Effective September 18, 2026

Data Processing Agreement

This agreement (the “DPA”) is between GPULogy AI LLC, a Texas limited liability company (“GPULogy”, “we”), and the customer that has accepted our Terms of Service (the “Customer”). It forms part of the Terms and applies whenever we process personal data on the Customer’s behalf in providing LetThemBuild and LetThemChat (the “Service”). No signature is needed for it to apply. A Customer who needs a countersigned copy can ask at [email protected].

1. Roles

For personal data the Customer and its users put into the Service (discussions, attachments, tickets, team member details), the Customer is the controller and GPULogy is the processor. For account, billing and security records we keep to run our business, GPULogy is a controller, as described in our Privacy Policy, and this DPA does not apply to them. Paddle.com is the merchant of record and a controller of the payment details it collects.

2. Instructions

We process Customer personal data only to provide, secure and support the Service, on the Customer’s documented instructions. The Terms, this DPA and the Customer’s use and configuration of the Service, including its team policies, are those instructions. We will tell the Customer if we believe an instruction breaks data protection law. We do not sell Customer personal data, and no model is trained on it by us.

3. Confidentiality

Only people who need access to operate the Service have it, and they are bound by confidentiality. Operator access to customer accounts is limited to named administrators, and each administrative action is recorded in an audit log.

4. Security

We maintain the technical and organisational measures in Annex II and may improve them. We will not reduce the overall level of protection they give.

5. Subprocessors

The Customer authorises the subprocessors in Annex III. Each is bound by written terms that protect personal data at least as well as this DPA. We will post any new subprocessor on this page, and email the owners of paying teams, at least 30 days before it starts processing Customer personal data. A Customer may object in that time on reasonable data protection grounds. If we cannot address the objection, the Customer may end the affected part of the Service and receive a pro-rated refund of prepaid fees for it. We remain responsible for our subprocessors.

The model providers process data only for discussions run on our keys. When the Customer connects its own key, subscription or command-line tool to a seat, calls to that provider are made under the Customer’s own agreement with it, and that provider is not our subprocessor.

6. International transfers

We and our subprocessors process data in the United States. Where the Customer is subject to the GDPR and the transfer is not covered by an adequacy decision, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply and are incorporated by reference: Module Two where the Customer is a controller, Module Three where it is a processor. For those clauses: clause 7 (docking) applies; clause 9 option 2 (general authorisation) applies with the notice period in section 5; the optional wording in clause 11 does not apply; clauses 17 and 18 are governed by and resolved in the courts of Ireland; Annexes I to III of this DPA complete their Annexes. For transfers from the United Kingdom, the UK International Data Transfer Addendum to those clauses applies; from Switzerland, the clauses apply with references read as references to Swiss law and the Swiss supervisory authority. Teams that need model calls kept in the EU can set that as a team policy, which sends managed calls to an EU route or refuses them.

7. Helping the Customer

Taking into account the nature of the processing, we help the Customer answer requests from individuals exercising their rights, and with security, breach notification, data protection impact assessments and prior consultation. Most requests can be met in the Service itself: discussions, tickets, team members and whole accounts can be exported or deleted by the Customer. If an individual contacts us directly about Customer data, we will pass the request to the Customer.

8. Personal data breaches

We will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer personal data. The notice will say what we know then, including the nature of the breach, the data and people affected, the likely consequences and the measures taken, and we will add to it as we learn more. Security issues can be reported to us at [email protected].

9. Deletion and return

The Customer can export and delete its data at any time while it uses the Service. When the Customer deletes data or its account, we delete it from our live systems immediately and from backups within 30 days, unless the law requires us to keep it. Team retention settings delete discussions on the schedule the team chooses.

10. Audits

We make available the information needed to show compliance with this DPA: our trust page, which lists every control and where it is enforced, the audit event catalogue, and written answers to reasonable security questionnaires. Where that is not enough, or a supervisory authority requires it, the Customer may carry out an audit once a year, with 30 days’ notice, during business hours, at its own cost, under confidentiality, and without access to other customers’ data.

11. Liability, term and precedence

Each party’s liability under this DPA is subject to the limits in the Terms, except where the law does not allow it to be limited. This DPA lasts as long as we process Customer personal data. If this DPA and the Terms conflict on personal data, this DPA wins; if the Standard Contractual Clauses conflict with anything else, the clauses win.

Annex I: Details of processing

Data exporterThe Customer, as identified in its account. Contact: the account or team owner.
Data importerGPULogy AI LLC, Texas, United States. Contact: [email protected].
Data subjectsThe Customer’s users and team members, and any person whose data the Customer puts into a discussion, attachment or ticket.
Categories of dataNames, email addresses and roles; the content of discussions, attachments, tickets and comments; usage and billing records of the account. The Service is not designed for special categories of data and the Customer should not put them in.
Nature and purposeStoring, syncing and displaying the Customer’s data; sending prompts to AI models and returning their answers; running the Customer’s team policies; support; security.
FrequencyContinuous, while the Customer uses the Service.
RetentionUntil the Customer deletes the data or its account, or a team retention setting removes it; then as in section 9.

Annex II: Technical and organisational measures

Annex III: Subprocessors

Updated 2026-09-18.

SubprocessorPurposeDataLocation
Fly.io, Inc.Application hostingAll customer data in transit through the serviceUnited States (Virginia)
Neon (Databricks, Inc.)DatabaseAccount, team, discussion, ticket and usage recordsUnited States (AWS us-east-1)
Anthropic, PBCAI model inference on Our KeysPrompts, attachments and responses of a discussionUnited States
OpenAI, L.L.C.AI model inference on Our KeysPrompts, attachments and responses of a discussionUnited States
Google LLCAI model inference on Our KeysPrompts, attachments and responses of a discussionUnited States and Google Cloud regions
X.AI LLCAI model inference on Our KeysPrompts, attachments and responses of a discussionUnited States
OpenRouter, Inc.Routing model calls on Our Keys to the providers abovePrompts, attachments and responses of a discussionUnited States; the EU for teams that keep model calls in the EU
Microsoft CorporationSupport mailbox and outbound emailSupport requests, email addresses and repliesUnited States
PostHog, Inc.Product analytics, only with consent and unless a team switches it offEmail address, plan, named events, masked session recordingsUnited States
Slack Technologies, LLCInternal alerts to our teamEmail address and text of a feedback or support reportUnited States