Darcy Dispatch Data Processing Addendum
Last Updated
Version 10012026 — Effective October 1, 2026
This Data Processing Addendum (this “DPA”) forms part of the agreement between Innovative Data Processing Solutions LLC (“Innovative”) and Customer for the MMR Services, consisting of the Innovative Managed Model Router Terms and Conditions (the “MMR Terms”), the Innovative Standard Terms and Conditions (the “Standard Terms”), the Darcy Dispatch Account Terms (the “Account Terms”), the Darcy Dispatch Acceptable Use Policy, and any Order Form, including an Online Order (together, the “Agreement”). This DPA applies automatically, without a separate signature, whenever Customer accepts the Agreement, including by signing an Order Form or accepting the Account Terms. Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. DEFINITIONS
1.1 “Customer Personal Data” means Personal Data contained in Customer Content that Innovative processes on Customer’s behalf in providing the MMR Services. Customer Personal Data does not include Account Data or Service Records.
1.2 “Account Data” means information about Customer and its Authorized Users that Innovative collects to create and administer accounts, verify eligibility, bill, communicate, provide support, and secure the MMR Services, such as names, business contact details, login credentials, and payment information.
1.3 “Service Records” means the records described in Section 9.2(d) of the MMR Terms, including Routing Telemetry, metering, billing, and payment records, Savings Statements, tags and classifications, guardrail and audit records, and configuration settings, none of which include the text of prompts or outputs.
1.4 “Personal Data” means information that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable individual or household, and any information defined as “personal information,” “personal data,” or a similar term under U.S. Privacy Laws.
1.5 “U.S. Privacy Laws” means all U.S. federal and state laws and regulations that apply to Innovative’s processing of Customer Personal Data under the Agreement, including, as applicable, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations (the “CCPA”), and the comprehensive consumer privacy laws of other U.S. states.
1.6 “Non-U.S. Data Protection Laws” means any law of a jurisdiction outside the United States that governs the processing of Personal Data, including the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Australian Privacy Act 1988, Canada’s Personal Information Protection and Electronic Documents Act and Quebec’s Law 25, Brazil’s Lei Geral de Proteção de Dados, China’s Personal Information Protection Law, Japan’s Act on the Protection of Personal Information, Korea’s Personal Information Protection Act, India’s Digital Personal Data Protection Act, and any similar law.
1.7 “Subprocessor” means any third party that Innovative engages to process Customer Personal Data, including Underlying Model Providers and infrastructure providers.
1.8 “Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data while it is processed by Innovative or its Subprocessors. Unsuccessful attempts and activities that do not compromise the security of Customer Personal Data, such as pings, port scans, blocked log-in attempts, and denial-of-service attacks, are not Security Incidents.
1.9 Other Terms. “Business,” “Service Provider,” “Controller,” “Processor,” “Consumer,” “Sell,” “Share,” “Business Purpose,” “Sensitive Personal Information,” and “Deidentified” have the meanings given in the applicable U.S. Privacy Law, and each corresponding term under another U.S. Privacy Law is included.
2. SCOPE AND ROLES
2.1 Roles. As to Customer Personal Data, Customer is the Business or Controller, and Innovative is Customer’s Service Provider or Processor. Where Customer acts as a Service Provider or Processor for a third party, Innovative is Customer’s Subprocessor, and Customer is responsible for obtaining that third party’s authorization for this DPA and for passing on any instructions.
2.2 Innovative’s Own Data. Innovative processes Account Data and Service Records as an independent business, under its privacy policy and the Agreement, including Section 9.3 of the MMR Terms. This DPA does not apply to Account Data or Service Records, except that Section 6 (Security) applies to them.
2.3 Details of Processing. Annex 1 describes the processing of Customer Personal Data.
3. UNITED STATES ONLY; PROHIBITED JURISDICTIONS AND DATA
The MMR Services are designed, priced, and contracted solely for U.S. organizations processing data about individuals in the United States. Innovative does not offer, and this DPA does not include, any standard contractual clauses, international data transfer agreement, or other mechanism required by Non-U.S. Data Protection Laws.
