RIL Warden · Terms · Privacy
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Rip It Labs, LLC ("Processor", "we") and the Customer ("Controller", "you") and applies to Personal Data we process on your behalf when your agents route traffic through RIL Warden. If it conflicts with the Terms for that data, this DPA controls.
1. Roles and scope
You are the controller (or, where you act for another controller, the processor) of the Personal Data in your gateway data. We process that data only as your processor. The subject matter is the operation of the Service; the duration is the term of your subscription plus the deletion window below. The nature and purpose, the types of data, and the categories of data subjects are set out in Annex A.
2. Processing on your instructions
We process Personal Data only to provide and secure the Service, as described in the Terms and this DPA, and on your documented instructions (including your workspace configuration). We will tell you if, in our view, an instruction breaches applicable data-protection law, unless prohibited from doing so. We will not use your gateway data or vaulted secrets to train models, and we will not sell Personal Data.
3. Confidentiality
We ensure that personnel authorized to process Personal Data are bound by confidentiality and access it only as needed to provide the Service.
4. Security
We implement and maintain technical and organizational measures appropriate to the risk, including those summarized in Annex B and in our Privacy Policy and security policy.
5. Sub-processors
You authorize us to use the sub-processors in Annex C to provide the Service. We impose data-protection obligations on each that are no less protective than this DPA, and we remain responsible for their performance. We will give you at least [14] days' notice before adding or replacing a sub-processor (by [email / a subscribable page]), and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected Service.
6. Data subject requests
Taking into account the nature of the processing, we will assist you with appropriate measures to respond to requests from data subjects to exercise their rights, and we will forward to you any such request we receive directly.
7. Personal data breaches
We will notify you without undue delay, and in any event within [72 hours] of becoming aware, of a personal data breach affecting your Personal Data, with the information you reasonably need to meet your own obligations. The tamper-evident log helps establish what happened.
8. Deletion and return
On termination, at your choice, we will delete or return your Personal Data within [30 days], except copies we must keep by law and integrity hashes already anchored on public blockchains (which contain no Personal Data and cannot be deleted).
9. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and scheduling. [Counsel: define frequency, cost-bearing, and any reliance on third-party reports once available.]
10. International transfers
Where we transfer Personal Data across borders, we will rely on a lawful transfer mechanism. [Counsel: incorporate Standard Contractual Clauses / UK Addendum as applicable once the hosting region and customer geographies are set.]
11. Liability
Each party's liability under this DPA is subject to the limitations in the Terms. [Confirm interaction with any statutory liability that cannot be limited.]
Annex A: details of processing
- Subject matter and duration: operation of RIL Warden for the subscription term plus the deletion window.
- Nature and purpose: gating agent web requests, injecting vaulted secrets toward approved hosts, and keeping a tamper-evident audit log.
- Types of Personal Data: data contained in the gateway logs (agent identity, destinations, methods, paths, sizes, timestamps, decisions, source IP) and any Personal Data you place in vaulted secrets or in your account. You control what your agents send.
- Categories of data subjects: your personnel and end users, as determined by your use.
Annex B: security measures
TLS in transit; encryption at rest for vaulted secrets and backups; hashed access keys; per-workspace isolation; role-based access and least-privilege staff access; hash-chained, signed, tamper-evident logging with on-chain integrity anchoring; a coordinated vulnerability-disclosure policy. [Expand as measures mature, e.g. once an independent penetration test or SOC 2 is completed.]
Annex C: sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner | Hosting | [region] |
| Cloudflare | Network / TLS / DNS | Global |
| Sign-In and email | Global | |
| Stripe | Payments | Global |
Customer-enabled destinations (ntfy, Slack, a SIEM) act on your instruction when you turn them on and are not our sub-processors.
Contact
Rip It Labs, LLC · [business address] · [email protected]