Data Privacy Addendum
Effective January 1, 2026
This Data Processing Addendum ("DPA") forms part of and is incorporated into the Prerun Terms of Service, Enterprise Agreement, Order Form, or other written agreement governing Customer's use of the Services (collectively, the "Agreement").
This DPA applies where Prerun AI, LLC ("Prerun," "Processor," "Service Provider," "we," "our," or "us") Processes Personal Data on behalf of a customer acting as a Controller, Business, or equivalent designation under applicable Data Protection Laws ("Customer," "Controller," or "Business").
To the extent of any conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA shall control.
1. DEFINITIONS
1.1 Applicable Data Protection Laws
"Applicable Data Protection Laws" means all laws, regulations, directives, and governmental requirements applicable to the Processing of Personal Data, including where applicable:
(a) Regulation (EU) 2016/679 ("GDPR");
(b) UK GDPR;
(c) the UK Data Protection Act 2018;
(d) the California Consumer Privacy Act ("CCPA");
(e) the California Privacy Rights Act ("CPRA");
(f) applicable U.S. state privacy laws; and
(g) other applicable privacy and data protection laws.
1.2 Controller
"Controller" shall have the meaning assigned under Applicable Data Protection Laws and includes "Business" where applicable.
1.3 Processor
"Processor" shall have the meaning assigned under Applicable Data Protection Laws and includes "Service Provider" where applicable.
1.4 Personal Data
"Personal Data" means information relating to an identified or identifiable natural person that is processed under the Agreement and subject to Applicable Data Protection Laws.
1.5 Personal Data Breach
"Personal Data Breach" means a breach of security leading to accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to Personal Data.
1.6 Processing
"Processing" shall have the meaning assigned under Applicable Data Protection Laws and includes collection, storage, organization, use, disclosure, transmission, deletion, and related operations.
1.7 Subprocessor
"Subprocessor" means any third party engaged by Prerun to Process Personal Data on behalf of Customer in connection with providing the Services.
1.8 Standard Contractual Clauses
"Standard Contractual Clauses" or "SCCs" means any approved transfer mechanism adopted by the European Commission, UK authorities, or other competent regulatory authorities for international transfers of Personal Data.
2. SCOPE OF PROCESSING
2.1 Subject Matter
Prerun shall Process Personal Data solely as necessary to provide the Services under the Agreement.
2.2 Nature of Processing
Processing activities may include:
(a) collection;
(b) storage;
(c) organization;
(d) retrieval;
(e) transmission;
(f) analysis;
(g) security monitoring;
(h) backup and disaster recovery;
(i) support services;
(j) authentication;
(k) API operations;
(l) MCP services;
(m) AI-assisted functionality;
(n) certification services; and
(o) related operational activities.
2.3 Purpose of Processing
Prerun shall Process Personal Data solely for purposes of:
(a) providing the Services;
(b) maintaining the Services;
(c) securing the Services;
(d) supporting customers;
(e) complying with documented customer instructions;
(f) complying with legal obligations; and
(g) activities otherwise permitted by the Agreement.
2.4 Duration of Processing
Prerun shall Process Personal Data for the duration of the Agreement and thereafter only as required by applicable law, legal obligations, security requirements, backup retention schedules, or documented customer instructions.
3. CUSTOMER INSTRUCTIONS
3.1 Documented Instructions
Prerun shall Process Personal Data only on documented instructions from Customer unless otherwise required by applicable law. GDPR Article 28 requires processors to act only on documented controller instructions.
3.2 Agreement as Instructions
The Agreement, this DPA, customer configurations, account settings, API instructions, MCP configurations, and customer use of the Services collectively constitute Customer's documented instructions.
3.3 Unlawful Instructions
If Prerun reasonably believes that a Customer instruction violates Applicable Data Protection Laws, Prerun may notify Customer and suspend the affected Processing activity until the issue is resolved.
4. CONFIDENTIALITY
4.1 Personnel Confidentiality
Prerun shall ensure that individuals authorized to Process Personal Data are subject to appropriate confidentiality obligations.
4.2 Access Limitation
Access to Personal Data shall be limited to individuals who require such access to perform their duties relating to the Services.
4.3 Continuing Obligation
Confidentiality obligations shall survive termination of employment, engagement, or contractual relationships.
5. SECURITY OF PROCESSING
5.1 Security Measures
Taking into account the nature, scope, context, purposes, and risks of Processing, Prerun shall maintain appropriate technical and organizational measures designed to protect Personal Data. GDPR requires processors to implement appropriate technical and organizational measures and assist controllers with security obligations.
