Data Processing Agreement
Last updated: July 28, 2026
This Data Processing Agreement ("DPA") is entered into between Unbox Inc., doing business as Openlayer ("Openlayer"), and the entity or individual that accepts the Openlayer Terms of Service or otherwise enters into an agreement with Openlayer for the Services ("Customer"), and forms part of that agreement (the "Principal Agreement"). This DPA reflects the parties' agreement with respect to the Processing of Personal Data by Openlayer on Customer's behalf. For an executable, counter-signable copy of this DPA, or to put a negotiated DPA in place, contact support@openlayer.com.
1. Definitions
Capitalized terms not defined here have the meaning given in the Principal Agreement. "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Principal Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and U.S. state privacy laws including the California Consumer Privacy Act as amended ("CCPA"). "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data contained within Customer Data that Openlayer Processes on Customer's behalf in providing the Services. "Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission in Decision 2021/914, as applicable, as updated from time to time.
2. Roles and Scope of Processing
As between the parties, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) of Customer Personal Data, and Openlayer is the Processor. Openlayer also acts as an independent Controller of account, billing, and usage/telemetry data it collects to operate and improve the Services; that processing is governed by Openlayer's Privacy Policy, not this DPA. Openlayer will Process Customer Personal Data only to provide, secure, and support the Services and as further described in Exhibit A, and otherwise on documented instructions from Customer, including as set out in the Principal Agreement and this DPA. The subject matter, duration, nature, and purpose of the Processing, and the types of Personal Data and categories of Data Subjects, are described in Exhibit A.
Openlayer does not sell Customer Personal Data and does not use Customer Data to train, fine-tune, or otherwise develop its own or any third party's foundation or machine learning models. Openlayer will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
3. Confidentiality
Openlayer ensures that personnel authorized to Process Customer Personal Data are bound by appropriate obligations of confidentiality and have received appropriate training on their data protection responsibilities.
4. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, Openlayer implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as further described in Exhibit C. Openlayer maintains security and privacy programs designed to comply with leading industry frameworks and regulations, including SOC 2, ISO 27001, GDPR, and HIPAA (in each case, as applicable to its operations).
5. Subprocessors
Customer provides general authorization for Openlayer to engage the subprocessors listed in Exhibit B, and to engage additional subprocessors to provide the Services. Openlayer imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains liable for each subprocessor's performance of its obligations. Openlayer will provide notice of any intended addition or replacement of a subprocessor (through its Trust Center, the Services, or by email) and will give Customer an opportunity to object on reasonable data-protection grounds within fifteen (15) days of notice. If the parties cannot reach a mutually acceptable resolution within a reasonable period, Customer’s sole and exclusive remedy is to terminate the portion of the Services that cannot be provided without the objected-to subprocessor, without penalty to either party. Where the engaged subprocessors include third-party model providers, Openlayer engages those providers under terms intended to prohibit their use of Customer Personal Data to train their models and to limit their retention of such data.
6. Assistance to Customer
Taking into account the nature of the Processing, Openlayer provides reasonable assistance to Customer, by appropriate technical and organizational measures and insofar as possible, to fulfill Customer's obligations to respond to requests from Data Subjects exercising their rights, and to ensure compliance with Customer's obligations relating to the security of Processing, Personal Data Breach notification, data protection impact assessments, and prior consultation with supervisory authorities. If Openlayer receives a request from a Data Subject in relation to Customer Personal Data, Openlayer will, where legally permitted, direct the Data Subject to Customer. Openlayer does not carry out solely automated decision-making, including profiling, that produces legal or similarly significant effects concerning Data Subjects on Customer’s behalf, and will not do so except on Customer’s documented instructions and with appropriate safeguards for Data Subject rights.
7. Personal Data Breach
Openlayer notifies Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and provides Customer with information reasonably available to it to assist Customer in meeting any obligations to notify supervisory authorities or Data Subjects.
8. International Transfers
Openlayer Processes Customer Personal Data primarily in the United States. Where Openlayer Processes Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland in a country that has not received an adequacy decision, the parties agree that the Standard Contractual Clauses (and the UK International Data Transfer Addendum or Swiss addenda, as applicable) are incorporated into this DPA by reference and apply to such transfers, with Customer as data exporter and Openlayer as data importer. For the purposes of the Standard Contractual Clauses: (a) Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) applies where Customer is itself a Processor; (b) in Clause 9, Option 2 (general written authorization) applies, with the notice period set out in Section 5; (c) the optional language in Clause 11 does not apply; (d) in Clause 17, the Clauses are governed by the law of Ireland; (e) in Clause 18(b), disputes will be resolved before the courts of Ireland; (f) Exhibit A completes Annexes I.A and I.B, Section 4 and Exhibit C complete Annex II, and Exhibit B completes the list of authorized sub-processors; and (g) for transfers subject to the UK GDPR, the UK International Data Transfer Addendum is incorporated with its Tables populated by the corresponding information in this DPA, and for transfers subject to Swiss law, references to the GDPR are read as references to the Swiss FADP and references to a supervisory authority include the Swiss Federal Data Protection and Information Commissioner. Any replacement of or amendment to the Standard Contractual Clauses will apply automatically once it takes effect.
