Data Processing Agreement
Version date: August 13, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Valkyr Labs Inc. ("Valkyr") and the customer identified in an Order Form or other agreement incorporating it ("Customer") (the "Principal Agreement"). It applies when Valkyr Processes Customer Personal Data as a Processor, Service Provider, or Contractor.
1. Definitions and scope
"Applicable Data Protection Law" means privacy and data-protection law applicable to the Processing, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, California Consumer Privacy Act as amended ("CCPA"), and U.S. state comprehensive privacy laws. "Customer Personal Data" means Personal Data contained in Customer Data that Valkyr Processes on Customer's behalf. "Data Subject," "Personal Data," "Personal Data Breach," "Process," "Processor," and "Controller" have the meanings in Applicable Data Protection Law. "Subprocessor" means a third party Valkyr engages to Process Customer Personal Data.
For Customer Personal Data, Customer is Controller or Processor, as applicable, and Valkyr is Processor or Subprocessor. For CCPA purposes, Valkyr is a Service Provider or Contractor and Customer is the Business or a Service Provider/Contractor. Each Party acts as an independent Controller for business-contact data, billing, account administration, legal compliance, and its own security logs to the extent it independently determines purposes and means.
If this DPA conflicts with the Principal Agreement regarding Customer Personal Data, this DPA controls. The Principal Agreement controls for all other subjects. The Optional Content Sharing Agreement does not waive this DPA for Personal Data.
2. Processing instructions
Valkyr will Process Customer Personal Data only: (a) to provide, secure, support, and improve the Services for Customer; (b) according to Customer's documented instructions in the Principal Agreement, Order Form, Service configuration, support request, or Authorized User action; and (c) as required by law. If law requires Processing contrary to instructions, Valkyr will notify Customer before Processing unless law prohibits notice.
Valkyr will promptly inform Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law. Valkyr may suspend the affected instruction while the Parties resolve it. Customer is responsible for lawful instructions, notices, consents, data minimization, and the accuracy and legal basis of Customer Personal Data.
Valkyr will not: (i) sell or share Customer Personal Data as those terms are defined by the CCPA; (ii) retain, use, or disclose it outside the direct business relationship or for a commercial purpose other than the specified business purposes; (iii) combine it with personal data received from another person or collected from Valkyr's own consumer interactions except as permitted by the CCPA; or (iv) use it to train generalized models or improve services for other customers without a valid separate opt-in and lawful basis. Valkyr certifies it understands and will comply with these restrictions.
3. Personnel and confidentiality
Valkyr will limit access to personnel who need it to perform the Principal Agreement, ensure they are bound by confidentiality duties, provide appropriate privacy and security training, and take reasonable steps to verify their trustworthiness. Valkyr remains responsible for their compliance.
4. Security
Valkyr will implement and maintain the technical and organizational measures in Annex II appropriate to the risk, including measures required by Article 32 GDPR where applicable. Valkyr may update measures without materially reducing overall protection. Customer is responsible for security controls allocated to Customer in the Principal Agreement, particularly in private or customer-managed deployments.
5. Personal Data Breach
Valkyr will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. Notification will include, as information becomes available: nature and scope; affected data and Data Subjects; likely consequences; containment and remediation; and a contact for follow-up. Valkyr may provide information in phases and will reasonably cooperate with Customer's investigation, notices, and remediation.
Notification is not an admission of fault. Customer is responsible for notices to regulators and Data Subjects unless law assigns that duty to Valkyr. Valkyr bears response costs to the extent a breach results from Valkyr's breach of this DPA; otherwise extraordinary assistance may be charged at agreed reasonable rates.
6. Subprocessors
Customer gives general authorization for Valkyr to use Subprocessors. Before a new Subprocessor Processes Customer Personal Data, Valkyr will ensure a written agreement imposes data-protection and security duties no less protective in material respects than this DPA. Valkyr remains responsible for Subprocessor performance to the extent required by law.
