1. Scope and roles
Customer is the controller or business and Octopus Core Pty Ltd is the processor or service provider for customer personal data submitted to Octoryn Router. Each party complies with the data protection laws applicable to its role.
For account administration, billing contacts, website visitors and direct business communications, Octopus Core may act as an independent controller as described in the Privacy Notice.
2. Documented instructions
We process customer personal data only on documented instructions, including the agreement, API requests, workspace configuration, routing policy and reasonable written directions consistent with the service.
If we believe an instruction violates applicable data protection law, we will inform the customer unless prohibited and may pause the affected processing while the parties resolve it.
3. Confidentiality and access
Personnel authorised to process customer personal data are bound by confidentiality obligations and receive access only where needed for their role. Access is reviewed and removed when no longer required.
4. Security measures
We maintain measures appropriate to the risk and service scope, including:
- Encryption in transit and protected management of workload credentials.
- Workspace, environment and role-based access boundaries.
- Logging, monitoring, vulnerability management and incident response.
- Backup, recovery and change-management controls appropriate to the deployed service.
- Supplier assessment and contractual safeguards for subprocessors.
5. Subprocessors and model providers
Customer authorises subprocessors necessary to operate the service and model providers enabled by the customer’s route. Subprocessors are bound by data protection obligations appropriate to their function.
The managed service uses infrastructure in the configured region. The website and edge security may use Cloudflare services. Model providers vary by customer policy and may include providers accessed through customer-owned credentials. Customer may request the current service-specific list from the privacy contact.
6. International transfers
We do not transfer customer personal data outside the configured processing boundary except as instructed through an eligible provider or as otherwise documented. Where a restricted transfer occurs, the parties use a lawful transfer mechanism and supplementary measures where required.
7. Data subject requests
Taking account of the nature of processing, we provide reasonable assistance for customer responses to access, correction, deletion, restriction, objection and portability requests. We do not respond directly to a customer’s end user unless authorised or legally required.
8. Security incidents
We notify the customer without undue delay after confirming a personal data breach affecting customer personal data, provide available information needed for assessment, and take reasonable steps to contain and remediate the incident.
Notification is not an admission of fault. Customer remains responsible for notifications it is required to make as controller.
9. Assistance and audit
We provide information reasonably necessary to demonstrate compliance with this DPA and support proportionate audits under the agreement. Audits must protect other customers, security information and confidential systems, and should use existing independent reports before requesting intrusive testing.
10. Return and deletion
At the end of the service, we return or delete customer personal data as instructed and technically feasible, unless law requires retention. Residual backup copies remain protected and are removed through the normal backup lifecycle.
11. Processing details
Subject matter: routing customer-authorised model requests. Duration: the agreement plus documented deletion periods. Nature: receiving, transmitting, securing, monitoring and returning requests and outputs. Purpose: providing the Router service.
Data subjects may include customer personnel, authorised users and people whose information a customer submits. Data may include identifiers, communications, prompts, outputs, usage metadata and other categories chosen by the customer. Customers must not submit special-category or regulated data unless the deployment and agreement expressly permit it.
DPA and subprocessor enquiries: privacy@octopusos.ai.
