gradiated

Data Processing Addendum

DPA

Effective date: August 26, 2026

This Data Processing Addendum (“DPA”) applies when a customer uses Gradiated to process personal data and the customer is the controller or processor. In that case, Gradiated Ltd acts as the processor or subprocessor. For account, billing, and business contact information, Gradiated acts as a controller under our Privacy Policy.

Instructions and scope

We process personal data only to provide, secure, support, and improve the service using non-content information. The customer’s instructions are the customer’s use of the service, this DPA, and any written instructions that we accept. The processing details are the customer’s prompts, messages, tool payloads, attachments, outputs, and related request metadata. The duration is the term of the customer’s use of the service.

Confidentiality and security

We require people who can access customer data to keep it confidential. We use technical and organizational measures appropriate to the risk, including access controls, encrypted connections, protected secrets, service isolation, monitoring, and incident response processes.

Gradiated-controlled systems do not persist inference content after request processing. Gradiated does not use it to train, fine-tune, evaluate, rank, advertise, or improve models. Limited non-content usage records may remain for billing, security, reliability, and legal purposes.

Subprocessors

You give Gradiated general authorization to use the subprocessors listed on ourSubprocessors and security page. We will update that page when we add or replace a material subprocessor. We will require each subprocessor to protect personal data under written terms that provide protection appropriate to its role.

International transfers

We may transfer personal data outside the UK. Where required, we use an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard.

Requests and incidents

We will provide reasonable help with requests from data subjects, data protection impact assessments, regulator inquiries, and security obligations. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and provide the information that we reasonably can.

Deletion and audits

When the service ends, we will delete or return personal data where the service and law allow. We may keep information that the law requires us to keep, subject to confidentiality and security controls. We will make available information reasonably needed to show compliance and will support reasonable audits, subject to security, confidentiality, and cost controls.

Contact

Contact team@gradiated.com with DPA questions or to request a signed copy for your organization. This DPA supplements the Terms of Service. If the documents conflict, this DPA controls for the processing of personal data.