1. Scope and precedence
This Data Processing Agreement (the “DPA”) forms part of each Order that incorporates it between the customer and Palace Leap LLC, operating as Palace Ring. It applies when Palace Ring processes Customer Personal Data on behalf of the customer in connection with the Agreement.
The Agreement consists of the Order, these data terms, the Terms of Service and incorporated service documents. For Customer Personal Data, this DPA controls over conflicting general terms. The EU Standard Contractual Clauses or UK Addendum control where they expressly require. Service-specific security, residency, retention or sovereignty commitments apply only to the scope stated in the Order.
2. Definitions
- Applicable Data Protection Law
- Privacy, data protection and breach-notification law applicable to Palace Ring’s processing of Customer Personal Data under the Agreement, including the GDPR, UK GDPR and applicable U.S. state privacy laws.
- Customer Personal Data
- Personal Data contained in Customer Content and processed by Palace Ring on behalf of the customer under the Agreement.
- GDPR
- Regulation (EU) 2016/679.
- Security Incident
- A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by Palace Ring. Unsuccessful attempts that do not compromise Customer Personal Data are excluded.
- Subprocessor
- A third party engaged by Palace Ring to process Customer Personal Data on behalf of the customer.
- UK GDPR
- The GDPR as it forms part of United Kingdom law, together with applicable UK data-protection legislation.
“Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “processing,” “Processor,” “sell” and “share” have the meanings given by Applicable Data Protection Law. Other capitalized terms have the meanings in the Agreement.
3. Processing instructions
The customer is Controller of Customer Personal Data or a Processor acting on another Controller’s behalf. Palace Ring is a Processor or Subprocessor. Each party will comply with the law applicable to its role. The customer determines the purposes and essential means of processing; Palace Ring processes Customer Personal Data only on documented instructions.
The Agreement, the customer’s authorized configuration and use of the Services, and written directions consistent with the Agreement constitute documented instructions. Palace Ring will process Customer Personal Data only to provide, secure, support and administer the Services, follow those instructions, and comply with law. Palace Ring will notify the customer before processing required by law unless the law prohibits notice.
If Palace Ring reasonably believes an instruction violates Applicable Data Protection Law, it will notify the customer and may suspend the affected processing while the parties identify a lawful instruction. Additional work outside the Service description may require a written change order and reasonable fees.
Palace Ring will provide information reasonably necessary to demonstrate compliance with its obligations under this DPA and will maintain records required of it as Processor.
4. Customer obligations
The customer warrants that it has a lawful basis and all required rights, notices, consents and authority for Customer Personal Data and its instructions. The customer is responsible for data accuracy, minimization, retention choices, authorized-user administration, Service configuration, responding to Data Subjects, and determining whether the Services are suitable for regulated or high-risk processing.
The customer will submit special-category, sensitive, criminal-offense, children’s, health, biometric, genetic, classified or export-controlled data only when the Order expressly authorizes that data class and required safeguards are in place. The customer will not instruct Palace Ring to process data in violation of law or outside the agreed Service.
If the customer acts as Processor, it confirms that its Controller authorized Palace Ring as Subprocessor and that the customer’s instructions reflect the Controller’s documented instructions. The customer remains the single point of contact for its Controller and Data Subjects.
5. Confidentiality
Palace Ring will restrict access to Customer Personal Data to personnel and contractors who require it for the Agreement. Those persons will be bound by contractual or statutory confidentiality duties, receive appropriate privacy and security instruction, and be subject to access controls and disciplinary consequences appropriate to their role. Confidentiality obligations survive the end of access and the Agreement.
6. Security
Taking account of the state of the art, implementation cost, nature, scope, context and purposes of processing, and risks to individuals, Palace Ring will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data. The baseline measures are described in Schedule 2; the Order may add service-specific measures.
Palace Ring may update measures to address evolving threats, technology and Services, provided the overall level of protection is not materially reduced during an Order. Palace Ring will periodically assess the effectiveness of relevant measures and remediate identified material risk in accordance with its risk-management process.
The customer is responsible for security within its accounts, endpoints, applications, identity systems, networks, integrations, data classification and configurations, and for features under its administrative control.
7. Subprocessors
The customer gives general written authorization for Palace Ring to use the Subprocessor categories in Schedule 3 and the specific Subprocessors made available through the contracting channel. Palace Ring will enter into a written agreement with each Subprocessor imposing data-protection obligations that provide materially equivalent protection for the processing assigned to it. Palace Ring remains responsible for a Subprocessor’s performance of those obligations to the extent required by Applicable Data Protection Law.
