Kurrens Data Processing Addendum
Last Updated: September 28, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other written agreement (the “Agreement”) between INFERERA PTE. LTD. (“Kurrens” or “Processor”) and the customer that accepts it (“Customer” or “Controller”). It applies when Kurrens processes Customer Personal Data on Customer’s behalf. It is accepted automatically when Customer accepts the Terms of Service; a countersigned copy is available on request to [email protected].
1. Definitions
- “Data Protection Laws” means all laws applicable to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Singapore Personal Data Protection Act 2012 (“PDPA”), and the California Consumer Privacy Act, each as applicable.
- “Customer Personal Data” means personal data contained in Customer Content (inputs and outputs) or otherwise processed by Kurrens on Customer’s behalf under the Agreement.
- “Sub-processor” means any third party engaged by Kurrens to process Customer Personal Data.
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- “SCCs” means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914, and “UK Addendum” means the UK International Data Transfer Addendum issued by the UK Information Commissioner.
- Terms such as “controller,” “processor,” “data subject,” “personal data,” and “processing” have the meanings given in the GDPR.
2. Roles and Scope
2.1. Customer is the controller (or a processor acting on behalf of its own controller), and Kurrens is the processor (or sub-processor) of Customer Personal Data. For California law purposes, Kurrens is a “service provider.”
2.2. The subject matter, nature, purpose, duration, categories of data, and data subjects are described in Annex I.
3. Processing Instructions
3.1. Kurrens will process Customer Personal Data only on Customer’s documented instructions, which are the Agreement, this DPA, and Customer’s configuration and use of the Services, unless required to do otherwise by law (in which case Kurrens will inform Customer unless legally prohibited).
3.2. Kurrens will not sell or share Customer Personal Data, retain, use, or disclose it for any purpose other than providing the Services, or combine it with personal data received from other sources, except as permitted by Data Protection Laws.
3.3. Zero Data Retention. Kurrens will process Customer Content in accordance with the Data Policy, including not storing, logging, or using Customer Content for training. Nothing in this DPA narrows those commitments.
4. Confidentiality
Kurrens ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
5. Security
Kurrens implements the technical and organizational measures described in Annex II. Kurrens may update these measures provided that the overall level of security is not reduced.
6. Sub-processors
6.1. Customer authorizes Kurrens to engage the Sub-processors listed at https://kurrens.ai/legal/subprocessors.
6.2. Kurrens will give at least [[thirty (30)]] days’ notice of any new Sub-processor by updating that page and notifying customers who subscribe to updates (subscription via [email protected]). Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected Services and receive a refund of prepaid, unused fees for them.
6.3. Kurrens imposes data protection obligations on each Sub-processor that are no less protective than this DPA and remains liable for its Sub-processors’ performance.
7. Data Subject Requests
Taking into account the nature of processing (including that Customer Content is not retained), Kurrens will provide reasonable assistance to Customer in responding to data subject requests. If Kurrens receives a request directly, it will refer the data subject to Customer where the request relates to Customer Personal Data.
8. Security Incidents
Kurrens will notify Customer without undue delay, and in any event within [[forty-eight (48)]] hours, after becoming aware of a Security Incident affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations.
9. Assistance
Kurrens will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Data Protection Laws and relating to Kurrens’s processing.
10. Deletion
Customer Content is not retained after each request (see the Data Policy). Upon termination of the Agreement, Kurrens will delete any other Customer Personal Data within the period described in the Privacy Policy, unless retention is required by law.
11. Audits
Kurrens will make available information reasonably necessary to demonstrate compliance with this DPA, including [[third-party audit reports or certifications when available]]. Where that information is insufficient, Customer may, no more than once per year and with at least thirty (30) days’ notice, conduct an audit at its own cost, during business hours, subject to reasonable confidentiality and security conditions.
12. International Transfers
12.1. Customer Personal Data may be processed in the locations listed on the Sub-processors page.
12.2. To the extent Kurrens processes Customer Personal Data originating in the EEA in a country not recognized as providing adequate protection, the parties agree to the SCCs, Module Two (controller to processor) or Module Three (processor to processor), as applicable, which are incorporated by reference, with the following selections: Clause 7 (docking clause) applies; Clause 9 Option 2 (general authorization) with the notice period in Section 6.2; Clause 11 optional language does not apply; Clause 17 governing law is [[Ireland]]; Clause 18 forum is the courts of [[Ireland]]. Annexes I and II of this DPA complete the SCC annexes.
12.3. For transfers from the UK, the UK Addendum applies. For transfers from Switzerland, the SCCs apply with references adapted to Swiss law.
12.4. For transfers from Singapore, Kurrens ensures a standard of protection comparable to the PDPA.
13. General
This DPA is governed by the governing law of the Agreement, except as required by the SCCs. If this DPA conflicts with the Agreement, this DPA controls with respect to its subject matter. If it conflicts with the SCCs, the SCCs control.
Annex I — Description of Processing
| Item | Description |
|---|---|
| Data exporter | Customer (see Customer’s account details) |
| Data importer | INFERERA PTE. LTD., 152 Beach Road, #11-05, Gateway East, Singapore 189721; contact [email protected] |
| Data subjects | Any individuals whose personal data Customer includes in inputs to the Services, and Customer’s authorized users |
| Categories of personal data | Determined by Customer; may include any personal data contained in prompts, files, and outputs; account users’ names, emails, and API usage metadata |
| Special categories | Not intended; Customer should not submit special category data unless it has a lawful basis and appropriate safeguards |
| Nature and purpose | Running AI model inference on Customer’s inputs and returning outputs; authentication, billing, and security |
| Frequency | Continuous, per API request |
| Duration | Customer Content: in memory for the duration of each request only. Account and metadata: for the term of the Agreement plus the retention periods in the Privacy Policy |
| Sub-processors | See https://kurrens.ai/legal/subprocessors |
Annex II — Technical and Organizational Measures
⚠️ Replace with measures that are actually implemented before publishing.
- Data minimization: inference inputs and outputs are held in memory only and are excluded from logs.
- Encryption: TLS 1.2+ for all data in transit; encryption at rest for account, billing, and metadata stores; API keys stored as salted hashes.
- Access control: least-privilege, role-based access to production systems; multi-factor authentication for administrative access; access reviews at least [[quarterly]].
- Logging and monitoring: administrative access and production changes are logged; logs exclude Customer Content.
- Network security: segmented networks for inference infrastructure; firewalls and rate limiting at the edge.
- Vulnerability management: regular patching, dependency scanning, and a public vulnerability disclosure program (https://kurrens.ai/security).
- Incident response: documented incident response procedure with customer notification as set out in Section 8.
- Business continuity: redundant capacity across [[N]] facilities; backups of account and billing data.
- Personnel: confidentiality agreements and security training for staff with production access.
- Sub-processor management: due diligence and contractual data protection obligations for all Sub-processors.