Data Processing Agreement

Effective date: 2026-05-13 (on Customer countersignature). Last updated: May 2026.

The data-processing bundle

For EU and UK customers, Komplex AI's data-processing arrangements are made up of three documents. They are designed to be read together:

  1. This Data Processing Agreement — the master document covering Article 28 GDPR / UK GDPR obligations.
  2. EU Standard Contractual Clauses (Module 2) — the EU Commission's 2021 SCCs, pre-filled and incorporated by reference.
  3. UK International Data Transfer Addendum — the UK ICO's addendum (B1.0) for UK GDPR transfers.

To save a signed copy: print this page (and the two linked pages) using your browser's “Save as PDF” option. We will generate signed PDFs from server-side rendering in a future release.

Good-faith draft — not legal advice.

These documents have been drafted by Komplexity AI LLC in good faith using public, regulator-issued templates (IAPP, the EU Commission, and the UK ICO). They have not been reviewed by outside counsel. If you rely on them in a legally consequential way, please consult your own lawyer. If anything looks unreasonable, tell us.

In plain language

  • We do not store the text you send us. Prompts and model responses you submit to the API are processed transiently and discarded as soon as we return a result. This is the single most important fact about our data handling, and it makes most of the obligations in a standard DPA short or inapplicable.
  • What we do keep is limited to operational telemetry: a timestamp, an API-key identifier, token counts, and response latency — what we need to bill you, enforce quotas, and answer support tickets.
  • You stay the Controller; we are the Processor. You decide what text to send us. We only process it on your instructions, which are these Terms and your API calls.
  • EU/UK transfers:our servers are in the United States. We rely on the EU Commission's 2021 Standard Contractual Clauses (Module 2) and the UK ICO's International Data Transfer Addendum.
  • Sub-processors at launch: Modal (inference compute), Stripe (payments), Vercel (web hosting), Neon (database — account/billing/usage metadata). See Annex C.

Table of Contents

  1. Definitions
  2. Scope and roles
  3. Processing on documented instructions
  4. Zero-retention of submitted text
  5. Confidentiality
  6. Security measures
  7. Sub-processors
  8. Data-subject requests
  9. Personal-data breaches
  10. Audit and information rights
  11. International data transfers
  12. Return and deletion of personal data
  13. Liability
  14. Term and termination
  15. Governing law and miscellaneous
  16. Annex A — Parties
  17. Annex B — Description of processing
  18. Annex C — Sub-processors
  19. Annex D — Technical and organizational measures
  20. Signature
  21. Companion: EU SCCs (Module 2) →
  22. Companion: UK Addendum →

This Data Processing Agreement (the “DPA”) is entered into between:

  • Komplexity AI LLC, a California limited liability company doing business as “Komplex AI,” with its principal place of business at 7514 Girard Ave, Ste 1 #935, San Diego, California 92037, United States (the “Processor” or “Komplexity”); and
  • the customer identified in Annex A who has accepted the Komplex AI Terms of Use or otherwise entered into an agreement for the Services (the “Customer” or “Controller”).

The Controller and the Processor are referred to individually as a “Party” and collectively as the “Parties.”

This DPA forms part of, and is incorporated by reference into, the Komplex AI Terms of Use (the “Agreement”) between the Parties. In the event of any conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Personal Data.

1. Definitions

Capitalized terms not otherwise defined in this DPA have the meanings given to them in the Agreement, or, where applicable, in Regulation (EU) 2016/679 (the “GDPR”) or the United Kingdom General Data Protection Regulation (the “UK GDPR”).

