Data Processing Agreement
Last updated: September 11, 2026
1. Purpose and scope
This Data Processing Agreement ("DPA") governs the processing of personal data by CanRouter AI on behalf of customers in the course of providing the API gateway service. It supplements the Terms of Service.
2. Roles of the parties
The customer is the data controller for personal data submitted to the service (including prompt content). CanRouter AI acts as a data processor, processing such data solely to route requests to model providers, meter usage, and provide support.
3. Data processed
Processing covers: account data (email, username), API request metadata (timestamps, model names, token counts, request IDs), and request content, which is forwarded transiently to the upstream model providers selected by the customer and is not stored by default.
4. Security measures
CanRouter AI maintains technical and organizational measures including: encryption in transit (TLS), encryption at rest for credentials (Fernet), one-way hashing of authentication secrets, role-based access control, immutable audit logs for administrative actions, and regular backups with restore testing.
5. Sub-processors
The customer acknowledges that requests are forwarded to third-party AI model providers (sub-processors) chosen via the service configuration, and to infrastructure providers for hosting, databases, and payment processing. An up-to-date list is available on request from [email protected].
6. Customer obligations
The customer is responsible for the lawfulness of the personal data it submits, for obtaining any required consents, and for instructing CanRouter AI on deletion or export requests via support ([email protected]).
7. Data subject requests and breach notification
CanRouter AI will reasonably assist the customer in responding to data subject requests and will notify the customer without undue delay upon becoming aware of a personal data breach affecting customer data.
8. Term and termination
This DPA applies for the duration of the service agreement. On termination, account data is deleted or anonymized within 30 days, subject to legal retention and financial-record obligations.