← BACK TO HOME
Data Processing Addendum (DPA)
LAST UPDATED: AUGUST 15, 2026 · SPECIFICATION 1.0
This Data Processing Addendum ("DPA") supplements the PromptMatrix Terms of Service entered into between PromptMatrix and the Customer when Customer data includes Personal Data subject to Data Protection Laws (e.g. GDPR, UK GDPR, CCPA).
1. Roles and Scope
- Customer: Acts as Data Controller regarding Personal Data submitted into prompt templates or metadata.
- PromptMatrix: Acts as Data Processor processing Personal Data exclusively on Customer instructions to deliver prompt governance and serving APIs.
2. Processing Instructions & Security
- PromptMatrix processes Customer data solely to maintain the prompt registry, serve prompt variables, and execute automated eval test suits requested by Customer.
- PromptMatrix maintains technical and organizational measures (TOMs) including TLS 1.3 encryption in transit, AES-256 encryption at rest, and tenant database partitioning.
3. Subprocessor Engagement
Customer provides general authorization for PromptMatrix to engage subprocessors (Vercel, Supabase, Razorpay, Brevo) for infrastructure delivery. PromptMatrix imposes contractual data protection obligations on each subprocessor.
4. Data Subject Rights & Incident Notification
- PromptMatrix will assist Customer in responding to Data Subject Requests (access, rectification, deletion) within statutory deadlines.
- In the event of a confirmed Security Incident involving Customer Personal Data, PromptMatrix will notify Customer within 72 hours of becoming aware.
5. Data Deletion & International Transfers
Upon termination of the Services, PromptMatrix will delete all customer workspace data from active databases within 30 days. Cross-border data transfers rely on Standard Contractual Clauses (SCCs).