  • “Applicable Data Protection Law” means all laws and regulations applicable to the Parties' processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection (“FADP”), the California Consumer Privacy Act and the California Privacy Rights Act (together, the “CCPA”), and any other applicable U.S. state privacy law.
  • “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” and “processing” have the meanings given to those terms under the GDPR.
  • “Customer Personal Data” means Personal Data that the Processor processes on behalf of the Controller in connection with the Services, as further described in Annex B.
  • “EU SCCs” means the Standard Contractual Clauses approved by European Commission Decision 2021/914 of 4 June 2021, as set out at Decision 2021/914.
  • “Services” means the Komplex AI hallucination detection products described in the Agreement, including the web interface and the API.
  • “Sub-processor” means any third party engaged by the Processor to process Customer Personal Data on its behalf.
  • “UK Addendum” means the United Kingdom International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner's Office under section 119A of the Data Protection Act 2018.

2. Scope and roles

This DPA applies to the processing of Customer Personal Data by the Processor under the Agreement. The subject matter, duration, nature, purpose, categories of Data Subjects, and categories of Personal Data are described in Annex B.

With respect to Customer Personal Data, the Customer is the Controller and Komplexity is the Processor. Each Party will comply with its obligations under Applicable Data Protection Law.

For Personal Data that Komplexity processes for its own purposes (for example, billing records, account-administration data, and aggregated service analytics), Komplexity acts as an independent Controller; that processing is governed by the Privacy Policy and falls outside the scope of this DPA.

3. Processing on documented instructions

The Processor will process Customer Personal Data only on documented instructions from the Controller. The Controller's documented instructions are:

  • the Agreement and this DPA;
  • the Customer's configuration of the Services (including API calls); and
  • any further written instructions agreed between the Parties (which the Processor may decline if compliance would be technically infeasible or would conflict with Applicable Data Protection Law).

The Processor will inform the Controller without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law. The Processor will not be required to act on an instruction it reasonably believes to be unlawful.

4. Zero-retention of submitted text

The Processor processes the text the Controller submits for hallucination analysis (the “Submitted Text”) only transiently, in memory, for the time strictly necessary to compute a result and return it to the Controller. The Processor:

  • does not persist Submitted Text to disk, object storage, database, log file, message queue, or any other durable medium;
  • does not use Submitted Text to train, fine-tune, evaluate, or improve any machine-learning model, including its own;
  • does not retain hallucination scores derived from Submitted Text on its servers once they have been returned to the Controller; and
  • does not share Submitted Text with any third party other than the inference Sub-processor identified in Annex C, which receives it only transiently for the duration of an inference call.

The only data the Processor retains in connection with API requests is the usage-metadata set described in Annex B (timestamp, API-key identifier, token count, response latency). This metadata is held for the period stated in Section 9 of the Privacy Policy.

The Parties acknowledge that the zero-retention model materially reduces the obligations under several clauses of this DPA. Where this DPA references retention, deletion, or return of Submitted Text, those obligations are satisfied by the fact that no Submitted Text persists beyond the response cycle.

5. Confidentiality

The Processor ensures that personnel authorized to process Customer Personal Data are subject to confidentiality obligations, whether by contract or by statutory duty, that survive the termination of their engagement with the Processor.

6. Security measures

The Processor will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk to Data Subjects' rights and freedoms. The measures in place at the effective date of this DPA are described in Annex D.

The Processor may update the measures in Annex D from time to time, provided that the overall level of security is not materially decreased.

Certifications. The Processor does not, as of the effective date, hold SOC 2, ISO 27001, or comparable third-party security certifications. The Processor will not represent that it holds such certifications unless and until they are obtained.

7. Sub-processors

The Controller provides a general written authorization for the Processor to engage Sub-processors to process Customer Personal Data, subject to this Section 7. The Sub-processors engaged by the Processor as of the effective date are listed in Annex C.

Before engaging a new Sub-processor or replacing an existing one, the Processor will give the Controller at least thirty (30) days' advance notice, by updating the list at komplexai.io/dpa and, where the Controller has provided a notice address, by email. The Controller may object to the change on reasonable data-protection grounds during the notice period. If the Parties cannot resolve the objection in good faith, the Controller may terminate the affected Services for cause and receive a pro-rata refund of any pre-paid fees for the unused portion of the term.

The Processor will impose on each Sub-processor data-protection obligations no less protective than those in this DPA and will remain liable to the Controller for the acts and omissions of its Sub-processors as for its own.

8. Data-subject requests

Taking into account the nature of the processing, the Processor will assist the Controller, by appropriate technical and organizational measures and insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for the exercise of Data Subject rights under Applicable Data Protection Law.

If the Processor receives a request from a Data Subject relating to Customer Personal Data, it will, without undue delay, forward the request to the Controller and will not respond to the request itself unless authorized by the Controller or required by law.

Practical note. Because the Processor does not retain Submitted Text, most rights requests (access, correction, deletion) related to the content of Submitted Text are automatically satisfied: there is nothing for the Processor to access, correct, or delete beyond the limited usage-metadata set described in Annex B.

9. Personal-data breaches

The Processor will notify the Controller without undue delay, and in any event within seventy-two (72) hours after becoming aware, of a Personal Data Breach affecting Customer Personal Data. The notification will, to the extent available at the time, include:

  • the nature of the breach and the categories of Personal Data affected;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and mitigate its possible adverse effects; and
  • a contact point at the Processor for further information.

Because the Processor does not retain Submitted Text, the realistic breach surface is limited to (i) account-administration data, (ii) usage metadata, and (iii) transient in-flight inference traffic. The Processor will provide reasonable assistance to the Controller in meeting the Controller's notification obligations under Applicable Data Protection Law.

10. Audit and information rights

The Processor will make available to the Controller, on reasonable written request, information necessary to demonstrate compliance with the obligations under Article 28 of the GDPR and the equivalent provisions of other Applicable Data Protection Law. This will ordinarily take the form of written responses to a standard security questionnaire and copies of any then-current third-party attestations or summaries.

Where reasonably necessary to confirm compliance and where written responses are insufficient, the Controller may conduct, or mandate a qualified independent auditor to conduct, an audit of the Processor's processing activities, at the Controller's expense, subject to: (a) at least thirty (30) days' advance written notice; (b) a maximum frequency of once per twelve (12) months, except where required to investigate a confirmed Personal Data Breach or by a competent supervisory authority; (c) execution of a reasonable non-disclosure agreement; and (d) conduct that does not disrupt the Processor's operations or compromise other customers' data.

11. International data transfers

The Processor processes Customer Personal Data in the United States. To the extent the Processor receives Customer Personal Data from the European Economic Area, Switzerland, or the United Kingdom, the Parties incorporate the following transfer mechanisms by reference:

  • EU SCCs (Module 2 — Controller to Processor). The Parties enter into the EU SCCs as set out at komplexai.io/sccs. The Controller is the data exporter and the Processor is the data importer. The clause-option selections, docking clause, governing law, and supervisory authority are set out in that document. Annexes I, II, and III of the EU SCCs are populated by Annexes A, D, and C of this DPA respectively.
  • UK Addendum. Transfers of Personal Data subject to the UK GDPR are governed by the UK Addendum, version B1.0, set out at komplexai.io/uk-addendum.
  • Swiss FADP. Where Personal Data is subject to the Swiss FADP, the EU SCCs apply, with references to GDPR concepts read as references to the equivalent FADP concepts and the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.

If a court or supervisory authority of competent jurisdiction determines that the transfer mechanism above does not, or no longer, provides an appropriate level of protection, the Parties will negotiate in good faith to adopt a successor mechanism.

12. Return and deletion of personal data

On termination or expiry of the Agreement, and at the Controller's choice, the Processor will delete or return all Customer Personal Data that it then holds, and will delete existing copies, unless retention is required by law. Given the zero-retention model:

  • Submitted Text: nothing to delete — none is retained.
  • Usage metadata: deleted within thirty (30) days of termination, except where retention is required for tax, accounting, or other legal compliance.
  • Account data: deleted within ninety (90) days of account closure, in line with Section 9 of the Privacy Policy.