Palace Ring will provide at least 15 days’ advance notice before authorizing a new Subprocessor that will materially process Customer Personal Data, unless an urgent security, continuity or legal need makes advance notice impracticable. The notice will identify the Subprocessor, location and function.
The customer may object during the notice period on reasonable, documented data-protection grounds. The parties will work in good faith toward a commercially reasonable alternative. If Palace Ring cannot provide one, the customer may terminate the affected Service without penalty and receive a refund of prepaid fees for the unused affected period. This is the customer’s exclusive remedy for a Subprocessor objection.
8. Data Subject requests
Taking account of the nature of processing, Palace Ring will provide commercially reasonable technical and organizational assistance for the customer to respond to verified requests under Applicable Data Protection Law. If Palace Ring receives a request concerning Customer Personal Data, it will direct the requester to the customer and will not independently respond unless the customer authorizes it or law requires it.
The customer will use available Service functions before requesting manual assistance. Palace Ring may charge reasonable fees for material assistance beyond standard functionality when the request results from the customer’s configuration, instruction or failure to use available tools, unless law allocates the cost differently.
9. Security Incidents
Palace Ring will notify the customer without undue delay after becoming aware of a Security Incident. Notice will be delivered to the customer contact configured for security notices or the contact in the Order. Palace Ring may provide information in phases as the investigation proceeds.
To the extent known and legally permitted, notice will describe the nature of the Security Incident, affected data and Data Subjects, likely consequences, containment and remediation, and a contact for follow-up. Palace Ring will take reasonable steps to contain, investigate and remediate the Security Incident and will preserve relevant evidence consistent with security and legal requirements.
The customer is responsible for deciding whether and how to notify regulators, Data Subjects or others. Palace Ring will provide reasonable assistance based on available information. Notification or cooperation is not an admission of fault or liability. The customer will notify Palace Ring promptly of incidents originating in customer-controlled systems that may affect the Services.
10. Assessments and regulatory cooperation
Taking account of the nature of processing and information available to Palace Ring, Palace Ring will reasonably assist the customer with data-protection impact assessments, transfer assessments, prior consultation with a supervisory authority, and compliance inquiries relating to Customer Personal Data. Assistance may include relevant architecture, processing, security, Subprocessor and transfer information.
Palace Ring will cooperate with competent supervisory authorities as required by law. If Palace Ring receives a legally binding demand for Customer Personal Data, it will notify the customer before disclosure unless prohibited, review the demand for legal validity, seek to narrow overbroad demands, and disclose only the information legally required.
11. Return and deletion
During the term, the customer may retrieve Customer Personal Data using available export functions or the process in the Order. At the customer’s choice, Palace Ring will return or delete Customer Personal Data after the affected Service ends and delete remaining copies, except where law requires retention. The customer must communicate its choice before termination or within the export window stated in the Order; absent a timely choice, Palace Ring may delete the data under its retention schedule.
Data in backups, disaster-recovery media, immutable security records or legal holds will remain protected, isolated from ordinary use and deleted or rendered inaccessible through the applicable lifecycle. Palace Ring may retain evidence of deletion and limited records needed to demonstrate compliance.
12. Audits
Palace Ring will make available information reasonably necessary to demonstrate compliance, which may include security summaries, certifications, independent assessments, policies, questionnaire responses and Subprocessor information. The customer will treat non-public assurance materials as Confidential Information.
Where those materials are insufficient, the customer may conduct one audit in any 12-month period, and an additional audit after a material Security Incident or when required by a competent authority. The customer will provide at least 30 days’ notice when practicable, use an independent qualified auditor bound by confidentiality, conduct remote review first, avoid disruption and refrain from accessing another customer’s data or Palace Ring trade secrets.
The customer bears its audit costs and Palace Ring’s reasonable costs for extraordinary assistance. Palace Ring bears its own costs when an audit identifies a material breach of this DPA by Palace Ring. The parties will promptly discuss findings and a proportionate remediation plan.
13. International transfers
Palace Ring will use a lawful transfer mechanism for a Restricted Transfer of Customer Personal Data. An adequacy decision or another valid mechanism applies where available. Otherwise, the following terms apply automatically to the relevant transfer.
