Effective September 18, 2026
Data Processing Agreement
This agreement (the “DPA”) is between GPULogy AI LLC, a Texas limited liability company (“GPULogy”, “we”), and the customer that has accepted our Terms of Service (the “Customer”). It forms part of the Terms and applies whenever we process personal data on the Customer’s behalf in providing LetThemBuild and LetThemChat (the “Service”). No signature is needed for it to apply. A Customer who needs a countersigned copy can ask at [email protected].
1. Roles
For personal data the Customer and its users put into the Service (discussions, attachments, tickets, team member details), the Customer is the controller and GPULogy is the processor. For account, billing and security records we keep to run our business, GPULogy is a controller, as described in our Privacy Policy, and this DPA does not apply to them. Paddle.com is the merchant of record and a controller of the payment details it collects.
2. Instructions
We process Customer personal data only to provide, secure and support the Service, on the Customer’s documented instructions. The Terms, this DPA and the Customer’s use and configuration of the Service, including its team policies, are those instructions. We will tell the Customer if we believe an instruction breaks data protection law. We do not sell Customer personal data, and no model is trained on it by us.
3. Confidentiality
Only people who need access to operate the Service have it, and they are bound by confidentiality. Operator access to customer accounts is limited to named administrators, and each administrative action is recorded in an audit log.
4. Security
We maintain the technical and organisational measures in Annex II and may improve them. We will not reduce the overall level of protection they give.
5. Subprocessors
The Customer authorises the subprocessors in Annex III. Each is bound by written terms that protect personal data at least as well as this DPA. We will post any new subprocessor on this page, and email the owners of paying teams, at least 30 days before it starts processing Customer personal data. A Customer may object in that time on reasonable data protection grounds. If we cannot address the objection, the Customer may end the affected part of the Service and receive a pro-rated refund of prepaid fees for it. We remain responsible for our subprocessors.
The model providers process data only for discussions run on our keys. When the Customer connects its own key, subscription or command-line tool to a seat, calls to that provider are made under the Customer’s own agreement with it, and that provider is not our subprocessor.
6. International transfers
We and our subprocessors process data in the United States. Where the Customer is subject to the GDPR and the transfer is not covered by an adequacy decision, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply and are incorporated by reference: Module Two where the Customer is a controller, Module Three where it is a processor. For those clauses: clause 7 (docking) applies; clause 9 option 2 (general authorisation) applies with the notice period in section 5; the optional wording in clause 11 does not apply; clauses 17 and 18 are governed by and resolved in the courts of Ireland; Annexes I to III of this DPA complete their Annexes. For transfers from the United Kingdom, the UK International Data Transfer Addendum to those clauses applies; from Switzerland, the clauses apply with references read as references to Swiss law and the Swiss supervisory authority. Teams that need model calls kept in the EU can set that as a team policy, which sends managed calls to an EU route or refuses them.
7. Helping the Customer
Taking into account the nature of the processing, we help the Customer answer requests from individuals exercising their rights, and with security, breach notification, data protection impact assessments and prior consultation. Most requests can be met in the Service itself: discussions, tickets, team members and whole accounts can be exported or deleted by the Customer. If an individual contacts us directly about Customer data, we will pass the request to the Customer.
8. Personal data breaches
We will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer personal data. The notice will say what we know then, including the nature of the breach, the data and people affected, the likely consequences and the measures taken, and we will add to it as we learn more. Security issues can be reported to us at [email protected].
9. Deletion and return
The Customer can export and delete its data at any time while it uses the Service. When the Customer deletes data or its account, we delete it from our live systems immediately and from backups within 30 days, unless the law requires us to keep it. Team retention settings delete discussions on the schedule the team chooses.
10. Audits
We make available the information needed to show compliance with this DPA: our trust page, which lists every control and where it is enforced, the audit event catalogue, and written answers to reasonable security questionnaires. Where that is not enough, or a supervisory authority requires it, the Customer may carry out an audit once a year, with 30 days’ notice, during business hours, at its own cost, under confidentiality, and without access to other customers’ data.
11. Liability, term and precedence
Each party’s liability under this DPA is subject to the limits in the Terms, except where the law does not allow it to be limited. This DPA lasts as long as we process Customer personal data. If this DPA and the Terms conflict on personal data, this DPA wins; if the Standard Contractual Clauses conflict with anything else, the clauses win.
Annex I: Details of processing
| Data exporter | The Customer, as identified in its account. Contact: the account or team owner. |
| Data importer | GPULogy AI LLC, Texas, United States. Contact: [email protected]. |
| Data subjects | The Customer’s users and team members, and any person whose data the Customer puts into a discussion, attachment or ticket. |
| Categories of data | Names, email addresses and roles; the content of discussions, attachments, tickets and comments; usage and billing records of the account. The Service is not designed for special categories of data and the Customer should not put them in. |
| Nature and purpose | Storing, syncing and displaying the Customer’s data; sending prompts to AI models and returning their answers; running the Customer’s team policies; support; security. |
| Frequency | Continuous, while the Customer uses the Service. |
| Retention | Until the Customer deletes the data or its account, or a team retention setting removes it; then as in section 9. |
Annex II: Technical and organisational measures
- Encryption in transit with TLS on every connection to the Service and between the Service and its subprocessors.
- Encryption at rest by the database provider; AI provider keys and other stored credentials additionally encrypted by the application with a key held outside the database.
- Sign-in through Google, Microsoft or Apple; per-sign-in sessions a user can see and end, including on every device at once.
- Access to customer accounts limited to named operators; every operator action recorded in an audit log.
- Team controls that the servers enforce, including keep-nothing routing for model calls, personal-data masking before a prompt leaves, retention periods and EU-only model routing. Where each control is enforced is listed on the trust page.
- Credentials and secrets masked out of prompts, transcripts and tool output.
- Rate limits on every public endpoint; request logs with IP addresses kept for one hour.
- Database backups kept by the database provider for up to 30 days.
- A software bill of materials for every release, dependency checks before release, and a written process for reporting vulnerabilities.
- Subprocessors chosen for published security attestations, as listed on the trust page.
Annex III: Subprocessors
Updated 2026-09-18.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Fly.io, Inc. | Application hosting | All customer data in transit through the service | United States (Virginia) |
| Neon (Databricks, Inc.) | Database | Account, team, discussion, ticket and usage records | United States (AWS us-east-1) |
| Anthropic, PBC | AI model inference on Our Keys | Prompts, attachments and responses of a discussion | United States |
| OpenAI, L.L.C. | AI model inference on Our Keys | Prompts, attachments and responses of a discussion | United States |
| Google LLC | AI model inference on Our Keys | Prompts, attachments and responses of a discussion | United States and Google Cloud regions |
| X.AI LLC | AI model inference on Our Keys | Prompts, attachments and responses of a discussion | United States |
| OpenRouter, Inc. | Routing model calls on Our Keys to the providers above | Prompts, attachments and responses of a discussion | United States; the EU for teams that keep model calls in the EU |
| Microsoft Corporation | Support mailbox and outbound email | Support requests, email addresses and replies | United States |
| PostHog, Inc. | Product analytics, only with consent and unless a team switches it off | Email address, plan, named events, masked session recordings | United States |
| Slack Technologies, LLC | Internal alerts to our team | Email address and text of a feedback or support report | United States |