Redpill.ai Data Processing Agreement (DPA)
Effective Date: 1st January, 2026
Parties:
- Controller: The customer agreeing to the Redpill.ai Terms of Service
- Processor: Hashforest Technology LLC, located in California, United States
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written or electronic agreement between the Controller and Processor (the “Agreement”) and reflects the parties’ agreement with respect to the Processing of Personal Data in accordance with applicable Data Protection Laws.
1. Definitions
For the purpose of this DPA, the terms below shall have the meanings set forth in the GDPR:
- "Data Protection Laws" means all applicable data protection and privacy legislation, including the GDPR.
- "GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation).
- "Personal Data", "Data Subject", "Processing", "Controller", "Processor", "Supervisory Authority" shall have the meanings set out in the GDPR.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Standard Contractual Clauses (SCCs)" means the clauses adopted by the European Commission under Decision (EU) 2021/914.
- “Services” means the Redpill.ai services, including confidential AI inference, model routing, and API-based access to third‑party large language models.
2. Scope and Roles
This DPA applies where Processor Processes Personal Data on behalf of Controller in the course of providing the Services.
- The Controller act as the Data Controller
- The processor acts as a Data Processor, Processing Personal Data solely on behalf of and in accordance with the instructions of the Controller.
The Controller retains full control over the determination of the purposes and means of the Processing of Personal Data.
3. Controller Instructions
The Processor shall Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law.
If the Processor reasonably believes that an instruction infringes Data Protection Laws, it shall promptly inform the Controller.
4. Compliance with Laws
Each party shall comply with its respective obligations under Data Protection Laws.
The Controller represents and warrants that it has obtained all necessary rights, consents, and lawful bases required to disclose Personal Data to the Processor and to authorize the Processing contemplated under this DPA.
5. Processor Obligations
Processor shall:
- Ensure that persons authorized to process Personal Data are under an appropriate confidentiality obligation.
- Implement technical and organizational measures to ensure a level of security appropriate to the risk.
- Process Personal Data solely for the purpose of providing the Services and in accordance with the Controller’s instructions.
- Not access, use, or process Personal Data for advertising, profiling, model training, analytics, benchmarking, or product improvement purposes, unless expressly authorized in writing by the Controller.
- Assist the Controller in fulfilling its obligations with respect to Data Subject rights, data protection impact assessments (DPIAs), and prior consultations with Supervisory Authorities, to the extent required by Data Protection Laws and technically feasible.
6. Data Access and Confidentiality
Data Confidentiality by Design
The Redpill.ai platform is architected to minimize data exposure and enforce strong isolation controls.
- Customer prompts, inputs, and outputs are processed within isolated execution environments.
- Where applicable, confidential computing technologies (including Trusted Execution Environments and GPU Confidential Computing) are used to protect data in use.
- Processor personnel do not access customer content except where explicitly authorized by the Controller or required for security incident investigation or legal compliance.
7. Sub-processors
Controller authorizes Processor to engage Sub-processors to provide the Services. The current list includes:
- Google Cloud Platform
- Github
- PostHog
- Stripe
- Attio
- HubSpot
- Fingerprint
- Customer.io
- HubSpot
The Processor shall:
- Enter into written agreements with each Sub-processor imposing data protection obligations substantially equivalent to those set out in this DPA;
- Remain fully liable for the acts and omissions of its Sub-processors;
- Notify the Controller of any intended addition or replacement of Sub-processors and provide the Controller with a reasonable opportunity to object on data protection grounds.
8. International Data Transfers
Processor may process Personal Data outside the EEA, including in the United States. Where such transfers occur, Processor shall ensure appropriate safeguards, including execution of Standard Contractual Clauses adopted by the European Commission.
Standard Contractual Clauses adopted by the European Commission pursuant to Commission Decision (EU) 2021/914, including Annex I (Parties and Processing Details), Annex II (Technical and Organizational Measures), and Annex III (Sub-Processors), are incorporated by reference.
