PhaseoPhaseo
PhaseoPhaseo
Checking statusChecking statusVisit status page
Component-level status is unavailable.

Explore

  • Models
  • Chat
  • Providers
  • Apps
  • Rankings
  • Tools
  • Monitor

Resources

  • Compare
  • Migration Guides
  • Methodology
  • Blog

Community

  • Discord
  • GitHub
  • LinkedIn
  • Reddit
  • X

Build

  • Documentation
  • API Reference
  • Quickstart
  • SDKs

Company

  • About
  • Trust Centre
  • Mission
  • Pricing
  • Works With
  • Acknowledgements
  • Support
  • Privacy
  • Terms

Explore

  • Models
  • Chat
  • Providers
  • Apps
  • Rankings
  • Tools
  • Monitor

Build

  • Documentation
  • API Reference
  • Quickstart
  • SDKs

Resources

  • Compare
  • Migration Guides
  • Methodology
  • Blog

Company

  • About
  • Trust Centre
  • Mission
  • Pricing
  • Works With
  • Acknowledgements
  • Support
  • Privacy
  • Terms

Community

  • Discord
  • GitHub
  • LinkedIn
  • Reddit
  • X

© 2025 • Phaseo

Help:Issue·Support

Need help with Phaseo?Open an issueorcontact support

PhaseoPhaseo
ModelsChatCompareProvidersAppsRankings
ModelsChatCompareProvidersAppsRankings
Trust Centre
Phaseo Trust Centre

Data Processing Addendum

Terms for processing personal data through Phaseo on a customer's behalf. This public version is a review draft. It does not bind either party until it is signed or expressly incorporated into an agreement.

Review draft · legal approval requiredLast reviewed 30 August 2026

Review draft

This draft is written to cover the mandatory controller-processor terms in Article 28 of the UK GDPR and EU GDPR. It still needs Phaseo's service address, confirmed transfer terms, a final approved list of Phaseo-managed AI Subprocessors, and qualified legal approval. Request an execution copy from [email protected].

Parties and effective date

This Data Processing Addendum (DPA) forms part of the agreement that governs the Customer's use of the Services (Agreement) once it has been signed or expressly incorporated into that Agreement.

  • Customer is the person or organisation identified in the Agreement, order form, or signature block.
  • Phaseo is Daniel Butler, trading as Phaseo, of [insert service address and any required tax or registration details].

The Effective Date is the date on which this DPA is last signed or validly incorporated into the Agreement.

If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls. The Agreement otherwise remains unchanged.

1. Definitions

  • Applicable Data Protection Law means the privacy and data-protection law that applies to the processing under this DPA. It includes the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 to the extent it amends UK data-protection law, the EU GDPR, and applicable national legislation that implements or supplements them.
  • Customer Data means data submitted to the Services by or for Customer, or data that Customer directs Phaseo to process through the Services.
  • Customer Personal Data means personal data contained in Customer Data that Phaseo processes on Customer's behalf.
  • AI Provider means a third party that receives a request to run an AI model or related service.
  • Services means the Phaseo services covered by the Agreement.
  • Subprocessor means another processor engaged by Phaseo to process Customer Personal Data for the Services.
  • Controller, Processor, Data Subject, Personal Data Breach, and Process have the meanings given by Applicable Data Protection Law.

2. Scope, roles, and instructions

  1. Customer is the Controller of Customer Personal Data and Phaseo is its Processor. If Customer is itself a Processor, Phaseo is Customer's Subprocessor and Customer confirms that its instructions are authorised by the relevant Controller.
  2. Phaseo will process Customer Personal Data only on Customer's documented instructions. The Agreement, this DPA, Customer's API requests, selected models and providers, routing rules, product settings, and written support requests are documented instructions. These instructions include transfers needed to provide the Services.
  3. If UK or EU law requires Phaseo to process Customer Personal Data without Customer's instruction, Phaseo will tell Customer before processing unless that law prohibits notice.
  4. Phaseo will tell Customer if it believes an instruction infringes Applicable Data Protection Law. Phaseo may suspend the affected processing until the parties resolve the issue.
  5. Annex 1 states the subject matter, duration, nature, purpose, personal-data types, Data Subject categories, and the parties' relevant rights and duties.
  6. Phaseo acts as an independent Controller where it determines its own purposes and means of processing, including account administration, billing, fraud prevention, legal compliance, and security of the Services. The Privacy Policy applies to that processing. Phaseo will not treat gateway content as independent-controller data merely because it passes through the Services.

