Data Processing Addendum
Last updated June 24, 2026
This DPA applies where Sumio processes personal data on your behalf (you are the controller, Sumio is the processor). It forms part of our agreement with you.
1. Roles and scope
You determine the purposes and means of processing the personal data in your files; Sumio processes it only to provide the service and on your documented instructions.
2. Subject matter and duration
Processing covers the personal data contained in files you upload and instructions you run, for as long as your account is active or as needed to provide the service.
3. Confidentiality
Personnel authorized to process your data are bound by confidentiality obligations and only access data as needed to operate and support the service.
4. Sub-processors
We use vetted sub-processors (hosting, authentication, the AI model provider) under contracts with data-protection terms at least as protective as this DPA. A current list is available on request, and we'll give notice of material changes.
5. Security measures
Encryption in transit and at rest, access controls and audit logging, and (on supported plans) PII masking before data reaches the AI model.
6. International transfers
Where data is transferred across regions, we rely on appropriate safeguards (e.g. Standard Contractual Clauses). You can configure data residency on supported plans.
7. Data subject requests & breach notice
We'll assist you in responding to data-subject requests and will notify you without undue delay after becoming aware of a personal-data breach affecting your data.
8. Return and deletion
On termination, you can export your data, after which we delete it within a commercially reasonable period, subject to legal retention requirements.