Cheaper Inference A Keak company

Legal · Effective July 29, 2026

Data Processing Addendum

This Data Processing Addendum describes how Keak AI, Inc. protects personal data processed for customers using Cheaper Inference.

Standard customer DPA This DPA becomes binding when it is incorporated into an Agreement with Keak or executed by both parties.
Request execution

Parties and effect

This Data Processing Addendum, including its Annexes (the “DPA”), forms part of the written or electronic agreement, order form, or terms governing the Customer’s use of Cheaper Inference (the “Agreement”) between the customer identified in the Agreement (“Customer”) and Keak AI, Inc., 651 North Broad Street, Middletown, Delaware 19709, United States (“Keak”).

If Customer is accepting this DPA on behalf of another entity, Customer represents that it has authority to bind that entity. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1 Scope and application

This DPA applies when Keak processes Customer Personal Data on behalf of Customer in providing Cheaper Inference and related support services. It does not apply when Keak processes personal data as an independent controller, such as business contact, account-administration, billing, security, or website data described in the Keak Privacy Policy.

2 Definitions

Applicable Data Protection Law
Laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss data protection law, PIPEDA, and United States state privacy laws.
Customer Personal Data
Personal Data contained in Customer Data that Keak processes on Customer’s behalf to provide the Services.
GDPR
Regulation (EU) 2016/679. UK GDPR means the GDPR as it forms part of United Kingdom law.
Personal Data
Information relating to an identified or identifiable individual, or any equivalent term under Applicable Data Protection Law.
Personal Data Breach
A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
Process
Any operation performed on Personal Data, including collection, transmission, storage, use, disclosure, or deletion.
Services
The Cheaper Inference services provided by Keak under the Agreement.
Subprocessor
A third party appointed by or on behalf of Keak to process Customer Personal Data in connection with the Services.

“Controller,” “Processor,” “Business,” “Service Provider,” and comparable terms have the meanings assigned by Applicable Data Protection Law.

3 Roles, instructions, and purpose limitation

  1. Customer is the Controller and Keak is the Processor of Customer Personal Data. If Customer acts as a Processor, Keak acts as Customer’s Subprocessor.
  2. Keak will process Customer Personal Data only to provide, secure, maintain, and support the Services in accordance with the Agreement, this DPA, Customer’s use and configuration of the Services, and other documented instructions agreed by the parties.
  3. Keak may process Customer Personal Data as required by applicable law. Unless legally prohibited, Keak will notify Customer before that processing.
  4. Keak will inform Customer if, in Keak’s reasonable opinion, a documented instruction infringes Applicable Data Protection Law.
  5. Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for providing required notices and obtaining required rights, consents, and authorizations.

4 Confidentiality and personnel

Keak will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations, receive appropriate security and privacy training, and access Customer Personal Data only as necessary to perform their responsibilities.

5 Security measures

  1. Keak will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration, or disclosure.
  2. The measures include the controls summarized in Annex II. Keak may update them to reflect technical progress, provided the overall level of protection is not materially reduced.
  3. Customer is responsible for securely configuring and using the Services, protecting credentials, and evaluating whether the Services are appropriate for the categories of data Customer submits.

6 Subprocessors

  1. Customer provides general authorization for Keak to engage the Subprocessors listed on the Subprocessor page.
  2. Keak will impose written data-protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to Keak under this DPA, to the extent relevant to the services performed by that Subprocessor.
  3. Keak will remain responsible for its Subprocessors’ performance of their data-protection obligations to the extent required by Applicable Data Protection Law.
  4. Keak will provide at least 30 days’ notice before authorizing a new Subprocessor to process Customer Personal Data, where reasonably practicable. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If no commercially reasonable alternative is available, either party may terminate the affected Services.

7 Data-subject requests

Taking into account the nature of processing, Keak will provide reasonable assistance to help Customer respond to requests by individuals to exercise their privacy rights. If Keak receives a request relating to Customer Personal Data, Keak will direct the requester to Customer or notify Customer, unless legally prohibited. Keak will not independently respond on Customer’s behalf without Customer’s authorization.

