Legal
Data Processing Addendum
This Data Processing Addendum ("DPA") applies when Dr.Gero processes personal data in Customer Content on behalf of a customer through the Dr.Gero Service.
1. Parties and scope
This DPA forms part of the Terms & Conditions or other agreement between you and Higuera Ex Machina SL, a Spanish limited liability company with tax identification number ESB21770680 and registered address at Escultor Llimona 15, 08031 Barcelona, Spain, operating the Dr.Gero service. It applies to personal data included in Customer Content that Dr.Gero processes to provide leaderboards, inference routing, datasets, traces, logs, fine-tuning, API access, integrations, and related support.
"Customer" means the entity or person that determines the purposes and means of processing Customer Content. "Dr.Gero" means Higuera Ex Machina SL acting through the Service. Capitalized terms not defined here have the meaning given in the Terms.
2. Roles
For Customer Content, Customer is the controller or processor, and Dr.Gero is the processor or subprocessor processing personal data on Customer's documented instructions. For account, billing, security, website, and business administration data, Dr.Gero may act as an independent controller as described in the Privacy Policy.
3. Processing details
| Subject matter | Provision, security, support, and improvement of the Dr.Gero Service for Customer. |
|---|---|
| Duration | The term of Customer's use of the Service, plus any retention period required for deletion, backups, security, legal, or dispute purposes. |
| Nature and purpose | Hosting, storing, transmitting, evaluating, transforming, labeling, routing, fine-tuning, logging, debugging, securing, and supporting Customer Content according to Customer instructions. |
| Data categories | Prompts, inputs, outputs, datasets, expected answers, rubrics, labels, traces, logs, metadata, endpoint configuration, model configuration, fine-tuning files, and support materials that may contain personal data. |
| Data subjects | Customer personnel, Customer end users, users or contacts represented in datasets, and other individuals whose data Customer includes in Customer Content. |
| Special categories | Not intended unless Customer has a lawful basis, appropriate safeguards, and a written agreement with Dr.Gero covering that processing. |
4. Customer instructions
Customer instructs Dr.Gero to process Customer Content to provide and secure the Service, comply with the agreement, respond to support requests, follow Customer's in-app and API configuration, and comply with applicable law. Dr.Gero will not process Customer Content for other purposes unless required by law or authorized by Customer.
Customer is responsible for the lawfulness, accuracy, quality, and content of Customer Content, including providing notices, obtaining consents, honoring data subject rights, and ensuring that Customer Content can be processed through the Service and selected integrations.
5. Dr.Gero obligations
Dr.Gero will:
- process Customer Content only on documented instructions from Customer, including the agreement and product configuration;
- ensure that personnel authorized to process Customer Content are bound by confidentiality obligations;
- implement appropriate technical and organizational measures designed to protect Customer Content;
- assist Customer with reasonable requests related to security, data subject rights, DPIAs, and regulator consultations, taking into account the nature of the processing;
- notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Content; and
- delete or return Customer Content as described in this DPA, the agreement, and product functionality.
6. Security measures
Dr.Gero maintains administrative, technical, and organizational measures designed to protect Customer Content. Measures may include access controls, least-privilege permissions, credential and token protection, encrypted transport where supported, cloud-provider security controls, logging and monitoring, backup and recovery procedures, separation between workspaces, security review of sensitive server-side routes, and incident-response procedures.
Customer is responsible for securely configuring the Service, protecting API tokens and provider keys, limiting workspace access, setting appropriate budgets and scopes, and avoiding unnecessary personal or sensitive data in prompts, datasets, traces, and logs.
7. Subprocessors and integrations
Customer authorizes Dr.Gero to use subprocessors to provide the Service. Subprocessors may include cloud hosting, database, storage, authentication, email, payment, marketplace, monitoring, security, support, model-provider, dataset-provider, and fine-tuning infrastructure providers. Customer also authorizes Dr.Gero to transmit Customer Content to integrations, model providers, endpoints, and infrastructure that Customer selects, configures, or requests through the Service.
Dr.Gero will impose data-protection obligations on subprocessors that are materially protective of Customer Content. Dr.Gero remains responsible for subprocessors' performance of those obligations to the extent required by applicable data protection law. To ask about current subprocessors or object to a new subprocessor on reasonable data-protection grounds, contact drgero@higuera.ai.
8. International transfers
Where Customer Content is transferred internationally and transfer safeguards are required, Dr.Gero will use appropriate safeguards such as standard contractual clauses, data processing terms, adequacy decisions, or another lawful transfer mechanism. Customer authorizes transfers needed to provide the Service and to use Customer-selected integrations.
9. Data subject requests
If Dr.Gero receives a request from an individual relating to Customer Content, Dr.Gero will, where legally permitted and appropriate, direct the individual to Customer or notify Customer. Customer is responsible for responding to requests. Dr.Gero will provide reasonable assistance using product features or support channels where required by applicable law.
10. Security incidents
Dr.Gero will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Content. The notice will include information reasonably available to Dr.Gero, taking into account the nature of the Service, the information available, and any need to preserve security or confidentiality.
11. Deletion and return
During the term, Customer may delete certain Customer Content through the Service where functionality is available. After termination or written request, Dr.Gero will delete or return Customer Content within a reasonable period, unless retention is required by law, necessary for security, backup, billing, dispute, or compliance purposes, or technically impracticable in archived backup systems until they expire.
12. Audits
Upon reasonable written request, Dr.Gero will provide information necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and trade-secret restrictions. If legally required and the provided information is insufficient, Customer may request an audit with reasonable notice, limited scope, and measures to avoid disruption, exposure of other customers' data, or security risk.
13. Sensitive and regulated data
The Service is not designed for protected health information, payment-card data, government classified information, children's data, or other highly regulated data unless a separate written agreement expressly permits it. Customer must not submit special-category or highly sensitive personal data unless Customer has confirmed that the use case is lawful and has appropriate safeguards.
14. Conflict and updates
If this DPA conflicts with the Terms, this DPA controls for processing of Customer Content personal data. We may update this DPA from time to time. Material changes will be notified through the Service, by email, or by updating this page.
15. Contact
DPA questions and data protection requests can be sent to drgero@higuera.ai or by post to Higuera Ex Machina SL, Escultor Llimona 15, 08031 Barcelona, Spain.