PROCESSING AGREEMENT

The agreement your legal team asked for.

Written to cover what Article 28(3) requires, in words a non-lawyer can follow. Where we cannot yet make a commitment it says so and dates it, rather than quietly leaving it out.

Version 1.3 In effect September 13, 2026 Operator Scaled Minds

How to read this

Drafted by the engineering team so that every factual statement traces to running code. Not reviewed by a qualified data-protection lawyer. Last checked September 13, 2026. Where we cannot yet make a commitment, the document says so, dates it, and names what would close it. We would rather you found the gap here than found it yourself.

What would change that: A review is commissioned when the first controller who is not us signs the processing agreement, or at the first paid business customer — whichever comes first. It is deferred rather than skipped: today there is no customer to make these statements to.

What changed in this version: The five gaps this agreement carries were RULED rather than left hanging, and each now names what would close it. The Article 27 answer changed and not in our favour: we measured the exemption we expected to rely on, it did not hold, and the agreement now says a representative is required and is not appointed. The attestation clause says plainly that our own security self-audit is not a penetration test.

A printed copy carries this version and its date, and leaves the navigation behind.

What we cannot yet commit to

These are listed rather than omitted. Each says which KIND of gap it is, when it was last checked, and what would close it — because “open” covered four different situations, and a limitation with no date on it is indistinguishable from one nobody has looked at.

  • Not reviewed by a data-protection lawyer. Decided to wait This agreement has not been reviewed by a qualified data-protection lawyer. It was written by the engineering team so that every factual statement traces to running code, and it should not be treated as legally vetted. What would close it: An external review, commissioned when the first controller who is not us signs this agreement, or at the first paid business customer. Last checked September 13, 2026.
  • A one-person operation, not a personnel programme. A limit of this document Stated in 4. Confidentiality of personnel. Last checked September 13, 2026.
  • Most upstream services are on their own published terms. A limit of this document Stated in 6. Sub-processors. Last checked September 13, 2026.
  • No SOC 2 report and no penetration test. Decided to wait Stated in 5. Security measures. Last checked September 13, 2026.
  • An Article 27 representative is required and is not appointed. Our recorded position Stated in 10. International transfers. Last checked September 13, 2026.
  • No countersigned copy. A limit of this document This is a published standard agreement. If your organisation requires an executed, counter-signed copy, ask and we will tell you what we can do — the availability of a page is not the same thing as a signed agreement, and we will not let it stand in for one. What would close it: Asking us. There is a person at the address at the foot of this page. Last checked September 13, 2026.

1. Roles, and what we actually do

The Customer is the controller. Host.Rodeo is a processor. Any company Host.Rodeo engages to process the Customer's data is a sub-processor of Host.Rodeo. This Agreement forms part of the agreement between the Customer and Host.Rodeo and applies whenever Host.Rodeo processes personal data on the Customer's behalf. It is written to satisfy Article 28(3) of the UK GDPR and of Regulation (EU) 2016/679.

Host.Rodeo is an AI gateway. Your application sends a request; we choose an upstream model service and forward the request to it; we return the answer with a signed receipt naming what handled it. Request content is transmitted to a third-party model service and is not written to our storage in transit. Content held on our side is enumerated in the privacy notice, store by store, with its own retention clock.

2. Instructions

We process personal data only on the Customer's documented instructions, which are: this Agreement, the Principal Agreement, and the requests the Customer's application actually sends, including the privacy and spending boundaries set on the account. We tell the Customer if an instruction appears to infringe data-protection law. Marking work private is an instruction with a mechanism behind it: it can only be served on hardware the Customer controls, and we refuse rather than reroute.

3. Subject matter, duration, nature, purpose, data and data subjects

Subject matter: routing inference requests and returning answers, with the account, conversation and bookkeeping records the service needs to do it. Duration: for as long as the Principal Agreement runs, plus the retention periods in the privacy notice. Nature and purpose: transmission to a chosen model service, and the records described. Types of personal data: whatever the Customer's application chooses to send, plus account and machine records. Data subjects: the Customer's own users and personnel.

4. Confidentiality of personnel

Everyone authorised by Host.Rodeo to process personal data is bound by a confidentiality obligation that survives the end of their engagement, and access is limited to those who need it.

A limit of this document, checked September 13, 2026. Host.Rodeo is operated by one person. The confidentiality commitment is real and binding on that person; there is no larger workforce to describe, and we would rather say so than imply a personnel programme that does not exist.
What would close it: Nothing, while that is true. If anyone else ever handles your data this clause changes before they do.

5. Security measures

Encryption in transit throughout. Secrets in a sealed vault rather than in code or configuration. Passwords and API keys held only as one-way scrambles. Administrative surfaces unreachable from the public internet. Per-account isolation of routing, spending and custody, enforced at the gateway rather than in the client. Signed receipts, so a customer can verify what handled a request without trusting our word for it.