3.1 U.S. Organizations Only. Customer represents and warrants that it is organized under the laws of a U.S. state or the District of Columbia and has its principal place of business in the United States, and that it will notify Innovative within ten (10) business days if either ceases to be true.
3.2 Permitted Territory Only. Customer shall ensure that Customer, its Authorized Users, its End Users, and every system that submits requests to Darcy Dispatch are located in the Permitted Territory under Section 10.2 of the MMR Terms, which is limited to the fifty (50) U.S. states and the District of Columbia unless a signed Order Form expressly states otherwise.
3.3 Prohibited Jurisdictions. Without limiting Section 3.2, Customer shall not permit any access to or use of the MMR Services from, and shall not submit any Personal Data of individuals located in or resident in: (a) any member state of the European Economic Area, the United Kingdom, or Switzerland; (b) Australia; (c) any country or region subject to comprehensive U.S. sanctions or embargoes, which as of the effective date of this DPA include Cuba, Iran, North Korea, and the Crimea, so-called Donetsk People’s Republic, and so-called Luhansk People’s Republic regions of Ukraine; (d) any country of concern under 28 C.F.R. Part 202, which as of the effective date of this DPA are China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia, and Venezuela; and (e) any other jurisdiction whose Non-U.S. Data Protection Laws would apply to that access or Personal Data (together, the “Prohibited Jurisdictions”). Innovative may update the Prohibited Jurisdictions at any time to reflect changes in law or sanctions, effective when posted.
3.4 No Data Subject to Non-U.S. Laws. Customer shall not submit to the MMR Services any Personal Data that is subject to Non-U.S. Data Protection Laws, and shall not use the MMR Services for any processing that would require a cross-border transfer mechanism, a data protection representative, or a data processing agreement under Non-U.S. Data Protection Laws.
3.5 Countries of Concern and Covered Persons. Neither party will knowingly give any country of concern or covered person, as defined in 28 C.F.R. Part 202, access to Customer Personal Data, and Customer shall not submit bulk U.S. sensitive personal data or U.S. government-related data, as defined in that Part, to the MMR Services. Innovative’s Provider Standards require restricted-party screening, and Innovative does not route Customer Content to Underlying Model Providers that are based in, or controlled from, a country of concern.
3.6 Prohibited Data. Unless a signed Order Form expressly permits it and any supplemental agreement it requires is in place, Customer shall not submit: (a) protected health information under HIPAA; (b) payment card data; (c) Social Security numbers, driver’s license, passport, or other government identification numbers, or financial account numbers; (d) biometric identifiers or information, genetic data, or precise geolocation data; (e) Personal Data of children under thirteen (13), or any Personal Data that Customer knows relates to a minor under eighteen (18) where U.S. Privacy Laws impose heightened requirements; (f) consumer report information under the Fair Credit Reporting Act; (g) criminal justice information, controlled unclassified information, classified information, or export-controlled data; or (h) any other Sensitive Personal Information or sensitive data whose processing requires consent or an assessment under U.S. Privacy Laws that Customer has not obtained or completed (together, “Prohibited Data”).
3.7 Consequences. Innovative has no obligation to detect Prohibited Data or activity from a Prohibited Jurisdiction, but it may use geolocation, verification, and other controls to prevent it. If Innovative believes that Customer has breached this Section 3, Innovative may, without notice, block requests, suspend or terminate the MMR Services in whole or in part, and delete the affected data, and Section 10.8 of the MMR Terms applies. Innovative’s obligations under this DPA do not extend to data Customer submits in breach of this Section 3, and Customer shall indemnify Innovative under the Agreement for any claim arising from that breach.
