Data Processing Agreement

Last updated: September 21, 2026

This Data Processing Agreement, including its Schedules ("DPA"), forms part of the Terms of Service, Subscription Agreement, Order Form, Statement of Work, or other written or electronic agreement (the "Agreement") between S&T Integrated Solutions LLC, doing business as Science & Technology Integrated Solutions ("SciTech," "we," "us," or "our"), and the customer entity named in the Agreement ("Customer") for the purchase or use of www.scitechsolutions.io services. www.scitechsolutions.io is operated by S&T Integrated Solutions LLC, doing business as Science & Technology Integrated Solutions.

By executing an Order Form, accepting the Agreement, or using services that process Personal Data on behalf of Customer, Customer agrees to this DPA. Customer enters into this DPA on behalf of itself and, where required by applicable Data Protection Laws, on behalf of its Authorized Affiliates.

In providing the services, SciTech may Process Personal Data on behalf of Customer. The parties agree to comply with this DPA with respect to such Personal Data. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1. Definitions

Affiliate means an entity that directly or indirectly controls, is controlled by, or is under common control with another entity.

Authorized Affiliate means Customer's Affiliate that is subject to Data Protection Laws and is permitted to use the services under the Agreement.

CCPA means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and implementing regulations.

Controller means the entity that determines the purposes and means of Processing Personal Data.

Customer Data means data submitted to, processed by, or generated through the services by or on behalf of Customer, including prompts, outputs, logs, configurations, telemetry, API requests, routing decisions, model usage data, and safety results, to the extent such data is processed under the Agreement.

Data Protection Laws means applicable privacy, data-protection, and data-security laws and regulations applicable to the Processing of Personal Data under the Agreement, including GDPR, UK GDPR, Swiss data protection laws, U.S. state privacy laws, and CCPA where applicable.

Data Subject means an identified or identifiable natural person to whom Personal Data relates.

GDPR means Regulation (EU) 2016/679 and, where applicable, the UK GDPR.

International Data Transfer means a transfer of Personal Data from the EEA, United Kingdom, or Switzerland to a country or international organization outside those regions that requires a transfer mechanism under applicable Data Protection Laws.

Personal Data means information relating to an identified or identifiable natural person where such information is Customer Data processed by SciTech on behalf of Customer.

Processing means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, restriction, erasure, or destruction.

Processor means an entity that Processes Personal Data on behalf of a Controller, including a "service provider" or "processor" under applicable U.S. state privacy laws where applicable.

Public Authority means a government, regulatory, law-enforcement, or judicial authority.

Sensitive Data means information that is treated as sensitive or special-category data under applicable Data Protection Laws, including government identifiers, financial account numbers, health information, biometric information, genetic information, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation, precise geolocation, account passwords, children's data, or other regulated sensitive information.

Standard Contractual Clauses or SCCs means the standard contractual clauses approved by the European Commission for international transfers of Personal Data, as updated or replaced from time to time.

Subprocessor means a third-party Processor engaged by SciTech or its Affiliates to Process Personal Data on behalf of Customer.

2. Processing of Personal Data

2.1 Roles of the Parties

The parties acknowledge that, with respect to Personal Data processed under this DPA, Customer is the Controller and SciTech is the Processor, unless the Agreement states otherwise. Where applicable U.S. state privacy laws use different terminology, SciTech acts as a processor or service provider.

2.2 Customer Instructions

Customer instructs SciTech to Process Personal Data to provide requested results; maintain contracted audit records; provide, secure, support, monitor, troubleshoot, and maintain the services; comply with applicable law and the Agreement; prevent abuse; and follow other documented reasonable instructions from Customer that are consistent with the Agreement.

Customer is responsible for the accuracy, quality, legality, and lawful basis for Personal Data; for obtaining necessary rights, notices, and consents; for determining whether the services are appropriate for the Personal Data and use case; and for reviewing and configuring any applicable third-party model-provider terms and settings.

