New B200 spot capacity is live in US East from $1.69 per GPU-hour. See availability
Legal

Data processing addendum

The terms that apply when you use the platform to process personal data for which you are the controller.

Version of 15 September 2026 · ask about a clause

1. When this applies#

This addendum applies when you use the service to process personal data for which you are the controller — for example a dataset containing personal data that you upload to a volume, or an application you run on an instance that handles the data of your own users. It forms part of the terms of service and takes precedence over them on this subject.

2. Roles#

2.1 For customer content — what you put inside your instances and volumes — you are the controller and we are the processor.

2.2 For account, billing, support and security data we are the controller, and the privacy policy governs it.

2.3 We never determine the purposes of processing customer content, and we do not use it for our own purposes — including training models.

3. Subject matter, duration, nature and purpose#

ItemDetail
Subject matterProvision of GPU compute, block storage and network for customer content
DurationFor as long as your account exists, or until you delete the data
Nature and purposeHosting, storage and execution of the workloads you configure
Types of personal dataWhatever you choose to place on the platform; we do not inspect it
Categories of data subjectsDetermined by you

4. Our obligations#

  • Process customer content only to provide the service and on your documented instructions, which include the configuration you set in the console and the API.
  • Tell you if an instruction appears to breach applicable data protection law, and not carry it out.
  • Bind everyone with access to confidentiality.
  • Apply the technical and organisational measures in clause 5.
  • Help you, so far as we reasonably can, with data subject requests, impact assessments and consultations with authorities.

5. Security measures#

  • Tenant isolation. One tenant per KVM virtual machine, with the GPU passed through; no shared kernel between customers.
  • Encryption. Persistent volumes encrypted at rest; TLS for the site, the console and the API.
  • Access control. Argon2id password hashing, optional TOTP two-factor, per-device sessions that can be revoked, API keys shown once and revocable, throttled sign-in attempts.
  • Media handling. Local scratch disks are destroyed when an instance ends, before the node is reallocated.
  • Operational access. Limited to the engineers who operate the platform, used for fault diagnosis and at your request.
  • Logging. Short-lived access logs for security and abuse handling, with the retention stated in the privacy policy.

We hold no third-party certification today, and we say so on the trust page rather than implying one. The measures above are what we actually do.

6. Sub-processors#

6.1 You authorise us to use sub-processors in the categories listed in the privacy policy: the operators of the facilities that host the hardware, the network and edge provider in front of the site and console, and the provider of the bot challenge on our forms.

6.2 The current list, with names and locations, is provided on request through the contact form.

6.3 We impose data protection obligations on each sub-processor no less protective than those in this addendum, and we remain responsible for their performance.

6.4 We give account holders at least 30 days' notice before adding or replacing a sub-processor that touches customer content. If you object on reasonable data protection grounds, you may terminate the affected service and we refund unused credit for it.

7. Data subject requests#

Customer content is under your control: you hold the access, correction and deletion tools, because you hold the instance and the volume. If a data subject contacts us directly about content we process for you, we will not answer for you — we will tell them to contact you, and tell you it happened.

8. Breach notification#

If we become aware of a personal data breach affecting customer content, we notify you without undue delay and in any case within 72 hours of becoming aware, with what we know: what happened, when, what is affected, what we have done and what we recommend. We will keep you updated as the picture becomes clearer rather than waiting for a complete report.

9. Deletion and return#

9.1 You can export customer content at any time — there are no egress fees and no export request to file.

9.2 Deleting a volume deletes its contents immediately and finally. Terminating an instance destroys its local scratch disk.

9.3 On closure of the account we delete remaining customer content, keeping only the billing and payment records we are required to keep, which contain no customer content.

10. Audits#

10.1 We will provide the information reasonably needed to demonstrate compliance with this addendum, in writing, on request.

10.2 Where a written answer is not enough and the law gives you an audit right, an audit may be carried out once in any twelve months, on reasonable notice, during working hours, without disrupting other customers, and subject to confidentiality. Physical access to a facility is subject to that facility's own rules.

11. International transfers#

You choose the region in which your instances and volumes live, from those listed on the site. Where personal data is transferred to a jurisdiction that requires a transfer mechanism, we rely on standard contractual clauses or another mechanism recognised under the applicable law, and we will provide the relevant documents on request.

12. Signing it#

This addendum takes effect when you accept the terms of service and process personal data on the platform; no signature is required for it to apply. If your organisation needs a countersigned copy, ask through the contact form and we will send one.


The other documents#