Skip to content

Data Processing Agreement

Last updated: August 18, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between cajeX ("Processor") and the customer ("Controller") and governs the processing of personal data by the Processor on behalf of the Controller. This DPA is designed to ensure compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and other relevant legislation.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller through the Service.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "Data Breach" means any unauthorized access to, or acquisition, use, or disclosure of Personal Data.

3. Scope and Purpose of Processing

The Processor shall process Personal Data only to the extent necessary to provide the Service as described in the Terms of Service. The categories of data processed include:

  • User account information (name, email, company).
  • Authentication and access log data.
  • Architecture project data and associated metadata.
  • Usage analytics and platform interaction data.

4. Obligations of the Processor

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller.
  • Ensure that all personnel authorized to process Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
  • Assist the Controller in responding to data subject requests.
  • Notify the Controller without undue delay upon becoming aware of a Data Breach.
  • Delete or return all Personal Data upon termination of the Service, at the Controller's choice.

5. Sub-processors

The Processor may engage Sub-processors to assist in providing the Service. The Processor shall maintain a current list of Sub-processors and shall notify the Controller of any intended changes. The Controller may object to a new Sub-processor within 30 days of notification. The Processor shall ensure that all Sub-processors are bound by data protection obligations no less protective than those in this DPA.

5.1 Current sub-processors

AI-assisted processing is performed by whichever model provider is in effect for a workspace — the platform default, or a model the Controller has explicitly selected in Settings → AI. As of August 2026, the platform default routes to United States-based providers only. The Controller controls this choice for every workspace, and may select a Cloudflare-hosted model to avoid engaging any external AI sub-processor entirely.

Sub-processorPurposeLocationPersonal data involved
Cloudflare, Inc.Hosting: compute, database, object storage, edge network, and inference for Cloudflare-hosted models (Kimi, Mistral).United StatesAll Service data.
OpenAIAI-assisted review, generation, and chat processing. The platform default model as of August 2026 — engaged for every workspace unless the Controller selects a different model.United StatesContent processed by AI features, for workspaces using the default or an OpenAI model.
GoogleAI-assisted document extraction (the default for this function as of August 2026), and AI-assisted review for workspaces configured to use a Gemini model.United StatesDocuments submitted for extraction, and content submitted for AI review for workspaces using this model.
AnthropicAI-assisted review processing, only for workspaces configured to use an Anthropic Claude model.United StatesContent submitted for AI review, for workspaces using this model only.
MiniMaxAI-assisted review processing, only for workspaces that specifically configure a MiniMax model — not the platform default and not engaged unless a workspace opts in.ChinaContent submitted for AI review, for workspaces using this model only.
Stripe, Inc.Payment processing and billing.United StatesBilling and payment data only — no architecture or governance data.
ResendTransactional email delivery.United StatesEmail address and notification content only.

MiniMax is located outside the EEA and the transfer safeguard for this Sub-processor is not yet finalized. It is not the platform default and is engaged only if a Controller specifically configures a workspace to use a MiniMax model. Controllers with EU data-residency requirements should not configure workspaces to use a MiniMax model, and may select any other listed model instead.

Controllers who require full control over which vendor processes their data — including avoiding every Sub-processor in this table — may enable Bring Your Own Key (BYOK) on Enterprise plans, which routes AI calls to a model endpoint the Controller configures and controls directly. A Controller-configured BYOK endpoint is the Controller's own vendor relationship and is not a Processor Sub-processor.

6. Data Transfers

The Processor shall not transfer Personal Data outside the European Economic Area (EEA) unless appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or an adequacy decision by the European Commission. Where data is processed in the United States, transfers are protected under the EU-US Data Privacy Framework where applicable.

7. Security Measures

The Processor implements the following security measures:

  • Encryption of data at rest (AES-256) and in transit (TLS 1.3).
  • Multi-tenant data isolation with strict access controls.
  • Regular security assessments and penetration testing.
  • Incident response procedures with defined escalation paths.
  • Employee security awareness training.
  • Access logging and monitoring with correlation IDs.

8. Data Breach Notification

In the event of a Data Breach, the Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach. The notification shall include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken to address the breach.

9. Audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller. The Processor shall provide documentation of its security practices upon reasonable request.

10. Term and Termination

This DPA shall remain in effect for the duration of the Terms of Service. Upon termination, the Processor shall delete or return all Personal Data within 30 days, unless retention is required by applicable law. The Controller may request a certificate of deletion.

11. Contact

For questions about this DPA, please contact our Data Protection Officer at privacy@cajex.ai.