European Economic Area
The European Commission Standard Contractual Clauses issued under Implementing Decision (EU) 2021/914 (the “EU SCCs”) are incorporated by reference. Module 2 applies when the customer is Controller and Palace Ring is Processor; Module 3 applies when the customer is Processor and Palace Ring is Subprocessor. Clause 7 applies; Clause 9 uses Option 2 with the notice period in the Subprocessor section; the optional language in Clause 11 is omitted; Clause 17 uses Option 1 and the law of Ireland; and the courts of Ireland apply under Clause 18(b). Schedules 1–3 complete Annexes I–III. The supervisory authority is determined under Clause 13.
The parties will document and reasonably cooperate on transfer impact assessments and supplementary measures. Palace Ring will notify the customer if it can no longer comply with the EU SCCs and will take appropriate steps, including suspension of the affected transfer when required.
United Kingdom
The ICO International Data Transfer Addendum to the EU SCCs, version B1.0 in force 21 March 2022 as revised under its mandatory update mechanism (the “UK Addendum”), is incorporated for Restricted Transfers governed by UK law. The parties and transfer details are those in the Order and Schedule 1; the selected EU SCC module and appendices are completed as above; both exporter and importer may exercise termination rights available when the approved Addendum changes. The mandatory clauses of the approved UK Addendum apply without modification that reduces their protection.
Switzerland and other jurisdictions
For Swiss transfers, references in the EU SCCs to the GDPR and EU law include the Swiss Federal Act on Data Protection where applicable; “Member State” is interpreted to preserve Swiss Data Subject rights; and the competent Swiss authority and courts apply as required. For another jurisdiction, the parties will use the applicable statutory clauses or execute a lawful transfer addendum.
14. U.S. state privacy laws
For Customer Personal Data governed by a U.S. state privacy law, Palace Ring acts as a “service provider,” “contractor” or “processor,” as applicable. Palace Ring will process the data only for the limited and specified purposes in the Agreement and will comply with obligations applicable to that role.
- Palace Ring will not sell or share Customer Personal Data, retain, use or disclose it outside the business purposes and direct relationship in the Agreement, or combine it with personal data received from another person or collected through Palace Ring’s own consumer interactions except as law permits.
- Palace Ring will provide the same level of privacy protection required by applicable law, notify the customer if it determines it can no longer meet its obligations, and permit the customer to take reasonable and appropriate steps to stop and remediate unauthorized use.
- Palace Ring will assist with verified consumer requests and required assessments in accordance with this DPA, require covered subcontractors to provide appropriate protection, and make compliance information available for reasonable monitoring.
- The customer may take reasonable steps to ensure Palace Ring uses Customer Personal Data consistently with the customer’s obligations, subject to the audit process above.
15. Term and general provisions
This DPA begins when incorporated into an Order and continues while Palace Ring processes Customer Personal Data. Duties concerning confidentiality, return or deletion, audits, transfers and liability survive as required for retained data or by law.
Liability under this DPA is subject to the exclusions and limitations in the Agreement, except to the extent Applicable Data Protection Law or the EU SCCs prohibit a limitation. Nothing in this DPA limits a Data Subject’s rights under mandatory law or the EU SCCs.
Palace Ring may update this public DPA to reflect changes in law or Services. An update will not materially reduce protection for Customer Personal Data during an active Order. Changes required by law take effect as required; other material changes apply on renewal or after notice through the contracting channel. The parties will execute reasonably necessary amendments to preserve lawful processing.
Questions about this DPA may be sent to privacy@palacering.com. Formal legal notices may be sent to legal@palacering.com and the notice address in the Order.