3. Customer's responsibilities

  1. Customer will comply with Applicable Data Protection Law, provide all required notices, and have a valid legal basis for its instructions and Customer Personal Data.
  2. Customer will not submit special-category data, criminal-offence data, full payment-card data, or other highly sensitive data unless the Agreement expressly permits it and Customer has assessed the selected settings and AI Providers.
  3. Customer is responsible for its AI Provider restrictions, retention and logging settings, credentials, and customer-directed destinations.
  4. Customer will limit access to the Services, protect its credentials, and notify Phaseo promptly if it suspects unauthorised access or unlawful processing.

4. Confidentiality and security

  1. Phaseo will limit access to Customer Personal Data to people who need access to provide, secure, or support the Services or to comply with law.
  2. Anyone authorised by Phaseo to process Customer Personal Data must be bound by a contractual duty of confidentiality or an appropriate statutory duty.
  3. Phaseo will maintain the technical and organisational measures in Annex 2. Those measures must provide a level of security appropriate to the risk, taking account of the factors listed in Article 32 of the UK GDPR and EU GDPR.
  4. Phaseo may change individual measures as the Services develop, but will not materially reduce the overall protection of Customer Personal Data during the term of the Agreement.

5. Subprocessors and AI Providers

  1. Customer gives general written authorisation for Phaseo to use the Subprocessors on the subprocessor schedule.
  2. Phaseo will give Customer at least 30 days' notice before a new Subprocessor begins processing Customer Personal Data. Notice will be sent to the account email address and recorded on the subprocessor schedule. If urgent security or service-continuity needs make advance notice impracticable, Phaseo will give notice as soon as practicable.
  3. Customer may object in writing during the notice period on reasonable data-protection grounds. The parties will try in good faith to resolve the objection. If they cannot, Phaseo may avoid the Subprocessor, offer a reasonable service change, or permit Customer to stop using the affected part of the Services under the Agreement.
  4. Phaseo will bind each Subprocessor by written terms that provide no less protection for Customer Personal Data than the applicable terms of this DPA. Phaseo remains responsible for the Subprocessor's performance to the extent required by Applicable Data Protection Law.
  5. An AI Provider used through a Phaseo-managed route is a Subprocessor where it processes Customer Personal Data on Phaseo's behalf. If Customer supplies its own provider credentials or has a direct agreement with the AI Provider, that provider is a customer-directed recipient unless the subprocessor schedule says otherwise. A provider's legal role depends on the actual processing and applicable law, not the label used in this DPA.
  6. Customer instructs Phaseo to disclose Customer Data to the AI Providers allowed by Customer's routing configuration. Customer may use available provider restrictions where provider identity, location, retention, or training policy matters.

6. Assistance and regulatory duties

  1. Taking account of the nature of the processing, Phaseo will use appropriate technical and organisational measures to help Customer respond to requests made by Data Subjects under Applicable Data Protection Law.
  2. If Phaseo receives a request about Customer Personal Data directly from a Data Subject, Phaseo will refer the request to Customer. Phaseo will not respond on Customer's behalf unless Customer instructs it to do so or law requires a response.
  3. Taking account of the nature of processing and information available to Phaseo, Phaseo will help Customer meet its obligations concerning security, Personal Data Breach notifications, data-protection impact assessments, and prior consultation with a supervisory authority.
  4. Phaseo will maintain records and cooperate with supervisory authorities where Applicable Data Protection Law requires it to do so.
  5. If Customer asks for substantial assistance beyond standard product features, Phaseo may charge reasonable, agreed costs unless the work is needed because Phaseo breached this DPA.

