Cedreon Data Processing Agreement
1. What this agreement is, and how it becomes applicable
This Data Processing Agreement ("DPA") governs Cedreon's processing of personal data that you submit as part of your content. It is incorporated by reference into the Cedreon Terms of Service and forms part of them. Accepting the Terms makes this DPA applicable between you and Cedreon; no separate signature is required for it to be in force.
An organisation may additionally sign an individually executed copy from its account page, for its own data-protection records. That produces an execution record naming both parties, the exact version and its hash. It does not change what this DPA says or when it started applying.
Terms defined in the GDPR (Regulation (EU) 2016/679) and in the Swiss Federal Act on Data Protection ("FADP") have the same meaning here. Where both apply, each applies to the processing it governs.
2. Roles
For content you submit through the service, you are the controller and Cedreon is the processor. Where your own client is the controller, you are their processor and Cedreon is a sub-processor; you confirm you have the authority to appoint us.
For account, billing and website data, Cedreon is a controller in its own right. That processing is described in the Privacy Policy, not here.
Cedreon does not determine the purposes of processing Customer Content and does not use it for any purpose of its own.
3. Subject matter, duration, nature and purpose
Cedreon processes personal data contained in the messages, documents and files you submit, for the purpose of operating the screened AI interface described in the Terms, for as long as you have an account and for the retention periods in clause 11.
Categories of data subject: your personnel; your clients, patients or counterparties; and any other individual whose data appears in content you submit.
Categories of personal data: whatever your content contains. In practice, for the professions Cedreon serves, this routinely includes identification data, contact data, financial identifiers, and case or matter details. It may include special categories of personal data under Article 9 GDPR and data relating to criminal convictions and offences under Article 10 GDPR where your practice involves them. You decide what you submit.
Processing operations: collection, recording, structuring, storage, screening and pseudonymisation, transmission to a Model Provider, retrieval, restoration of pseudonymised values for the authorised reader, erasure.
4. Your instructions
Cedreon processes personal data only on your documented instructions. Your configured use of the service is your instruction, and the settings you choose, including the store-nothing mode and any Compliance Profile, form part of it.
We will tell you if, in our opinion, an instruction infringes applicable data protection law, and we may suspend processing of that instruction until it is resolved.
If we are required by Swiss or EU law to process for another purpose, we will tell you before doing so unless that law forbids it.
Instructions beyond the scope of this DPA and the Terms are given in writing or by email. Where we agree to follow one, clause 15 applies to the cost.
5. Confidentiality of processing
Everyone we authorise to process your personal data is bound by a confidentiality obligation that survives the end of their engagement with us, whether by contract or by statutory duty. Access is granted on a need-to-know basis and is limited to what an individual needs to operate, support or secure the service.
Organisations subject to professional-secrecy obligations may sign an additional professional-confidentiality agreement; see /switzerland and /europe.
6. Security of processing
Cedreon implements the technical and organisational measures described at /security, which forms Annex 3 to this DPA. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risks to data subjects, those measures are appropriate to the risk within the meaning of Article 32 GDPR.
The measures specific to this product, rather than to hosting in general, are:
- Screening and pseudonymisation before forwarding. Recognised sensitive values in your content are replaced with reversible placeholders before any request reaches a Model Provider. The provider receives the placeholder. The mapping is encrypted at rest and is restored only for the authorised reader.
- A European routing boundary. Requests leave through a gateway endpoint that will not route to a provider outside Europe, and each is pinned to one named European processor with fallback disabled. See clause 8 and Annex 2.
- Encryption in transit and at rest of stored content, of the placeholder mapping, and of stored documents.
- An append-only, hash-chained record of every exchange. It does not store the plaintext of your prompts or of model responses; it retains integrity and operational metadata, described in clause 11.
- Erasure that crypto-shreds the placeholder mapping, which makes the original values unrecoverable while the integrity record stays intact.
- A store-nothing mode in which no copy of content is written at all.
Detection is layered and best-effort. It combines checksum-validated patterns with a locally run recognition model. Unusual formats can be missed, and we state that rather than warranting complete detection.
We may change a measure for one that is equivalent or better. We will not reduce the overall level of security.
7. Sub-processors
You give general written authorisation for Cedreon to engage sub-processors. The current list, what each one does and where it processes, is published at /subprocessors and forms Annex 2 to this DPA.
We will publish a change to that list, and notify the account contact of each organisation, at least 30 days before it takes effect. If you reasonably object on data-protection grounds within that period, we will work with you in good faith to find a solution; if none is found, you may terminate the affected part of the service without penalty and receive a pro-rata refund for the unused remainder of the paid period.
Where we engage a sub-processor, we impose on it data protection obligations equivalent to those in this DPA, by contract or another legally binding instrument. Cedreon remains fully liable to you for a sub-processor's performance of those obligations.
Engaging a third party for ancillary services that do not involve access to Customer Content, such as telecommunications or facilities, is not the engagement of a sub-processor.
8. International transfers
Application data is processed in the European Union and in Switzerland.
Model inference is processed in the European Union. Every model request is made through a gateway established in the European Union, on an endpoint that routes only to providers cleared for processing in Europe and rejects a request no such provider can serve. Each request is additionally pinned to a single named Model Provider with provider fallback disabled, so it is served by the entity named in Annex 2 or it fails. Every Model Provider named in Annex 2 is established in the EU or EEA and processes there. Transfers from Switzerland to the EEA rest on the Federal Council's adequacy recognition, and no further transfer mechanism is required for this processing.
That is a statement about where a request is processed. It is not a statement about where the model was built: most are built outside Europe by companies that do not receive the request. An organisation that requires both may use a Compliance Profile under clause 10 of the Terms.
Two optional features, both off by default and both switched on per conversation, may process outside the EEA: web search, whose provider's serving region is not yet contractually pinned, and search of a Google account you have connected. Where such a transfer leaves the EEA or Switzerland, it is made under an adequacy decision, or under the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with the Swiss addendum recognised by the FDPIC where Swiss law applies. The two features carry different supplementary measures, and we state the difference rather than averaging it: a query sent to your connected Google account is destructively masked before it leaves, so the recipient receives no identifying value the screening layer recognised; a web-search query is sent as you typed it, because masking a search changes its answer, which is why the feature stays off until you deliberately switch it on, and why the switch itself says so. A Compliance Profile withholds both features entirely.
If a transfer mechanism is invalidated or ceases to be recognised, we will adopt an alternative permitted mechanism without undue delay.
An organisation may narrow this further with a Compliance Profile, which restricts processing to routes approved for that profile. See clause 10 of the Terms.
9. Assisting you
Taking into account the nature of the processing and the information available to us, Cedreon will assist you:
- to answer a data subject's request under Articles 15 to 22 GDPR. Content is owner-scoped and can be read and retrieved from the product by its owner; where you need our help, write to [email protected]. If a data subject contacts us directly about content you control, we will not respond substantively and will refer them to you without undue delay;
- to meet your obligations under Articles 32 to 36 GDPR on security, breach notification, data protection impact assessments and prior consultation.
10. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Content. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point.
Where we cannot provide all of that at once, we will provide it in phases without further undue delay. We will document every breach and assist you with your own notification duties.
Notifying you is not an acknowledgement of fault.
11. Retention, return and deletion
- Content you delete is deleted, together with the placeholder mapping for it.
- Account content is deleted when the account is closed. The deletion is immediate and cannot be undone. There is no recovery window: closing an account destroys the stored conversations and documents it owns and crypto-shreds its placeholder mapping in the same act, which is what makes the original values unrecoverable. Take a copy of anything you need before closing.
- The append-only record is retained for 10 years. It does not store the plaintext of your prompts or of model responses. It retains integrity and operational metadata: identifiers, timestamps, model information, content digests, references to the encrypted stored payload, screening outcomes, policy decisions and token counts. Deleting content destroys the encrypted mapping and the stored payload a reference points at; the metadata survives, and what survives is not readable as content.
- Where your workspace runs in store-nothing mode, no content copy is written at all.
On termination of the service, we will delete or return personal data at your choice. You must tell us your choice within 30 days of termination; if you do not, we may delete it, unless Swiss or EU law requires us to keep it. Where law requires retention, the data stays subject to this DPA for as long as it is retained. We will confirm deletion in writing on request.
12. Audit
Cedreon will make available the information needed to demonstrate compliance with this DPA and will contribute to audits, including inspections, conducted by you or an auditor you mandate and who is not a competitor of Cedreon.
In the first instance we will provide our current documentation, any third-party certifications or audit reports we hold, and answers to your questions. Where that is genuinely not sufficient, you may request an on-site inspection on 30 days' written notice, during business hours, no more than once in a calendar year outside a breach, in a way that minimises disruption, and subject to confidentiality and to not compromising other customers' data. A breach or a regulator's requirement lifts the once-a-year limit.
The append-only record is deliberately part of the answer here: it is machine-verifiable evidence of what was processed, when, and under which policy decision, without exposing content.
13. Data protection officer and representative
Cedreon appoints a data protection officer where Article 37 GDPR requires one, and will publish the contact details at /privacy where it does. Until then, data protection enquiries go to [email protected].
14. Records of processing
Cedreon maintains a record of processing activities carried out on your behalf under Article 30(2) GDPR, and will make the relevant extract available to you or to a supervisory authority on request.
15. Costs
Everything Cedreon does under this DPA is covered by the fees agreed in the Terms, with two exceptions: assistance we give under clauses 9 and 12 that goes materially beyond what those clauses require, and processing under an instruction beyond the scope of this DPA and the Terms. Those are charged at our standard rates, and we will tell you the expected cost before we begin.
No charge is made for anything required to meet our own obligations under data protection law, or for assistance following a breach caused by us.
16. Liability
The liability provisions of the Terms apply to this DPA, and the cap in them is a single aggregate cap across both.
Article 82 GDPR governs each party's liability to data subjects. As between the parties, each bears the share of any administrative fine or damages that corresponds to its own responsibility, as determined by a final decision of a competent court or supervisory authority.
17. Term and final provisions
This DPA takes effect with the Terms and remains in force for as long as Cedreon processes personal data on your behalf. It survives termination of the Terms to the extent needed to complete deletion or return under clause 11, and ends when that is done.
Where this DPA and the Terms conflict on the processing of personal data, this DPA prevails.
We may update this DPA where changes in applicable law, regulatory guidance or a binding decision of a supervisory authority require it. We will give at least 30 days' written notice unless a shorter period is legally required. If you object on reasonable grounds and no mutually acceptable solution is found within a reasonable period, you may terminate the affected processing activities on written notice.
If a provision is invalid, the rest stands and is interpreted to achieve the same result as far as the law allows.
Annex 1: Details of the processing
Subject matter: provision of the screened AI interface described in the Terms.
Duration: the term of the Terms, plus the retention periods in clause 11.
Nature and purpose: screening, pseudonymisation, transmission to a Model Provider, storage of a minimised copy, restoration of pseudonymised values for the authorised reader, and generation of an append-only integrity record.
Types of personal data: as set out in clause 3.
Categories of data subject: as set out in clause 3.
Annex 2: Sub-processors
Published and maintained at /subprocessors, which forms part of this DPA.
Annex 3: Technical and organisational measures
Published and maintained at /security, which forms part of this DPA.
Version 1.2, in force from 2026-08-28