Decided to wait, checked September 13, 2026. Host.Rodeo holds no SOC 2 report and has had no third-party penetration test. Neither has ever been claimed. We run an adversarial security self-audit of our own, and it is required before any change to how keys or custody are handled — but a self-audit is not a penetration test and we will not describe it as one. If your procurement requires either, treat it as a real gap today, not as a pending formality.
What would close it: A penetration test at the first paid business customer, or at any key-handling change we cannot self-audit. SOC 2 at the first enterprise buyer who asks for it in writing.

6. Sub-processors

The Customer gives general written authorisation for the sub-processors published on our live list. We give 30 days' notice before a new one may process the Customer's data. If the Customer objects on reasonable data-protection grounds we will work to offer an alternative, and if we cannot, the Customer may terminate the affected part and get a pro-rata refund of anything prepaid.

We impose data-protection obligations on each sub-processor no less protective than these, so far as applicable to its role, and remain fully liable to the Customer for its performance.

A limit of this document, checked September 13, 2026. Most model services are used on their standard published terms rather than under an individually negotiated agreement with us. For those, flow-down means we have selected companies whose published terms we have read and recorded — not that we hold a signed contract with each of them.
What would close it: An individually negotiated agreement with a named company, which we would list here by name rather than in general.

The live list, and how to object

7. Assisting with data-subject rights

We assist the Customer in answering data-subject requests, taking into account the nature of the processing and the information available to us. Where a request concerns content that has already passed through to a model service, we can say which service and when; we cannot compel that service to act, and we will not imply we can.

8. Breach, assessments and audits

  • Breach notice: without undue delay after becoming aware, with what we know at the time rather than a delayed complete account.
  • Assistance with data-protection impact assessments and prior consultation, proportionate to what we hold.
  • A security questionnaire answered within 20 working days.
  • Audit: once per 12 months on 30 days' notice, at the Customer's cost, during business hours and without unreasonable disruption. More often if a regulator requires it, or after a breach affecting the Customer.

9. Deletion and return

On the Customer's choice, at the end of the service we delete or return the personal data we hold, and delete existing copies unless the law requires us to keep them. A deletion receipt distinguishes access revoked immediately, records purged from live storage, records waiting on a backup cycle, and records retained under a legal obligation with the reason and the date they go. We do not claim an instantaneous physical deletion everywhere, because that is not what happens.

10. International transfers

Our servers are in the United States and most model services are too. Where personal data leaves the UK or the EEA, we rely on the Standard Contractual Clauses and the UK Addendum, incorporated by reference, with the annexes below. Where a sub-processor's own destination cannot be established — some of them are routers that choose another company per request — we say so rather than assert a country we cannot evidence, and the Customer should treat those as unknown-destination when making their own transfer assessment.

Our recorded position, checked September 13, 2026. A representative in the UK or the EEA under Article 27 is required, and none is appointed. We had expected to record the Article 27(2)(a) exemption — processing that is occasional and low-risk — as our basis for not appointing one. Rather than write that down as a sentence we built it as a measurement against the live account list, and the measurement refused it: there is an account here that is not ours and is in the EEA. We would rather publish the answer we did not want than the one we planned. No Data Protection Officer is appointed either; we do not believe one is mandatory for us.
What would close it: Appointing a representative. It is a recurring cost and therefore the owner’s decision, and it is the one gap on this page that got more urgent when we measured it instead of assuming it.

Annex I — the parties and the processing

Exporter (controller): the Customer, as named in the Principal Agreement. Importer (processor): Host.Rodeo, operating host.rodeo and api.host.rodeo. Data-protection and security contact: [email protected]. Sub-processors and their roles: the live list, which is generated from the running service.

We could not read the live list as this page loaded, and we will not show you a remembered one — an out-of-date list here is worse than none, because you would act on it. Reload, or fetch /v1/sub-processors directly, which is the same document this table is made of.

Annex II — technical and organisational measures, including what is missing

The measures in section 5, plus: bounded and scrubbed conversation storage with enforced expiry; per-account spending ceilings enforced before a supplier is called; refusal rather than rerouting when a privacy boundary cannot be met; and an append-only change log for the sub-processor list.

Every limitation this agreement carries is listed in what we cannot yet commit to — 6 in all, each with the clause it qualifies and the date it was last checked (most recently September 13, 2026). Nothing is accounted for only here.

11. Liability, precedence and law

This Agreement is subject to the limits of liability in the Principal Agreement. Where this Agreement and the Principal Agreement conflict on the processing of personal data, this Agreement prevails. Where the Standard Contractual Clauses conflict with this Agreement, the Clauses prevail. Governing law follows the Principal Agreement.

Earlier versions

Every version this document has had. The one above is what you are reading now.

  • Version 1.3 took effect September 13, 2026— current
  • Version 1.2 took effect September 12, 2026
  • Version 1.1 took effect August 21, 2026

We do not publish the superseded text, because a stack of old contracts on a public page is a way to be read out of context. The version you accepted stays retrievable: ask us naming the version and we will send you that exact text.

The rest of the shelf

Questions about any of this reach a real person at the contact page, with or without an account — [email protected] for anything about your own data, [email protected] for a security report. We answer within 10 working days.