SemSwitch Data Processing Addendum
Version: 2.0
Revision date: September 4, 2026
This Data Processing Addendum ("DPA") sets out the terms on which SemSwitch, Inc. ("SemSwitch") processes personal data on behalf of a customer ("Customer") in providing the services identified in their agreement, including Setsuna where applicable.
This is SemSwitch's standard form for customer contracting. It becomes binding when both parties sign it or expressly incorporate this version into an accepted Order or other written agreement (the "Agreement"). Before the covered processing begins, the parties must complete or incorporate an agreed service schedule describing the actual processing (the "Service Schedule"). Publication of this page, a preview invitation alone, or technical ability to submit data does not complete that schedule or establish an international-transfer safeguard.
To arrange execution, contact legal@semswitch.com or privacy@semswitch.com. The Service Schedule is exchanged privately and may be included in an Order; no separate public legal page is necessary.
1. Definitions and interpretation
Applicable Data Protection Law means the privacy and personal-data-protection laws applicable to the processing under the Agreement, including, where applicable, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and applicable UK data-protection legislation, the Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended ("CCPA"). Listing a law does not establish that it applies to every party or every processing activity.
Customer Personal Data means personal data SemSwitch processes on Customer's behalf in providing the covered service, including personal data contained in workload inputs, outputs, files, commands, or related content-bearing records. Data does not lose this status because it is labeled a log, diagnostic, identifier, or telemetry record.
Personal Data Breach means a security breach resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. An unsuccessful attempt that does not compromise Customer Personal Data is not, by itself, a Personal Data Breach.
Subprocessor means another processor engaged by SemSwitch to process Customer Personal Data for Customer. An independent service selected and contracted by Customer is not a SemSwitch Subprocessor merely because Customer directs a workload to connect to it.
Other data-protection terms, including controller, processor, business, service provider, contractor, personal data, and processing, have their applicable statutory meanings. Capitalized commercial terms not defined here have the meanings in the Agreement.
2. Roles and covered processing
Customer acts as controller or business, or as a processor authorized by its controller to engage SemSwitch. SemSwitch acts as Customer's processor, service provider, or permitted downstream processor for Customer Personal Data. Where Customer is itself a processor, it must ensure that its instructions and this engagement are authorized by the relevant controller.
The Service Schedule identifies the parties and contacts; the covered service and deployment; subject matter, nature, purposes, frequency, and duration of processing; data-subject and personal-data categories; authorized subprocessors and processing locations; technical and organizational measures; and return and deletion arrangements. Those details may be supplied through specifically identified, mutually accepted exhibits, rather than duplicated documents.
For an authorized Setsuna workload, processing may involve receiving and transmitting inputs, executing commands and code, maintaining temporary execution state, returning outputs, and handling related operational or support records. This description is not permission to process every category of personal data or to enable every deployment model. The agreed Service Schedule determines the actual scope.
SemSwitch separately acts as a controller for information it processes for its own legitimate business purposes, such as ordinary business contacts, billing administration, and necessary account or security administration, as described in the Privacy Policy. The role depends on the actual purpose and applicable law, not the record's label. This distinction does not permit SemSwitch to repurpose Customer Personal Data for independent advertising, model training, or another incompatible purpose.
3. Documented instructions and customer obligations
Customer instructs SemSwitch to process Customer Personal Data only to deliver and support the covered service under the Agreement, the Service Schedule, and lawful documented instructions, including authorized configurations and operations initiated by Customer's users. Customer remains responsible for the lawfulness, accuracy, necessity, and minimization of the data it supplies; required notices and legal bases; and its instructions and customer-controlled systems.
SemSwitch will process Customer Personal Data only on those instructions, including for any transfer, unless processing is required by a law to which it is subject and is permitted under Applicable Data Protection Law and any applicable transfer instrument. SemSwitch will inform Customer of a legal requirement before processing where legally permitted. A law-enforcement or other third-party request does not create a general contractual right to disclose data beyond what is lawfully required.
