Data Processing Agreement.
The Article 28 terms that govern how routeur.ai processes personal data on your behalf when you use the gateway — between you (the controller) and Oliver Tappin Ltd, trading as routeur.ai (the processor).
Introduction & scope
This Data Processing Agreement ("DPA") forms part of, and is subject to, the routeur.ai Terms of Service (the "Agreement") between the customer ("you", the "Controller") and Oliver Tappin Ltd, trading as routeur.ai ("routeur.ai", "we", "us", the "Processor"). It applies whenever we process Personal Data on your behalf in providing the Service.
Where there is any conflict between this DPA and the rest of the Agreement on the subject of the processing of Personal Data, this DPA prevails. A counter-signed copy is available to customers on request at legal@routeur.ai.
Definitions
"Data Protection Law" means the UK GDPR, the EU GDPR and the Data Protection Act 2018, as applicable. Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given to them in Data Protection Law.
"Customer Personal Data" means Personal Data contained in the prompts, responses, configuration and account data that we process on your behalf. "Sub-processor" means any third party engaged by us to process Customer Personal Data.
Roles of the parties
You are the Controller of Customer Personal Data and we are your Processor: you determine the purposes and means of the processing, and we process only on your behalf. Where you are itself a processor acting for another controller, you appoint us as a Sub-processor and confirm you have the authority to do so.
The upstream model providers you choose to enable act as further Sub-processors or, where they so determine under their own terms, as independent controllers. You decide which providers are enabled for your account.
Scope & duration of processing
We process Customer Personal Data only while the Agreement is in force and as needed to provide the Service, plus any further period required to meet our legal obligations. Annex 1 sets out the subject matter, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects.
Our obligations as Processor
We will:
- process Customer Personal Data only on your documented instructions — which include the Agreement, your configuration of the Service, and this DPA — unless required to do otherwise by law, in which case we will inform you first unless that law prohibits it;
- ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality;
- not sell Customer Personal Data, and not use it to train our own models, whether or not payload retention is enabled;
- implement the technical and organisational measures set out in Annex 2; and
- inform you if, in our opinion, an instruction infringes Data Protection Law.
Security
We implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access — taking into account the state of the art, the costs of implementation, and the nature, scope and risk of the processing. A summary is set out in Annex 2 and described further on our security page.
routeur.ai is metadata-only by default: prompt and response content is processed in transit and is not retained unless you explicitly enable payload retention.
Sub-processors
You give a general authorisation for us to engage Sub-processors to help provide the Service. A current list is set out in Annex 3 and available on request. We impose data-protection obligations on each Sub-processor that are substantially the same as those in this DPA, and we remain responsible for their performance.
We will give you reasonable prior notice of any intended addition or replacement of a Sub-processor, and a means to object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the Service.
International transfers
Customer Personal Data is hosted in the region described on our security page (currently Google Cloud europe-west1). Where Customer Personal Data is transferred outside the UK or EEA — including to payment processors, or to the upstream providers you enable — we or you (as applicable) rely on an appropriate transfer mechanism, such as a UK or EU adequacy decision, the UK International Data Transfer Agreement and Addendum, or the EU Standard Contractual Clauses. You remain responsible for selecting upstream providers appropriate to your own transfer obligations.
Assistance to the Controller
Taking into account the nature of the processing and the information available to us, we will assist you with appropriate technical and organisational measures, insofar as possible, to: respond to requests from Data Subjects exercising their rights; and meet your obligations relating to security, breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority.
If we receive a request directly from a Data Subject relating to Customer Personal Data, we will — where lawful — refer them to you and not respond ourselves except on your instruction.
Personal data breaches
We will notify you without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, its likely consequences, and the measures taken or proposed — so that you can meet your own notification obligations. We will take reasonable steps to mitigate and remediate the breach.
Audits & inspections
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
To minimise disruption, we may satisfy an audit request by providing our security documentation, certifications, and responses to a reasonable security questionnaire. On-site inspections are by prior written agreement, during business hours, no more than once per year — except where required by a Supervisory Authority or following a Personal Data Breach.