5.2 Security Controls
Such measures may include:
(a) encryption in transit;
(b) authentication controls;
(c) authorization controls;
(d) access management;
(e) audit logging;
(f) monitoring systems;
(g) vulnerability management;
(h) incident response procedures;
(i) backup systems;
(j) infrastructure protections; and
(k) security review processes.
5.3 Security Evolution
Customer acknowledges that security measures may evolve over time provided such changes do not materially reduce the overall level of protection provided to Personal Data.
6. PERSONAL DATA BREACHES
6.1 Notification
Prerun shall notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data where notification is required by Applicable Data Protection Laws.
6.2 Information Provided
To the extent reasonably available, such notification may include:
(a) the nature of the incident;
(b) categories of affected information;
(c) known or anticipated consequences;
(d) mitigation actions taken; and
(e) recommended response actions.
6.3 No Admission
Notification of a Personal Data Breach shall not constitute an admission of fault, liability, wrongdoing, or legal responsibility.
7. ASSISTANCE TO CUSTOMER
7.1 Data Subject Requests
Taking into account the nature of Processing, Prerun shall provide reasonable assistance to Customer in responding to requests from Data Subjects where required by Applicable Data Protection Laws.
7.2 Compliance Assistance
Prerun shall provide reasonable assistance to Customer regarding:
(a) security obligations;
(b) breach notification obligations;
(c) impact assessments;
(d) regulatory inquiries; and
(e) other obligations imposed by Applicable Data Protection Laws.
7.3 Reasonableness
Assistance obligations shall be limited to information and resources reasonably available to Prerun and may be subject to reimbursement where substantial effort is required.
8. SUBPROCESSORS
8.1 General Authorization
Customer generally authorizes Prerun to engage Subprocessors in connection with providing the Services.
8.2 Use of Subprocessors
Prerun may engage Subprocessors to provide services including:
(a) cloud infrastructure;
(b) hosting services;
(c) content delivery services;
(d) analytics services;
(e) monitoring services;
(f) customer support services;
(g) payment processing services;
(h) authentication services;
(i) security services;
(j) email delivery services;
(k) artificial intelligence services; and
(l) operational support services.
8.3 Subprocessor Obligations
Prerun shall require Subprocessors to maintain privacy, confidentiality, and security obligations that are substantially similar to those applicable to Prerun under this DPA where required by applicable law.
8.4 Responsibility for Subprocessors
Prerun shall remain responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Laws and contractual obligations.
8.5 Subprocessor List
Prerun shall maintain a current Subprocessor List available at:
https://www.prerun.ai/legal/subprocessors
8.6 Changes to Subprocessors
Prerun may update its Subprocessor List from time to time as vendors, infrastructure providers, and service providers are added, removed, or modified.
9. AUDITS AND INFORMATION RIGHTS
9.1 Information Availability
Prerun shall make available information reasonably necessary to demonstrate compliance with this DPA.
9.2 Audit Alternatives
Customer acknowledges that security documentation, certifications, audit reports, questionnaires, Trust Center materials, and similar compliance documentation may satisfy audit requests where appropriate.
9.3 Audit Limitations
Any audit rights shall:
(a) occur during normal business hours;
(b) be subject to reasonable advance notice;
(c) avoid disruption to Prerun operations;
(d) protect confidential information of other customers; and
(e) be subject to reasonable confidentiality obligations.
9.4 Frequency
Unless otherwise required by law, audits shall not occur more than once during any twelve (12) month period.
10. INTERNATIONAL DATA TRANSFERS
10.1 Transfer Authorization
Customer authorizes Prerun to transfer Personal Data internationally where necessary to provide the Services.
10.2 Transfer Mechanisms
Where required by Applicable Data Protection Laws, Prerun shall implement appropriate safeguards for international transfers of Personal Data.
Such safeguards may include:
(a) Standard Contractual Clauses;
(b) UK International Data Transfer Addendums;
(c) adequacy decisions;
(d) approved transfer mechanisms; and
(e) other lawful transfer frameworks.
10.3 Supplementary Measures
Where appropriate, Prerun may implement supplementary safeguards including:
(a) encryption;
(b) access controls;
(c) contractual commitments;
(d) transfer assessments; and
(e) technical protections.
10.4 Customer Acknowledgement
Customer acknowledges that Personal Data may be processed in jurisdictions where Prerun, its Affiliates, service providers, or Subprocessors operate.