Schedule 1 · Processing and transfer details
| Element | Details |
|---|---|
| Parties and roles | The customer and Palace Leap LLC, operating as Palace Ring. The customer is Controller or Processor; Palace Ring is Processor or Subprocessor. For the EU SCCs, the customer is data exporter and Palace Ring is data importer unless the transfer facts require the reverse. |
| Subject matter | Provision of the AI, model access, inference, training, compute, infrastructure, support and professional Services described in the Order. |
| Duration | The Order term plus the period needed for authorized return, deletion, security, backup expiry, legal hold and compliance records. |
| Nature and purpose | Receiving, recording, organizing, structuring, storing, adapting, retrieving, consulting, using, transmitting to authorized recipients, aligning, restricting, securing, returning and deleting data to provide and support the Services under customer instructions. |
| Frequency | Continuous, recurring or ad hoc according to authorized use of the Services. |
| Data Subjects | Customer authorized users; workforce, contractors and representatives; customers, constituents, citizens, students, researchers, applicants, suppliers, patients or other individuals whose data the customer lawfully submits, depending on the Order. |
| Personal Data | Identity, professional and contact data; account, authentication and authorization data; device, network, usage, security and support records; prompts, inputs, files, datasets and Output; and other categories expressly described in the Order. |
| Sensitive data | None by default. Special-category, sensitive, criminal-offense, health, biometric, genetic, children’s, classified or export-controlled data is permitted only when expressly authorized in the Order with appropriate safeguards. |
| Processing locations | Locations of Palace Leap LLC and authorized Subprocessors, subject to residency commitments in the Order and the transfer terms in this DPA. |
| Controller rights | The customer retains all rights and duties of Controller, including instructions, access, correction, deletion, restriction, export, objection and termination as provided by the Agreement and law. |
| Competent authority | For EU SCCs, the authority determined under Clause 13 from the customer’s establishment, representative or affected Data Subjects. For the UK Addendum or Swiss law, the authority designated by the applicable law. |
Schedule 2 · Technical and organizational measures
Palace Ring applies the following baseline control domains as appropriate to the Service and risk. Service-specific implementations and customer-controlled responsibilities are recorded in the Order or security documentation.
| Control domain | Measures |
|---|---|
| Governance and risk | Documented security responsibilities, risk assessment, policy review, asset and data classification, change control, exception handling and management oversight. |
| Identity and access | Role-based and least-privilege access, unique identities, strong authentication for privileged access, access approval and revocation, periodic review, session controls and logging appropriate to the environment. |
| Cryptography | Industry-standard encryption for data in transit over untrusted networks and encryption at rest where supported by the selected Service, with controlled key access and lifecycle practices. |
| Environment protection | Logical tenant separation, network controls, hardened configurations, secrets management, malware defenses where relevant, restricted administrative interfaces and controlled production access. |
| Secure development and change | Code and configuration review, dependency and vulnerability management, testing, release controls, separation of duties appropriate to team size, and remediation prioritized by risk. |
| Logging and detection | Security and administrative logging, time synchronization, protected log access, monitoring of material events, alert triage and retention appropriate to risk and the Order. |
| Incident response | Documented escalation, containment, investigation, evidence preservation, recovery, notification and post-incident improvement procedures, with contact paths for customers and providers. |
| Availability and resilience | Capacity monitoring, backup or recoverability appropriate to the Service, redundancy where contracted, continuity planning, recovery testing and dependency management. |
| Personnel | Confidentiality commitments, role-appropriate screening where lawful, security and privacy instruction, acceptable-use duties, and prompt access removal after role change or departure. |
| Suppliers | Risk-based diligence, written data-protection and security terms, access limitation, material-change oversight and offboarding procedures for Subprocessors. |
| Data lifecycle | Collection limitation, configurable retention where offered, controlled export, deletion processes, media handling and protection of backups and legal holds. |
| Physical protection | Facility access controls, visitor management, environmental safeguards and secure equipment handling provided directly or through qualified datacentre and infrastructure operators. |
| Assurance | Periodic control assessment, vulnerability testing, independent assurance where available, corrective-action tracking and provision of appropriate compliance information. |
Schedule 3 · Authorized Subprocessor categories
The following categories are authorized when needed for the Service. The current entity-level list, function and processing country are available through the contracting channel and subject to the notice and objection process above.
| Category | Processing function |
|---|---|
| Cloud, datacentre and network providers | Compute, hosting, storage, connectivity, content delivery, facilities and resilience. |
| AI model and platform providers | Customer-selected or Service-integrated inference, embeddings, evaluation, fine-tuning, training and model operations. |
| Security and observability providers | Identity, access, logging, monitoring, abuse prevention, vulnerability management and incident response. |
| Software and data-service providers | Databases, object storage, workflow, deployment, support tooling and service administration. |
| Communications and support providers | Transactional email, support case management, customer communications and service notifications. |
| Billing and payment providers | Usage metering, invoicing, payment processing, fraud prevention and financial administration. |
| Professional and managed-service providers | Authorized implementation, operations, audit, technical support, field service and incident assistance where access to Customer Personal Data is required. |
| Affiliated entities | Contract administration, support, security, engineering and delivery under common control and equivalent protections. |