Return & deletion of data
On termination of the Agreement, or on your written request, we will delete or return Customer Personal Data and delete existing copies, unless storage is required by law. Retention periods for the different categories of data are set out in our Privacy Policy; in particular, account data is deleted within 30 days of account closure, and encrypted backups age out on the schedule described on our security page.
Your obligations as Controller
You warrant that you have a lawful basis to process Customer Personal Data and to provide it to us and our Sub-processors; that your instructions comply with Data Protection Law; and that you have provided any notices and obtained any consents required from Data Subjects. You are responsible for the content of the prompts you send and for the upstream providers you enable.
Liability & general terms
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits any liability that cannot be limited under Data Protection Law.
This DPA takes effect when the Agreement begins and continues for as long as we process Customer Personal Data. If any provision is found invalid, the remainder continues in force. We may update this DPA to reflect changes to the Service, our Sub-processors, or Data Protection Law, giving notice of material changes. This DPA is governed by the laws of England and Wales.
Contact
To exercise rights under this DPA, request the current Sub-processor list or a counter-signed copy, or raise any data-protection matter, contact our Data Protection Officer, Oliver Tappin, at legal@routeur.ai.
Annex 1 — Details of processing
- Subject matter
- Provision of the routeur.ai LLM gateway service to the Controller.
- Duration
- The term of the Agreement, plus any retention period required by law or described in the Privacy Policy.
- Nature & purpose
- Routing, securing, logging and operating LLM requests on the Controller's behalf — including data-loss prevention, prompt shielding, output moderation, billing and observability.
- Types of Personal Data
- Account and contact data; billing metadata; and any Personal Data the Controller includes in prompts and that is returned in responses (content is processed in transit and retained only if payload retention is enabled). The Controller determines what Personal Data it sends.
- Categories of Data Subjects
- The Controller's personnel and authorised users; and any individuals whose Personal Data the Controller includes in prompts — which may include the Controller's own customers and end users.
Annex 2 — Technical & organisational measures
The measures below summarise our security posture; see the security page for detail.
- ✓Encryption in transit (TLS 1.2+, 1.3 preferred) and at rest (AES-256), with application-layer envelope encryption for credentials.
- ✓Metadata-only by default — prompt and response content is not retained unless payload retention is enabled.
- ✓Access control — authentication, MFA, role/group-based permissions and least privilege; staff production access is need-to-know, logged and reviewed.
- ✓Network isolation — private service-to-service networking and deny-by-default firewalling.
- ✓Append-only, tamper-evident audit logging of administrative actions.
- ✓Key management — hardened, access-logged key service with rotation.
- ✓Resilience — encrypted, restore-tested backups and documented disaster recovery (RTO 4h, RPO 1h).
- ✓Secure development — peer review, automated testing, dependency scanning and OWASP-aligned practices.
- ✓Incident response — a documented, tested process with breach notification.
Annex 3 — Sub-processors
The following Sub-processors are engaged to provide the Service. A current, authoritative list is available on request, and we notify customers of changes as described in section 07.
| Sub-processor | Purpose | Location / transfer |
|---|---|---|
| Google Cloud Platform | Cloud hosting, storage and key management | EU — Google Cloud europe-west1 |
| Google Workspace | Business email and customer correspondence | EU / USA — Standard Contractual Clauses |
| Resend | Transactional and platform email delivery | USA — Standard Contractual Clauses |
| Stripe | Subscription billing & payment processing | EU / USA — Standard Contractual Clauses |
| Upstream LLM providers (customer-configured — e.g. OpenAI, Google, Anthropic, Mistral, DeepSeek) | Model inference for the prompts you route | Provider's regions — per provider terms / SCCs |
| Google Analytics | Website usage analytics (consent-gated) | EU / USA — Standard Contractual Clauses |
| Microsoft Clarity | Website interaction analytics (consent-gated) | EU / USA — Standard Contractual Clauses |
This is the complete list. Google Analytics and Microsoft Clarity process website-visitor data — for which routeur.ai acts as controller, and which loads only with your consent (see our Privacy Policy) — rather than the Customer Personal Data you route through the gateway.