If SemSwitch believes an instruction violates Applicable Data Protection Law, it will promptly inform Customer and may suspend the affected processing while the parties address the issue. It will not silently substitute a materially different processing purpose. Instructions requiring a material expansion of the service must be agreed before implementation.
SemSwitch will not sell Customer Personal Data, disclose it for cross-context behavioral advertising, use it for independent general-purpose model training, or make it available to another customer. A customer-directed training or evaluation activity requires authorization within the covered service; it does not grant independent training rights to SemSwitch or its providers.
Special-category data, children's data, protected health information, regulated financial datasets, and other data requiring additional safeguards are not included unless expressly identified and authorized in the Service Schedule and the necessary legal and operational safeguards are in place. A use restriction does not eliminate either party's duties for data actually processed.
4. Confidentiality and security
SemSwitch will ensure that people it authorizes to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty and have access only as reasonably necessary for their authorized responsibilities.
SemSwitch will implement and maintain technical and organizational measures appropriate to the risks, nature, scope, context, and purposes of the covered processing, taking into account the state of the art and implementation costs, and meeting applicable statutory security requirements, including Article 32 GDPR where applicable. The Service Schedule records the measures actually applicable to the service, including relevant access, transmission, storage, isolation, operational, and lifecycle controls and the allocation of responsibilities.
SemSwitch will assess the effectiveness of the applicable measures and address identified deficiencies in a manner proportionate to risk. It may evolve the measures without materially reducing the agreed overall protection. A material change in risk or processing scope must be addressed before the changed processing begins. Customer is responsible for the controls assigned to it, but that allocation does not excuse SemSwitch from its own duties.
Neither publication of this DPA nor a provider's certification represents that SemSwitch holds an independent certification, supplies confidential computing, guarantees secure physical erasure of every copy, or supports a regulated use without the required arrangement. Necessary safeguards must exist in operation, not only in this document.
5. Subprocessors
Customer authorizes the Subprocessors identified in the agreed Service Schedule for their stated functions and locations. Before engaging a Subprocessor, SemSwitch will assess its suitability and enter a binding agreement imposing data-protection obligations that provide at least the level of protection required for that processing under this DPA and applicable law. SemSwitch remains responsible to Customer for the Subprocessor's performance of those obligations.
Where Customer grants general written authorization, SemSwitch will provide written notice of an intended addition or replacement at least 30 days before the new Subprocessor begins covered processing. The notice will identify the provider, function, relevant data, and processing locations, and give Customer an opportunity to object on reasonable data-protection grounds. SemSwitch will maintain and provide the current applicable list. Updating an unrelated website vendor list is not a substitute for required notice to Customer.
Customer should object within 15 days of receiving notice and explain its grounds. The parties will work in good faith to resolve the concern through appropriate safeguards or a commercially reasonable alternative. While a timely objection remains unresolved, SemSwitch will not send Customer Personal Data to the objected-to new Subprocessor; it may pause affected processing if necessary. If no acceptable solution is available, either party may terminate the affected portion without penalty, and SemSwitch will refund unused prepaid fees for that portion.
Any shorter notice required by an urgent legal or security necessity is permitted only to the extent allowed by Applicable Data Protection Law and the applicable transfer instrument. SemSwitch must explain the necessity, give notice as soon as practicable, and preserve Customer's applicable objection and termination rights.
6. Personal Data Breaches
SemSwitch will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. It will not wait for a complete investigation or final determination of every affected record before giving an initial notice.
The notice will provide available information about the nature of the breach; affected categories and approximate numbers of individuals and records; likely consequences; containment and remedial actions; and a contact for follow-up. Information may be supplied in stages, with further updates without undue delay as material facts become available.
SemSwitch will take appropriate steps to contain, investigate, mitigate, and remediate the breach, preserve relevant evidence, and reasonably assist Customer with its assessment and applicable notification duties. Notification is not an admission of liability. Customer determines its own regulatory and individual notifications, except where SemSwitch has a separate legal duty. SemSwitch will coordinate with Customer where legally permitted before naming Customer in a notification.