2.3 SciTech Processing

SciTech will treat Personal Data as Confidential Information and will Process Personal Data only on behalf of Customer and in accordance with Customer's documented instructions, including to:

  • provide the services;
  • route requests to customer-configured providers in BYOK mode;
  • operate Meter-SPW, APIs, dashboards, logs, and related features;
  • retain Meter-SPW per-call audit records containing a SHA-256 prompt hash and routing and billing metadata; cache model answers for 24 hours in memory and up to seven (7) days in the shared cache; and, for flagged calls, retain prompt and answer text in a human-review buffer for no more than seven (7) days, subject to the backup limitation in Schedule 1;
  • detect, prevent, and investigate security incidents, fraud, abuse, policy violations, and unauthorized access;
  • comply with law and the Agreement.

2.4 Details of Processing

The subject matter, duration, nature, purpose, categories of Data Subjects, categories of Personal Data, and retention criteria are described in Schedule 1.

2.5 Sensitive Data

The services are not intended to Process Sensitive Data unless expressly permitted in the Agreement or a mutually agreed amendment. Customer will not submit Sensitive Data unless Customer has determined that the services, provider settings, security measures, and legal basis are appropriate and the Agreement permits such Processing. Customer is responsible for notifying SciTech of Sensitive Data and any additional restrictions or safeguards required.

2.6 U.S. State Privacy Requirements

To the extent applicable U.S. state privacy laws apply to SciTech's Processing of Personal Data on Customer's behalf, SciTech will not:

  • sell Personal Data or share it for cross-context behavioral advertising;
  • retain, use, or disclose Personal Data outside the direct business relationship with Customer or for purposes other than the business purposes specified in the Agreement and this DPA, except as permitted by applicable Data Protection Laws; or
  • combine Personal Data processed on Customer's behalf with Personal Data received from or on behalf of another customer or person, or collected from SciTech's own interaction with a Data Subject, except as directed by Customer or permitted by applicable Data Protection Laws.

SciTech will notify Customer without undue delay if SciTech determines that it can no longer comply with its obligations under applicable Data Protection Laws.

Customer may take reasonable and appropriate steps to help ensure that SciTech Processes Personal Data consistently with Customer's obligations under applicable U.S. state privacy laws, including through the rights provided in Section 6. If Customer reasonably believes that SciTech is Processing Personal Data without authorization, Customer may notify SciTech, and the parties will work in good faith to stop and remediate the unauthorized Processing. If the issue cannot be remediated, SciTech will stop the affected Processing upon Customer's written instruction, except to the extent Processing is required by applicable law.

3. Data Subject Requests

SciTech will, to the extent legally permitted, promptly notify Customer if SciTech receives a request from a Data Subject relating to Personal Data processed on Customer's behalf. SciTech will not respond to such request except to redirect the requester to Customer or as required by law.

Taking into account the nature of Processing, SciTech will use commercially reasonable efforts to assist Customer with responding to Data Subject requests where Customer cannot reasonably fulfill the request through the services and where such assistance is required under Data Protection Laws. Customer is responsible for reasonable costs associated with such assistance unless the Agreement states otherwise.

4. Personnel

SciTech will ensure that personnel authorized to Process Personal Data are subject to confidentiality obligations and receive appropriate security and privacy training. SciTech will take commercially reasonable steps to limit access to Personal Data to personnel who need access to provide, secure, support, or administer the services.

5. Subprocessors

5.1 Authorization

Customer authorizes SciTech to engage Subprocessors to provide the services. SciTech will enter into written agreements with Subprocessors that impose data-protection obligations materially no less protective than those in this DPA, to the extent applicable to the Subprocessor's role.

5.2 List and Notice

Current Subprocessors are listed in Schedule 3 of this DPA, published at https://www.scitechsolutions.io/dpa. Customer may subscribe to Subprocessor notices by contacting privacy@scitechsolutions.ai. Excluding model providers used by Customer in BYOK mode or configured by Customer, SciTech will provide commercially reasonable notice before authorizing a new Subprocessor to Process Personal Data where required by applicable law or the Agreement.

5.3 Objection

Customer may object to a new Subprocessor on reasonable data-protection grounds by providing written notice within thirty (30) days after notice. SciTech will use commercially reasonable efforts to make available a change in the services or recommend a commercially reasonable configuration to avoid Processing by the objected-to Subprocessor. If no commercially reasonable alternative is available, Customer may terminate the affected services to the extent they cannot be provided without the Subprocessor, subject to the Agreement.