On written request, the Processor will provide written confirmation that deletion has occurred.

13. Liability

Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under Applicable Data Protection Law, including liability under Article 82 of the GDPR.

14. Term and termination

This DPA takes effect on the date the Controller accepts the Agreement (or, if later, the date both Parties sign Annex A) and continues for as long as the Processor processes Customer Personal Data on behalf of the Controller. Sections that by their nature should survive termination, including Sections 5, 6, 9, 10, 12, 13, and 15, survive.

15. Governing law and miscellaneous

This DPA is governed by the laws of the State of California, United States, without regard to its conflict-of-laws provisions, except that the EU SCCs and the UK Addendum are governed by the laws specified in those documents. Disputes arising out of or relating to this DPA are subject to the dispute-resolution provisions of the Agreement, except that the dispute-resolution provisions of the EU SCCs and the UK Addendum apply to disputes arising under those instruments.

If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in full force and effect. No waiver of any provision of this DPA will be effective unless in writing. This DPA, together with the Agreement, the EU SCCs, and the UK Addendum, constitutes the entire agreement of the Parties with respect to its subject matter and supersedes any prior understandings on that subject.

Annex A — Parties

Data Importer (Processor)

NameKomplexity AI LLC (d/b/a Komplex AI)
Address7514 Girard Ave, Ste 1 #935, San Diego, California 92037, USA
Contact personGalen Wilkerson, Managing Member — legal@komplexai.io
Activities relevant to the data transferredOperation of the Komplex AI hallucination detection API and web interface; transient processing of Submitted Text; retention of limited usage metadata for billing and quota management.
RoleProcessor (and, with respect to the EU SCCs, data importer)
SignatureSee signature block below

Data Exporter (Controller)

Name[Customer to complete — legal entity name]
Address[Customer to complete]
Contact person[Customer to complete — name, role, email]
Activities relevant to the data transferredSubmission of text to the Services for hallucination analysis; receipt of results.
RoleController (and, with respect to the EU SCCs, data exporter)
Signature[Customer to complete]

Annex B — Description of processing

Subject matterProvision of an AI-based hallucination detection service that scores the likelihood that a piece of text was hallucinated by a large language model.
DurationThe term of the Agreement. Submitted Text is processed transiently per request; usage metadata is retained for twenty-four (24) months per the Privacy Policy.
Nature and purpose of processingReceiving Submitted Text by API or web interface; running it through the Processor's hallucination-detection inference pipeline; returning a score and a regime classification to the Controller; recording usage metadata for billing and quota enforcement.
Categories of Data SubjectsEnd users of the Controller's own products whose prompts or generated responses the Controller chooses to submit; in some cases, third parties referenced inside the text submitted. The Controller determines whose data is submitted.
Categories of Personal Data — Submitted TextWhatever the Controller chooses to submit. The Processor does not require Personal Data in Submitted Text and discourages it. The Processor expressly prohibits submission of HIPAA-protected health information.
Categories of Personal Data — Retained (usage metadata)Account name and email; hashed API-key identifier; request timestamp; token counts; response latency; IP address (transient, for rate-limiting and abuse prevention).
Sensitive dataThe Processor does not knowingly process special-category data under Article 9 GDPR. The Controller must not submit such data without an appropriate legal basis and additional safeguards.
Frequency of transferContinuous (each API request initiates a transfer).
Retention period — Submitted TextZero. Discarded immediately after the result is returned.
Retention period — Usage metadata24 months from the date of each request, then deleted or anonymized.
Retention period — Account informationUntil account deletion plus 90 days, for legal-compliance buffer.
Transfers to Sub-processorsSee Annex C. Transient Submitted Text passes through the inference Sub-processor only; metadata passes through billing, hosting, and email Sub-processors as relevant.

