Data Processing Agreement

Last updated: September 11, 2026

1. Purpose and scope

This Data Processing Agreement ("DPA") governs the processing of personal data by CanRouter AI on behalf of customers in the course of providing the API gateway service. It supplements the Terms of Service.

2. Roles of the parties

The customer is the data controller for personal data submitted to the service (including prompt content). CanRouter AI acts as a data processor, processing such data solely to route requests to model providers, meter usage, and provide support.

3. Data processed

Processing covers: account data (email, username), API request metadata (timestamps, model names, token counts, request IDs), and request content, which is forwarded transiently to the upstream model providers selected by the customer and is not stored by default.

4. Security measures

CanRouter AI maintains technical and organizational measures including: encryption in transit (TLS), encryption at rest for credentials (Fernet), one-way hashing of authentication secrets, role-based access control, immutable audit logs for administrative actions, and regular backups with restore testing.

5. Sub-processors

The customer acknowledges that requests are forwarded to third-party AI model providers (sub-processors) chosen via the service configuration, and to infrastructure providers for hosting, databases, and payment processing. An up-to-date list is available on request from [email protected].

6. Customer obligations

The customer is responsible for the lawfulness of the personal data it submits, for obtaining any required consents, and for instructing CanRouter AI on deletion or export requests via support ([email protected]).

7. Data subject requests and breach notification

CanRouter AI will reasonably assist the customer in responding to data subject requests and will notify the customer without undue delay upon becoming aware of a personal data breach affecting customer data.

8. Term and termination

This DPA applies for the duration of the service agreement. On termination, account data is deleted or anonymized within 30 days, subject to legal retention and financial-record obligations.