The Article 28 terms that govern personal data in the Raidu customer relationship, including the standard contractual clauses and the sub-processor list.
Most vendors publish a Data Processing Addendum that describes, at length, how carefully they will handle the customer data they hold. Raidu’s Addendum has a shorter job, because of how the product is built.
Raidu software is installed inside the customer’s own cloud account. Prompts, completions, governance decision records, and the signed audit log are created, processed, and stored inside that account, under the customer’s own encryption keys. None of it is transmitted to Raidu. Raidu has no production access to it, no copy of it, and no technical means of retrieving it.
So the personal data this Addendum actually governs is the business layer around the product: the administrator who signs in to manage a licence, the support ticket a customer opens, the diagnostic file a customer chooses to send us. That is a small surface, and section 3 says exactly where each part of it sits.
If you are reviewing this for a procurement or privacy assessment, sections 3, 7, and 13 and Annex II are the ones that will answer your questions. A countersigned PDF is available from privacy@raidu.com.
This Data Processing Addendum (the “Addendum”) supplements the Master Service Agreement, order form, evaluation agreement, or other written or electronic agreement between Raidu Inc. (“Raidu”) and the customer entity identified in that agreement (“Customer”) under which Raidu provides the Services (the “Agreement”).
This Addendum applies where and to the extent that Raidu processes Customer Personal Data on Customer’s behalf in the course of providing the Services.
This Addendum is incorporated into the Agreement by reference and takes effect on the effective date of the Agreement. No signature is required for it to apply. Customers who require a countersigned copy for their records may request one at privacy@raidu.com.
Raidu may update this Addendum in accordance with section 16.3. The version and effective date at the top of this page identify the current version.
Terms not defined here have the meaning given in the Agreement or, where the term is one used by Data Protection Law, the meaning given by that law.
Raidu occupies a different role for each of three categories of data. The distinction is architectural, not contractual convenience, and it determines which obligations in this Addendum apply.
The Raidu software is deployed into infrastructure that Customer owns and administers. Customer Content is generated, evaluated, signed, and stored entirely within that environment, encrypted with keys Customer controls.
Raidu does not receive, store, transmit, or have production access to Customer Content. Raidu therefore does not process Customer Content and is neither a controller nor a processor of it within the meaning of Article 4 GDPR. Customer is the controller of Customer Content and determines, through its own configuration of the software, which model providers and other recipients receive it.
Where Customer routes Customer Content to a model provider, that provider is Customer’s own processor or controller under Customer’s own contract with it. Raidu is not a party to that relationship and does not appear in the chain. See Annex III and the sub-processor list.
Nothing in this Addendum should be read as Raidu accepting processor obligations over Customer Content, and no annex, order form, or amendment will have that effect unless it says so expressly and is signed by both parties.
Where Customer or its authorised users transmit Service Data to Raidu, Raidu processes any personal data within it as a processor on Customer’s behalf. Customer is the controller. Sections 4 to 13 of this Addendum apply to this processing, and Annex I describes it.
This is the processing to which the Article 28 obligations, the sub-processor commitments, and the Standard Contractual Clauses attach.
Raidu processes business contact data of Customer’s personnel for its own purposes of contract administration, billing, security, statutory record keeping, and, where permitted, marketing. For that processing Raidu acts as an independent controller and is governed by its Privacy Policy rather than by this Addendum.
Each party is independently responsible for its compliance with Data Protection Law in respect of processing it carries out as a controller.
4.1 Raidu will process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which Raidu is subject. Where such a legal requirement applies, Raidu will inform Customer of it before processing, unless the law prohibits that notice on important grounds of public interest.
4.2 The Agreement, this Addendum, and Customer’s use and configuration of the Services constitute Customer’s complete documented instructions. Additional instructions outside their scope require written agreement between the parties.
4.3 Raidu will inform Customer without undue delay if, in Raidu’s opinion, an instruction infringes Data Protection Law. Raidu may suspend the affected processing until the instruction is amended or confirmed.
4.4 Customer is responsible for the accuracy and lawfulness of the Customer Personal Data it transmits to Raidu and for having an appropriate legal basis for that processing, including any notices or consents required from data subjects.
4.5 Raidu does not sell Customer Personal Data, does not share it for cross-context behavioural advertising, and does not use it to train, fine-tune, or evaluate any machine learning model.
5.1 Raidu grants access to Customer Personal Data only to personnel who require it to perform the Agreement.
5.2 All Raidu personnel with such access are bound by written confidentiality obligations that survive termination of their engagement, complete security and privacy awareness training on hire and annually thereafter, and are subject to background screening where lawful in their jurisdiction.
5.3 Access is provisioned on a least privilege basis, reviewed at least quarterly, and revoked on the same working day that an individual’s role no longer requires it or their engagement ends.
