Get early access Open the demo

Data Processing Addendum

Last updated 23 August 2026. Forms part of the agreement between you and m2Dev LLC.

Template — not yet reviewed by counselThis document is a starting draft prepared for m2Dev LLC. Bracketed items need real values, and the whole thing needs review by a qualified attorney before it is relied on. Do not publish as-is.

1. Scope

This addendum applies where m2Dev LLC processes personal data on your behalf in providing Swurl and where that processing is subject to the UK GDPR, the EU GDPR, or comparable law. You are the controller; we are the processor. It is incorporated automatically into every paid agreement — no signature is required, though we will countersign on request.

2. Subject matter and duration

Subject matter: provision of a multi-provider AI routing, metering and workspace service. Duration: the term of the agreement plus the retention periods in the Privacy Policy. Nature and purpose: transmission to model providers, storage of threads, metering and billing, support. Data subjects: your personnel and any individuals referenced in content you submit. Categories: account identifiers, usage metadata, and whatever personal data your content happens to contain.

3. Our obligations

  • Process only on your documented instructions, of which the agreement and your product configuration are the primary ones.
  • Ensure personnel with access are bound by confidentiality.
  • Implement the technical and organisational measures described at /security/, which form Annex II.
  • Assist you with data subject requests, impact assessments and regulator consultations, taking account of the nature of processing.
  • Notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data.
  • Delete or return personal data at the end of the term, per the Privacy Policy schedule.
  • Make available the information needed to demonstrate compliance and allow an audit no more than once a year, or after a breach, on reasonable notice — satisfied by written responses and evidence until an independent report exists.

4. Subprocessors

You give general written authorisation for us to engage subprocessors. The current list is at /subprocessors/, which you can subscribe to. We give 30 days' notice before adding one, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may terminate the affected service without penalty. We remain liable for our subprocessors' performance.

5. Model providers

Model providers are subprocessors. Content is transmitted to them to generate responses. Wherever a provider offers zero-retention processing we use it; where one does not, our agreement with them prohibits training on customer data and requires deletion within their stated window. Which provider receives a given request depends on the model you select or, if you enable it, on Auto-Route — the decision is logged and exportable.

6. International transfers

Where we transfer personal data out of the UK or EEA we rely on the EU standard contractual clauses (Commission Implementing Decision 2021/914, module two, controller to processor) and the UK International Data Transfer Addendum, both incorporated by reference. Annex I is populated from your account record; Annex II is the security page. A transfer risk assessment is available on request. Enterprise customers may pin processing to a region and avoid the transfer entirely.

7. Liability

Each party's liability under this addendum is subject to the limitations in the agreement, except where that limitation is not permitted by applicable data protection law.

8. Conflict

Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails.