Skip to main content

Data Processing Agreement

Document control
FieldValue
Version1.0 (draft)
Effective dateTo be set
Last revised22 September 2026
Approved byPending
Contracting entitySubstrate Artificial Inteligence, S.A.

The full version history is available in the Legal document changelog.

Draft

This is a working draft adapted from the Serenity Star Data Processing Agreement. It has not been reviewed by Legal and is not yet in force.

This Data Processing Agreement will form part of the Agreement between Substrate Artificial Inteligence, S.A. and each Commercial Customer of Serenity Edge, in accordance with Article 28 of the GDPR. What follows is the outline of the final document, following the structure of the Serenity Star Data Processing Agreement.

Preamble

1. Definitions

2. Role of the Parties

2.1 Substrate AI as Data Processor for Inputs and Outputs · 2.2 Substrate AI as Data Controller for account, contract and request metadata. Substrate AI does not use Inputs or Outputs to train or fine-tune any Model.

3. General obligations of the Parties

3.1 General obligations of Substrate AI · 3.2 General obligations of the Customer.

4. Data subject rights

4.1 Information · 4.2 Data subject requests · 4.3 Direct requests.

5. Security and personal data breach

5.1 Security measures · 5.2 Personal data breach (definition aligned with Article 4(12) GDPR; notification without undue delay).

6. Sub-processing

6.1 Categories of Sub-processor · 6.2 General authorisation for Platform Sub-processors with 30 days of prior notice · 6.3 Objection right · 6.4 Access routes chosen by the Customer (OpenRouter, Serenity Star account) · 6.5 Notification of changes through the Sub-processors page.

7. International data transfers

7.1 Platform Sub-processors (all within the European Union) · 7.2 Location of Processing: inference on Substrate AI's own GPUs in Valencia, Spain; request handling in Microsoft Azure Spain Central; authentication and billing for Serenity Star account traffic in Azure France Central · 7.3 Standard Contractual Clauses, should a transfer ever become necessary.

8. Audits

8.1 Audit rights · 8.2 Audit process.

9. Return or deletion of personal data

9.1 End of Services · 9.2 Retention period: prompts and completions are not retained; request metadata is deleted after 90 days.

10. Term and termination

11. Limitation of liability

12. Compliance with laws and regulations

13. Changes to this DPA

14. Dispute resolution

Spanish law; courts of Madrid.

Exhibit 1. Description of the Processing

Subject matter, duration, nature and purpose, categories of data subjects, categories of personal data (whatever the Customer includes in Inputs), and the processing elements common to every access route.

Exhibit 2. Technical and organisational measures

General security architecture; measures specific to the inference platform (zero retention, isolation of prompt cache per API key, encryption in transit, access control to the GPU facility in Valencia).