Skip to document
Octoryn
ModelsSynthesisChatMarketplaceRoutingControlDevelopers
EN⌄
EnglishEN简体中文ZH
Open developer docs↗

DATA PROCESSING

Data Processing Addendum

This Data Processing Addendum forms part of the agreement between the customer and Octopus Core Pty Ltd when Octoryn Router processes personal data on the customer’s behalf. A signed or negotiated DPA controls if it differs from this published version.

Effective28 July 2026Contact ↗
Legal documentsPrivacy→Terms→DPA→Cookies→Acceptable use→Account deletion→

1. Scope and roles

Customer is the controller or business and Octopus Core Pty Ltd is the processor or service provider for customer personal data submitted to Octoryn Router. Each party complies with the data protection laws applicable to its role.

For account administration, billing contacts, website visitors and direct business communications, Octopus Core may act as an independent controller as described in the Privacy Notice.

2. Documented instructions

We process customer personal data only on documented instructions, including the agreement, API requests, workspace configuration, routing policy and reasonable written directions consistent with the service.

If we believe an instruction violates applicable data protection law, we will inform the customer unless prohibited and may pause the affected processing while the parties resolve it.

3. Confidentiality and access

Personnel authorised to process customer personal data are bound by confidentiality obligations and receive access only where needed for their role. Access is reviewed and removed when no longer required.

4. Security measures

We maintain measures appropriate to the risk and service scope, including:

  • Encryption in transit and protected management of workload credentials.
  • Workspace, environment and role-based access boundaries.
  • Logging, monitoring, vulnerability management and incident response.
  • Backup, recovery and change-management controls appropriate to the deployed service.
  • Supplier assessment and contractual safeguards for subprocessors.

5. Subprocessors and model providers

Customer authorises subprocessors necessary to operate the service and model providers enabled by the customer’s route. Subprocessors are bound by data protection obligations appropriate to their function.

The managed service uses infrastructure in the configured region. The website and edge security may use Cloudflare services. Model providers vary by customer policy and may include providers accessed through customer-owned credentials. Customer may request the current service-specific list from the privacy contact.

6. International transfers

We do not transfer customer personal data outside the configured processing boundary except as instructed through an eligible provider or as otherwise documented. Where a restricted transfer occurs, the parties use a lawful transfer mechanism and supplementary measures where required.

7. Data subject requests

Taking account of the nature of processing, we provide reasonable assistance for customer responses to access, correction, deletion, restriction, objection and portability requests. We do not respond directly to a customer’s end user unless authorised or legally required.

8. Security incidents

We notify the customer without undue delay after confirming a personal data breach affecting customer personal data, provide available information needed for assessment, and take reasonable steps to contain and remediate the incident.

Notification is not an admission of fault. Customer remains responsible for notifications it is required to make as controller.

9. Assistance and audit

We provide information reasonably necessary to demonstrate compliance with this DPA and support proportionate audits under the agreement. Audits must protect other customers, security information and confidential systems, and should use existing independent reports before requesting intrusive testing.

10. Return and deletion

At the end of the service, we return or delete customer personal data as instructed and technically feasible, unless law requires retention. Residual backup copies remain protected and are removed through the normal backup lifecycle.

11. Processing details

Subject matter: routing customer-authorised model requests. Duration: the agreement plus documented deletion periods. Nature: receiving, transmitting, securing, monitoring and returning requests and outputs. Purpose: providing the Router service.

Data subjects may include customer personnel, authorised users and people whose information a customer submits. Data may include identifiers, communications, prompts, outputs, usage metadata and other categories chosen by the customer. Customers must not submit special-category or regulated data unless the deployment and agreement expressly permit it.

DPA and subprocessor enquiries: privacy@octopusos.ai.

Octoryn

One governed model layer for Octopus customers and the Octoryn product family.

Production online
ProductModelsSynthesis↗Chat↗MarketplaceRoutingProvidersPricingEnterpriseLabsDownloads
CompanyAboutBlogCareersPrivacyTermsDPACookiesAcceptable useDelete accountSupportData
DeveloperDocumentationAPI referenceSDKCLI installStatus
ConnectOctopus Core↗Octopus OS↗Legal centreGitHub↗All channels
© 2026 Octopus Core Pty Ltd.Sydney production · ap-southeast-2
EN⌄
EnglishEN简体中文ZH