4. PROCESSING INSTRUCTIONS AND SERVICE PROVIDER COMMITMENTS
4.1 Instructions. Innovative processes Customer Personal Data only on Customer’s documented instructions. The Agreement, together with Customer’s configuration of Darcy Dispatch, including routing controls, tags, guardrails, budgets, and any logging or history features Customer enables, constitutes Customer’s complete instructions. Innovative will inform Customer if, in its opinion, an instruction violates U.S. Privacy Laws, and may decline to follow it.
4.2 Business Purpose. Customer discloses Customer Personal Data to Innovative only for the limited and specified Business Purpose of providing the MMR Services described in the Agreement, including routing, metering, savings calculation, security, fraud prevention, and support.
4.3 Restrictions. Innovative will not: (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the Business Purpose, including any commercial purpose other than providing the MMR Services, or as otherwise permitted by U.S. Privacy Laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Innovative and Customer; (d) combine Customer Personal Data with Personal Data it receives from or on behalf of another person or collects from its own interactions with individuals, except as permitted for Service Providers under U.S. Privacy Laws; or (e) use Customer Personal Data or Customer Content to train, fine-tune, or otherwise improve any artificial intelligence or machine learning model, consistent with Section 9.2 of the MMR Terms.
4.4 Compliance and Notice. Innovative will comply with the obligations that U.S. Privacy Laws impose on Service Providers and Processors, will provide the level of privacy protection they require, and will notify Customer if it determines that it can no longer meet those obligations. Customer may then take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data, including by suspending use of the MMR Services.
4.5 Deidentified Data. Where Innovative creates aggregated or deidentified data as permitted by Section 9.3 of the MMR Terms, it will do so only from Service Records or in a manner that meets the requirements for Deidentified data under U.S. Privacy Laws, will take reasonable measures to ensure the data cannot be associated with an individual or household, will publicly commit to maintaining and using it only in deidentified form, and will not attempt to reidentify it.
4.6 No Remuneration. The parties acknowledge that Customer does not provide Customer Personal Data to Innovative in exchange for monetary or other valuable consideration, and that no Sale or Sharing of Customer Personal Data occurs under the Agreement.
4.7 Customer Responsibilities. Customer is responsible for the accuracy and lawfulness of Customer Personal Data and its instructions, for providing all notices and obtaining all consents required to submit Customer Personal Data to the MMR Services, including notices of the use of AI where required, and for honoring opt-outs and other rights of Consumers.
5. ZERO DATA RETENTION AND DELETION
5.1 Zero Data Retention. Innovative does not store Customer Personal Data contained in prompts or outputs after returning the response to a Metered Request, other than transiently as needed to process it, except (a) where Customer enables logging, history, or similar features; (b) short-term caching used solely to serve Customer’s own requests; (c) for trust and safety review under Section 10.8(b) of the MMR Terms, or as required by law or to investigate a security incident; and (d) to the extent Personal Data appears in Service Records, such as a user identifier in a billing record. Each Underlying Model Provider must meet the Zero Data Retention standard in Section 9.4(a)(iii) of the MMR Terms.
5.2 Deletion. Customer may delete Customer Personal Data retained through logging or history features at any time through Darcy Dispatch or by request. Within ninety (90) days after the MMR Services end, Innovative will delete any Customer Personal Data it still retains, except data it must retain by law, which remains subject to this DPA for as long as it is retained. Innovative will confirm deletion in writing on request.
6. SECURITY
6.1 Measures. Innovative will implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the data and the risks of processing, designed to protect Customer Personal Data, Account Data, and Service Records against Security Incidents, including the measures in Annex 2. Innovative may update those measures, provided it does not materially reduce the overall protection of Customer Personal Data.
6.2 Personnel. Innovative will ensure that personnel authorized to process Customer Personal Data are subject to a duty of confidentiality and receive appropriate privacy and security training, and will limit access to those who need it.
7. SUBPROCESSORS
7.1 General Authorization. Customer generally authorizes Innovative to engage Subprocessors, including Underlying Model Providers and infrastructure, hosting, and security providers, to process Customer Personal Data.