7. Personal Data Breach

  1. Phaseo will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
  2. To the extent known at the time, the notice will describe the nature of the breach, the categories and approximate number of affected Data Subjects and records, likely consequences, measures taken or proposed, and a contact for further information. Phaseo may provide this information in stages.
  3. Phaseo will take appropriate steps to contain, investigate, mitigate, and remediate the breach. It will provide the information and assistance Customer reasonably needs to make any notification required by law.
  4. Phaseo's notice is not an admission of fault or liability. Customer remains responsible for deciding whether it must notify a supervisory authority or affected Data Subjects.

8. International transfers

  1. Phaseo will not make a restricted transfer of Customer Personal Data except on Customer's documented instructions and in compliance with Applicable Data Protection Law.
  2. The parties may rely on an applicable adequacy decision or regulation. Where that is unavailable, they will enter into and complete the European Commission's 2021 Standard Contractual Clauses for international transfers, the UK International Data Transfer Agreement, the UK Addendum to those EU clauses, or another valid safeguard.
  3. Where a transfer safeguard requires a transfer risk assessment or UK data protection test, Phaseo will provide information reasonably available to it and implement any supplementary measure agreed by the parties.
  4. If a transfer mechanism no longer provides a lawful basis for the transfer, the parties will adopt another lawful mechanism or stop the affected processing.
  5. Before execution, Annex 4 must identify the exporter and importer, relevant SCC module, governing law, supervisory authority, optional clauses, UK mechanism, and processing locations for any transfer not covered by adequacy.

9. Return and deletion

  1. Customer may retrieve or delete supported Customer Data using available product controls during the term of the Agreement.
  2. At the end of the Services, Phaseo will, at Customer's choice, return or delete Customer Personal Data and delete existing copies unless applicable law requires retention. Customer must communicate its choice before termination or within 30 days afterward. If Customer makes no choice, Phaseo will delete the data.
  3. Phaseo will complete deletion of Customer Personal Data from its active systems without undue delay and no later than 30 days after the applicable instruction or termination date. The self-service workflow removes the Auth account and active database records, deletes linked Stripe customer profiles, and queues private R2 objects and Gateway KV entries for a retryable scheduled purge. Completion records retain no user or workspace identifier.
  4. Copies in backups remain protected and isolated from ordinary use until deleted through the backup cycle. The production Supabase project currently has seven days of daily database restore points and point-in-time recovery is disabled. Phaseo will recheck this window before execution and after a backup-plan change.
  5. Phaseo's deletion does not remove data held by an independent Controller or customer-directed recipient. Customer must direct those parties separately.

10. Information and audits

  1. Phaseo will provide information reasonably necessary to show compliance with this DPA and Article 28, subject to duties of confidentiality and security.
  2. Customer will normally review Phaseo's current trust materials and written responses before requesting an inspection. This does not limit an audit required by Applicable Data Protection Law or a supervisory authority.
  3. Customer may audit Phaseo once in any 12-month period and after a Personal Data Breach or credible evidence of material non-compliance. Customer must give at least 30 days' notice unless the matter is urgent or a supervisory authority requires shorter notice.
  4. An audit must be conducted by Customer or an independent qualified auditor bound by confidentiality. It must avoid access to other customers' data, source code, and systems unrelated to the processing. Phaseo will contribute to the audit and may provide equivalent evidence where direct access would create a security risk.
  5. Customer will bear its audit costs and Phaseo's reasonable costs unless the audit finds a material breach of this DPA by Phaseo.
  6. Phaseo does not currently have a SOC 2 report, ISO 27001 certificate, or independent penetration-test report.

11. Term, liability, and general terms

  1. This DPA remains in force while Phaseo processes Customer Personal Data under the Agreement.
  2. Nothing in this DPA relieves either party of duties or liability imposed directly on it by Applicable Data Protection Law.
  3. The liability limits and exclusions in the Agreement apply to this DPA to the extent permitted by law.
  4. The Agreement's governing-law and dispute terms apply unless Applicable Data Protection Law or an incorporated transfer mechanism requires otherwise.

