Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and Nextgen Computing GmbH ("Processor"). By using the AI Router Switzerland API, the Controller agrees to this DPA.
This DPA is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (GDPR), where applicable.
1. Parties
Processor:
Nextgen Computing GmbH
Schönaustrasse 61, 5430 Wettingen, Switzerland
Controller:
The customer using the API under the Terms of Service.
2. Subject Matter
Provision of AI API services for natural language processing and inference. Input data (e.g., prompts) submitted by the Controller may contain personal data.
3. Nature and Purpose of Processing
The Processor performs the following processing activities:
- Transient processing of input data for AI inference
- Generation of outputs and return to the Controller
The Processor:
- does not store input data or outputs beyond the duration of each request, except for a transient response cache (exact request/response pairs, automatically evicted after 24 hours, not used for any other purpose)
- does not use data for training
- does not enrich, analyze, or profile data
The Processor does not determine the purposes or means of processing and acts solely on behalf of the Controller.
For security, abuse prevention, system stability, and usage statistics, the Processor retains technical and security logs (e.g., IP addresses, timestamps, request metadata) for at least 12 months. These logs do not contain prompt or output content and are used solely for these purposes.
4. Duration
Processing occurs only for the duration of each API request. No personal data is retained after completion of the request, except for technical and security logs and a transient response cache, each as described in Section 3.
This DPA remains in effect for the duration of the service relationship.
5. Categories of Data and Data Subjects
The Processor processes data submitted by the Controller, which may include personal data relating to:
- end-users
- customers
- other individuals, depending on the Controller's use case
The Controller is responsible for determining whether submitted data contains personal data.
6. Instructions and Obligations of the Processor
The Processor shall:
- process personal data only on documented instructions (i.e., API requests)
- ensure confidentiality of personnel with access to data
- implement appropriate technical and organizational measures (TOMs)
- not retain personal data beyond the request lifecycle, except for technical and security logs and a transient response cache as described in Section 3
- not use data for any purpose other than providing the service
- notify the Controller without undue delay upon becoming aware of a personal data breach
- assist the Controller in fulfilling data subject rights, where reasonably possible given the transient nature of processing
7. Obligations of the Controller
The Controller is responsible for:
- ensuring lawful collection and processing of personal data
- providing required notices to data subjects
- responding to data subject rights requests
- where the Controller processes data as a processor for its own clients, obtaining the necessary authorizations (including sub-processor authorizations) from those clients
- warranting that the personal data processed under this DPA is lawfully obtained and that its processing instructions do not violate applicable law or third-party rights
- ensuring it has the right to pass through the obligations of this DPA to the Processor
8. Sub-processors
The Processor operates the service exclusively on its own infrastructure (firewall, reverse proxy, load balancer, API router, and inference nodes) and does not engage sub-processors for the processing of personal data.
In exceptional cases (e.g., temporary capacity scaling), the Processor may operate its own software images on third-party GPU hardware located in Switzerland or the European Economic Area. Such providers are pure infrastructure providers: they have no access to personal data (all traffic is tunneled and end-to-end encrypted, and the Processor retains exclusive control over the software and data). They therefore do not process personal data on behalf of the Processor and are not sub-processors within the meaning of Article 28 GDPR.
Should the Processor intend to engage an actual sub-processor at any time, it will inform the Controller in advance and grant the Controller the right to object on reasonable data protection grounds. Any sub-processor engaged will be bound by data protection obligations equivalent to this DPA.
Where the Controller processes personal data as a processor on behalf of its own clients, the Parties acknowledge that the Processor acts as a sub-processor of the Controller for such data, and all obligations of this DPA apply accordingly. The Controller shall ensure it has the necessary authorizations from its own clients, including any required sub-processor authorizations.
9. Technical and Organizational Measures (TOMs)
The Processor implements appropriate security measures, including:
- encryption in transit (TLS)
- access controls and authentication
- network isolation (containerized workloads)
- no persistent storage of API input data
10. International Data Transfers
Personal data processed under this DPA is processed in Switzerland or, in exceptional cases (Section 8), on temporary infrastructure located in Switzerland or the European Economic Area.
Where personal data is otherwise processed outside Switzerland or the European Economic Area, the Processor ensures appropriate safeguards, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- safeguards recognized under Swiss data protection law
11. Data Subject Rights
Due to the transient nature of processing, the Processor does not retain personal data beyond the technical and security logs and the transient response cache described in Section 3 and cannot independently fulfill access, correction, or deletion requests for prompt or output content.
The Controller remains responsible for handling such requests.
The Processor will provide reasonable assistance where possible.
12. Compliance and Audit
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA.
This obligation may be satisfied through documentation and written responses.
On-site audits are excluded unless required by applicable law.
13. Liability
Liability is governed by the Terms of Service.
14. Governing Law
This DPA is governed by Swiss law. Jurisdiction lies with the courts at the Processor's registered office in Switzerland.
Last updated: August 10, 2026