7.2 Subprocessor Terms. Innovative will engage each Subprocessor under a written contract, or under terms that Innovative accepts in writing, that requires the Subprocessor to meet obligations with respect to Customer Personal Data that are appropriate to its role, and, for Underlying Model Providers, that meet the Provider Standards in Section 9.4 of the MMR Terms, including no training, U.S.-only inference and storage, and Zero Data Retention.
7.3 Subprocessor Page. Innovative will maintain at https://darcyiq.com/dispatch/subprocessors a page (the “Subprocessor Page”) identifying its infrastructure Subprocessors by name and its Underlying Model Providers by category and by the Provider Standards they meet. Because Underlying Model Providers change frequently and their identities are Innovative’s Confidential Information under Section 4.5(c) of the MMR Terms, the Subprocessor Page does not name them.
7.4 Changes and Objection. Innovative may change Subprocessors at any time and will update the Subprocessor Page to reflect changes to infrastructure Subprocessors and categories. To the extent U.S. Privacy Laws require it, and notwithstanding Section 13.7 of the Standard Terms as modified by Article 13 of the MMR Terms, Customer may object to a change on reasonable data protection grounds by written notice within fifteen (15) days after the Subprocessor Page is updated. The parties will discuss the objection in good faith. If they cannot resolve it, Customer’s sole remedy is to stop using, or terminate, the affected MMR Services, and no Early Termination Fee or Shortfall Charge applies to a termination under this Section.
7.5 Responsibility. Subject to the limitations of liability in the Agreement, Innovative is responsible for the acts and omissions of its Subprocessors with respect to Customer Personal Data to the extent U.S. Privacy Laws require. Section 12.4 of the MMR Terms continues to apply, and no commitment of an Underlying Model Provider is passed through to Customer.
8. ASSISTANCE
8.1 Consumer Requests. Customer is responsible for responding to requests from Consumers to exercise their rights under U.S. Privacy Laws. Because of Zero Data Retention, Innovative generally does not hold Customer Personal Data that could be accessed, corrected, or deleted. Taking into account the nature of the processing, Innovative will provide reasonable assistance, including through Darcy Dispatch features, and will promptly forward to Customer any request it receives that identifies Customer, without responding to it except as required by law.
8.2 Assessments. Innovative will provide information reasonably necessary for Customer to conduct any data protection or risk assessment that U.S. Privacy Laws require of Customer in connection with the MMR Services, to the extent the information is available to Innovative and does not disclose its Confidential Information, including the identity of Underlying Model Providers. Innovative may charge a reasonable fee for assistance beyond information it makes generally available.
8.3 Legal Requests. If a government authority requests Customer Personal Data from Innovative, Innovative will, unless legally prohibited, attempt to redirect the authority to Customer and will notify Customer promptly so that it may seek a protective order or other remedy.
9. SECURITY INCIDENTS
Innovative will notify Customer without undue delay after confirming a Security Incident. The notice will describe, to the extent then known, the nature of the Security Incident, the categories of data affected, and the steps Innovative has taken or will take to contain and remediate it, and Innovative will supplement it as more information becomes available. Innovative will take reasonable steps to contain, investigate, and mitigate each Security Incident and will reasonably cooperate with Customer’s investigation and any notices Customer must give. Unless U.S. Privacy Laws require otherwise, Customer is responsible for notices to individuals and regulators about Customer Personal Data. Innovative’s notice of, or response to, a Security Incident is not an acknowledgment of fault or liability.