5.4 Liability

SciTech remains responsible for Subprocessors' acts and omissions to the extent required by applicable Data Protection Laws and the Agreement.

6. Audit

Upon reasonable written request, and no more than once per year unless required by a Public Authority or following a confirmed security incident affecting Customer Personal Data, SciTech will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be conducted during normal business hours, with reasonable notice, by an independent auditor subject to confidentiality, at Customer's expense, and in a manner that minimizes disruption and does not compromise security, confidentiality, other customers' data, or proprietary information.

SciTech may satisfy audit requests by providing security summaries, certifications, audit reports, questionnaires, policies, or other documentation where appropriate. SciTech may object to or suspend an audit request that is unreasonable, excessive, unlawful, insecure, or inconsistent with Data Protection Laws or the Agreement.

7. Security and Incident Notification

SciTech will implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the state of the art, implementation costs, nature, scope, context, purpose of Processing, and risk to Data Subjects. Current security practices are summarized in Schedule 2.

SciTech will notify Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a confirmed unauthorized destruction, loss, alteration, disclosure of, or access to Personal Data processed by SciTech or its Subprocessors under this DPA (a "Customer Data Incident"). SciTech will take commercially reasonable steps to investigate, contain, and remediate the incident. This obligation does not apply to incidents caused by Customer, Authorized Users, customer systems, customer provider keys, BYOK provider accounts, or third-party providers outside SciTech's control.

8. Government Access Requests

If SciTech receives a legally binding request from a Public Authority for Personal Data processed on behalf of Customer, SciTech will, unless legally prohibited, promptly notify Customer and provide a summary of the request. Where legally prohibited from notification, SciTech will use commercially reasonable efforts to obtain permission to provide notice where appropriate. SciTech may challenge a request if it reasonably determines the request is unlawful and a challenge is commercially reasonable, but this DPA does not require SciTech to take action that could result in civil or criminal penalty.

9. Return and Deletion

SciTech will return or delete Personal Data in accordance with the Agreement, product settings, and applicable law. Customer may request deletion by contacting privacy@scitechsolutions.ai unless a product-specific deletion workflow applies. Unless a different agreement or legal obligation applies, SciTech will use commercially reasonable efforts to delete Customer Data from active systems within thirty (30) business days after a valid deletion request, subject to technical, legal, security, backup, fraud-prevention, and compliance limitations. Backups are on a 30-day cycle and expire on that cycle rather than being edited in place.

Two categories are excepted from deletion, and Customer should understand this before submitting Personal Data: the append-only credit ledger, and the Meter-SPW per-call audit records. A ledger that can be rewritten is not a financial record, and the audit record is the evidence behind every charge and every dispute. Neither contains prompt text. On deletion, these records are retained as evidence and unlinked from the live account, and SciTech will continue to protect them under this DPA.

Meter-SPW model answers remain in memory for 24 hours and may remain in the shared cache for up to seven (7) days. Prompt and answer text held in the flagged-call human-review buffer is deleted when review concludes or after no more than seven (7) days. Deletion from the live database does not remove copies already present in database backups, which expire on their own 30-day cycle. The per-call audit record, including the prompt hash and routing and billing metadata, is retained as evidence behind each charge. Until Personal Data is deleted or returned, SciTech will continue to protect it under this DPA.

10. Data Protection Impact Assessments

Where Customer is required under Data Protection Laws to conduct a Data Protection Impact Assessment, transfer impact assessment, or prior consultation with a supervisory authority, SciTech will, upon written request, use commercially reasonable efforts to assist Customer to the extent Customer does not otherwise have access to relevant information and the assistance relates to Processing by SciTech under the Agreement.

11. Authorized Affiliates

Customer enters into this DPA on behalf of itself and, where applicable, its Authorized Affiliates. The Customer entity that is party to the Agreement remains responsible for coordinating communications, instructions, notices, audits, requests, and remedies on behalf of Authorized Affiliates. Customer will exercise rights under this DPA in a consolidated manner where reasonably possible.

12. Limitation of Liability

Each party's liability under this DPA is subject to the limitation-of-liability provisions in the Agreement. References to a party's liability mean the aggregate liability of that party and its Affiliates under the Agreement and this DPA, unless applicable law requires otherwise.

