Skip to content
Legal

Data Processing Addendum

Last updated June 24, 2026

This DPA applies where Sumio processes personal data on your behalf (you are the controller, Sumio is the processor). It forms part of our agreement with you.

1. Roles and scope

You determine the purposes and means of processing the personal data in your files; Sumio processes it only to provide the service and on your documented instructions.

2. Subject matter and duration

Processing covers the personal data contained in files you upload and instructions you run, for as long as your account is active or as needed to provide the service.

3. Confidentiality

Personnel authorized to process your data are bound by confidentiality obligations and only access data as needed to operate and support the service.

4. Sub-processors

We use vetted sub-processors (hosting, authentication, the AI model provider) under contracts with data-protection terms at least as protective as this DPA. A current list is available on request, and we'll give notice of material changes.

5. Security measures

Encryption in transit and at rest, access controls and audit logging, and (on supported plans) PII masking before data reaches the AI model.

6. International transfers

Where data is transferred across regions, we rely on appropriate safeguards (e.g. Standard Contractual Clauses). You can configure data residency on supported plans.

7. Data subject requests & breach notice

We'll assist you in responding to data-subject requests and will notify you without undue delay after becoming aware of a personal-data breach affecting your data.

8. Return and deletion

On termination, you can export your data, after which we delete it within a commercially reasonable period, subject to legal retention requirements.

This document is a working template, not legal advice. Have your counsel review and tailor it to your organization before relying on it.