Data Processing Agreement
This Data Processing Agreement (DPA) applies when you use Elpis to process personal data of your own customers or employees, for example incidents that contain personal data. It supplements our Terms of Service.
1. Roles
You are the controller of personal data you submit to Elpis. Elpis is the processor handling that data on your instructions, namely to provide the service. Where Elpis determines its own purposes (billing, security logs, our own marketing), Elpis acts as a controller for that data.
2. Subject matter, duration and nature
Subject matter: personal data contained in incidents, evidence, configurations and runbooks you put into Elpis. Duration: for as long as your account is active, plus deletion of backups on their normal rotation. Nature: storage, retrieval, AI analysis and display, strictly to deliver the service as described in the Privacy Policy.
3. Your instructions
We process personal data only on your documented instructions, which include your configuration of Elpis (for example which services it watches and which LLM provider it uses). If we ever believe an instruction violates applicable law, we will notify you unless legally prohibited.
4. BYOK note
When you connect your own LLM provider key, Elpis transmits incident content to that provider to fulfil your instruction. In that case that provider processes the data under your relationship with them, and their terms also apply to that transfer.
5. Our security obligations
We implement the technical and organisational measures described on our Security page, which we may improve over time, and we will not materially reduce them in a way that weakens protection for your data. Anyone allowed to process data under this DPA is bound to confidentiality.
6. Subprocessors
You authorize Elpis to use subprocessors as listed on our Subprocessors page. We remain responsible for their handling of your data as if it were our own, and we update that page when the list changes.
7. International transfers
Where personal data is transferred across borders, we rely on standard contractual clauses (or another recognized transfer mechanism) with the receiving party where required by law.
8. Assistance and data subject requests
Taking into account the nature of the processing, we will help you fulfil your obligations to respond to data subject requests, by enabling you to access, correct or delete personal data through the service or by deleting it on your documented instruction.
9. Breach notification
If we become aware of a breach of personal data under your control processed through Elpis, we will notify you without undue delay and provide the information reasonably needed for you to meet your own notification duties.
10. Deletion and return
When the agreement ends, we will delete or return personal data, at your choice, unless retention is required by law. Just email us your instruction after account deletion.
11. Audit
You may request reasonable information about our compliance with this DPA. If an audit right is required by your regulator, we will agree a sensible process (for example a questionnaire or an inspection with reasonable notice) that does not disrupt other customers.
12. Acceptance
By entering a paid engagement you accept this DPA on behalf of your organisation. Need a signed copy or changes? Email notsekiro11@gmail.com and we will countersign.