13. International Data Transfers

Customer authorizes SciTech and its Subprocessors to conduct International Data Transfers as necessary to provide the services and in accordance with Data Protection Laws.

Where required for transfers from the EEA to a country without an adequacy decision, the parties agree that Module 2 (Controller to Processor) of the SCCs is incorporated by reference. Customer is the data exporter and SciTech is the data importer. The Annexes are deemed completed with the information in Schedules 1 and 2 of this DPA. Where the United Kingdom or Switzerland requires additional transfer terms, the applicable UK addendum or Swiss modifications are incorporated to the extent required by law.

If a transfer mechanism becomes invalid or insufficient, the parties will work in good faith to implement a valid alternative mechanism or otherwise address the transfer as required by Data Protection Laws.

14. Miscellaneous

This DPA may be modified as described in the Agreement or by written amendment. If any provision is invalid or unenforceable, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in effect. If there is a conflict between the SCCs, this DPA, and the Agreement, the SCCs control to the extent of the conflict, then this DPA, then the Agreement.

Schedule 1: Details of Processing

A. List of Parties

Data Importer / Processor: S&T Integrated Solutions LLC, doing business as Science & Technology Integrated Solutions, operator of www.scitechsolutions.io.

Contact: privacy@scitechsolutions.ai; security@scitechsolutions.ai; legal@scitechsolutions.ai.

Role: Processor or service provider with respect to Personal Data processed on behalf of Customer.

Data Exporter / Controller: The customer entity identified in the Agreement.

Contact: As provided in the Agreement or customer account.

Role: Controller or business with respect to Personal Data submitted to the services.

B. Description of Processing

Categories of Data Subjects: Customer's employees, contractors, administrators, authorized users, end users, customers, prospects, and other individuals whose data is submitted to or processed through the services by Customer.

Categories of Personal Data: Names, business contact information, online identifiers, IP addresses, timestamps, account IDs, user IDs, display names, single sign-on provider identifiers, hashed authentication material (Argon2 password and API-key hashes, two-factor secrets, hashed recovery codes), API-key metadata, provider-key metadata, prompts, outputs, unstructured Input, logs, telemetry, model usage data, routing decisions, cost data, latency data, token counts, safety results, credit-ledger entries, configurations, and other information necessary to provide the services.

Sensitive Data: No Processing of Sensitive Data is intended unless expressly permitted by the Agreement or a mutually agreed amendment. Customer is responsible for determining whether Sensitive Data is submitted and for implementing required restrictions or safeguards.

Frequency: Continuous for the duration of the Agreement or as initiated by Customer and Authorized Users.

Nature and Purpose: Providing, routing, securing, supporting, monitoring, troubleshooting, improving, and enforcing the services; operating Meter-SPW, APIs, dashboards, BYOK mode, logs, safety controls, and related features; preventing abuse and security incidents; complying with law.

Location of Processing: The services run in Google Cloud's us-south1 region in the United States. Backups are stored across us-south1 and us-east1. Request metadata is processed in transit by Cloudflare.

Retention: Meter-SPW model answers remain in memory for 24 hours and may remain in the shared cache for up to seven (7) days. Prompt and answer text in its flagged-call review buffer is deleted when review concludes or after no more than seven (7) days, although copies already present in database backups expire on the 30-day backup cycle rather than being edited in place. Prompts in a benchmark set the Customer uploads under Settings → Routing profile are stored as text until the Customer deletes the set or the account. Meter-SPW retains its per-call audit record, including the prompt hash and routing and billing metadata, as evidence behind each charge, and keeps it after account deletion unlinked from the live account. The credit ledger is append-only and is likewise retained as evidence after account deletion, unlinked from the live account. Other Personal Data is retained for as long as necessary to provide the services, comply with law, maintain business records, resolve disputes, enforce agreements, prevent abuse, and protect rights and security, subject to deletion obligations in the Agreement and this DPA.

Subprocessor Transfers: Subprocessors may Process Personal Data only as necessary to provide their services to SciTech and may not Process Personal Data for unrelated purposes.

Supervisory Authority: Where the EU GDPR applies, the competent supervisory authority is determined under the SCCs. Where the UK GDPR applies, the UK Information Commissioner's Office may be the competent authority.