6.1 Raidu implements and maintains the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.
6.2 Raidu may update the measures in Annex II from time to time provided the updates do not materially reduce the overall level of security.
6.3 Customer is responsible for the security of the environment into which it deploys the Raidu software, including its cloud account configuration, its identity provider, its encryption key management, and its own network controls. Raidu publishes hardening guidance for that deployment and will assist on request.
7.1 Customer grants Raidu general authorisation to engage Sub-processors to process Customer Personal Data, subject to this section.
7.2 The current list of authorised Sub-processors is published at raidu.com/subprocessors and forms Annex III of this Addendum. The list identifies each Sub-processor, its legal entity, the purpose of the engagement, the categories of data involved, the location of processing, and the transfer mechanism relied on.
7.3 Raidu will give Customer at least 30 days’ notice before a new Sub-processor begins processing Customer Personal Data. Notice is given by updating the published list and sending an email notification to the addresses subscribed at privacy@raidu.com. Customer is responsible for subscribing and for keeping its notification address current.
7.4 Customer may object to a new Sub-processor on reasonable data protection grounds by notifying privacy@raidu.com within the 30 day notice period, stating those grounds. The parties will work in good faith to resolve the objection, which may include Raidu offering a commercially reasonable change to the Services or configuration that avoids use of that Sub-processor for Customer’s data. If no resolution is reached within 30 days of the objection, Customer may terminate the affected Services on written notice and receive a pro rata refund of prepaid fees for the terminated portion of the then current term.
7.5 Raidu imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this Addendum. Raidu remains fully liable to Customer for the performance of each Sub-processor’s obligations.
7.6 The model providers that Customer selects and configures within its own environment are not Sub-processors of Raidu. Section 3.1 explains why, and the published list records the position expressly.
8.1 Taking into account the nature of the processing, Raidu will assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests to exercise data subject rights under Chapter III GDPR.
8.2 If Raidu receives a request directly from a data subject relating to Customer Personal Data, Raidu will not respond to it substantively except to acknowledge receipt and to direct the data subject to Customer, and will forward the request to Customer without undue delay.
8.3 For Customer Content, Customer can satisfy data subject requests directly through the administrative interfaces of the software running in its own environment, without Raidu’s involvement, because that data never leaves Customer’s control.
9.1 Raidu will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
9.2 The notification will describe, to the extent known at the time and supplemented as further information becomes available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information.
9.3 Raidu will take reasonable steps to contain and remediate the breach and will provide Customer with the information Customer reasonably requires to meet its own notification obligations to supervisory authorities and data subjects.
9.4 Raidu’s notification is not, and will not be construed as, an acknowledgement of fault or liability.
9.5 Because Customer Content resides in Customer’s own environment, a security event affecting that environment is Customer’s to detect and notify. Raidu will provide reasonable cooperation on request.
Taking into account the nature of the processing and the information available to it, Raidu will provide reasonable assistance to Customer with data protection impact assessments and with prior consultation of supervisory authorities under Articles 35 and 36 GDPR. Raidu maintains a standing data protection impact assessment for the AI Firewall, available on request, together with the technical documentation Customer needs for its own assessments under the EU AI Act.
11.1 On termination or expiry of the Agreement, Raidu will, at Customer’s election, delete or return Customer Personal Data, and delete existing copies, unless retention is required by law to which Raidu is subject.
11.2 Customer must make that election within 30 days of termination. Absent an election, Raidu will delete Customer Personal Data within 90 days of termination.
11.3 Raidu will certify deletion in writing on request.
11.4 Backup copies are deleted on the ordinary backup expiry cycle, which does not exceed 90 days. Until deletion, backup copies remain subject to this Addendum.
11.5 Customer Content is not affected by this section. It resides in Customer’s own environment throughout and after the Agreement, and its retention and deletion are entirely within Customer’s control.
12.1 Raidu will make available to Customer the information necessary to demonstrate compliance with Article 28 GDPR.
12.2 Raidu satisfies this obligation in the first instance by providing, on request and subject to confidentiality obligations, its then current third party audit reports and certifications, its security documentation, and its responses to a standard security questionnaire.
12.3 Where those materials do not reasonably satisfy Customer’s audit obligations, Customer may conduct an audit, or mandate an independent auditor who is not a competitor of Raidu to conduct one, on 30 days’ written notice, no more than once in any 12 month period, during business hours, without unreasonably disrupting Raidu’s operations, and subject to confidentiality obligations. A supervisory authority may audit at any time where Data Protection Law requires it.
12.4 Customer bears its own costs and the costs of any mandated auditor. Where an audit reveals a material breach by Raidu of this Addendum, Raidu bears its own reasonable costs of the audit.
13.1 Raidu processes Customer Personal Data in the United States. Sub-processor locations are identified in the published sub-processor list.