Valkyr will make a current Subprocessor list available in the applicable Order Form, administrative console, trust center, or on written request. The list will identify the Subprocessor, location, and function, including hosted Model Providers. Valkyr will give at least 30 days' advance notice of a new Subprocessor when Customer subscribes to notices, except an emergency replacement needed to maintain security or availability, for which notice will be prompt.
Customer may object on reasonable data-protection grounds within 15 days after notice. The Parties will work in good faith on a commercially reasonable alternative. If none is available within 30 days, Customer may terminate only the affected Service and receive a pro rata refund of prepaid unused fees. Customer-selected providers used through Customer's own account or key are not Valkyr Subprocessors; Customer directs those transfers and is responsible for provider terms, while Valkyr remains responsible for secure transmission under Customer's instruction.
7. Data Subject requests and regulatory assistance
Taking into account the nature of Processing, Valkyr will provide reasonable technical and organizational assistance for Customer to respond to Data Subject requests. If Valkyr receives a request concerning Customer Personal Data, it will direct the requester to Customer and not respond substantively unless Customer instructs it or law requires.
Valkyr will reasonably assist Customer with data-protection impact assessments, prior consultations, regulatory inquiries, and demonstrations of compliance, taking into account the Processing and information available. Valkyr will notify Customer of a legally binding government demand for Customer Personal Data unless prohibited, assess its validity, challenge overbroad demands where there are reasonable grounds, disclose only what is legally required, and document requests where permitted.
8. Audits and compliance information
Valkyr will provide information reasonably necessary to demonstrate compliance, such as current independent audit reports, certifications, penetration-test summaries, or security questionnaires, subject to confidentiality. No more than once annually, unless a confirmed breach or regulator requires more, Customer may conduct an audit through an independent auditor bound by confidentiality on at least 30 days' notice. Audits must use existing reports first, avoid access to other customers' data, occur during business hours, and minimize disruption. Customer bears cost unless the audit identifies Valkyr's material breach. The Parties will agree scope and remediation timing appropriate to risk.
9. Return and deletion
During the term, Customer may access and export Customer Personal Data using available functionality. On expiration or termination, Valkyr will provide the export period stated in the Principal Agreement, then delete Customer Personal Data from active systems within 30 days and backups within 90 additional days, unless law requires retention. Retained data will remain protected, isolated from ordinary use, and deleted when the legal requirement ends. At Customer's written request, Valkyr will certify completion. Customer-managed deployments and copies controlled by Customer are Customer's responsibility.
10. International transfers
Valkyr will not transfer Customer Personal Data across borders without a lawful mechanism. Where Customer transfers EEA Personal Data to Valkyr in a country not covered by an adequacy decision, the 2021 EU Standard Contractual Clauses ("EU SCCs") are incorporated by reference as follows: Module Two applies to Controller-to-Processor transfers; Module Three applies to Processor-to-Processor transfers; the optional docking clause applies; Clause 9 uses Option 2 with the notice period in Section 6; Clause 11 optional language does not apply; Clause 17 uses the law of Ireland; Clause 18 selects courts of Ireland; and Annexes I–III are completed by this DPA, the Principal Agreement, and the Subprocessor list. If Customer is established in another EEA state and mandatory law requires its law or courts, that state replaces Ireland.
For UK restricted transfers, the then-current UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office is incorporated; the Parties and selected modules are those above, the information in this DPA completes its tables, and neither Party may terminate solely due to an approved-addendum change unless the mandatory Addendum permits. For Swiss transfers, references in the EU SCCs are adapted to the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner where applicable, and Swiss Data Subjects may enforce applicable rights.
The Parties will conduct and reasonably cooperate on required transfer-impact or transfer-risk assessments and supplementary measures. If a transfer mechanism is invalidated, the Parties will promptly use a valid successor mechanism. The unmodified mandatory text of the applicable transfer clauses controls over this DPA.
11. Liability and duration
The Principal Agreement's liability allocation applies to this DPA, subject to rights and liabilities that cannot lawfully be limited. This DPA remains in effect while Valkyr Processes Customer Personal Data. Obligations intended to survive, including confidentiality, deletion, and transfer duties, continue afterward.