9. Return and Deletion
Upon termination or expiration of the Principal Agreement, Openlayer will, upon request made within thirty (30) days following such termination or expiration, make Customer Data available to Customer for export. Thereafter, Openlayer will delete Customer Personal Data in its possession in the ordinary course in accordance with its data retention practices, except to the extent retention is required by applicable law, in which case Openlayer continues to protect such data in accordance with this DPA.
10. Audits
Openlayer makes available to Customer information reasonably necessary to demonstrate compliance with this DPA. Customer may satisfy its audit rights by reviewing Openlayer's then-current third-party audit reports and certifications (such as SOC 2) and security documentation made available through Openlayer's Trust Center at trust.openlayer.com or on request, subject to confidentiality obligations.
11. U.S. State Privacy Laws
To the extent the CCPA or other U.S. state privacy laws apply, Openlayer acts as a "service provider" (or "processor") with respect to Customer Personal Data. Openlayer will not sell or share such data, will not retain, use, or disclose it for any purpose other than performing the Services or as otherwise permitted by applicable law, and will not combine it with Personal Data from other sources except as permitted by law. Openlayer certifies that it understands and will comply with these restrictions.
12. General and Order of Precedence
This DPA is incorporated into and forms part of the Principal Agreement. In the event of a conflict between this DPA and the Principal Agreement with respect to the Processing of Customer Personal Data, this DPA controls; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control. This DPA is governed by the law and jurisdiction specified in the Principal Agreement, unless required otherwise by Data Protection Laws. Each party’s liability arising out of or related to this DPA and the Standard Contractual Clauses, whether in contract, tort, or under any other theory, is subject to and counts toward the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA or the Standard Contractual Clauses limits the rights of Data Subjects under Data Protection Laws.
Exhibit A: Details of Processing
Subject matter and duration
Openlayer's provision of the Services to Customer, for the duration of the Principal Agreement plus any period during which Customer Data is retained in accordance with Section 9.
Nature and purpose of Processing
Hosting, storage, evaluation, testing, observability, and monitoring of Customer's AI and machine learning systems, including ingesting and analyzing datasets, model inputs and outputs, prompts and completions, traces, spans, inference logs, and evaluation results, and transmitting relevant portions to third-party model providers to deliver features Customer enables.
Types of Personal Data
Any Personal Data contained within Customer Data that Customer chooses to submit to the Services. Because the Services ingest data of Customer's choosing, this may include identifiers, contact details, and, depending on Customer's use, potentially special categories of data. Customer is responsible for determining and limiting what Personal Data it submits.
Categories of Data Subjects
Customer's end users and any other individuals whose Personal Data is contained in the data Customer submits to the Services.
Exhibit B: Subprocessors
The current, authoritative list of subprocessors Openlayer engages to Process Customer Personal Data is maintained on Openlayer's Trust Center at trust.openlayer.com, together with a mechanism to subscribe to notifications of additions or replacements. The notice and objection process is described in Section 5. As of the "last updated" date above, these subprocessors fall into the following categories: cloud hosting and infrastructure (e.g., Amazon Web Services); website hosting (e.g., Vercel); error monitoring and diagnostics (e.g., Sentry); product analytics (e.g., PostHog); payment processing (e.g., Stripe); enterprise authentication and directory sync (e.g., WorkOS); and transactional email (e.g., Resend).
In addition, Openlayer engages OpenAI as a model-provider subprocessor to power Openlayer's managed AI features (such as the Openlayer Assistant and AI-assisted insights), under terms intended to prohibit OpenAI from using the data Openlayer sends to train its models and to limit retention.
Customer-configured model providers are not Openlayer subprocessors. Where Customer connects its own third-party model providers and credentials (for example, to run evaluations or LLM-as-a-judge against a provider such as OpenAI, Anthropic, Microsoft Azure OpenAI, Amazon Web Services (Bedrock), Google, or Cohere), those providers Process data under Customer's own account and agreements and are Customer's vendors, not Openlayer's subprocessors. Self-hosted and on-premise deployments do not use Openlayer's cloud subprocessors except those the customer chooses to configure.
Exhibit C: Technical and Organizational Measures
- Encryption of Personal Data in transit and at rest; encryption of secrets and credentials before storage;
- Role-based access controls, least-privilege access, and multi-factor authentication for administrative access;
- Network controls, logging, and monitoring of access to systems Processing Personal Data;
- Secure software development practices, change management, and vulnerability management;
- Logical separation of customer environments and data;
- Personnel confidentiality obligations, security training, and background checks where permitted by law;
- Business continuity, backup, and incident response procedures; and
- Vendor risk management and ongoing assessment of subprocessors.
- AI-specific safeguards for managed AI features, including engaging model-provider subprocessors under terms that prohibit training on and limit retention of Customer Personal Data, logical separation of Customer Personal Data from any model-improvement data, input and output controls, and monitoring for unauthorized disclosure.