In plain language
- This agreement applies when personal data in your code or tickets goes through our relay with Reqursor Credits, or when you send us material for support.
- In those cases you are the controller and we are your processor. We act only on your instructions.
- The relay does not store your prompts or the model's answers.
- Our sub-processors are listed on a public page, and we tell you 30 days before we add or change one.
- If you use your own model provider account, we do not receive your prompts, and this agreement has nothing to process.
- It applies automatically, with no signature needed. We sign a copy on request.
1. About this agreement and when it applies
This agreement is between Reqursor Technologies ("Reqursor", "we", "us"), a company based in Rotterdam, The Netherlands (KvK number: 42184274), and the business that uses Reqursor Development ("you", "the customer"). It is part of the Terms of Service and meets the requirements of article 28 of the General Data Protection Regulation (GDPR).
It applies where we process personal data on your behalf as your processor. That happens in two situations:
- Reqursor Credits. When you use Reqursor Credits, your model requests pass through our relay on their way to the model provider. The requests can contain personal data, for example names or email addresses in code, tickets, comments or files.
- Support material. When you send us material for support, such as a diagnostics bundle, logs or attachments, that contains personal data. We are the controller for the contact details of the person who writes to us, and your processor for the attachments, logs and files they send.
It does not apply where we are the controller. We are the controller for the account, license, billing and usage data we use to run licenses, credits and billing, and for the other data described in our Privacy Policy. It also does not apply if you use your own model provider account, because then your prompts go straight to your provider and we do not receive them.
This agreement covers Reqursor Development. Reqursor Platform has its own Data Processing Addendum.
This agreement forms part of the agreement under the Terms of Service from the moment you accept them, by starting a trial, activating or buying a license, or using Reqursor Development, and you do not need to sign it. If you need a signed copy, email [email protected] and we sign it.
2. Terms used
"Personal data", "controller", "processor", "data subject", "processing", "personal data breach" and "supervisory authority" have the meaning they have in the GDPR. "Customer personal data" means the personal data that we process on your behalf under this agreement. "Sub-processor" means a processor that we engage to process customer personal data.
3. What we process and why
- Subject matter and purpose. We forward your model requests to the model provider and return the answers, and we count the usage for credits. The usage records we keep are controller data, as section 1 says. We also handle the support material you send us in order to help you.
- Nature of the processing. For credits, the relay receives and checks each request in memory, forwards it and returns the answer. It does not store the request or the answer. For support, we receive, read and keep the material for as long as we need it to help you.
- Duration. For credits, for as long as you use them, and only in transit through our relay. For support material, until the support request is closed, and no longer than we need it.
- Types of personal data. Any personal data that is in your tickets, code, comments, files, commit data or tool results that you send. You decide what that is. It can include names, email addresses, usernames and other identifiers.
- Categories of data subjects. People whose data appears in your material, such as your employees, contractors, customers and users.
- Sensitive data. The product is not designed for special categories of personal data (such as health data) or data about criminal convictions, and we offer no safeguards beyond those in this agreement. Do not send them through Reqursor Credits. If you do, you do so on your own responsibility, and you must have a legal basis and have checked that these safeguards, including that Anthropic may keep requests for a limited time, are enough for you.
4. Your instructions
We process customer personal data only on your documented instructions, including on transfers to a third country, unless Union or Member State law that applies to us requires otherwise. In that case we tell you before the processing, unless that law forbids it on important grounds of public interest. This agreement, the Terms of Service and your use of the product are your instructions, including your choice to use Reqursor Credits, which sends your requests to Anthropic and to our other sub-processors. We tell you if we think an instruction breaks data protection law.
You are responsible for having a legal basis for the data you send, for giving the notices that the law requires to the people concerned, and for the instructions you give us. If you process the data for someone else as their processor, you confirm that you are authorized to give us these instructions, and we act as your sub-processor on the terms of this agreement.
5. Confidentiality
We make sure that the persons authorized to process customer personal data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality.
6. Security
We take appropriate technical and organizational measures to protect customer personal data, as article 32 of the GDPR requires. For Reqursor Credits, these measures include:
- The relay encrypts the connection with TLS.
- The relay does not store requests or answers. It reads them in memory only for as long as it needs to check them and to count the usage.
- The relay logs only what it needs to run the service, and never a request body, a query string or a header value. Access logs are kept for at most 30 days.
- The relay does not forward your license credentials, cookies or Reqursor headers to the provider. It forwards the checked request and a short list of standard headers, and it adds our own provider credentials.
- The relay accepts only standard fields of a model request, applies request and spending limits per license, and can be switched off by us.
- Usage records carry no code or ticket text. The relay deletes delivered records 7 days after delivery. A record that our license server rejects stays on the relay, with identifiers and token counts only, until we have reviewed and deleted it.
Our security page describes our controls in more detail. We review and improve our measures as the risks and the technology change.