Customer must maintain a reachable security or privacy contact in the Service Schedule. That requirement does not excuse SemSwitch from reasonable efforts to notify Customer through another known channel when necessary.
7. Individual requests and compliance assistance
Taking account of the nature of the processing, SemSwitch will assist Customer through appropriate technical and organizational measures, insofar as possible, to respond to requests to access, correct, delete, restrict, obtain a portable copy of, or otherwise exercise rights concerning Customer Personal Data.
If SemSwitch receives such a request directly, it will promptly notify Customer, unless prohibited by law, and will not respond substantively except on Customer's instructions or as legally required. It may acknowledge receipt and explain the appropriate contact route. It will not obstruct rights an individual may lawfully exercise directly against SemSwitch.
Taking account of the processing and information available, SemSwitch will also assist Customer with applicable security obligations, breach notification, data-protection impact assessments, and prior consultation with a regulator. It will provide reasonably necessary information about its processing and safeguards.
Ordinary assistance necessary to fulfill this DPA is included in the covered service. The parties may agree reasonable charges in advance for exceptional work outside that scope, but fees or commercial disagreement may not prevent either party from fulfilling a mandatory obligation, and SemSwitch will not charge Customer to remedy SemSwitch's breach.
8. Information, audits, and remediation
SemSwitch will make available information reasonably necessary to demonstrate compliance with this DPA and applicable processor obligations, and will allow and contribute to audits and inspections by Customer or an independent auditor Customer appoints. Relevant existing documentation may be used first where it adequately answers the request; this does not create a claim that any certification or independent audit report already exists.
Routine audits will use reasonable advance notice, confidentiality protections, appropriate scope, and methods that minimize disruption and protect other customers' information. Ordinarily, one routine audit per year is sufficient. That administrative expectation does not restrict an audit required by law, a regulator, an applicable transfer instrument, a Personal Data Breach, or reasonable evidence of material non-compliance. An inspection may be required when documents do not adequately demonstrate compliance.
Customer ordinarily bears its external auditor's costs; SemSwitch bears its own reasonable compliance-assistance costs and the cost of remedying its non-compliance. No procedural restriction or charge may defeat a mandatory audit right. The parties will promptly address material findings and agree a risk-appropriate remediation plan. Customer may take reasonable steps to stop and remediate unauthorized processing.
9. Return, deletion, and residual copies
At the end of covered processing, SemSwitch will, at Customer's choice, return or delete Customer Personal Data and delete remaining copies, unless retention is required by applicable law. The Service Schedule specifies how and when this is completed, including the customer's export method and any applicable maximum deletion period. During service, SemSwitch will carry out supported and lawful deletion instructions in accordance with that schedule and applicable law.
Customer's instructed lifecycle may include destroying temporary execution data during service. A later return request does not require reconstruction of data already deleted pursuant to those instructions. SemSwitch will describe relevant ephemeral-storage limitations before Customer authorizes the processing; the parties must agree an appropriate retrieval method where a return obligation is needed.
If immediate removal from a backup or archive is not practicable, the Service Schedule must identify the applicable bounded deletion cycle. Until removal, the data must be placed beyond ordinary use, access restricted, and protection maintained. It may not be reused for a separate purpose, and any necessary restoration must preserve or reapply outstanding deletion instructions. An unspecified backup is not permission for indefinite retention.
Where law requires continued retention, SemSwitch will identify the basis and relevant scope to Customer where legally permitted, isolate the retained data from other uses, and delete it when the obligation ends. Upon request, SemSwitch will confirm completion of its applicable return or deletion obligations in writing. Its confirmation must accurately state any lawful residual retention; it must not describe logical deletion as verified physical-media overwriting.
