Data Processing Agreement
Last updated: August 13, 2026. The summary of how we process personal data on your behalf; the signable version comes with your agreement. Illustrative text for a demonstration product; not legal advice.
1. Roles and scope
For personal data your organization submits through the Service, you are the controller and SwitchGate is the processor. We process it only on your documented instructions: to route requests to the providers you select, operate features you enable, and produce your ledger. Providers you route to act as your sub-processors for that request, under their own terms which we surface per model.
2. Security measures
TLS 1.3 in transit, AES-256 at rest, tenant-scoped caches, least-privilege access with audit trails, and the key-level controls described on the security page. We notify you of a personal data breach affecting your data without undue delay and no later than 72 hours after becoming aware.
3. Sub-processors
Our infrastructure sub-processors are listed at legal/subprocessors. We give 30 days' notice before adding one; you may object on reasonable data-protection grounds, and if we can't resolve it you may terminate the affected service with a pro-rata refund of remaining purchased credits.
4. Assistance and rights
We assist with data-subject requests, impact assessments and regulator consultations as the law requires. On termination we delete or return personal data, except what law requires us to keep, and confirm deletion on request.
5. Transfers
The control plane and ledger are hosted in Canada (EU adequacy). Requests transit to the provider and region you select; enterprise policies can restrict routing to approved regions. EEA/UK transfers rely on adequacy decisions and standard contractual clauses.