1. Application and definitions
This Data Processing Addendum (“DPA”) is entered into by the Customer identified in the Agreement and Neutron AI Ltd (“Neutron”). It is incorporated into and forms part of the Terms of Service or other agreement governing Customer’s use of the Service (the “Agreement”). It becomes legally binding when Customer accepts the Agreement; no separate signature is required. If the parties sign a separate DPA, that signed version controls.
“Applicable Data Protection Law” means privacy and data-protection law applicable to Processing under the Agreement, including as relevant the UK GDPR, Data Protection Act 2018, EU GDPR, Swiss Federal Act on Data Protection (“FADP”), and United States state comprehensive privacy laws. “Customer Personal Data” means Personal Data contained in Customer Content that Neutron Processes for Customer. “EU GDPR” means Regulation (EU) 2016/679. “UK GDPR” has the meaning in section 3(10) of the Data Protection Act 2018.
“Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Process”, “Processor”, and “Supervisory Authority” have the meanings in Applicable Data Protection Law. “Subprocessor” means a third party appointed by Neutron to Process Customer Personal Data. Capitalised terms not defined here have the meanings in the Agreement.
2. Roles and documented instructions
Where Customer is a Controller of Customer Personal Data, Neutron is its Processor. Where Customer is a Processor for another Controller, Neutron is Customer’s Subprocessor. Each party will comply with the obligations applicable to its role.
Neutron will Process Customer Personal Data only on Customer’s documented instructions, including the Agreement, Customer’s use and configuration of the Service, API or MCP requests, authorised support requests, and other written instructions consistent with the Agreement. Processing details are in Schedule 1. Neutron will not Process Customer Personal Data for its own advertising or general-purpose model training.
If Neutron reasonably believes an instruction infringes Applicable Data Protection Law, it will inform Customer without undue delay and may suspend the affected Processing until the parties agree a lawful instruction. Neutron may Process Customer Personal Data where Union, Member State, or UK law requires it, but will inform Customer before doing so unless law prohibits notice for important public-interest reasons.
Neutron acts as an independent Controller for account administration, billing, fraud and abuse prevention, Service security, corporate records, and other purposes described in the Privacy Notice. This DPA does not apply to that independent Controller Processing.
3. Customer obligations
Customer will:
- comply with Applicable Data Protection Law and ensure its instructions are lawful, fair, transparent, and within the Agreement;
- have all rights, notices, lawful bases, consents, and authorisations needed for Neutron and its Subprocessors to Process Customer Personal Data;
- determine whether the Service and selected configuration are appropriate for the nature, sensitivity, volume, location, and risk of the Processing;
- limit Customer Personal Data to what is adequate, relevant, and necessary; avoid live credentials and raw payment-card data; and use redaction or pseudonymisation where appropriate;
- configure Nucleus and Scope boundaries, Authorised Users, credentials, integrations, retention, deletion, approvals, and exports securely;
- respond to Data Subjects and provide any information only Customer can supply; and
- not submit special-category, criminal-offence, children’s, health, biometric, precise-location, financial-account, or similarly sensitive data unless the Agreement expressly supports it and Customer has completed required risk and impact assessments.
If Customer is a Processor, it represents that its instructions and appointment of Neutron as a Subprocessor are authorised by the relevant Controller and that its contract with that Controller permits the terms of this DPA.
4. Confidentiality and personnel
Neutron will ensure that people authorised to Process Customer Personal Data are subject to a binding duty of confidentiality, receive access only where necessary for their role, and receive appropriate privacy and security guidance. Access is removed when no longer required. Neutron remains responsible for its personnel’s compliance with this DPA.
5. Security of Processing
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of Processing as well as risks to individuals, Neutron will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Current measures are described in Schedule 2.
Customer acknowledges that security is a shared responsibility. Customer is responsible for secure endpoints, applications, integrations, user devices, provider credentials, identity administration, lawful data classification, and configuration within its control. Customer will notify Neutron promptly of any vulnerability or compromise relevant to the Service and will not materially weaken Service safeguards.
Neutron may update security measures as technology and risk change, provided the overall protection of Customer Personal Data is not materially reduced during a subscription term.
6. Subprocessors
Customer gives Neutron general written authorisation to appoint the Subprocessors on the Subprocessor List. Neutron will impose written data-protection obligations that provide substantially the same protection for Customer Personal Data as this DPA, to the extent applicable to the Subprocessor’s services. Neutron remains responsible to Customer for each Subprocessor’s performance of those obligations.
Neutron will update the Subprocessor List before a new Subprocessor begins Processing Customer Personal Data and will provide at least 15 days’ advance notice through the page, Service, or account email where practicable. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected Service, and Neutron will refund prepaid unused fees for that terminated portion. Customer’s use after the notice period without objection constitutes authorisation.