10. COMPLIANCE INFORMATION AND AUDITS
On written request no more than once in any twelve (12) month period, Innovative will make available information reasonably necessary to demonstrate its compliance with this DPA, which may include a summary of its security program, a copy of Innovative’s current organization-wide SOC 2 Type II report, subject to confidentiality, completed security questionnaires, and confirmation that its Underlying Model Providers meet the Provider Standards. Where U.S. Privacy Laws require more, Innovative will allow and cooperate with reasonable assessments by Customer or an independent auditor bound by confidentiality, at Customer’s expense, on at least thirty (30) days’ notice, during business hours, and in a manner that does not disrupt Innovative’s operations or require access to other customers’ data or the identities of Underlying Model Providers. Alternatively, Innovative may arrange, at its expense, for a qualified and independent assessor to evaluate its compliance and provide a report to Customer. All information and results provided under this Section are Innovative’s Confidential Information.
11. LIABILITY; PRECEDENCE; CHANGES
11.1 Liability. Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement, including Section 12.8 of the MMR Terms, as if this DPA were part of the MMR Terms.
11.2 Precedence. As to the processing of Customer Personal Data, this DPA controls over any conflicting term of the Agreement, except that the Agreement controls as to limitations of liability, the non-disclosure of Underlying Model Providers, and Customer’s obligations under Articles 9 and 10 of the MMR Terms, which this DPA supplements.
11.3 Changes. Innovative may update this DPA to reflect changes in law, the MMR Services, or its Subprocessors, effective when posted. An update that materially reduces the protection of Customer Personal Data applies to an existing Customer beginning with its next Renewal Term, or thirty (30) days after posting for a Customer with no Commitment, unless the update is required by law.
11.4 Term. This DPA remains in effect for as long as Innovative processes Customer Personal Data under the Agreement.
ANNEX 1 — DETAILS OF PROCESSING
Subject matter | Provision of the MMR Services, including routing Customer’s requests to Underlying Models through Darcy Dispatch. |
Duration | The term of the Agreement and any period afterward during which Innovative retains Customer Personal Data as permitted by Section 5. |
Nature and purpose | Receiving, transmitting, and transiently processing prompts and outputs to route and serve Metered Requests; applying guardrails and tags; metering; security; and support, all as instructed under Section 4.1. |
Categories of individuals | Customer’s Authorized Users and End Users, and individuals whose Personal Data Customer includes in prompts, all located in the United States. |
Categories of Personal Data | Any Personal Data Customer chooses to include in prompts or that appears in outputs, as determined solely by Customer, excluding Prohibited Data. |
Sensitive data | None, unless a signed Order Form expressly permits a category of Prohibited Data. |
Retention | Zero Data Retention, subject to the exceptions in Section 5.1. |
Location | United States only. |
ANNEX 2 — SECURITY MEASURES
Encryption. Data in transit is encrypted using TLS 1.2 or higher, and any Customer Personal Data retained at rest is encrypted using AES-256 or an equivalent standard.
Access control. Role-based, least-privilege access; multi-factor authentication for administrative access; unique credentials; prompt removal of access for departing personnel; and periodic access reviews.
Zero Data Retention by design. Prompts and outputs are processed in memory and not written to persistent storage, except as described in Section 5.1.
Guardrails. Customer-configurable detection, redaction, or blocking of secrets and personal data before any model receives them, with audit records that do not contain the detected data.
Logging and monitoring. Security logging, monitoring, and alerting for Darcy Dispatch infrastructure, retained as Service Records.
Vulnerability management. Regular patching, vulnerability scanning, and periodic penetration testing.
Incident response. A documented incident response plan that is tested at least annually.
Vendor management. Due diligence and written terms for Subprocessors, including the Provider Standards for Underlying Model Providers, and periodic review of their security attestations.
Business continuity. Redundant infrastructure and tier failover designed to maintain service availability.
Attestation. Innovative maintains a current SOC 2 Type II report covering its organization-wide security controls, available to Customer on request, subject to confidentiality.
ANNEX 3 — SUBPROCESSOR CATEGORIES
Underlying Model Providers. Providers of AI model inference that meet the Provider Standards, located in the United States. Not individually named, as described in Section 7.3.
Cloud infrastructure. Amazon Web Services, Inc., United States: hosting of Darcy Dispatch.
