Final Router

Legal

Data Processing Addendum

The GDPR-compliant processor terms that apply whenever you route personal data through Final Router. It forms part of our Terms of Service.

Effective 1 August 2026

1.Scope and roles

This Addendum applies where you use Final Router to process personal data that is subject to the EU General Data Protection Regulation, the UK GDPR, or an equivalent law. It forms part of, and is governed by, our Terms of Service.

For that data you are the controller and INNOVIDEN GP - a general partnership registered in Greece at Zalokosta 8, Kolonaki, Athens, Greece, trading as Final Router - is the processor. Where you are yourself processing on behalf of someone else, you are a processor and we are a sub-processor; the same obligations apply to us either way.

This Addendum takes effect automatically when you accept the Terms of Service. If your procurement process needs a countersigned copy, email privacy@finalrouter.com and we will send one.

2.Subject matter and duration

ItemDetail
Subject matterRouting API requests to large language model providers and metering the result
DurationFor as long as your account is open, plus the retention periods in the Privacy Policy
Nature and purposeTransmission, temporary in-memory processing, and storage of request metadata
Types of personal dataAny personal data you include in a prompt; account identifiers; API key identifiers; IP addresses in security logs
Categories of data subjectYour end users, your staff, and anyone referred to in the content you route

We do not require special category data to run the service and we ask you not to send it. If your use case involves health, biometric or similar data, contact us before you start so we can agree the additional controls in writing.

3.Our obligations as processor

  1. We process personal data only on your documented instructions. Your configuration in the dashboard — routing policy, allowed models, provider keys — is a documented instruction. If a law compels us to process beyond that, we tell you first unless the law forbids it.
  2. We do not sell personal data, and we do not use it to train models — ours or anyone else's.
  3. Everyone with access is bound by a confidentiality obligation that survives their engagement ending.
  4. We apply the technical and organisational measures set out below and keep them under review.
  5. We assist you, at your cost where the effort is material, with data protection impact assessments and with prior consultation of a supervisory authority.
  6. We help you respond to data subject requests. Prompt content is not retained unless you have switched on prompt storage, so most requests are satisfied from your own systems; where storage is on you can delete that text yourself at any time. For account data and metadata we act within 10 working days.
  7. On termination we delete personal data on the schedule in the Privacy Policy, or return it on request, except where retention is legally required.
  8. We make available the information needed to demonstrate compliance and submit to audits as described below.

4.Your obligations as controller

  • Ensure you have a lawful basis for the personal data you route, and that your privacy notice covers it.
  • Choose which providers your traffic may reach, and satisfy yourself that their retention and location terms suit your use case.
  • Do not send personal data you do not need. Redaction before the request is the cheapest control available to you.
  • Configure spend caps, model restrictions and key scopes appropriately — we enforce the settings you give us, and cannot infer the ones you meant.

5.Sub-processors

You give general authorisation for the sub-processors below. Each is bound by written terms no less protective than this Addendum.

Sub-processorPurposeLocation
SupabaseDatabase, authentication, credential storageEU (Frankfurt)
VercelApplication hosting and edge deliveryEU (Frankfurt) primary
StripePayment processingEU / US under SCCs
CloudflareDNS, WAF, bot mitigationGlobal edge
ResendTransactional email deliveryUS
Google reCAPTCHABot mitigation on sign-upUS
Model providers you enableServing the inference request you routed to themPer provider, disclosed in the dashboard

A model provider becomes a sub-processor only for traffic you route to it. Enabling or disabling a provider in the dashboard is how you grant or withdraw that authorisation, and it takes effect on your next request.

We give 30 days notice before adding or replacing any other sub-processor. If you object on reasonable data protection grounds within that window and we cannot offer an alternative, you may terminate the affected service and we refund unused credits pro rata.

6.Technical and organisational measures

These are the Article 32 measures we commit to. They are described more fully, and kept current, on our security page.

  • Encryption in transit with TLS 1.2 or better on every connection, internal ones included.
  • Encryption at rest for the database, and envelope encryption with AES-256-GCM for provider credentials under a key held outside the database.
  • Gateway API keys stored only as hashes, so the plaintext key exists in one place: your clipboard, once.
  • Row-level security on every table, so tenant isolation is enforced by the database rather than by application code alone.
  • Least-privilege access, multi-factor authentication for staff, and access reviewed quarterly.
  • Prompt and completion bodies held in memory only for the life of a request, and not written to persistent storage unless you switch on prompt storage — in which case they are kept for 30 days, readable only by your account, and deleted the moment you switch it off.
  • Rate limiting, WAF and bot mitigation at the edge.
  • Backups encrypted, held in the EU, and restore-tested.
  • Dependency scanning and secret scanning on every change before it reaches production.

7.Personal data breach

If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 48 hours of becoming aware.

The notification describes what happened, the categories and approximate number of records affected, the likely consequences, and what we are doing about it. Where we cannot supply all of that at once, we send what we have and follow up rather than waiting. We do not notify your supervisory authority on your behalf — that is your call as controller — but we give you everything you need to make it.

8.International transfers

Where personal data leaves the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses (Module Two, controller to processor, or Module Three where you are a processor), incorporated into this Addendum by reference, with the UK International Data Transfer Addendum applied where the UK GDPR governs.

Docking clause: Clause 7 applies. Supervisory authority: the authority of the Member State in which you are established. Option 2 of Clause 9(a) applies with the 30 day notice period set out above. In Clause 17 the governing law is Irish law, and in Clause 18(b) the forum is Ireland.

You can keep prompt content inside the EEA by restricting your account to EU-hosted models in the dashboard.

9.Audit

On request, and not more than once a year unless a supervisory authority requires otherwise, we provide our current security documentation and answer a reasonable due diligence questionnaire within 30 days.

Where that is genuinely not sufficient for your compliance obligations, we will accommodate an on-site or remote audit by you or an independent auditor, subject to 30 days notice, reasonable confidentiality terms, and scoping that does not compromise other customers' data.

10.Precedence

Where this Addendum conflicts with the Terms of Service, this Addendum wins for matters of data protection. Where it conflicts with the Standard Contractual Clauses, the Clauses win.

For a signed copy, a security questionnaire, or a bespoke DPA, write to privacy@finalrouter.com.