10. International transfers
The Service Schedule identifies the locations of covered processing, including relevant storage, remote support or administrative access, and Subprocessor processing. SemSwitch will respect agreed location restrictions and will not make a restricted transfer without a valid legal basis and the safeguards required by Applicable Data Protection Law.
Where the parties rely on European Commission standard contractual clauses, they must put the applicable approved clauses into binding effect, select the correct module and permitted options, complete the required annexes using the actual parties and processing details, and undertake any necessary transfer assessment and supplementary measures. A controller-to-processor transfer and a processor-to-processor transfer require the appropriately selected arrangement.
Where UK transfer rules apply, the parties must complete and put into binding effect the applicable UK international data transfer agreement or approved UK addendum to the relevant European clauses, including its required tables and mandatory provisions, or establish another valid mechanism. European clauses alone are not a UK transfer arrangement. Swiss or other jurisdiction-specific requirements must likewise be addressed where applicable.
A provider's participation in a framework does not establish SemSwitch's participation or independently resolve a customer-to-SemSwitch transfer. This DPA does not represent that any incomplete or unsigned transfer paperwork is effective. The affected restricted transfer must not begin until its required arrangement is completed.
If a safeguard ceases to provide the required protection, the parties will promptly address the problem. If compliant processing cannot be maintained, SemSwitch will suspend the affected transfer and the parties may terminate the affected service, with the applicable unused-fee refund, rather than continue an unlawful transfer. Mandatory rights and protections in an executed transfer instrument prevail, including its rules concerning government requests, applicable law, courts, and individual remedies.
11. U.S. state service-provider and processor terms
Where the CCPA applies, SemSwitch acts as a service provider or contractor for Customer Personal Data, as applicable. The specific business purposes are the service activities identified in the Agreement and Service Schedule, not an unrestricted commercial purpose.
SemSwitch will not sell or share that information; retain, use, or disclose it outside those specified purposes or outside the direct business relationship except as expressly permitted by law; or combine it with personal information received from another person or collected through its own interactions except to the limited extent lawfully permitted for the specified service. It will not use these exceptions to circumvent the stricter limitations in this DPA.
SemSwitch certifies that it understands and will comply with these restrictions. It will provide the same level of privacy protection required by applicable law, notify Customer if it determines that it can no longer meet its obligations, and allow Customer to take reasonable and appropriate steps to verify compliance and stop and remediate unauthorized use. Sections 5, 7, 8, and 9 provide the applicable subcontracting, assistance, assessment, and deletion arrangements.
Equivalent applicable requirements of other U.S. state controller-processor laws apply to the covered processing, including instructions, confidentiality, reasonable security, assistance, subcontractor safeguards, and the information or assessments needed to demonstrate compliance. Nothing here purports to elect voluntarily into a regulatory regime where a separate formal election is required.
12. Duration, precedence, and changes
This DPA applies for the duration of covered processing, including authorized residual retention after the commercial service ends. Its confidentiality, deletion, and other relevant protections continue for as long as SemSwitch or its Subprocessors retain Customer Personal Data.
This DPA prevails over conflicting provisions of the Agreement concerning personal-data processing. Mandatory provisions of an applicable international-transfer instrument prevail over this DPA. A Service Schedule may specify operational details or greater protection but may not reduce a mandatory legal protection. Commercial liability provisions in the Agreement apply except where they would override a non-waivable obligation, an individual's enforceable rights, or mandatory transfer terms.
A website update does not unilaterally amend an executed DPA or expand Customer's processing instructions. Amendments require the parties' written agreement, except for changes expressly permitted through this DPA's Subprocessor or security procedures or the applicable transfer instrument. The parties will cooperate on changes needed to comply with applicable law; if they cannot maintain lawful processing, the affected processing must stop.
Privacy and DPA administration: privacy@semswitch.com
Execution and legal notices: legal@semswitch.com
Security reports: security@semswitch.com
SemSwitch, Inc.
8 The Green, Suite B
Dover, DE 19901
United States