Semantic Rails Cloud Data Processing Addendum
Version 2026-09-12. This DPA applies to covered processing when incorporated in the Cloud agreement, without a separate signature unless the parties agree otherwise.
1. Scope, roles and instructions
This DPA forms part of the Cloud agreement between Semantic Rails, Inc. and Customer. Customer Personal Data means personal data we process on Customer's behalf in providing Cloud, including personal data within projects, connection information, instructed queries and returned data. GDPR terms have their GDPR meanings. Applicable Data Protection Law means GDPR and other data-protection law applicable to the processing.
Customer is controller, or a processor authorized by its controller; Semantic Rails is processor, or subprocessor, respectively. Our separate controller processing of account, billing and security information is described in the Privacy Notice and is not permission to repurpose Customer Personal Data.
The agreement, authorized configuration, tool/API requests and written support instructions are Customer's documented instructions. We process Customer Personal Data only on those instructions, including for transfers, unless law requires otherwise. We notify Customer of a conflicting legal requirement when permitted and inform Customer if an instruction appears unlawful. Customer must have authority to provide the data and instructions; this does not remove our own legal responsibilities.
2. Confidentiality and safeguards
We restrict access to authorized personnel who need it for the Service and are bound by confidentiality. We maintain the measures in Schedule B appropriate to processing risk and do not materially reduce their overall protection during the agreement. We do not sell Customer Personal Data, use it for targeted advertising or train general-purpose AI models on it. We assist Customer with security, impact assessments and prior regulatory consultation, taking account of the processing and information available to us.
3. Subprocessors
Customer gives general written authorization for the applicable providers in Schedule C. Before using a subprocessor for Customer Personal Data, we put in place applicable contractual data-protection duties and verify its suitability. We remain responsible for its obligations to the extent required by Applicable Data Protection Law.
We notify Customer's administrative contact at least 30 days before a planned new or replacement subprocessor begins processing Customer Personal Data. Customer may object within that period on reasonable data-protection grounds. We work in good faith to provide an alternative or otherwise resolve the concern; we do not transfer affected data to the proposed provider while a timely objection is unresolved. If no reasonable solution is available, either party may terminate the affected portion before the change, with a refund of prepaid unused fees.
An independently selected customer warehouse, repository or AI client/provider is not our subprocessor solely because Customer connects it to the Service. Its role depends on the actual arrangement and instructions.
4. Individual requests and incidents
We promptly route an individual request concerning Customer Personal Data to Customer and assist with appropriate technical or organizational measures. We do not determine the response independently unless instructed or legally required. Assistance must not frustrate Customer's legal deadlines.
We notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We provide available information about its nature, affected data and individuals, likely consequences, response measures and a contact, and supply further facts as the investigation develops. Initial notice does not wait for a complete investigation. We cooperate with containment, remediation and Customer's required notifications. An incident notice is not an admission of liability, and unsuccessful attacks without a personal data breach do not themselves trigger this clause.
5. Assurance
We provide information needed to demonstrate this DPA's obligations and allow and contribute to appropriate audits and inspections by Customer or its mandated independent auditor. Reasonable confidentiality, scope and security arrangements protect other customers without defeating audit rights or regulatory access. Ordinary reviews should use available documentation first, with reasonable advance notice for an inspection unless an incident or regulator requires urgency. Any assistance fees must be agreed in advance and must not prevent mandatory assistance or remedy of our noncompliance. No certification or SOC 2 report is promised by this DPA.
6. Return and deletion
At Customer's choice, we return available Customer Personal Data in its existing machine-readable formats or delete it after processing ends. A customer can request return during the subscription and for 30 days after termination. Plaintext warehouse secrets are not included in ordinary configuration exports; we arrange secure handling of a legally required credential-related request without sending secrets through normal email or support tickets.