Schedule 2: SciTech Security Practices

Information Security Team

SciTech maintains personnel responsible for information security, operational security, incident response, and privacy practices. Security matters may be sent to security@scitechsolutions.ai.

Security Controls

SciTech will implement and maintain technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. Controls may include:

  • SOC 2 program in progress;
  • TLS encryption in transit;
  • passwords and API keys stored only as Argon2 hashes, which SciTech cannot read or recover;
  • two-factor secrets held per account, with recovery codes stored hashed and displayed to the user exactly once;
  • per-tenant webhook secrets encrypted at rest with AES-256-GCM;
  • BYOK provider keys encrypted at rest with AES-256-GCM, never stored in plaintext; the encryption key is never in the database or repository;
  • application credentials held in Google Secret Manager rather than in files on a server;
  • access controls, role-based access, MFA, and least privilege; production access restricted to personnel who need it;
  • logging, monitoring, alerting, and operational review;
  • Cloudflare WAF, rate-limiting, bot protection, and DDoS mitigation in front of the services;
  • vulnerability management and security review processes;
  • incident response procedures and customer notification process;
  • backups retained for 30 days, stored across two United States regions;
  • personnel confidentiality obligations and security training;
  • Meter-SPW per-call audit records containing a SHA-256 hash of each prompt — never the prompt text on the ordinary call path — plus routing and billing metadata;
  • Meter-SPW model-answer caching for 24 hours in memory and up to seven (7) days in the shared cache, and a flagged-call human-review buffer that holds prompt and answer text for no more than seven (7) days, subject to the 30-day backup cycle;
  • append-only storage for the credit ledger, which is a deliberate integrity property rather than a retention default.

Incident Management

SciTech will maintain incident-management procedures designed to investigate, contain, and remediate confirmed or reasonably suspected unauthorized access to Customer Data. SciTech will provide Customer with information reasonably available and legally permitted regarding the nature, scope, remediation, and status of a Customer Data Incident.

Data Deletion

Customer may request deletion of Customer Data by contacting privacy@scitechsolutions.ai unless a product-specific deletion workflow applies. SciTech will use commercially reasonable efforts to delete Customer Data from active systems within thirty (30) business days of a valid request unless a different retention period, legal obligation, security requirement, backup limitation, or Agreement provision applies. Backups expire on their own 30-day cycle. The append-only credit ledger and the Meter-SPW per-call audit records are excepted, as described in Section 9.

Personnel Practices

Personnel with access to systems processing Customer Data are subject to confidentiality obligations. Access is reviewed and revoked when no longer required or when the personnel relationship ends.

Schedule 3: Current Authorized Subprocessors

This is the current list. It is maintained on this page; Section 5.2 describes how Customer is notified of additions and how Customer may object.

  • Google Cloud (United States) — hosting, database, and backups. Services run in us-south1; backups are stored across us-south1 and us-east1. Also provides Google Secret Manager for application credentials.
  • Cloudflare (global edge) — TLS termination, WAF, DDoS protection, and filtering in front of the services. Processes request metadata in transit. For Meter-SPW, also provides the Turnstile sign-up/sign-in challenge and lightweight edge analytics that reports aggregate page-load timing without using cookies to track users between sites.
  • Stripe (United States) — payments, as merchant of record for purchases of credit. Stripe holds cardholder data and billing address, issues the receipt, and calculates, collects and remits any tax due; SciTech receives the result and the amount, and holds only the resulting credit-ledger entry.
  • Proton Mail (Switzerland) — delivery of transactional email such as balance alerts, password resets, and receipts. No marketing email is sent.
  • Google and GitHub (United States) — identity verification only, and only where a user chooses single sign-on, to confirm the user's email address at the moment of sign-in.

SciTech engages no advertising, session-replay, or cross-site behavioural-tracking Subprocessor. Meter-SPW uses Cloudflare, already listed above, for its lightweight edge analytics; that feature reports aggregate page-load timing and does not use cookies to track users between sites.

Third-party model providers are engaged only where Customer routes requests to them through Meter-SPW. In BYOK mode, Customer controls provider account settings and provider selection, and model providers used through Customer-configured keys process data under Customer's direct provider relationship and provider terms.