Data processing addendum

Last updated August 2026. This version has not yet been reviewed by counsel.

Draft — legal review required

This document was written to describe how Larsa actually works, but it is not a finished legal instrument. Have it reviewed by a lawyer qualified in your jurisdiction before you rely on it, and fill in the bracketed placeholders — the operator's legal name, its registered address, and the governing law — before publishing it.

1. Purpose and roles

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (“Customer”) and [OPERATOR LEGAL NAME] (“Larsa”, “Processor”), and applies wherever Customer's use of the Service involves Larsa processing personal data on Customer's behalf. Where that personal data is subject to a data protection law, Customer is the controller (or, where Customer itself processes on behalf of another controller, a processor acting under that controller's instructions) and Larsa is the processor.

This DPA supplements the Terms of Service and the Privacy Policy, which describe how Larsa handles data about Customer's own account; it does not replace either. Capitalized terms not defined here have the meaning given in the Terms of Service.

2. Scope and duration of processing

Larsa processes personal data only to provide the Service to Customer: to run inference on the content Customer sends, to store content Customer places in a Knowledge Base until Customer deletes it, and to meter and secure that usage. The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects, are set out in Annex 1.

Processing continues for the term of the Terms of Service and ends, subject to Section 11, when Customer deletes the relevant data or closes its account.

3. Customer's instructions

Larsa processes personal data only on Customer's documented instructions, which consist of the Terms of Service, this DPA, and Customer's use of the Service's ordinary functionality (an API call, a Knowledge Base upload, a configuration change) — unless required to do otherwise by law, in which case Larsa will inform Customer before processing unless the law forbids it. Larsa will tell Customer if, in Larsa's opinion, an instruction would violate applicable data protection law.

4. Confidentiality of personnel

Larsa ensures that anyone it authorizes to process personal data is under an appropriate obligation of confidentiality and is trained on handling personal data before being given access.

5. Security measures

Larsa maintains technical and organizational measures appropriate to the risk, including: encryption of data in transit and at rest; access control limiting production access to staff who need it, logged and reviewed; separation between customer environments; separation between Larsa's own operational data and the inference pipeline, so request content is not retained beyond the operational window described in the Privacy Policy; and a documented incident response process. Annex 1 lists these measures in more detail.

6. Sub-processing

Customer authorizes Larsa to engage the sub-processors listed in Annex 1 and any general category of sub-processor described there. Larsa will impose data protection terms on each sub-processor no less protective than this DPA, and remains responsible for a sub-processor's performance. Larsa will give Customer notice of a new sub-processor by [MECHANISM, e.g. posting to a sub-processor list and, on request, email], and Customer may object on reasonable data-protection grounds within [OBJECTION PERIOD, e.g. 14 days]; if the parties cannot resolve the objection, Customer's remedy is to stop using the feature that relies on that sub-processor.

7. International transfers

Where processing under this DPA involves a transfer of personal data out of the jurisdiction it was collected in, Larsa will put in place a lawful transfer mechanism appropriate to that transfer — [TRANSFER MECHANISM, e.g. the Standard Contractual Clauses, incorporated by reference as Annex 2] — before the transfer occurs.

8. Assistance with data subject requests

Larsa will give Customer reasonable assistance, by appropriate technical and organizational measures, to respond to a data subject's request to exercise their rights under applicable law, and to Customer's own data protection impact assessments and consultations with a supervisory authority where those relate to Larsa's processing. Where a data subject contacts Larsa directly about Customer's data, Larsa will direct them to Customer without responding to the substance of the request.

9. Personal data breach notification

Larsa will notify Customer without undue delay, and in any case within [BREACH NOTICE WINDOW, e.g. 72 hours] of becoming aware, of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal data Larsa processes on Customer's behalf. The notice will describe what Larsa knows at the time — the nature of the breach, the data and data subjects affected where known, and the measures taken or proposed — and Larsa will update it as more is learned.

10. Audit

On reasonable notice, and no more than once per year absent a specific security incident or a supervisory authority's requirement, Larsa will make available the information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a summary of a third-party audit or certification Larsa holds rather than an on-site inspection, unless applicable law gives Customer a right to more.

11. Deletion or return of data on termination

On termination of the Service, or earlier on Customer's request, Larsa will, at Customer's choice, delete or make available for export the personal data Customer has stored in a Knowledge Base, and will delete it from active storage within 30 days and from backups on their normal rotation, except for the billing and usage records described in the Privacy Policy that Larsa is required to keep.

12. Liability

Each party's liability arising out of this DPA is subject to the limitation of liability in the Terms of Service.

Annex 1 — categories of data and processing detail

Subject matter
Provision of the Larsa API — inference, storage in Knowledge Bases, and the metering and security processing needed to run the Service.
Duration
For the term of the Terms of Service, and until deletion as described in Section 11.
Categories of data subjects
Customer's own personnel who access the console; and, where Customer's use of the Service involves personal data about other people — end users of something Customer built on the Service, or individuals named in a document Customer uploads for OCR or retrieval — those individuals.
Categories of personal data
Account identifiers (name, email); content Customer submits to the Service, which may contain personal data depending on what Customer sends — for example a name in a transcript, a face in an image sent for OCR, or a data subject's details in a document placed in a Knowledge Base; usage metadata (IP address, timestamps, request identifiers).
Special categories
Larsa does not intentionally process special categories of data. If Customer's own use of the Service involves special category data — for example sending medical or biometric content to a model — Customer is responsible for having a lawful basis to do so before submitting it.
Sub-processors
Payment processor (billing data only); email delivery provider (account and security notices); infrastructure providers for backups and outbound email. Inference runs on hardware Larsa operates; request content is not routed through a third-party model API. Current names are available on request — see Section 6.