Data Processing Addendum
Status: interim, pending counsel-reviewed publication. This addendum forms part of the order form between LogiRoot AI Inc. ("LogiRoot") and the customer named on that order form (the "Customer").
1. Roles
For the content the Customer submits for governance (prompts, tool calls, model outputs, workspace transcripts and the decisions recorded about them), the Customer is the controller and LogiRoot is the processor. For account data (sign-in email, tenant name, billing tier, marketplace identifiers), LogiRoot is the controller and processes it only to operate the account and bill for it.
2. What LogiRoot processes, and why
- Governance decisions: the action a governed agent asked to take, the decision returned, its reason codes, timing and the model identifier, recorded as a signed receipt so the Customer can check it later.
- Workspace transcripts: the turns of a governed conversation, stored so a session can be reopened, encrypted at rest under a key bound to the Customer's tenant, and deletable by the Customer.
- Usage and audit events: counts and operational events needed to meter the subscription and to show the Customer what happened on its tenant.
LogiRoot does not use Customer content to train or improve models, does not sell or share it, and does not run third-party analytics on the dashboard. Model providers the Customer connects with its own credentials are engaged by the Customer, not by LogiRoot.
3. Sub-processors
LogiRoot runs on Amazon Web Services. AWS is the only sub-processor that stores Customer content. LogiRoot will give active Customers at least 30 days' notice by email before adding a sub-processor that would store Customer content (a contractual undertaking).
4. Security measures
The measures LogiRoot applies today are stated on the security page, where each statement is limited to what has been measured on the production system, and where anything not yet available is listed as not yet available. That page is the description of security measures for this addendum; it is not a certification, and no third-party audit has been completed yet.
5. Retention and deletion
Default retention windows are set out in the order form. On a Customer's written request, LogiRoot deletes the Customer's workspace transcripts and account data within 30 days and confirms the deletion in writing (a contractual undertaking). Signed decision receipts are retained for the lifetime of the account plus any legal hold, because they are the evidence the governance exists to produce; the Customer may export them at any time from the dashboard.
6. Security incidents
If LogiRoot becomes aware of unauthorised access to Customer content, it will notify the Customer by email without undue delay and within 72 hours of becoming aware, with what is known at the time and what is being done (a contractual undertaking).
7. Assistance and audit
LogiRoot will assist the Customer with data-subject requests that concern Customer content, and will answer reasonable written security questionnaires. On request, and no more than once a year unless an incident has occurred, LogiRoot will make the measurements behind the security page available for review.
8. Transfers
Customer content is stored in the United States. Where the Customer is subject to GDPR or UK GDPR, the parties rely on the standard contractual clauses (module two, controller to processor), incorporated by reference into the order form.
9. Term and precedence
This addendum lasts as long as LogiRoot processes Customer content. If it conflicts with the order form on the handling of personal data, this addendum prevails. Material changes are communicated to active Customers by email at least 30 days before they take effect.
Contact
Privacy and processing questions: privacy@logirootai.com
Data Protection Officer (interim): dpo@logirootai.com