Global Data Processing Addendum
Effective Date: June 11, 2026

This Global Data Processing Addendum ("DPA") is entered into between DeepCerebra Inc. ("DeepCerebra," "Processor") and the Customer identified in the applicable DeepCerebra Terms of Service or other written agreement ("Agreement"). This DPA forms part of the Agreement and governs the processing of Personal Data by DeepCerebra on behalf of the Customer in connection with the provision of the DeepCerebra Coder Services.

1 Definitions

2 Processing of Personal Data: Roles and Scope

2.1 Roles of the Parties

In relation to Customer Personal Data, Customer acts as the Data Controller (or as a Processor acting on behalf of a Controller), and DeepCerebra acts as the Data Processor. DeepCerebra will process Customer Personal Data only on behalf of and in accordance with the documented instructions of the Customer.

2.2 Scope and Purpose of Processing

DeepCerebra processes Customer Personal Data solely to provide the Services as described in the Services Description and as further documented in Schedule 1. Prompt and code context routed to large language models is processed under Zero Data Retention (ZDR) terms and is not retained beyond what is strictly required to return a response, nor used to train foundation models.

2.3 DeepCerebra as a Controller

DeepCerebra may process certain Personal Data as an independent Controller for its own legitimate business purposes, including billing and account management, usage metering, security monitoring and fraud prevention, compliance with legal obligations, and improvement of the Services using aggregated and anonymized data.

3 DeepCerebra's Obligations as a Processor

3.1 Processing Instructions

DeepCerebra will process Customer Personal Data only in accordance with Customer's documented instructions, unless required to do otherwise by applicable law, and will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

3.2 Confidentiality

DeepCerebra will ensure that all personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

3.3 Security Measures

DeepCerebra implements and maintains appropriate technical and organizational measures to protect Customer Personal Data:

3.4 Subprocessors

Customer grants DeepCerebra general authorization to engage Authorized Subprocessors. DeepCerebra will maintain a current list (Schedule 1), will notify Customer of intended additions or replacements, will impose equivalent data protection obligations on Authorized Subprocessors, and will remain liable for their acts and omissions to the extent provided in the Agreement.

3.5 Data Subject Rights Assistance

DeepCerebra will promptly notify Customer if it receives a request from a Data Subject to exercise their rights and will assist Customer in responding by providing necessary tools and information.

3.6 Personal Data Breach Notification

DeepCerebra will notify Customer without undue delay (and within 72 hours of becoming aware) of a Personal Data Breach affecting Customer Personal Data, including the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken to address it.

4 Customer's Obligations

Customer is responsible for ensuring that its use of the Services complies with Applicable Data Protection Law, including providing all necessary notices and obtaining all necessary consents from Data Subjects before processing their Personal Data through the Services, ensuring that Customer Personal Data and any source code submitted is lawfully collected and used, and managing the keys, repositories, and third-party tools it connects to the Services.

5 International Data Transfers

Where DeepCerebra transfers Customer Personal Data from the EEA, UK, or Switzerland to a third country not recognized as providing an adequate level of data protection, such transfers will be subject to appropriate safeguards, including the applicable Standard Contractual Clauses (SCCs), which are hereby incorporated into this DPA by reference.

6 Deletion and Return of Data

Upon termination of the Agreement, DeepCerebra will, at the Customer's choice and within a reasonable timeframe, return or securely delete Customer Personal Data held on its systems and those of its Authorized Subprocessors, except as required to be retained by applicable law. Because project files are held in confidential in-browser storage, they remain under the Customer's control. DeepCerebra will provide written confirmation of deletion upon Customer's request.

7 Audit Rights

Upon Customer's reasonable written request (no more than once per year), DeepCerebra will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality obligations and advance notice.

8 Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitation of liability set out in the Terms of Service. Accordingly, DeepCerebra's total cumulative liability for all claims arising out of or related to this DPA and the Agreement shall not exceed two hundred U.S. dollars (US $200), to the maximum extent permitted by applicable law.

S1 Schedule 1: Details of Processing and Authorized Subprocessors

Details of Processing

CategoryDescription
Subject MatterProvision of the DeepCerebra Coder agentic coding services
DurationFor the term of the Agreement and as required by applicable law
Nature of ProcessingCollection, storage, transmission, routing to models, and deletion
Purpose of ProcessingAuthenticating users, generating and editing code, executing authorized workflows, metering, and billing
Types of Personal DataAccount data, prompt/code context, usage and metering data, device/network data
Categories of Data SubjectsRegistered users and their authorized team members

Authorized Subprocessors

SubprocessorPurposeLocationData Processed
ZDR LLM API gatewayZero-Data-Retention routing to LLM providersUnited StatesPrompts, code context
Google (Gemini)Model inferenceUnited StatesPrompts, code context
AnthropicModel inference (optional)United StatesPrompts, code context
OpenAIModel inference (optional)United StatesPrompts, code context
StripePayment processingUnited StatesBilling and payment data
SendGrid / ResendEmail deliveryUnited StatesEmail addresses
RailwayCloud hosting and infrastructureUnited StatesAccount and service data
CloudflareCDN and DDoS protectionUnited StatesNetwork traffic

Where a Customer supplies its own model keys (BYOK) or connects third-party tools or local model runtimes (such as Ollama or LM Studio), those providers and runtimes act under the Customer's own arrangements and are not DeepCerebra subprocessors.

9 Contact Information

For any privacy-related inquiries, data subject requests, or to report a Personal Data Breach, please contact:

Data Protection: privacy@deepcerebra.ai

Security Team: security@deepcerebra.ai

Website: https://deepcerebra.ai