Legal

Data processing agreement

If your organization needs written data protection terms before it can buy, we can sign a data processing agreement. Here is what it covers.

In short

Four things this page says, before the detail. The detail below is what actually applies.

Why you may need one

Many organizations cannot buy a service that handles personal data without written terms. Self-service APIs usually offer terms that cannot be amended — often where legal review stops. We can sign one, and we can discuss it.

  • Section 1
  • Negotiable

What it covers

Roles, scope, instructions, confidentiality, security, sub-processors, assistance, breach notification, deletion or return, and audit.

  • Section 2
  • Ten headings

What this page is not

It describes the shape of the agreement, not the agreement itself, and it is not legal advice. The binding text is the document we sign with your organization.

  • Section 3
  • Not the contract

How to get one

Ask in the inquiry form, or raise it with your account contact. Tell us your entity, where your users are, and what your legal team needs to see.

  • Section 6
  • Draft on request

This summary is a reading aid, not a substitute. It does not change the meaning of the numbered sections below — where the two differ, the numbered sections govern.

1. Why this matters

Many organizations cannot buy a service that handles personal data without a written agreement setting out what the supplier may do with it. Self-service APIs typically offer a standard set of terms that cannot be amended — which is often the point at which a legal review stops.

We can sign a data processing agreement, and we can discuss its terms.

2. What the agreement covers

In outline, a data processing agreement between us and your organization covers:

  • Roles. Which party is the controller and which is the processor for the data involved.
  • Scope. What categories of data may be processed, for what purposes, and for how long.
  • Instructions. That we process data only on your documented instructions.
  • Confidentiality. That people with access to the data are under confidentiality obligations.
  • Security. The technical and organizational measures we apply.
  • Sub-processors. How sub-processors are authorized, and how you are told about changes to them.
  • Assistance. Our commitment to help you respond to data subject requests and to security incidents.
  • Breach notification. How and how quickly we tell you if something goes wrong.
  • Deletion or return. What happens to the data when the agreement ends.
  • Audit. What information we can provide to support your compliance obligations.

3. What this page is not

This page describes the shape of the agreement. It is not the agreement itself, and it is not legal advice. The binding text is the document we sign with your organization, which will be drafted to reflect the actual data flows in your setup.

4. Data you send through the API

Depending on what you build, the content you send to the model may contain personal data — names and addresses on an invoice, for example. We process it to serve your requests. What we may and may not do with it is set out in the agreement.

We do not sell your data. Our privacy policy covers the data we collect through this website, which is a separate matter.

5. Data residency

If you have residency requirements — a need for data to be processed in a particular jurisdiction, or not to leave one — tell us before you commit. We will confirm in writing what we can and cannot support rather than assume.

6. How to get one

Ask in the inquiry form, or raise it with your account contact. Tell us your entity, where your users are, and what your legal team needs to see. We will send a draft and work through the amendments.

Last updated: 30 September 2026. The binding terms are those in the agreement signed with your organization; this page describes what that agreement covers.

DPA · WHERE YOUR DATA GOES

Diagram of the flow: three stages connected by arrows, with the middle stage highlighted.

YOUR SIDE

Your documents

sent over the API to be processed

US

Workhorse

passes them through, keeps the records

THE MODEL PROVIDER

DeepSeek

runs the model — a named sub-processor

  • Sub-processors named in the DPA
  • Sent only to run your requests
  • Deletion terms in writing
Who touches your data, and in what role.Diagram of the process. Not a screenshot.

Need a DPA to move forward?

Tell us what your legal team needs and we will send a draft to work from.