Data Protection Addendum

Last updated: 18 September 2025 | Version: 2025.09.18

📊 Data Processing Agreement

This Data Protection Addendum ("DPA") forms part of the Terms of Service between SpicyAPI ("Processor") and Customer ("Controller") to reflect the parties' agreement with regard to the processing of personal data in accordance with GDPR, UK GDPR, and other applicable data protection laws.

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person.

"Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion.

"Controller" means the Customer who determines the purposes and means of Processing Personal Data.

"Processor" means SpicyAPI, which Processes Personal Data on behalf of the Controller.

"Data Subject" means the individual to whom Personal Data relates.

"Sub-processor" means any third party engaged by Processor to Process Personal Data.

2. Roles and Responsibilities

2.1 Customer as Controller: Customer acts as the Controller for all Personal Data submitted through the Services, including prompts, generated content, and end-user data. Customer is responsible for:

  • Ensuring lawful basis for Processing
  • Obtaining necessary consents from Data Subjects
  • Providing privacy notices to Data Subjects
  • Responding to Data Subject rights requests
  • Determining retention periods for Personal Data

2.2 SpicyAPI as Processor: SpicyAPI acts solely as a Processor, Processing Personal Data only on documented instructions from Customer and in accordance with this DPA.

3. Processing Instructions

3.1 Scope: Processor shall Process Personal Data only to provide the Services as described in the Terms of Service and as necessary for the following purposes:

  • Content generation based on Customer prompts
  • API request processing and response delivery
  • Service improvement and model training (anonymized only)
  • Security monitoring and abuse prevention
  • Legal compliance and law enforcement cooperation

3.2 Instructions: Customer instructs Processor to Process Personal Data in accordance with this DPA and the Terms of Service. Additional instructions require written agreement.

4. Security Measures

Technical and Organizational Measures:

  • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
  • Access Control: Role-based access, MFA, least privilege principle
  • Monitoring: 24/7 security monitoring, intrusion detection, audit logging
  • Infrastructure: SOC 2 certified cloud providers, regular security updates
  • Incident Response: Documented procedures, 72-hour breach notification
  • Training: Regular security awareness training for all personnel
  • Testing: Annual penetration testing and vulnerability assessments
  • Physical Security: Secured data centers with biometric access controls

5. Sub-processors

5.1 Authorization: Customer authorizes Processor to engage Sub-processors to Process Personal Data, provided Processor:

  • Maintains a current list of Sub-processors
  • Imposes data protection obligations substantially similar to this DPA
  • Remains liable for Sub-processor compliance

5.2 Current Sub-processors:

  • • Google Cloud Platform (Infrastructure - US/EU/UK)
  • • Amazon Web Services (Storage - US/EU)
  • • Cloudflare (CDN/Security - Global)
  • • Stripe (Payment Processing - US/EU)
  • • SendGrid (Email Services - US)

Updated list available at: spicyapi.com/sub-processors

6. International Transfers

6.1 Transfer Mechanisms: Where Personal Data is transferred outside the UK/EEA, appropriate safeguards include:

  • UK International Data Transfer Agreement (IDTA)
  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable

6.2 Data Localization: Customer may request data residency in specific regions (additional fees may apply).

7. Data Subject Rights

7.1 Cooperation: Processor shall assist Customer in responding to Data Subject requests regarding:

  • Access to Personal Data
  • Rectification or erasure
  • Data portability
  • Restriction of Processing
  • Objection to Processing

7.2 Response Time: Processor will respond to Customer requests within 5 business days.

8. Data Retention and Deletion

8.1 Retention Periods:

  • API request logs: 90 days (extended to 6 years for legal holds)
  • Generated content: 30 days (unless Customer deletes earlier)
  • Account data: Duration of account plus 30 days
  • Legal/abuse records: 6 years

8.2 Deletion: Upon termination, Personal Data will be deleted within 30 days unless retention is required by law.

9. Audits and Compliance

9.1 Audit Rights: Customer may audit Processor's compliance annually with 30 days notice, or immediately following a breach.

9.2 Certifications: Processor will maintain and provide upon request:

  • SOC 2 Type II reports
  • ISO 27001 certification (planned)
  • Penetration test summaries

9.3 Regulatory Cooperation: Processor will cooperate with supervisory authorities and provide information as required.

10. Breach Notification

10.1 Notification: Processor will notify Customer without undue delay and within 72 hours of becoming aware of a Personal Data breach.

10.2 Information Provided:

  • Nature of the breach and categories of data affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Contact point for more information

10.3 Documentation: Processor maintains records of all breaches and remediation efforts.

11. Liability and Indemnification

11.1 Processor Liability: Processor's liability for data protection violations shall be subject to the limitations in the Terms of Service, except for willful misconduct or gross negligence.

11.2 Customer Indemnification: Customer indemnifies Processor against claims arising from Customer's violation of data protection laws or instructions that infringe applicable law.

12. Term and Termination

This DPA remains in effect for the duration of the Terms of Service. Upon termination, data deletion obligations in Section 8 apply. Sections relating to confidentiality and liability survive termination.

13. Governing Law

This DPA is governed by the laws of England and Wales. Disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.

CONTACT FOR DATA PROTECTION MATTERS:

Data Protection Officer: contact@spicyapi.com

Postal Address: SpicyAPI Ltd, London, United Kingdom

Response Time: Within 5 business days