8 Personal Data Breaches

  1. Keak will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
  2. As information becomes available, Keak will provide reasonable details concerning the nature of the breach, affected data and individuals, likely consequences, and measures taken or proposed to address it.
  3. Keak will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will reasonably cooperate with Customer’s legally required notifications.
  4. Notification is not an acknowledgment of fault or liability.

9 Compliance assistance and audits

  1. Taking into account the nature of processing and information available to Keak, Keak will provide reasonable assistance with Customer’s data protection impact assessments, prior consultations, security obligations, and breach-notification obligations where required by Applicable Data Protection Law.
  2. On reasonable written request, Keak will make available information necessary to demonstrate compliance with this DPA, including relevant security and compliance materials available through the Keak Trust Center .
  3. If that information is insufficient to meet a legal audit right, Customer may conduct one audit in any 12-month period, and additional audits following a confirmed Personal Data Breach or regulator request. Audits require reasonable advance notice, appropriate confidentiality protections, and methods that minimize disruption and avoid exposing other customers’ data. Customer bears its audit costs unless Applicable Data Protection Law requires otherwise.

10 Return and deletion

Following termination or expiration of the affected Services, Keak will, at Customer’s choice and subject to the Agreement, delete or return Customer Personal Data and delete remaining copies, except where retention is required by law. Data maintained in protected backups will remain isolated from ordinary use and will be deleted through the normal backup lifecycle. Keak may retain data that it processes as an independent Controller in accordance with its legal obligations and published retention practices.

11 International data transfers

  1. Keak will use a valid transfer mechanism where Applicable Data Protection Law restricts transfers of Customer Personal Data across borders.
  2. For EEA Personal Data transferred to a country that has not received an adequacy decision, the European Commission Standard Contractual Clauses issued June 4, 2021 (the “EU SCCs”) are incorporated into this DPA: Module Two applies when Customer is a Controller, and Module Three applies when Customer is a Processor.
  3. For the EU SCCs, the optional docking clause applies; Clause 9 uses Option 2 with the notice period in Section 6; the optional language in Clause 11 does not apply; Ireland is the governing Member State under Clause 17; and the courts of Ireland have jurisdiction under Clause 18. Annexes I and II of this DPA complete the corresponding SCC Annexes.
  4. For United Kingdom Personal Data, the EU SCCs apply as amended by the then-current UK International Data Transfer Addendum issued by the UK Information Commissioner. For Swiss Personal Data, references in the EU SCCs are adapted to the Swiss Federal Act on Data Protection, and the competent Swiss authority is the Federal Data Protection and Information Commissioner.
  5. If another lawful transfer mechanism applies, the parties may rely on that mechanism instead. Transfer terms prevail over conflicting terms of this DPA to the extent required by law.

12 United States and Canadian regional terms

  1. To the extent United States state privacy laws apply, Keak acts as a Service Provider or Processor for Customer Personal Data. Keak will not sell or share Customer Personal Data for cross-context behavioral advertising; retain, use, or disclose it outside the direct business relationship with Customer; or combine it with personal data from other sources except as permitted by applicable law and necessary to provide the Services.
  2. Keak will notify Customer if it determines that it can no longer meet these regional obligations and will reasonably cooperate with Customer’s efforts to stop and remediate unauthorized use.
  3. To the extent Canadian privacy law applies, Keak will process Customer Personal Data only for the purposes described in this DPA, maintain safeguards appropriate to its sensitivity, and support Customer’s accountability for Personal Data transferred for processing.

13 General terms

  1. If this DPA conflicts with the Agreement on the protection of Customer Personal Data, this DPA controls. Transfer terms control over both this DPA and the Agreement where required.
  2. Except as modified by this DPA, the Agreement remains in effect. The Agreement’s governing law, dispute-resolution, limitation-of-liability, and termination provisions apply to this DPA, except where Applicable Data Protection Law or the EU SCCs require otherwise.
  3. Keak may update this DPA to reflect changes in law, regulation, or the Services. Keak will provide reasonable notice of material changes and will not materially reduce Customer’s protections during an active Agreement without a valid legal basis.
  4. Notices and requests concerning this DPA may be sent to support@keak.com.

