How to execute this DPA
This Data Processing Addendum ("DPA") is incorporated into the LLMTUNE Inc. Terms of Service and applies where LLMTUNE processes personal data on behalf of a business customer (the "Customer," acting as controller) in the course of providing the Service.
To execute, email privacy@llmtune.io from your account email with your full legal entity name, address, and account ID. We will countersign and return a copy. No further negotiation is required for the terms below; deviations require a separately signed agreement.
1. Roles and Scope
- 1.1 Roles: Customer is the controller (or processor acting on its controller's instructions); LLMTUNE Inc. is the processor.
- 1.2 Subject matter: provision of the LLMTUNE platform (fine-tuning, inference, agent tooling, GPU compute marketplace).
- 1.3 Duration: the term of the Terms of Service plus the retention period in Section 6.
- 1.4 Nature and purpose: hosting, transmitting, and processing Customer Content (including datasets, prompts, model outputs) as instructed by Customer through use of the Service.
- 1.5 Categories of data subjects: Customer's end users, employees, and other individuals whose personal data is included in Customer Content.
- 1.6 Categories of data: identifiers, content data, usage/telemetry data, and technical data included in Customer Content by Customer.
2. Processing Instructions
LLMTUNE processes personal data only on Customer's documented instructions under the Terms (including configuration and use of features), unless required by Union or Member State law. Customer warrants its instructions comply with applicable data protection law. LLMTUNE will inform Customer if it believes an instruction infringes applicable law.
3. Confidentiality
LLMTUNE personnel authorized to process Customer personal data are bound by confidentiality obligations and receive appropriate data protection training. Access is granted on a least-privilege basis.
4. Security Measures
LLMTUNE maintains technical and organizational measures including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Identity and access management with least-privilege, audited access
- Confidential compute (TEE) options for sensitive workloads
- Logging, monitoring, and incident response procedures
- Secure development practices and dependency management
LLMTUNE may update these measures but will not materially reduce overall protection.
5. Subprocessors
Customer generally authorizes LLMTUNE's use of subprocessors listed in the Privacy Policy (Section 5.1), including Google Cloud (hosting), Amazon Web Services (database), IO.net (decentralized GPU compute), Stripe / NowPayments / InFlow (payments), and Better Stack (logging). LLMTUNE remains liable for its subprocessors' performance and imposes data protection obligations no less protective than this DPA. LLMTUNE will give at least 30 days' notice of new subprocessors via the Privacy Policy; Customer may object on reasonable grounds by contacting privacy@llmtune.io.
6. Data Retention and Deletion
LLMTUNE retains Customer Content while the account is active and up to 30 days after deletion requests, except transaction records retained as required by tax law. On termination, Customer may export its data; LLMTUNE will delete Customer Content within 90 days of termination except where retention is required by law.
7. Data Subject Rights and Assistance
LLMTUNE assists Customer in responding to data subject requests (access, rectification, erasure, portability, objection, restriction) by making functionality available in the Service or, where not available, by responding to requests at privacy@llmtune.io within a reasonable period. LLMTUNE notifies Customer without undue delay if it receives a request directly.
8. Personal Data Breach
LLMTUNE notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, providing at least the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. Notification may be preliminary with updates to follow.
9. Audits
LLMTUNE makes available information necessary to demonstrate compliance (including this DPA, security documentation, and certifications where held). Customer may audit LLMTUNE's compliance once per year on 30 days' notice, during business hours, subject to confidentiality, or rely on an independent third-party audit report where available.
10. International Transfers and Standard Contractual Clauses
Where Customer is established in the EU/UK and personal data is transferred to LLMTUNE in the United States, the parties agree that:
- The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two: controller to processor) are incorporated by reference and apply, completed as follows: Annex I (parties, description of transfer) per Sections 1 and 5 of this DPA; Annex II (technical and organizational measures) per Section 4; Annex III (subprocessor list) per Section 5 and the Privacy Policy.
- The UK Addendum to the EU SCCs (International Data Transfer Addendum, Version B1.0) applies for UK transfers, with LLMTUNE as importer; Tables 2, 3 and 4 are completed per the corresponding Annexes above, and the "Selecting a security measure" option is not modified.
- Clause 17 (governing law): Delaware law. Clause 18(b) (forum): Delaware courts.
- Clause 14(a): the parties acknowledge data may be transferred to subprocessors under Section 5.
- LLMTUNE will document a transfer impact assessment on request and supplement safeguards where required.
11. Government Access Requests
If LLMTUNE receives a legally binding request from a public authority to disclose Customer personal data, it will direct the authority to request it from Customer, notify Customer (where legally permitted), challenge overbroad requests, and disclose only the minimum required. LLMTUNE publishes aggregate transparency information about such requests on request.
12. Limitations
This DPA does not apply to data LLMTUNE processes as an independent controller (e.g., account and billing data), which is governed by the Privacy Policy. Liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA limits either party's statutory obligations under GDPR.
13. Contact
LLMTUNE Inc., a Delaware corporation
1007 N Orange St, 4th Floor, Wilmington, DE 19801, United States
Data protection inquiries: privacy@llmtune.io