We remove Customer Personal Data from active systems within 30 days of a verified deletion instruction, or within 60 days after termination if no earlier instruction is received. Backup copies expire within 90 days of that removal, remain protected and are used only for recovery until expiry. We reapply completed deletion instructions following restore. We confirm completion on request and identify any remaining restricted copies and their expiry.
Data required to be retained by law remains protected and is processed only for that requirement. Separate controller records follow the Privacy Notice; the classification does not permit indefinite retention of customer content or usable credentials for unrelated business purposes.
7. Transfers and precedence
Cloud is hosted on infrastructure operated by Semantic Rails. Before processing involving a restricted international transfer, the parties must establish an applicable lawful mechanism, complete required assessments and safeguards, and document actual locations. Where EU Standard Contractual Clauses, the UK Addendum/IDTA or another instrument is required, it must be completed and executed before the transfer. This DPA is not, by itself, one of those instruments or a claim of framework certification. We will provide relevant transfer information on request.
Mandatory law and applicable executed transfer terms prevail over conflicts in the Cloud agreement, including liability restrictions. Contractual liability otherwise follows the Cloud terms; individuals' statutory rights and regulatory powers are unaffected.
Schedule A — processing description
| Item | Description |
|---|---|
| Subject and purpose | Hosted project configuration, validation and authorized warehouse/API/MCP operations; related customer-directed support and security |
| Nature | Receive, store, retrieve, use, transmit, return and delete data required for instructed operations; no sale, advertising use or general-purpose model training |
| Individuals | Customer's authorized users and people represented in the data Customer authorizes Cloud to process |
| Data categories | Identifiers and contact information where supplied, project/schema/connection metadata, credentials, and personal data within instructed queries, results, files and enabled feature records |
| Sensitive data | Special-category, criminal-offence and separately regulated data excluded unless expressly agreed in writing with appropriate safeguards |
| Duration and frequency | On-demand operations and enabled jobs during the subscription, followed by the limited return/deletion periods in section 6 |
| Customer instructions/contact | Authorized workspace configuration and written instructions; Customer's administrative contact in the subscription record |
| Semantic Rails contact | will.tremml@semantic-rails.com |
Schedule B — technical and organizational measures
- Workspace-scoped authorization, membership/role checks and tenant-scoped database access; constrained runtime database roles and separate migration access.
- HTTPS for public Cloud endpoints and envelope encryption of stored warehouse credential payloads, with key access restricted to authorized service use. Decryption is required for instructed connections; protection is not a claim that a compromised running host cannot access credentials.
- Restricted service permissions, protected secret/configuration files and logging rules that exclude raw credentials and ordinary query-result content. Authorized optional query-feature records are governed as Customer Data.
- Change checks and supported security updates, vulnerability review, audit records, incident handling and proportionate access review. Audit recording is not a guarantee that every possible event can never be lost.
- Encrypted recovery backups, restricted recovery credentials and restore verification. No uptime SLA, fixed recovery guarantee or SOC 2 attestation is included.
- Customer instruction, access/export/deletion and retention processes described in this DPA, including restricted backup handling and deletion after restores.
Schedule C — authorized service providers and purposes
Semantic Rails operates the current Cloud host and its configured recovery storage; those internal operations remain subject to this DPA. The following external providers are authorized only for the stated functions and only when enabled for Customer's Service. Their applicable contracting entities and processing locations are recorded in the operational vendor register and provided to Customer on request before a restricted transfer. Authorization here does not replace our obligation to execute applicable vendor agreements.
| Provider | Function and relevant data |
|---|---|
| Cloudflare | Network/website delivery and configured ingress; request content and transport metadata necessary for routed traffic |
| Google Workspace | Business email delivery and support communications; recipient information and message content needed for that function |
Google sign-in's independent identity-provider activity, Stripe's payment functions and optional PostHog product measurement are separately described in the Privacy Notice. They are not authorized by this table to receive customer warehouse content. If a new use makes one of them our subprocessor for Customer Personal Data, the notice/authorization process above applies before that use.