnaire responses are Andy Labs’ Confidential Information.


13. LIABILITY AND ORDER OF PRECEDENCE

13.1 Liability. Each party’s liability under this DPA is subject to the exclusions and limitations in Section 6 of the Agreement.

13.2 Precedence. This DPA controls over the rest of the Agreement on the subject of processing Personal Data. On all other subjects, the Agreement controls. Where an applicable Standard Contractual Clause conflicts with this DPA, that clause controls to the extent of the conflict.

13.3 Term. This DPA takes effect on the Effective Date of the first Order Form and continues for as long as Andy Labs processes Personal Data on Customer’s behalf.


Andy Labs Data Processing Addendum, Version 3.0, dated September 4, 2026. Forms part of the Andy Labs Master Services Agreement, Version 3.0, dated September 4, 2026.