Annex 1: Details of processing

Subject matterProviding the dashboard, API gateway, model routing, usage and billing records, configured logging, optional data contribution, observability exports, notifications, and support covered by the Agreement.
DurationThe term of the Agreement and the deletion period in Section 9.
Nature and purposeReceive, transmit, route, secure, cache, record, retrieve, classify when Customer opts in, export when Customer configures a destination, support, return, and delete data to provide and secure the Services.
FrequencyContinuous or intermittent, depending on Customer's use of the Services.
Data SubjectsCustomer's users, personnel, contractors, end users, customers, suppliers, and other people whose data Customer submits through the Services.
Personal-data typesPrompt, message, document, image, audio, video, tool, and model-output content; identifiers; account and workspace references; device, IP, coarse location, authentication, routing, provider, usage, cost, latency, error, security, and support metadata.
Sensitive dataThe Services do not require special-category or criminal-offence data. Phaseo cannot reliably determine whether Customer has included such data in free-form content. The restriction in Section 3 applies.
RetentionResponse cache: five minutes by default and no more than 24 hours when configured. Optional private I/O logs: 90, 180, or 365 days. Optional data contributions: no more than 30 days. Other Customer Personal Data follows Section 9 and the Agreement.
Controller rights and dutiesCustomer may give lawful instructions, configure the Services, exercise audit and assistance rights under this DPA, and require return or deletion. Customer must meet the obligations in Section 3.

Annex 2: Technical and organisational measures

  • HTTPS for public service delivery and connections from Phaseo to AI Providers.
  • AES-256-GCM encryption before storage for bring-your-own-provider credentials. Supported webhook and notification secrets also use encrypted storage.
  • One-way keyed or password-based derivation for API, management, and OAuth secrets.
  • Workspace roles, database access policies, scoped API and OAuth permissions, consent screens, and revocation controls.
  • Rate limits on sensitive authentication and realtime routes, plus structured validation at request and configuration boundaries.
  • Exclusion of raw gateway content from the primary request database and analytics, subject to the response-cache, I/O-logging, data-contribution, AI Provider, and customer-directed destination paths described in the security whitepaper.
  • Managed infrastructure logs, request metadata, provider-health signals, and a public incident status page.
  • Version control, dependency lockfiles, automated linting, type checking, targeted tests, and private vulnerability reporting.

These measures are self-attested. Phaseo does not claim an independently audited security programme, tested disaster-recovery programme, or formal certification.

Annex 3: Subprocessors

The dated subprocessor schedule forms Annex 3 when this DPA is executed. Section 5 governs additions and replacements.

Phaseo has completed a preliminary classification of the active Phaseo-managed AI Providers. Before execution, Phaseo must complete the outstanding processor-contract, account-setting, transfer, and retention checks identified in the schedule, and must remove or restrict any managed provider that is not approved for Customer Personal Data. Customer-directed providers used under Customer's own credentials or agreement remain identified separately.

Annex 4: Restricted-transfer terms

Complete this annex before execution if Customer Personal Data will be transferred without an applicable adequacy decision or regulation. Identify the transfer mechanism, exporter and importer, countries, categories of data and Data Subjects, frequency, purpose, retention, competent supervisory authority, governing law, optional SCC clauses, and any supplementary measures.

Drafting basis

This draft follows the current processor-contract checklist published by the UK Information Commissioner's Office and the European Commission's Article 28 and international-transfer materials. The ICO notes that parts of its processor-contract guidance are being reviewed following the Data (Use and Access) Act 2025. Qualified counsel should check the final execution copy against the law and guidance then in force.

  • ICO: required controller-processor contract terms
  • ICO: international transfers
  • European Commission: controller-processor standard clauses

Signature block

CustomerDaniel Butler, trading as Phaseo
Name: [insert]
Title: [insert]
Signature: [insert]
Date: [insert]
Name: Daniel Butler
Capacity: Sole trader
Signature: [insert]
Date: [insert]
Trust CentrePrivacy PolicyTerms of Service
Privacy questions
Sign Up