When your API requests contain personal data, you stay in control of it and we process it only to answer the request. This DPA sets that out in GDPR Art. 28 terms: transient, EU/EEA-based processing, no retention of content, no training on your data, and a published list of sub-processors.
This Data Processing Agreement ("DPA") forms part of the Terms of Servicebetween you (the "Customer") and snowLEX Oy, Helsinki, Finland. It applies to personal data contained in the content you submit to the API and the output returned for it ("API Content"), for which you are the controller and snowLEX Oy the processor within the meaning of GDPR Art. 4.
For account, billing and request metadata, snowLEX Oy is an independent controller — that processing is described in the Privacy Policy and is outside this DPA.
snowLEX processes API Content only on the Customer's documented instructions (GDPR Art. 28(3)(a)). The Terms, this DPA and each API call — including its parameters — constitute those instructions. snowLEX does not use API Content to train models. snowLEX will inform the Customer if, in its opinion, an instruction infringes the GDPR or other EU or member-state data protection law.
Persons authorized to process API Content are bound by contractual or statutory confidentiality obligations (Art. 28(3)(b)), and access is limited to what their role requires.
snowLEX implements appropriate technical and organizational measures under GDPR Art. 32, including:
The Customer grants a general written authorization to engage the sub-processors listed at /legal/subprocessors (Art. 28(2)). snowLEX imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains liable for their performance. Changes to the list are announced in advance via the console or email; the Customer may object on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, the Customer may terminate the affected service with a refund of its unused prepaid balance.
Taking into account the nature of the processing, snowLEX assists the Customer with appropriate technical and organizational measures in fulfilling data-subject requests (Arts. 12–23) and in meeting the Customer's obligations under Arts. 32–36 (security, breach notification, impact assessments), insofar as the information is available to snowLEX. Because API Content is not retained, requests concerning it can typically be answered from the Customer's own records.
API Content is processed transiently and is not stored by the platform, so deletion occurs by design at the end of each request. Upon termination of the Terms, snowLEX deletes remaining personal data it processes as controller in accordance with the Privacy Policy, except where EU or member-state law requires continued storage (Art. 28(3)(g)).
snowLEX notifies the Customer without undue delay after becoming aware of a personal data breach affecting API Content, providing the information reasonably available to it to support the Customer's obligations under Arts. 33–34.
snowLEX makes available the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits conducted by the Customer or an auditor it mandates (Art. 28(3)(h)): at most once per year, on at least 30 days' notice, during business hours, under confidentiality, at the Customer's expense, and without access to other customers' data.
API Content is processed within the EU/EEA; the current processing locations are listed at /legal/subprocessors. snowLEX will not transfer API Content outside the EU/EEA unless a Chapter V transfer mechanism (such as an adequacy decision or Standard Contractual Clauses) is in place, and will inform the Customer in advance of any such change.
In case of conflict between this DPA and the Terms, this DPA prevails for data-protection matters. Liability under this DPA is subject to the limitations in the Terms to the extent permitted by law. Governing law and venue follow the Terms (Finnish law; Helsinki District Court).