Data processing addendum
This page is the processing addendum for customers who need one on file. It states who processes what when you use the API or the console, and it binds us to the same facts the privacy page states in plain language. If your compliance process needs a countersigned copy, mail support@tiyuvta.ai and we will execute this text as a PDF.
Roles
For the content of your requests — prompts, file inputs, completions — you are the controller and tiyuvta (sole proprietorship, Israel) is the processor. We process that content only to answer the request. Paddle.com Market Ltd is the merchant of record for payments and acts as an independent controller for the payment data it collects; we never see your card.
What is processed, and for how long
- Prompts and completions — paid traffic
- Processed in memory to serve the request; not written to durable storage by the serving stack; never used for training, fine-tuning, distillation or evaluation. Retention: zero.
- Prompts and completions — trial credit, or paid with the training switch on
- May be retained and used to improve our models, exactly as the privacy page describes. The posture is recorded per request, so which rule applied to which call is auditable.
- Billing metadata
- Token counts, model, timestamps, key prefix, computed cost — no request content. Kept up to 12 months.
- Operational logs
- Status codes, latency, error classes, calling IP — no request content. Kept up to 30 days.
- Account data
- Email, key prefixes, credit ledger. Kept while the account exists.
Subprocessors
The complete list. Nothing else touches your data.
- Cloudflare, Inc. (US, global edge) — site and API delivery, DDoS and TLS termination, the console application and its database, outbound email. Edge and storage pinned to the EU where the platform allows it.
- Paddle.com Market Ltd (UK/EU) — payments, tax, invoicing, saved payment methods, as merchant of record.
- GPU compute provider — the datacenter the model runs in. Inference is processed in the EU; the current serving datacenter is in Germany. Request content exists there only in memory for the life of the request (paid traffic), per the retention rules above.
Security measures
- TLS on every public surface; no plaintext listener exists.
- API access by bearer key only; keys are revocable per key and scoped to inference and model discovery — a customer key cannot reach admin, billing or key management.
- Administrative surfaces are on a separate origin behind service-token access control, never on the API host.
- Per-tenant cache isolation: one account's cached prefixes are never served to another account, in either direction.
- Billing records are content-free by construction — the metering pipeline carries token counts, never text.
Data subject requests and deletion
Mail support@tiyuvta.ai. Access, correction and deletion work as the privacy page states; deletion removes the account, keys and email while the content-free billing records complete their statutory retention.
International transfers
Inference runs in the EU. Cloudflare operates a global edge; its EU data-localisation controls are applied where available. Payments run under Paddle.com Market Ltd’s own compliance regime as merchant of record.
Changes to this list
Adding or replacing a subprocessor is announced by email before it takes effect, like every change that widens what happens to your data. The date at the top moves with every change.