7. Sub-processors
You give us a general written authorization to engage sub-processors. The current list is on our sub-processor page.
- We will tell you at least 30 days before we add or replace a sub-processor, by email to the contacts on your license and by updating the list. Keep the contact addresses on your license up to date, because we send notices there.
- You can object to a new sub-processor on reasonable grounds relating to data protection, by email to [email protected] within 30 days of our notice. If you do not object in time, the change takes effect at the end of the notice period. We work with you in good faith to find a solution. If we cannot find one, you can stop using Reqursor Credits and use your own model provider account instead, and nothing in the software requires credits. You can also end your subscription by written notice before the change takes effect, and we then refund the prepaid fees for the period after the end date. Credits you have bought stay on your balance, as the Refund, Cancellation and Credits Policy says. We do not send customer personal data to the new sub-processor while your objection is open.
- We have a written agreement with each sub-processor that imposes data protection obligations that meet article 28(4) of the GDPR. We remain responsible to you for what our sub-processors do.
8. International transfers
We are established in the European Union. When we transfer customer personal data to a sub-processor outside the European Economic Area, we make sure that the transfer has an appropriate safeguard, such as an adequacy decision of the European Commission or the standard contractual clauses of the European Commission for transfers to processors (module 3).
If a competent authority or the law that applies to you requires a transfer safeguard for personal data that we return to you outside the European Economic Area, and no other safeguard applies, the parties will conclude the standard contractual clauses of the European Commission that fit that situation, which at the date of this agreement is module 4 (processor to controller) of Decision (EU) 2021/914. We sign them on request, and we agree with you in writing the choices that the clauses leave open before they apply. The clauses prevail over this agreement where they conflict.
9. Helping you
We help you meet your obligations under the GDPR, taking into account the nature of the processing:
- Requests from data subjects. If a data subject asks us to use their rights over customer personal data, we send them to you and tell you, unless the law forbids it. The relay does not store prompts or answers, so we hold none there, but Anthropic may keep requests and answers for a limited time, as section 11 says. We help you with the support material we hold.
- Security, breaches, impact assessments and consultations. We give you the information you reasonably need for your obligations under articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultations.
10. Personal data breaches
We tell you without undue delay after we become aware of a personal data breach that affects customer personal data, including a breach at a sub-processor, by email to the contacts on your license. We tell you what we know about the nature of the breach, the data and the people concerned, the likely consequences and the measures we take, and we update you as we find out more. You decide whether and how to tell the supervisory authority and the people concerned.
11. Deletion and return
For credits, the relay does not store customer personal data, so there is nothing for us to return or delete there. Our sub-processor Anthropic may keep requests and answers for a limited time under its commercial terms, and we cannot delete them earlier or return them to you. We have no zero-retention agreement with Anthropic. At your choice, we return or delete the support material that contains customer personal data when we no longer need it for the support request, or earlier if you ask us to. When we stop providing the services to you, we delete or, at your choice, return the customer personal data we still hold, and we delete existing copies, unless Union or Member State law requires us to keep them. The usage records and the other data we hold as a controller are covered by our Privacy Policy.
12. Information and audits
We give you the information you reasonably need to show that we meet this agreement. We first answer your questions and security questionnaires in writing, if you send them to [email protected]. If that is not enough, you can have an audit carried out by you or an independent auditor bound by confidentiality, once a year, and also whenever a supervisory authority requires it or after a personal data breach that affects customer personal data, with at least 30 days' notice (less where the authority requires it), during business hours, without unreasonable disruption and at your cost.
13. Liability
The liability limits of the Terms of Service apply to this agreement, and one limit applies to the Terms of Service and this agreement together. They do not limit the rights of data subjects against either of us under article 82 of the GDPR, or any liability that cannot be limited by law. If standard contractual clauses apply under section 8, clause 12 of those clauses prevails.
14. Term, order of precedence and law
This agreement lasts as long as we process customer personal data for you. If it conflicts with the Terms of Service, an order or a license agreement on the processing of personal data, this agreement prevails. We may update this agreement for a valid reason, such as a change in the law, and we tell you 30 days in advance, as the Terms of Service describe for changes. A change never reduces the protection that article 28 of the GDPR requires and never changes standard contractual clauses that apply. Dutch law applies, and the District Court of Rotterdam (Rechtbank Rotterdam) has exclusive jurisdiction, as the Terms of Service state, without limiting the rights of data subjects.
15. Contact
For questions about this agreement, to ask for a signed copy or to object to a sub-processor, contact us:
- Legal: [email protected]
- Privacy: [email protected]
- Security questionnaires: [email protected]
- Contact form: reqursor.com/contact
- Reqursor Technologies, Rotterdam, The Netherlands. KvK number: 42184274
Data Protection Contact
[email protected] · Reqursor Technologies, Rotterdam, The Netherlands