Customer-selected integrations, models, tools, or providers that Neutron connects to solely on Customer’s instruction are not Neutron-appointed Subprocessors. Customer is responsible for their terms, transfer mechanism, permissions, and security.
7. Data Subject requests
Taking into account the nature of Processing, Neutron will provide reasonable technical and organisational assistance for Customer to respond to requests to exercise Data Subject rights. Where functionality is available, Customer will first use the Service’s access, export, correction, retention, and deletion controls.
If Neutron receives a request relating to Customer Personal Data, it will not respond on Customer’s behalf except to confirm that the request concerns a customer-controlled service, redirect the requester to Customer, act on Customer’s documented instruction, or comply with law. Neutron will notify Customer where legally permitted. Customer is responsible for determining the response and verifying the requester’s identity and entitlement.
Assistance outside standard functionality may be subject to reasonable fees based on the work required, unless the assistance is necessary because Neutron breached this DPA.
8. Personal Data Breaches
Neutron will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Notification will be sent to Customer’s account or designated security contact and, as information becomes available, will describe the nature of the breach, relevant categories and approximate number of Data Subjects and records where known, likely consequences, measures taken or proposed, and a contact point.
Neutron will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will provide information reasonably needed for Customer’s legally required notices and records. Neutron’s notification is not an admission of fault or liability. Customer is responsible for notifying Supervisory Authorities, Data Subjects, and others unless law assigns that obligation directly to Neutron.
Unsuccessful attacks, blocked attempts, port scans, pings, denial-of-service attempts, and other events that do not compromise Customer Personal Data are not Personal Data Breaches under this section, though Neutron may report material security events where useful.
9. Impact assessments, prior consultation, and compliance
Taking into account the nature of Processing and information available to it, Neutron will provide reasonable assistance with Customer’s data-protection impact assessments and prior consultation with Supervisory Authorities where required by Articles 35 or 36 of the EU or UK GDPR. Customer remains responsible for deciding whether an assessment or consultation is required and for the content and submission.
Neutron will provide information reasonably necessary to demonstrate compliance with the Processor obligations applicable to it, subject to confidentiality, security, legal, and third-party restrictions. Neutron will inform Customer if it can no longer meet a material obligation under this DPA and will take reasonable steps to remediate the issue.
10. Government and law-enforcement requests
Unless prohibited by law, Neutron will notify Customer before disclosing Customer Personal Data in response to a binding government, regulatory, or law-enforcement demand. Neutron will review the demand, disclose only data legally required, and challenge a demand where there are reasonable grounds and a challenge is legally available. If notice is prohibited, Neutron will use reasonable efforts to seek permission to notify Customer.
Neutron will not voluntarily provide a public authority with bulk, indiscriminate, or direct access to Customer Personal Data or encryption keys. Nothing in this section requires Neutron to violate law or disclose privileged legal advice.
11. Return and deletion
During the term, Customer may retrieve or delete Customer Personal Data using supported Service functions. On termination or expiry, Neutron will, at Customer’s choice communicated before termination, return Customer Personal Data through available export tools or delete it, and will delete remaining copies within a commercially reasonable period, unless law requires storage.
Customer acknowledges that active-system deletion and backup expiry are not always simultaneous. Isolated backups remain protected and are overwritten or deleted through their normal cycle. Minimal identifiers, audit evidence, legal records, and deletion tombstones may be retained only as necessary to comply with law, establish or defend claims, prevent fraud, and ensure deleted data is not restored. Any retained Customer Personal Data remains subject to this DPA and may not be used for another purpose.
12. Information and audits
On written request no more than once in a 12-month period, Neutron will provide information reasonably necessary to demonstrate compliance, which may include then-available security documentation, architecture descriptions, Subprocessor information, independent assessments, penetration-test summaries, or a reasonable questionnaire. This frequency limit does not apply following a relevant Personal Data Breach, a reasonable indication of material non-compliance, or a Supervisory Authority’s requirement.
If provided material is insufficient to satisfy a legal audit requirement, Customer may request an audit by an independent, qualified auditor bound by confidentiality. The parties will agree scope, timing, duration, evidence handling, and security safeguards. An audit must minimise disruption, avoid access to other customers’ data and vulnerability details that would create risk, and ordinarily occur during business hours. Customer bears its costs and Neutron’s reasonable assistance costs unless the audit identifies Neutron’s material breach.
Audit information is Neutron Confidential Information. Neutron need not disclose trade secrets, data that would violate another duty, information protected by privilege, or information whose disclosure would compromise security, but will seek a reasonable alternative form of evidence.