13.2 European Economic Area. Where Customer Personal Data originating in the EEA is transferred to Raidu in a country that has not been the subject of an adequacy decision, the Standard Contractual Clauses are incorporated into this Addendum by reference and apply as follows:
13.3 United Kingdom. Where Customer Personal Data originating in the United Kingdom is transferred, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (the “UK Addendum”) is incorporated by reference. Table 1 is populated by Annex I.A of this Addendum. Tables 2 and 3 are populated by section 13.2 and by the Annexes to this Addendum. In Table 4, neither party may end the UK Addendum as set out in section 19 of it.
13.4 Switzerland. Where Customer Personal Data originating in Switzerland is transferred, the Standard Contractual Clauses apply with the following modifications: references to the GDPR are read as references to the Swiss Federal Act on Data Protection; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term “member state” is read so as not to deprive data subjects in Switzerland of the right to bring proceedings in their place of habitual residence.
13.5 Raidu will notify Customer if it becomes subject to a legally binding request from a public authority for disclosure of Customer Personal Data, unless prohibited by law, and will challenge requests that appear unlawful. Raidu publishes the substance of such requests, to the extent legally permitted, in its transparency reporting.
13.6 In the event of a conflict between this Addendum and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
14.1 Where the California Consumer Privacy Act as amended applies, Raidu acts as a “service provider” in respect of Service Data. Raidu will not sell or share personal information, will not retain, use, or disclose it for any purpose other than performing the Services or as otherwise permitted by the CCPA, will not retain, use, or disclose it outside the direct business relationship between the parties, and will not combine it with personal information received from other sources except as permitted by the CCPA. Raidu certifies that it understands these restrictions and will comply with them.
14.2 Customer may take reasonable and appropriate steps to ensure that Raidu uses personal information consistently with Customer’s obligations under the CCPA, and to stop and remediate unauthorised use, through the rights in section 12.
14.3 Equivalent processor or service provider terms apply where the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, or a comparable state law applies.
Each party’s liability arising out of or related to this Addendum, whether in contract, tort, or any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement. Reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this Addendum together.
Nothing in this section limits either party’s liability to a data subject under the third party beneficiary rights in the Standard Contractual Clauses.
16.1 Order of precedence. In the event of a conflict, the order of precedence is: the Standard Contractual Clauses, then this Addendum, then the Agreement.
16.2 Severability and term. If any provision of this Addendum is held invalid or unenforceable, the remainder continues in effect. This Addendum remains in force for as long as Raidu processes Customer Personal Data.
16.3 Changes. Raidu may update this Addendum where required by a change in Data Protection Law, a change in the Services, or a change in Raidu’s Sub-processors or security measures. Raidu will give at least 30 days’ notice of a material change by updating this page and notifying subscribed addresses. Changes will not materially reduce the protections afforded to Customer Personal Data. Sub-processor changes follow section 7 rather than this section.
16.4 Governing law. Except where the Standard Contractual Clauses require otherwise, this Addendum is governed by the law that governs the Agreement.
Raidu Inc. 134 N 4th St, Brooklyn, NY 11249, United States
| Role | Name | Contact |
|---|---|---|
| Privacy Lead, acting Data Protection Officer | Ali Sarafzadeh | privacy@raidu.com |
| Security and incident response | Security team | security@raidu.com |
| Contracts and legal | Legal team | legal@raidu.com |
The Privacy Lead is the point of contact for data subjects, for Customer’s privacy team, and for supervisory authorities. Requests reach that individual through the address above, which is monitored so that a request is not delayed by one person’s absence.
Raidu has not appointed a formal Data Protection Officer under Article 37 GDPR. Raidu is not a public authority. Its core activities do not consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, and do not consist of large-scale processing of special categories of data or of data relating to criminal convictions. The Article 37(1) threshold is therefore not met.
The Privacy Lead named above discharges the equivalent responsibilities: advising on and monitoring Raidu’s data protection compliance, maintaining the record of processing activities and the sub-processor register, approving new processing activities and high-risk vendors, and acting as the point of contact for data subjects and supervisory authorities.
Raidu reviews this determination at least annually and on any material change to its customer base, processing scale, or product scope, and will appoint a formal Data Protection Officer if the threshold is met.
Note for Customer’s own assessment: where Customer Content includes special category data, the controller obligations for that processing, including any Article 37 obligation to appoint a Data Protection Officer, rest with Customer. That data is processed inside Customer’s own environment and Raidu never receives it, so it does not count toward Raidu’s own Article 37 assessment.
Raidu has not appointed an Article 27 representative in the Union. Raidu reviews that assessment at each annual refresh of this Addendum and will appoint a representative if the threshold is met.
Data exporter. The Customer identified in the Agreement, acting as controller, or as processor where Customer processes on behalf of a third party controller. Contact details and activities relevant to the transfer are those recorded in the Agreement. Role: controller or processor as applicable.