Annex I

Details of processing

A. Parties

Party Details
Data exporter Customer and its relevant affiliates identified in the Agreement. Customer’s activities concern its use of the Services.
Data importer Keak AI, Inc., 651 North Broad Street, Middletown, DE 19709, United States. Privacy contact: support@keak.com. Keak’s activities concern providing the Services described in the Agreement.

B. Processing description

Subject matter Provision, security, maintenance, and support of Cheaper Inference.
Nature and purpose Receiving and routing API requests to Customer-selected or eligible model providers; returning outputs; authenticating requests; managing workspaces; metering usage; billing; preventing abuse; monitoring reliability and security; and providing support.
Duration The term of the Agreement and the period reasonably required to return or delete data, satisfy legal obligations, and complete protected backup cycles.
Frequency Continuous or intermittent, depending on Customer’s use of the Services.
Data subjects Customer’s personnel, contractors, authorized users, customers, end users, suppliers, and other individuals whose Personal Data Customer submits to the Services.
Personal Data categories Business contact and workspace information; identifiers; IP addresses; device, authentication, usage, request, billing, and support metadata; and Personal Data that Customer elects to include in prompts, inputs, files, images, or model outputs.
Sensitive data The Services do not require sensitive or special-category data. Customer must not submit such data unless it has a valid legal basis, has assessed the Services as appropriate, and applies suitable safeguards.
Retention Cheaper Inference does not store prompt or model-response bodies in its application database. Request content is transmitted to the serving provider. Temporary uploads expire after one hour. Operational logs are generally retained for up to 12 months, and account and billing records for the Agreement term plus seven years, unless law or a documented legal hold requires otherwise.
Subprocessor transfers As necessary to provide the Services and as described on the Subprocessor page.

Annex II

Technical and organizational measures

Governance and risk

Documented security and privacy ownership, policies, risk reviews, exceptions, management oversight, and recurring workforce training.

Identity and access

Individual accounts, least privilege, role-based permissions, multi-factor authentication for privileged access, access reviews, and documented joiner-mover-leaver procedures.

Encryption

TLS 1.2 or higher for web, API, administrative, and other sensitive communications; provider-level encryption for managed storage and databases; encrypted backups; and full-disk encryption on managed endpoints.

Application security

Peer-reviewed changes, version-controlled infrastructure and configuration, automated dependency and secret scanning, secure deployment pipelines, and testing before release.

Vulnerability management

Recurring vulnerability and dependency scanning, risk-based patch deadlines, ticketed remediation, and verification after remediation.

Logging and monitoring

Centralized access-controlled logging, security-event alerting, documented escalation paths, protected audit records, and recurring review.

Incident response

Defined incident roles, reporting channels, on-call contacts, containment and recovery procedures, evidence preservation, communications, and post-incident corrective actions.

Resilience and recovery

Encrypted backups, geographically separate storage where appropriate, restricted restoration rights, recurring restore tests, and documented business-continuity and disaster-recovery procedures.

Endpoint and remote access

Managed-device requirements, supported and patched operating systems, endpoint protection, disk encryption, automatic locking, secure remote access, and device access removal upon loss or offboarding.

Data lifecycle

Data classification, minimization, restricted sharing, retention schedules, periodic deletion reviews, secure wipe or cryptographic erasure, and disposal records.

Vendor management

Risk-tiered due diligence, contractual confidentiality and security requirements, recurring reassessment, subprocessor oversight, and access revocation at termination.

Physical protection

Reliance on assessed cloud and service providers for data-center controls, together with asset inventory, secure media handling, and controls appropriate to a fully remote workforce.

Execution

Where the Agreement incorporates this DPA, no separate signature is required. If Customer requires a countersigned copy, contact support@keak.com .

Customer Legal name: Authorized signature: Name and title: Date:
Keak AI, Inc. Authorized signature: Name and title: Date: