Data Processing Agreement

Last updated: August 11, 2026

1. Scope and applicability

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and lynox AI, operated by Brandfusion Burlet, Neue Jonastrasse 71, 8640 Rapperswil SG, Switzerland ("Processor") for the provision of lynox Managed Hosting services.

This DPA applies where the Processor processes personal data on behalf of the Controller in the course of providing the Managed Hosting service. It supplements the Terms of Service and Privacy Policy.

This DPA does not apply to self-hosted installations of lynox, where the user is both controller and operator of their own infrastructure.

2. Definitions

3. Roles of the parties

The Controller determines the purposes and means of processing Personal Data through their use of the Services. The Processor processes Personal Data solely on behalf of and under the documented instructions of the Controller.

4. Subject matter and duration

The subject matter of processing is the provision of AI-assisted business operations via the lynox Managed Hosting platform. Processing begins when the Controller's managed instance is provisioned and continues for the duration of the subscription agreement.

5. Nature and purpose of processing

The Processor processes Personal Data to provide the following services on behalf of the Controller:

6. Types of personal data

The following categories of Personal Data may be processed depending on the Controller's use of the Services:

7. Categories of data subjects

8. Processor obligations

In accordance with Art. 28(3) GDPR and Art. 9 revDSG, the Processor shall:

8.1 Instructions

Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes applicable data protection law.

8.2 Confidentiality

Ensure that all persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

8.3 Security measures

Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in Annex: Security Measures.

8.4 Sub-processors

Not engage another processor without prior specific or general written authorization of the Controller. In the case of general written authorization, the Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes. The current list of sub-processors is set out in Section 9.

8.5 Data subject rights

Assist the Controller, taking into account the nature of the processing, by appropriate technical and organizational measures, for the fulfillment of the Controller's obligation to respond to requests for exercising data subject rights under Chapter III GDPR and Art. 25-29 revDSG.

8.6 Assistance with compliance

Assist the Controller in ensuring compliance with obligations pursuant to Art. 32-36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and the information available to the Processor.

8.6a Personal data breach notification

Processor shall notify Controller of a Personal Data Breach without undue delay after becoming aware, providing the information required under Art. 33(3) GDPR to the extent then known. Where information cannot be provided at the same time, it will be provided in phases without further undue delay.

8.7 Deletion or return

At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of Services, and delete existing copies unless applicable law requires storage of the Personal Data. See Section 12 for timelines.

8.8 Audits

Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits shall be conducted with reasonable notice (at least 30 days) and during normal business hours, and shall not unreasonably interfere with the Processor's operations.

9. Sub-processors

The Controller hereby grants the Processor general authorization to engage the following sub-processors. The Processor shall notify the Controller at least 30 days in advance of any intended addition or replacement of sub-processors. This DPA is the contractually binding list. The customer-facing mirror at /subprocessors and the public reference at SUBPROCESSORS.md in the source repo are kept in sync, but if any version diverges this DPA prevails.

Sub-processor Purpose Location DPA in place
Anthropic, PBC Primary LLM inference (Claude family, direct API) United States Yes — Anthropic DPA
Mistral AI SAS Inference and voice in the default managed setup: the background worker profile (ministral-14b-2512), the fallback profile for named sub-agent spawns (mistral-medium-2604), speech-to-text (voxtral-mini-2602) and text-to-speech (Voxtral). Text-to-speech has no alternative implementation — spoken output always goes to Mistral; on a managed instance neither can be switched away — transcription_provider is not tenant-writable and LYNOX_TRANSCRIBE_PROVIDER is self-host-only, so the local whisper.cpp fallback in the image is unreachable there. Mail-triage classification does not run here by default — it follows the instance's main provider, which is Anthropic unless the customer changes it. Any customer may select Mistral as their main inference provider to keep primary inference within the EU. Retention: Mistral keeps API inputs and outputs "for the period necessary to generate the Output and then for thirty (30) rolling days to monitor abuse" (Privacy Policy §5). Zero Data Retention is opt-in — Scale plan only, stateless endpoints only, granted at Mistral's discretion — and lynox does not hold it (Pay-as-you-go, checked 2026-08-11); Mistral's Data Processing Addendum carries no zero-retention commitment. No training on API inputs or outputs — contractual, under Mistral's Commercial Terms of Service §4.2. France (EU) Yes — Mistral Terms & DPA
Fireworks AI, Inc. LLM inference for the opt-in "Efficient" and "Balanced" model strategies — engaged for a managed instance by one of two routes: the instance selects one of those presets (or a Fireworks model) in its own model settings, or lynox pins a preset for that instance from the control plane. A pin takes effect only where the instance has not chosen a strategy itself. The option is enabled platform-wide, but neither route is the default: an instance with no selection and no pin routes to Anthropic and Mistral only, and no data is transmitted to Fireworks until one of the two routes applies. Where a preset is selected, all three model tiers (fast / balanced / deep) run on Fireworks' serverless inference on open-weight models of Chinese origin — DeepSeek v4 Flash, MiniMax M3, GLM 5.2 and Kimi K3. The weights are open; the inference runs on Fireworks' own infrastructure. None of the sub-processors listed in Schedule 4 of its DPA is a Chinese entity. The processing locations named there include the United States, Germany, the United Kingdom, Japan and Iceland; one row, a content-delivery provider, is listed with no fixed country at all. Schedule 4 is Fireworks' list and can change — it is the list as we read it on 2026-08-11, and Fireworks owes 30 days' notice of changes to it (Fireworks DPA, Schedule 4). Fireworks does not retain prompt inputs or model outputs beyond the lifecycle of a request (Zero Data Retention — Fireworks' default for open models, which we have not opted out of by enabling prompt logging, and a contractual obligation under §4.5 of its DPA), and is contractually prohibited from using the data to train, fine-tune or otherwise improve any shared or foundational model (§4.3(f)). United States Yes — Fireworks DPA (SCCs 2021/914, Module 2; Zero Data Retention; SOC 2 Type II, ISO 27001 / 27701 / 42001)
Stripe, LLC (US) / Stripe Payments Europe, Limited (Ireland) Payment processing and subscription billing Ireland (EU) — as a customer outside North and South America, our contracting entity is Stripe Payments Europe, Limited. The onward transfer to Stripe, LLC in the United States happens inside the Stripe group. Yes — Stripe DPA
Hetzner Online GmbH Server infrastructure — shared tenant hosts (isolated container per customer); dedicated VPS available as Enterprise upgrade Germany (EU) Yes — Hetzner DPA
Brevo (Sendinblue SAS) Transactional email delivery (SMTP relay) and contact list management EU (France/Germany) Yes — Brevo DPA
Cloudflare, Inc. DNS, CDN, DDoS protection, tunnel relay United States / EU (edge network) Yes — Cloudflare DPA
Plausible Insights OÜ Anonymous website analytics (no personal data) EU (Estonia) Yes — Plausible DPA
Self-hosted (Bugsink) Error reporting (always active for managed instances) EU (self-hosted) No third-party transfer — self-hosted on EU infrastructure

Prompt caching. The inference providers above cache prompt prefixes to cut latency and cost: on Anthropic we set explicit cache breakpoints with a one-hour time-to-live, while Mistral and Fireworks apply their own automatic prefix caching. Cached data expires on its own and, for Fireworks, its documentation states the data stays in volatile memory and is never written to persistent storage. Caching is the one carve-out from the Fireworks zero-retention commitment cited above.

Customer-configured endpoints (BYOK). If you connect your own LLM provider via Settings → LLM (bring-your-own-key) — for example OpenAI, an OpenAI-compatible endpoint, Google Vertex AI, or a self-hosted model — that provider processes your data under your own agreement with it. Such providers are not lynox sub-processors and are not covered by this DPA; you act as controller for that transfer and are responsible for its legal basis. Our Acceptable Use Policy applies regardless of the provider you configure.

10. International data transfers

Where Personal Data is transferred to sub-processors located outside of Switzerland or the EU/EEA, the Processor ensures that appropriate safeguards are in place:

11. Liability and indemnification

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection law to the extent such liability cannot be limited under applicable law. Statutory liability under Art. 82 GDPR applies as provided by law.

12. Term and termination

This DPA remains in effect for the duration of the Controller's subscription to the Managed Hosting service.

Annex: Technical and organizational security measures

The Processor implements the following measures to protect Personal Data processed on behalf of the Controller:

Encryption

Tenant isolation

Access control

Container hardening

Monitoring and audit trail

Backup and recovery

Regular testing and evaluation

13. EU representative

lynox AI is established in Switzerland, not in the EU/EEA. Pursuant to Art. 27 GDPR, we have appointed Prighter Group with its local partners as our EU representative and point of contact for data subjects in the European Union.

To exercise your privacy-related rights or contact our EU representative, please visit:
https://app.prighter.com/portal/13646667120

14. Contact

For all questions related to this DPA or data processing:
[email protected]

15. Governing law

This DPA is governed by Swiss law. The exclusive place of jurisdiction is Rapperswil-Jona, Canton of St. Gallen, Switzerland. Where the Controller is subject to the GDPR, the provisions of the GDPR shall prevail in the event of any conflict with this DPA or the governing law.