Data importer. Raidu Inc., 134 N 4th St, Brooklyn, NY 11249, United States. Contact person: Ali Sarafzadeh, Privacy Lead and acting Data Protection Officer, privacy@raidu.com. Activities relevant to the transfer: provision of the Services described in the Agreement. Role: processor.
| Element | Detail |
|---|---|
| Categories of data subjects | Customer’s authorised administrators and other personnel who register for, configure, or seek support for the Services. Individuals whose personal data Customer elects to include in a support request or diagnostic export. |
| Categories of personal data | Name, work email address, job role, organisation, telephone number where provided. Authentication identifiers and access logs. Support correspondence and its attachments. Technical diagnostic data that Customer elects to transmit. |
| Special category data | None is requested or required. Raidu does not knowingly process special category data and instructs Customer not to include it in support correspondence or diagnostic exports. Where Customer nonetheless transmits it, the measures in Annex II apply and access is restricted to the minimum personnel necessary to resolve the request. |
| Frequency of transfer | Continuous for account and authentication data. On an occasional, Customer initiated basis for support correspondence and diagnostic exports. |
| Nature and purpose of processing | Hosting, storage, access management, technical support, defect diagnosis and resolution, service administration, and security monitoring, all for the purpose of providing the Services under the Agreement. |
| Retention period | For the term of the Agreement plus the deletion window in section 11. Support correspondence is retained for 24 months from closure of the request. Security and access logs are retained for 12 months. Diagnostic exports are deleted within 90 days of resolution of the request to which they relate. |
| Sub-processor transfers | As set out in Annex III, for the purposes and durations stated there. |
Where Customer is established in the EEA, the supervisory authority of the member state in which Customer is established. Where Customer is not established in the EEA but has appointed an Article 27 representative, the supervisory authority of the member state in which that representative is established. Otherwise, the supervisory authority of the member state in which the data subjects whose personal data is transferred are located, being for the purposes of Clause 13 the Irish Data Protection Commission.
The measures below apply to Raidu’s own systems, which are the systems that hold Customer Personal Data. Measures marked “in Customer’s environment” describe controls the Raidu software enforces inside Customer’s own cloud, where Customer Content resides.
| Area | Measures |
|---|---|
| Pseudonymisation and encryption | TLS 1.2 or higher for all data in transit. Encryption at rest for all storage. In Customer’s environment, encryption at rest under Customer managed keys held in Customer’s own key management service, and automated detection and redaction of over 60 categories of personal data before an interaction reaches a model provider. |
| Confidentiality | Role based access control on a least privilege basis. Single sign on with mandatory multi factor authentication for all personnel. Quarterly access reviews. Same day revocation on role change or departure. Production databases reachable only over private networking, with no public endpoint. |
| Integrity | Change management with peer review and automated testing before release. Signed build artefacts. In Customer’s environment, an append only audit log in which each entry is hash chained to its predecessor and signed with RSA-PSS 4096, so that any alteration or deletion of a record is detectable. |
| Availability and resilience | Managed, redundant infrastructure with automated backup. Documented business continuity and disaster recovery plan, tested at least annually. |
| Restoring availability | Point in time recovery for primary datastores. Recovery objectives are documented in the business continuity plan and provided on request. |
| Testing and evaluation | Continuous automated control monitoring. Annual penetration testing by an independent third party. Static analysis and dependency vulnerability scanning in the build pipeline. Annual review of this Addendum and of the measures in this Annex. |
| User identification and authorisation | Unique named accounts for all personnel. No shared credentials. Privileged access is time bound and logged. |
| Transport and transmission control | Data in transit is encrypted end to end. Removable media is prohibited for Customer Personal Data. |
| Data minimisation | Support tooling is configured to exclude personal data from error telemetry. Customer is instructed not to transmit personal data in diagnostic exports where the diagnosis does not require it. |
| Accountability | Documented information security policy set, reviewed annually and approved by the CEO. Named security and privacy owners. Security awareness training on hire and annually. A SOC 2 Type II programme is underway; the current status and report availability can be confirmed at security@raidu.com. |
| Sub-processor governance | Written data protection terms with every Sub-processor. Annual review of each Sub-processor’s attestations. Breach notifications from Sub-processors routed to security@raidu.com and handled under the incident response process. |
The authorised Sub-processors for the Services, together with their purpose, the categories of data involved, the location of processing, and the transfer mechanism relied on, are published and maintained at:
That page is incorporated into this Addendum by reference and is the operative Annex III. It also records, expressly, the third parties that are not Sub-processors of Raidu and the reason in each case.
Changes to the list are governed by section 7 of this Addendum, including the 30 day advance notice period and Customer’s right to object. To receive notifications of changes, email privacy@raidu.com.