Data Processing Addendum
Last updated: September 25, 2026
This Data Processing Addendum (“DPA”) forms part of the applicable agreement between Attababy Technologies LLC, a Delaware limited liability company (“Attababy”), and the customer identified in the applicable agreement (“Customer”).
This DPA applies only to the extent Attababy processes Personal Data on behalf of Customer in connection with the Services.
Attababy and Customer may each be referred to as a “Party” and collectively as the “Parties.”
1. Purpose and Scope
This DPA governs Attababy’s Processing of Personal Data on behalf of Customer in connection with the Services.
The nature, purpose, duration, categories of Personal Data, categories of Data Subjects, deployment requirements, and other Processing details may be further described in the applicable agreement, statement of work, deployment documentation, or Customer instructions.
2. Definitions
For purposes of this DPA:
- Applicable Data Protection Laws means privacy and data-protection laws applicable to the Processing of Personal Data under the Services, which may include the GDPR, UK GDPR, CCPA/CPRA, and other applicable national, state, or regional privacy laws.
- Controller means the entity that determines the purposes and means of Processing Personal Data.
- Customer Data means data provided or made available by Customer through the Services.
- Data Subject means an identified or identifiable natural person.
- Personal Data means information relating to an identified or identifiable natural person or otherwise defined as personal information or personal data under Applicable Data Protection Laws.
- Processing means any operation or set of operations performed on Personal Data.
- Processor means an entity that Processes Personal Data on behalf of a Controller.
- Sub-processor means a third party engaged by Attababy to Process Personal Data on behalf of Customer.
- Deployment Requirements means Customer-provided regional, tenant, residency, infrastructure, retention, security, or related configuration requirements applicable to a workload.
Terms not defined in this DPA have the meanings given in Applicable Data Protection Laws or the governing agreement.
3. Roles of the Parties
To the extent Customer determines the purposes and means of Processing and Attababy Processes Personal Data on Customer’s behalf:
- Customer acts as Controller.
- Attababy acts as Processor.
Customer is responsible for:
- Determining whether and how Personal Data may lawfully be Processed.
- Providing lawful instructions to Attababy.
- Establishing applicable retention and residency requirements.
- Obtaining necessary notices, consents, permissions, or other legal bases.
- Configuring or communicating applicable Deployment Requirements.
Attababy will Process Personal Data only in accordance with Customer’s documented instructions, the applicable agreement, and Applicable Data Protection Laws, unless otherwise required by law.
4. Processing Instructions
Customer instructs Attababy to Process Personal Data as reasonably necessary to:
- Provide and operate the Services.
- Configure hosted, connected, or hybrid infrastructure environments.
- Perform workload deployment, routing, retrieval, model, agent, and infrastructure functions.
- Provide security, support, observability, and maintenance.
- Comply with Customer’s documented Deployment Requirements.
- Perform other Processing expressly authorized in writing by Customer.
If Attababy reasonably believes a Customer instruction violates Applicable Data Protection Laws, Attababy may notify Customer and suspend the affected Processing until the matter is resolved.
5. Confidentiality
Attababy will ensure that personnel authorized to Process Personal Data are subject to appropriate confidentiality obligations.
Access to Personal Data will be limited to personnel and service providers with a legitimate need for such access in connection with the Services.
6. Security Measures
Attababy will maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Depending on the applicable deployment, such measures may include:
- Encryption in transit and at rest.
- Authentication and access controls.
- Tenant-specific infrastructure environments.
- Enclave-capable execution environments.
- Configurable persistence controls.
- Security monitoring and operational logging.
- Infrastructure and deployment observability.
- Segmentation of participating environments.
- Incident-response procedures.
Specific security controls may vary by deployment architecture and may be further described in the applicable customer agreement or security documentation.
7. Sub-processors
Customer authorizes Attababy to engage Sub-processors as reasonably necessary to provide the Services.
Sub-processors may include providers of:
- Cloud and compute infrastructure.
- Data-center and hosting services.
- Networking.
- Monitoring and security services.
- Logging and observability.
- Support services.
- Payment and business operations services.
Attababy will require Sub-processors that Process Personal Data on behalf of Customer to be subject to data-protection obligations appropriate to the services they provide.
Where required by Applicable Data Protection Laws or the governing agreement, Attababy will provide notice of material new Sub-processors and a reasonable opportunity for Customer to raise a legitimate data-protection objection.
A current Sub-processor list may be provided separately or upon request.
8. International and Cross-Regional Transfers
Attababy will Process Personal Data in accordance with Customer’s documented Deployment Requirements and the applicable agreement.
Where Customer specifies regional or jurisdictional requirements, Attababy will configure the applicable Attababy-controlled infrastructure services consistent with those requirements, subject to:
- The agreed deployment architecture.
- Customer-controlled and third-party infrastructure.
- Technical limitations disclosed to Customer.
- Applicable law.
- Any authorized support or operational activity.
Where Personal Data is transferred internationally and Applicable Data Protection Laws require a transfer mechanism, the Parties will use an appropriate lawful transfer mechanism.
9. Data Subject Requests
Taking into account the nature of the Processing, Attababy will provide reasonable assistance to Customer with requests from Data Subjects to exercise rights under Applicable Data Protection Laws where Customer cannot reasonably fulfill the request without Attababy’s assistance.
Attababy will not independently respond to a Data Subject request relating to Customer-controlled Personal Data except as required by law or authorized by Customer.
10. Security Incidents
Attababy will notify Customer without undue delay after becoming aware of a confirmed security incident involving Personal Data Processed by Attababy on behalf of Customer, where notification is required under Applicable Data Protection Laws or the governing agreement.
Such notification will include information reasonably available to Attababy concerning the nature of the incident and relevant mitigation or response measures.
Notification does not constitute an admission of fault or liability.
11. Data Protection Assessments
Taking into account the nature of the Processing and information available to Attababy, Attababy will provide reasonable assistance with data-protection impact assessments and consultations with supervisory authorities where required by Applicable Data Protection Laws.
12. Data Retention, Return, and Deletion
Retention behavior depends on the applicable workload, configuration, deployment architecture, and Customer instructions.
Attababy supports configurable persistence and retention controls for certain infrastructure services.
Upon termination or expiration of the applicable Services, Attababy will delete or return Personal Data in accordance with Customer’s documented instructions and the applicable agreement, unless retention is required by applicable law.
Backups, security records, billing records, or other information may be retained for limited periods where reasonably necessary for legal, security, operational, or contractual purposes.
13. Audits and Information
Attababy will make available information reasonably necessary to demonstrate compliance with this DPA as required by Applicable Data Protection Laws.
Where required, the Parties may agree on reasonable audit procedures that protect the security, confidentiality, intellectual property, and operations of Attababy and other customers.
14. Special Categories and Regulated Data
Customer will not provide regulated or specially protected data to Attababy unless:
- The applicable Services and deployment are designed to support such data.
- The Parties have agreed to the applicable requirements in writing.
- Customer has satisfied its own legal obligations.
Processing of protected health information subject to HIPAA may require a separate Business Associate Agreement.
15. Governing Law
Unless otherwise provided in the governing customer agreement or required by Applicable Data Protection Laws, this DPA is governed by the laws of the State of Delaware.
16. Order of Precedence
This DPA supplements the governing agreement.
If there is a conflict between this DPA and the governing agreement regarding the Processing of Personal Data, this DPA will control with respect to that Processing unless the Parties expressly agree otherwise in writing.
If you have questions about this Data Processing Addendum, please contact us at
legal@attababy.com