13. International transfers
Customer authorises Neutron and its Subprocessors to Process Customer Personal Data in countries listed or described on the Subprocessor List, subject to this section. Where Processing involves a Restricted Transfer that requires an adequacy decision or contractual safeguard, the parties will first rely on a valid adequacy decision. If one is unavailable or ceases to apply, the transfer terms below apply automatically.
“Restricted Transfer” means a transfer of Personal Data that Applicable Data Protection Law permits only with an approved transfer mechanism. The parties will reasonably cooperate on transfer-risk assessments and supplementary measures. If a transfer mechanism is invalidated, they will use a lawful replacement. If none is reasonably available, Neutron may suspend the affected transfer or Customer may terminate the affected Service.
14. European Commission Standard Contractual Clauses
For a Restricted Transfer subject to the EU GDPR, the standard contractual clauses in European Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated by reference and completed as follows:
- Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor.
- Customer is the data exporter and Neutron is the data importer. If Customer is a Processor, the relevant Controller may exercise its rights as permitted by Module Three.
- Clause 7, the optional docking clause, applies.
- For Clause 9(a), Option 2 applies and the notice period for Subprocessor changes is 15 days.
- The optional language in Clause 11 does not apply.
- For Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland.
- For Clause 18(b), disputes will be resolved by the courts of Ireland.
- Annex I is completed with the parties and Processing details in the Agreement and Schedule 1; the competent Supervisory Authority is determined under Clause 13.
- Annex II is Schedule 2, and Annex III is the Subprocessor List referenced in Schedule 3.
If the EU SCCs conflict with this DPA, the EU SCCs control for the Restricted Transfer. The parties’ acceptance of the Agreement is their signature to the EU SCCs on the DPA effective date. A copy of the official EU SCC text is available from the European Commission.
15. United Kingdom transfer terms
For a Restricted Transfer subject to the UK GDPR, the then-current UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (“UK Addendum”) is incorporated by reference.
- Table 1 is completed with Customer as exporter, Neutron as importer, and the party details in the Agreement and Schedule 1.
- Table 2 selects the EU SCC Module identified in section 14 and the options completed there.
- Table 3 consists of the Processing details in Schedule 1, security measures in Schedule 2, and Subprocessors in Schedule 3.
- For Table 4, neither party may end the UK Addendum solely because the Information Commissioner issues a revised approved addendum; mandatory termination rights in the approved terms remain.
The parties agree to be bound by the UK Addendum’s mandatory clauses. References in the EU SCCs are adapted as specified by the UK Addendum. If the UK Addendum conflicts with this DPA, it controls for the relevant Restricted Transfer. If an adequacy regulation validly covers the transfer, the parties may rely on that adequacy regulation instead.
16. Switzerland
For a Restricted Transfer governed by the FADP, the EU SCCs apply with these adaptations: references to the EU GDPR include the FADP; “Member State” and “EU” are interpreted to include Switzerland where needed to preserve rights; the competent authority is the Swiss Federal Data Protection and Information Commissioner; and Data Subjects in Switzerland may enforce their rights in Switzerland.
Where both the FADP and EU GDPR apply, the EU SCC completion in section 14 applies without preventing the Swiss authority’s jurisdiction under the FADP.
17. United States state privacy terms
To the extent a United States state privacy law applies to Customer Personal Data, Neutron acts as Customer’s service provider, contractor, or processor. Neutron will Process the data only for the limited and specified business purposes in the Agreement and Customer’s instructions; will not sell or share it for cross-context behavioural advertising; will not retain, use, or disclose it outside the direct business relationship except as permitted by law; and will not combine it with personal data received from another person or collected from Neutron’s own interaction with an individual except as legally permitted to provide the Service.
Neutron certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps to help ensure Processing is consistent with applicable law and, after notice, to stop and remediate unauthorised use. Neutron will notify Customer if it determines it can no longer meet a relevant obligation. Each party will comply with legally required consumer-request, assessment, security, and contracting duties applicable to its role.
18. General
This DPA replaces prior data-processing terms for the same Processing from its effective date. If it conflicts with the Agreement, this DPA controls for data protection; the EU SCCs, UK Addendum, or another mandatory transfer instrument controls over both for the relevant transfer. All other Agreement terms, including confidentiality, governing law, liability, and dispute resolution, remain in effect unless a mandatory data-protection instrument says otherwise.
Liability arising under this DPA is subject to the Agreement’s exclusions and aggregate limits, and counts toward—not in addition to—the Agreement’s liability cap, except to the extent Applicable Data Protection Law or an incorporated transfer mechanism prohibits that limitation.
Amendments must be in writing except that Neutron may update this DPA to reflect changes in law, an approved transfer mechanism, or Service operations if the update does not materially reduce protection. Material changes will be notified as described in the Agreement.
Schedule 1: Details of Processing
Parties
Data exporter: Customer and, where Module Three applies, the relevant Controller. Customer’s identity, address, contact details, signature, and role are those in the Agreement or account. Activities are the use of the Service described in the Agreement.
Data importer: Neutron AI Ltd, 5 Hallett Close, Havant, United Kingdom, PO9 2BW; admin@neutronai.dev; Processor or Subprocessor providing the Service. Acceptance of the Agreement constitutes signature for these purposes.
Subject matter, nature, and purpose
Hosting and operating scoped memory, semantic embedding and retrieval, deterministic codec and ranking, context packaging, optional authorised AI inference, bounded Consequence simulations, account and workspace administration, support, security, deletion, backup, and related processing necessary to provide the Service.
Duration and frequency
Processing occurs on a continuous or request-driven basis for the Agreement term and the limited deletion or legal-retention period described in the DPA. Individual memory, cache, and Consequence objects follow Customer configuration and Service limits.
Categories of Data Subjects
Customer’s and its clients’ personnel, Authorised Users, administrators, contractors, agents’ end users, customers, prospects, suppliers, partners, support contacts, and other individuals whose data Customer submits to the Service.
Categories of Personal Data
Identifiers and contact details; account, workspace, role, and authentication metadata; professional information; device, network, usage, and audit data; communications; source and integration metadata; and any personal data Customer includes in Memory Cells, summaries, Scopes, Nuclei, prompts, Context Capsules, decisions, approvals, observations, reflections, or other Customer Content.
Sensitive data and safeguards
Neutron does not require special-category or highly sensitive data for ordinary use. If Customer lawfully submits it under an Agreement that supports the workload, safeguards include data minimisation, explicit Nucleus and Scope isolation, role and credential controls, encryption, logging restrictions, bounded retention, deletion tombstones, and human review for sensitive consequence workflows.
Return and deletion
As described in section 11 of this DPA.
Schedule 2: Technical and organisational measures
- Governance: documented security and privacy responsibilities, least-privilege administration, confidentiality obligations, incident procedures, change controls, and provider review proportionate to risk.
- Tenant isolation: validated Nucleus and Scope identifiers; tenant-scoped reads, writes, queries, caches, queues, archives, audit events, and consequence artifacts; mismatch rejection for compatibility aliases.
- Access control: authenticated APIs and applications, role-aware workspace administration, credential hashing, expiring sessions and one-time codes, credential rotation and revocation, and restricted production access.
- Encryption: transport encryption for public Service connections and infrastructure-provider encryption at rest for managed storage where supported, with secrets managed outside public code and runtime configuration.
- Data lifecycle: configurable TTLs, bounded caches, tombstoned deletion, controls designed to prevent resurrection from queues, compaction, caches, or archives, and protected backup lifecycle.
- Application security: runtime validation of untrusted input, authorisation checks, stable error boundaries, bounded pagination and concurrency, timeouts, rate limits, abuse controls, dependency and release checks, and separation of public and privileged runtime configuration.
- AI safety: structured outputs and runtime validation where supported, bounded depth, branch, runtime, call and cost budgets, approval gates for high-risk or irreversible actions, and prohibition on raw hidden reasoning or secrets in model context.
- Logging and monitoring: request and audit identifiers, safe operational fields, availability and error monitoring, and redaction designed to exclude credentials, cookies, authorisation headers, raw prompts, and sensitive payloads.
- Availability and recovery: distributed edge infrastructure, capacity and rate controls, idempotent queue processing, cancellable deep simulations, data export where supported, and recovery procedures proportionate to the Service.
- Testing and response: type, contract, behavioural, security-boundary, and build checks; vulnerability remediation; incident containment, investigation, recovery, and customer notification processes.
- Subprocessor management: diligence, contractual data-protection and confidentiality duties, change notice, and ongoing responsibility under this DPA.
Measures describe the hosted Service generally. A specific enterprise control, certification, residency commitment, recovery objective, or service level applies only if stated in an Order.
Schedule 3: Authorised Subprocessors
The current Subprocessor List is incorporated into this DPA and identifies the provider, purpose, data involved, and processing location. Its change-notice process is governed by section 6.
Contact and company information
Questions about this document may be sent to admin@neutronai.dev.
Neutron AI LtdRegistered in England and Wales under company number 17317740
Registered office: 5 Hallett Close, Havant, United Kingdom, PO9 2BW