Annex C — Sub-processors

As of the effective date of this DPA, the Processor engages the following Sub-processors. The Processor will update this list and notify Customers in accordance with Section 7 before adding or replacing a Sub-processor.

Sub-processorProcessing activityLocation of processingTransfer mechanism
Modal Labs, Inc. (modal.com)Serverless GPU compute that runs the hallucination-detection inference. Receives Submitted Text only transiently for the duration of an inference call; does not retain it.United StatesEU SCCs Module 3 (Processor to Sub-processor) between Komplexity and Modal; Modal's published DPA
Stripe, Inc. (stripe.com)Payment processing, invoicing, subscription management, and tax compliance for paid plans. Stripe holds billing and payment data as a Controller in its own right.United States, with global infrastructureStripe's published DPA and SCCs
Vercel, Inc. (vercel.com)Hosting of the komplexai.io website and the public-facing API gateway. May briefly touch request metadata in transit; does not store Submitted Text.United States, with global edge infrastructureVercel's published DPA and SCCs
Neon, Inc. (neon.tech)Managed Postgres database storing account identifiers, subscription/billing state, and usage metadata (timestamps, token counts, API-key identifiers). Does not receive or store Submitted Text.United StatesNeon's published DPA and SCCs

Other operational vendors named in the Privacy Policy (Clerk for authentication, Resend for transactional email, OpenAI's Moderation API for screening correspondence, and Cloudflare for contact-form bot-protection and inbound-mail routing) process limited account, correspondence, or telemetry data; they do not receive Submitted Text. They are disclosed in the Privacy Policy as third-party service providers and are not treated as Sub-processors for the purposes of this DPA.

Annex D — Technical and organizational measures

The Processor implements the following measures, recognizing that the zero-retention model is itself the most consequential security control:

  • Data minimization by design. Submitted Text is never written to persistent storage and is held in process memory only for the duration of an inference call. There is no offline copy to encrypt, back up, or rotate keys for, and there is no historical archive to breach.
  • Transport encryption. All traffic between the Controller and the Services, and between the Services and Sub-processors, uses TLS 1.2 or higher.
  • Access controls. Production access is limited to authorized personnel and is gated by multi-factor authentication. API access is gated by per-customer API keys.
  • Authentication. User authentication is performed by Clerk; user passwords are stored as salted hashes by Clerk and are never accessible to the Processor in plaintext.
  • Payment-card data. The Processor does not handle or store payment-card data; Stripe is the PCI-DSS-compliant processor for all payment flows.
  • Logging. Application logs record usage metadata (timestamp, API key identifier, token counts, latency, status codes) but do not record Submitted Text or model outputs.
  • Personnel. Personnel with production access are bound by confidentiality obligations.
  • Vendor due diligence. Each Sub-processor in Annex C has a published DPA and either a SOC 2 attestation or an equivalent third-party security review. The Processor does not itself hold a SOC 2 or ISO 27001 certification at this time.
  • Incident response. The Processor maintains an internal incident- response procedure and will notify the Controller in accordance with Section 9.
  • Business-continuity. Inference compute is provided by Modal under its own redundancy commitments; the web layer is provided by Vercel under its own redundancy commitments. The Processor does not run its own data center.

The Processor will update this list as its security program matures. Any update will preserve at least the level of protection in place on the effective date of this DPA.

Signature

By accepting the Agreement and continuing to use the Services, the Customer is deemed to have entered into this DPA. Where the Customer requires a countersigned copy, the following signature block applies:

Processor

Komplexity AI LLC (d/b/a Komplex AI)
7514 Girard Ave, Ste 1 #935
San Diego, California 92037, USA

By: Galen Wilkerson, on behalf of Komplexity AI LLC

Title: Managing Member

Date: May 25, 2026

Signature: /s/ Galen Wilkerson

Controller

[Customer to complete]

Entity: ____________________

By: ____________________

Title: ____________________

Date: ____________________

Signature: ____________________