This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Sigil Labs, Inc. ("Sigil", "Processor") and the Customer ("Controller"). It applies when Sigil processes Personal Data on the Customer's behalf in providing the Service. Terms not defined here have the meaning given in the Agreement or in applicable Data Protection Laws.
1. Definitions
Data Protection Laws means the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, the CCPA/CPRA and any other data protection law that applies to the processing.
Personal Data means personal data contained in Customer Data that Sigil processes on the Customer's behalf.
Subprocessor means a third party engaged by Sigil to process Personal Data.
Security Incident means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
2. Roles and instructions
The Customer is the controller and Sigil is the processor of Personal Data. Sigil will process Personal Data only on the Customer's documented instructions, which are the Agreement, this DPA and the Customer's configuration of the Service, unless the law requires otherwise. Sigil will tell the Customer if it believes an instruction violates Data Protection Laws.
3. Details of processing
Subject matter and duration: providing the Service for the term of the Agreement.
Nature and purpose: routing, logging, tracing, budgeting and auditing requests made by the Customer's AI agents.
Data subjects: the Customer's users, and any individuals whose data the Customer's agents process.
Categories of data: identifiers and contact details, account and usage data, and any Personal Data contained in prompts, outputs and traces.
Special categories: none are intended. The Customer will not send special-category data unless agreed in writing.
4. Confidentiality
Sigil ensures that everyone authorized to process Personal Data is bound by confidentiality obligations and only accesses it as needed to provide the Service.
5. Security
Sigil maintains appropriate technical and organizational measures, including encryption in transit and at rest, least-privilege access, SSO and MFA for staff, immutable audit logs, network isolation, backups, vulnerability management and annual third-party penetration tests. Sigil may update these measures as long as protection is not materially reduced.
6. Subprocessors
The Customer authorizes Sigil to engage Subprocessors. Sigil keeps a current list available on request at privacy@sigil.dev and will give at least 30 days' notice before adding or replacing one. The Customer may object on reasonable data protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a refund of prepaid fees for it. Sigil imposes data protection terms on each Subprocessor that are at least as protective as this DPA and remains responsible for their performance. Model providers the Customer chooses to route requests to are engaged by the Customer, not by Sigil, and are not Subprocessors.
7. Data subject requests
Taking into account the nature of the processing, Sigil will assist the Customer, through the Service's features or otherwise, in responding to requests from data subjects to exercise their rights. Sigil will forward any request it receives directly to the Customer.
8. Security Incidents
Sigil will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a Security Incident. It will provide the information the Customer reasonably needs to meet its own notification obligations, and will take reasonable steps to contain and remediate the incident.
9. Assistance
Sigil will provide reasonable assistance with data protection impact assessments and consultations with supervisory authorities, to the extent they relate to the Service.
10. International transfers
Where Personal Data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree to the European Commission's Standard Contractual Clauses (Module Two, controller to processor), the UK International Data Transfer Addendum and the Swiss amendments, which are incorporated into this DPA by reference.
11. Audits
Sigil will make available the information reasonably necessary to demonstrate compliance with this DPA, including its latest third-party security reports. The Customer may conduct an audit no more than once a year, on 30 days' notice, during business hours and at its own cost, if those reports are not sufficient or if a supervisory authority requires it.
12. Deletion and return
On termination of the Agreement, the Customer may export Customer Data for 30 days. Sigil will then delete Personal Data, including from backups within 90 days, unless the law requires it to be kept. For self-hosted deployments, Personal Data stays in the Customer's infrastructure and is not accessible to Sigil.
13. CCPA
To the extent the CCPA applies, Sigil acts as a service provider. It will not sell or share Personal Data, retain, use or disclose it outside the direct business relationship, or combine it with other data except as the CCPA permits.
14. General
This DPA remains in effect for as long as Sigil processes Personal Data for the Customer. If it conflicts with the Agreement, this DPA controls with respect to Personal Data. Liability under this DPA is subject to the limitations in the Agreement.
Contact
Sigil Labs, Inc. · privacy@sigil.dev