Annex I — Processing details
A. Parties
- Data exporter: Customer and permitted Affiliates identified in the Principal Agreement; contact details and role are stated in the Order Form.
- Data importer: Valkyr Labs Inc., 195 Tamal Vista Blvd #201, Corte Madera, CA 94925; legal@valkyrlabs.com; Processor or Subprocessor.
B. Subject matter, nature, purpose, and duration
- Subject matter: provision of the Services described in the Principal Agreement.
- Nature: collection, receipt, hosting, storage, organization, retrieval, consultation, generation, transmission, support access, security analysis, return, and deletion according to Customer instructions.
- Purposes: providing, securing, supporting, and maintaining the configured Services, including customer-directed AI inference, agent workflows, integrations, memory, code generation, and private-deployment support.
- Duration: the Service term plus the export, backup, and legally required retention periods.
C. Data Subjects
Authorized Users; Customer personnel and contractors; Customer's customers, prospects, suppliers, and business contacts; individuals represented in Customer Data; and other Data Subjects whose Personal Data Customer lawfully submits. Children and regulated categories are excluded unless an Order Form expressly authorizes them.
D. Personal Data categories
Account and contact data; identifiers; authentication and authorization data; device, network, log, and usage data; communications and support data; prompts, files, code, schemas, business records, AI memory and context, retrieval receipts, workflow inputs and outputs; integration data; and other Personal Data Customer submits according to the Principal Agreement.
E. Sensitive data
No special-category, sensitive, criminal-offense, protected-health, payment-card, biometric, precise-location, government-identifier, or children's data is authorized unless expressly listed in an Order Form with safeguards and a lawful basis. Customer must not include credentials or secrets in prompts or ordinary content fields.
F. Frequency and retention
Processing is continuous or initiated by Authorized Users during the term. Customer selects available retention settings; default retention is the term plus the deletion periods in Section 9. GrayMatter memory may persist according to Customer-configured workspace policy until deletion, export, or termination.
G. Competent authority
The supervisory authority is determined under Clause 13 of the EU SCCs based on the exporter's establishment or representative. Where the exporter is not established in the EEA and has no representative but is subject to GDPR Article 3(2), the authority of the EEA state where relevant Data Subjects are located will apply.
Annex II — Technical and organizational measures
Valkyr will maintain measures appropriate to the Services and risk, including:
- Governance: documented security and privacy responsibilities, risk assessment, workforce confidentiality and training, vendor review, and incident response.
- Identity and access: unique identities, role- and scope-based access, least privilege, privileged-access controls, multifactor authentication where appropriate, periodic access review, and prompt revocation.
- Tenant isolation: validated server-side tenant context; authorization and object-level access controls; rejection of client- or model-supplied identity overrides; and separation of customer workspaces and records.
- Encryption: industry-standard encrypted transport; encryption at rest where appropriate; managed key access; and secret-handling controls. Customer-managed keys apply only if purchased and configured.
- Secure development: change control, peer review, dependency and vulnerability management, security testing proportionate to risk, separation of development and production, and remediation prioritization.
- Operations: logging and monitoring, backups, recovery procedures, malware protection where appropriate, capacity and availability management, and restricted production access.
- AI and agents: scoped credentials, configurable approval controls, logging or receipts for material agent actions where supported, provider access limited to configured purposes, and no generalized training on Customer Data by default.
- Incident response: documented detection, escalation, containment, investigation, recovery, notification, and post-incident improvement.
- Data lifecycle: data minimization, configurable retention where supported, secure deletion, media disposal, and export controls.
- Business continuity: backup and recovery testing appropriate to the Service and documented dependencies for customer-managed deployments.
Specific certifications, recovery objectives, penetration-test commitments, residency, customer-managed responsibilities, and higher-assurance controls apply only if stated in an Order Form or Security Exhibit.
Annex III — Subprocessors
The current Subprocessor schedule provided under Section 6 forms Annex III. Before signature, the Order Form should attach or link the verified schedule for the selected deployment and identify each infrastructure provider, support provider with potential access, hosted Model Provider, integration processor, and its processing location and function.