AI Router
← Back

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and Nextgen Computing GmbH ("Processor"). By using the AI Router Switzerland API, the Controller agrees to this DPA.

This DPA is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (GDPR), where applicable.

1. Parties

Processor:
Nextgen Computing GmbH
Schönaustrasse 61, 5430 Wettingen, Switzerland

Controller:
The customer using the API under the Terms of Service.

2. Subject Matter

Provision of AI API services for natural language processing and inference. Input data (e.g., prompts) submitted by the Controller may contain personal data.

3. Nature and Purpose of Processing

The Processor performs the following processing activities:

The Processor:

The Processor does not determine the purposes or means of processing and acts solely on behalf of the Controller.

For security, abuse prevention, system stability, and usage statistics, the Processor retains technical and security logs (e.g., IP addresses, timestamps, request metadata) for at least 12 months. These logs do not contain prompt or output content and are used solely for these purposes.

4. Duration

Processing occurs only for the duration of each API request. No personal data is retained after completion of the request, except for technical and security logs and a transient response cache, each as described in Section 3.

This DPA remains in effect for the duration of the service relationship.

5. Categories of Data and Data Subjects

The Processor processes data submitted by the Controller, which may include personal data relating to:

The Controller is responsible for determining whether submitted data contains personal data.

6. Instructions and Obligations of the Processor

The Processor shall:

7. Obligations of the Controller

The Controller is responsible for:

8. Sub-processors

The Processor operates the service exclusively on its own infrastructure (firewall, reverse proxy, load balancer, API router, and inference nodes) and does not engage sub-processors for the processing of personal data.

In exceptional cases (e.g., temporary capacity scaling), the Processor may operate its own software images on third-party GPU hardware located in Switzerland or the European Economic Area. Such providers are pure infrastructure providers: they have no access to personal data (all traffic is tunneled and end-to-end encrypted, and the Processor retains exclusive control over the software and data). They therefore do not process personal data on behalf of the Processor and are not sub-processors within the meaning of Article 28 GDPR.

Should the Processor intend to engage an actual sub-processor at any time, it will inform the Controller in advance and grant the Controller the right to object on reasonable data protection grounds. Any sub-processor engaged will be bound by data protection obligations equivalent to this DPA.

Where the Controller processes personal data as a processor on behalf of its own clients, the Parties acknowledge that the Processor acts as a sub-processor of the Controller for such data, and all obligations of this DPA apply accordingly. The Controller shall ensure it has the necessary authorizations from its own clients, including any required sub-processor authorizations.

9. Technical and Organizational Measures (TOMs)

The Processor implements appropriate security measures, including:

10. International Data Transfers

Personal data processed under this DPA is processed in Switzerland or, in exceptional cases (Section 8), on temporary infrastructure located in Switzerland or the European Economic Area.

Where personal data is otherwise processed outside Switzerland or the European Economic Area, the Processor ensures appropriate safeguards, such as:

11. Data Subject Rights

Due to the transient nature of processing, the Processor does not retain personal data beyond the technical and security logs and the transient response cache described in Section 3 and cannot independently fulfill access, correction, or deletion requests for prompt or output content.

The Controller remains responsible for handling such requests.

The Processor will provide reasonable assistance where possible.

12. Compliance and Audit

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA.

This obligation may be satisfied through documentation and written responses.

On-site audits are excluded unless required by applicable law.

13. Liability

Liability is governed by the Terms of Service.

14. Governing Law

This DPA is governed by Swiss law. Jurisdiction lies with the courts at the Processor's registered office in Switzerland.

Last updated: August 10, 2026