1. Roles
For Customer Personal Data processed in the Services as instructed by Customer: Customer is the controller (or a processor on behalf of a third-party controller) and Echo Prime Tech LLC("Processor") is the processor (or sub-processor). For account data Echo processes as a business for its own purposes (billing, platform security, marketing with consent), Echo acts as an independent controller under the Privacy Policy.
2. Subject matter and duration
Subject matter: hosting and processing Customer Personal Data submitted to or generated in Echo Forge workspaces. Duration: for the term of the Services plus any post-termination retention under Data Retention & Deletion. Nature: collection, storage, transmission, analysis for forge jobs, logging, backup, and deletion. Purpose: provide the Services. Types of data: account identifiers, content of prompts/files, technical logs — as determined by Customer. Data subjects: Customer's personnel, end users, and any individuals whose data Customer submits.
3. Processing instructions
Processor will process Customer Personal Data only on documented instructions from Customer (including configuration of the Services and this DPA), unless required by law. If Processor believes an instruction violates applicable data-protection law, it will inform Customer. Customer is responsible for the lawfulness of instructions and of data it submits.
4. Confidentiality
Processor ensures persons authorized to process Customer Personal Data are bound by confidentiality obligations.
5. Security measures
Processor implements appropriate technical and organizational measures, including access control, encryption in transit, segregation of production environments, logging, vulnerability management, and incident response procedures proportional to risk.
6. Subprocessors
Customer authorizes Processor to engage subprocessors listed at /subprocessors. Processor will impose data-protection obligations no less protective than this DPA. Material additions will be reflected on that page; Customer may object on reasonable data-protection grounds within 15 days of notice by emailing [email protected]. If unresolved, Customer may terminate the affected Services as its sole remedy.
7. Data subject rights and assistance
Taking into account the nature of processing, Processor will assist Customer by appropriate technical and organizational measures, insofar as possible, for Customer to respond to data-subject requests. Customer remains primary responder. Processor will assist with security, breach notification, DPIAs, and prior consultations where required and reasonable, at Customer's expense for extraordinary effort unless the need arises from Processor's breach of this DPA.
8. Personal data breach
Processor will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with available details to help Customer meet its obligations. Notification is not an admission of fault.
9. Return and deletion
Upon termination, Processor will delete or return Customer Personal Data in accordance with Data Retention & Deletion, except where retention is required by law or for bona fide legal holds.
10. Audits
Upon reasonable written request no more than once annually (unless a regulator or incident requires more), Processor will make available information necessary to demonstrate compliance with this DPA, including summaries of security controls. On-site audits require 30 days' notice, confidentiality agreements, and are at Customer's expense unless a material non-compliance is found.
11. International transfers
Where Customer Personal Data is transferred from the EEA/UK/Switzerland to a country not deemed adequate, the parties rely on Standard Contractual Clauses (controller-to-processor or processor-to-processor as applicable) or other lawful transfer mechanisms. Details available on request to [email protected].
12. Liability
Liability under this DPA is subject to the limitations in the Terms of Service unless mandatory law provides otherwise.
13. Order of precedence
If this DPA conflicts with the Terms regarding data-protection obligations for Customer Personal Data, this DPA controls. Signed enterprise DPAs control over this public DPA for that engagement.