Full text available at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
A signed version with SCCs can be provided upon request.
9. Data Subject Rights
The Processor shall, taking into account the nature of the Processing, assist the Controller by appropriate technical and organizational measures in responding to requests from Data Subjects exercising their rights under Data Protection Laws. The Processor shall not respond directly to Data Subjects unless authorized in writing by the Controller. Requests are currently supported through a ticket‑based support process.
10. Data Logging and Retention
Operational Logging and Minimization
- Operational logs are limited to what is strictly necessary for security, reliability, and abuse prevention;
- Logs do not contain customer prompts, outputs, or model content;
- Logs are retained for no longer than 24 hours, unless extended retention is required for active security investigations or legal obligations;
- Logs are protected by access controls and are not used for analytics or profiling.
11. Data Portability and Export
Where technically feasible, Processor shall assist Controller in exporting Personal Data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV), consistent with the capabilities of the Services.
12. Security Measures
Processor implements appropriate technical and organizational measures, as described in Annex II, to ensure a level of security appropriate to the risk. These measures include data encryption, access control, and use of hardware-based confidential computing environments.
13. Data Breach Notification
In the event of a Personal Data Breach affecting Controller’s Personal Data, Processor shall notify Controller without undue delay, and in any event within 72 hours of becoming aware. Such notice shall include:
- Nature of the breach;
- Likely consequences;
- Measures taken or proposed to address the breach;
- A contact point for further information.
14. Return and Deletion of Data
Upon termination of the Services, Processor shall delete all Personal Data, unless retention is required by applicable law. Upon request, Processor will provide Controller with a 30-day transition period to export any Personal Data before deletion.
15. Audit Rights
Controller may audit Processor’s compliance with this DPA:
- No more than once per 12-month period;
- With at least 30 days’ prior written notice;
- During normal business hours;
- In a manner that minimizes disruption to Processor's operations.
If available, Processor may satisfy audit obligations by providing relevant third-party audit reports as part of its certification program.
16. Limitation of Liability
Each party’s liability under this DPA shall be subject to the limitations of liability in the Agreement. Processor shall not be liable for indirect, incidental, or consequential damages, and shall only be liable for direct damages arising from breach of this DPA.
17. Governing Law
This DPA shall be governed by the laws of the State of California, United States, unless otherwise required by Data Protection Laws.
Annex I – Processing Details
- Nature and Purpose: Provision of AI inference, confidential model execution, API routing, billing, and platform security for Redpill.ai Services.
- Categories of Data Subjects: As determined by the Controller.
- Categories of Personal Data: As submitted by the Controller through the Services.
- Duration: For the term of the Agreement and up to 30 days post-termination.
- Data Locations: Personal Data is processed in data centers located in the United States, India, France, and other jurisdictions within the European Economic Area (EEA), depending on infrastructure availability and operational requirements. Processor maintains an internal inventory of processing locations and ensures that any cross-border data transfers comply with applicable Data Protection Laws.
Annex II – Technical and Organizational Measures
- End-to-end encryption (TLS 1.3, AES-256 at rest)
- Hardware-isolated execution environments(TDX TEE GPU Confidential Computing)
- Strict access control and least‑privilege enforcement
- Continuous monitoring, alerting, and intrusion detection
- 24‑hour maximum log retention with anonymization
- Regular vulnerability assessments and penetration testing
- Documented incident response and breach notification procedures
Annex III – Sub-Processors
| Name | Purpose | Jurisdiction |
|---|---|---|
| Google Cloud | Infrastructure hosting | US, EU |
| HubSpot | CRM & Marketing | US |
| PostHog | Product analytics | US/EU |
| Stripe | Payment processing | US |
| Attio | CRM | UK |
| customer.io | Marketing & Email services | US |
| Fingerprint | Security analytics | US |
| Github | Code repository and software development platform | US |
Contact
For data protection inquiries, please contact: [email protected]