11. RETURN AND DELETION OF PERSONAL DATA
11.1 Customer Options
Upon termination or expiration of the Agreement, Customer may request:
(a) return of Personal Data;
(b) export of Personal Data; or
(c) deletion of Personal Data.
11.2 Deletion Timeline
Subject to applicable law, operational requirements, backup schedules, security obligations, and legal retention requirements, Prerun shall delete or return Personal Data within a commercially reasonable period following termination.
11.3 Exceptions
Prerun may retain Personal Data where required to:
(a) comply with law;
(b) comply with regulatory obligations;
(c) resolve disputes;
(d) maintain security records;
(e) prevent fraud; or
(f) enforce contractual rights.
11.4 Backup Systems
Customer acknowledges that residual copies may remain within backup systems, archives, audit logs, disaster recovery systems, and security records for a limited period following deletion from active systems.
12. CCPA AND CPRA TERMS
12.1 Service Provider Status
To the extent applicable, Prerun acts as a Service Provider under the CCPA and CPRA with respect to Personal Information processed on behalf of Customer.
12.2 Processing Restrictions
Prerun shall not:
(a) sell Customer Personal Information;
(b) share Customer Personal Information for cross-context behavioral advertising;
(c) retain Customer Personal Information except as permitted by the Agreement;
(d) use Customer Personal Information outside the direct business relationship between the parties; or
(e) combine Customer Personal Information with information obtained from other customers except as permitted by law.
12.3 Business Purposes
Prerun may Process Personal Information for business purposes consistent with:
(a) the Agreement;
(b) this DPA;
(c) customer instructions; and
(d) Applicable Data Protection Laws.
12.4 Customer Rights
Customer retains responsibility for responding to requests from consumers exercising rights under applicable privacy laws.
13. AI PROCESSING TERMS
13.1 AI Services
Customer acknowledges that the Services may utilize artificial intelligence systems, machine learning systems, retrieval systems, and large language models.
13.2 Customer Authorization
Customer authorizes Prerun to process Personal Data through AI systems where reasonably necessary to provide requested functionality.
13.3 Third-Party AI Providers
Prerun may utilize third-party AI providers as Subprocessors or service providers in connection with the Services.
13.4 AI Training Restrictions
Except where expressly authorized by Customer, Prerun does not use Customer Content to train proprietary foundation models.
13.5 Public Model Training
Prerun does not intentionally contribute Customer Content to publicly available foundation model training datasets.
13.6 Enterprise AI Providers
Where commercially reasonable, Prerun seeks to utilize enterprise-grade arrangements that restrict use of Customer Content for model training purposes.
13.7 AI Outputs
Customer acknowledges that AI-generated outputs may contain inaccuracies, omissions, incomplete information, or unexpected results.
Customer remains responsible for reviewing and validating outputs before relying upon them.
14. LIABILITY
14.1 Agreement Controls
The liability limitations contained within the Agreement shall apply to this DPA.
14.2 No Expansion of Liability
Nothing within this DPA shall increase or expand either party's liability beyond the liability limitations expressly set forth in the Agreement.
15. ORDER OF PRECEDENCE
15.1 DPA Priority
To the extent of any conflict relating to Personal Data Processing obligations, this DPA shall control over the Agreement.
15.2 Remaining Terms
Except as expressly modified by this DPA, all provisions of the Agreement shall remain in full force and effect.
16. ANNEX I – DESCRIPTION OF PROCESSING
Controller
Customer and its Affiliates utilizing the Services.
Processor
Prerun AI, LLC
Categories of Data Subjects
Personal Data may relate to:
(a) customer employees;
(b) customer contractors;
(c) customer representatives;
(d) customer end users;
(e) customer clients;
(f) prospective customers;
(g) website visitors;
(h) API users;
(i) MCP users; and
(j) other individuals whose information is submitted to the Services.
Categories of Personal Data
Personal Data may include:
(a) names;
(b) email addresses;
(c) company information;
(d) account information;
(e) authentication information;
(f) technical information;
(g) device information;
(h) usage information;
(i) support information;
(j) billing information; and
(k) Customer Content containing Personal Data.
Sensitive Data
Processing of sensitive categories of Personal Data shall occur only where submitted by Customer and authorized under Applicable Data Protection Laws.
Frequency of Processing
Continuous and as necessary to provide the Services.
Purpose of Processing
Provision, maintenance, support, security, operation, and improvement of the Services.
17. ANNEX II – TECHNICAL AND ORGANIZATIONAL MEASURES
Prerun maintains security measures designed to protect Personal Data, including where appropriate:
(a) encryption in transit;
(b) authentication controls;
(c) authorization controls;
(d) access management procedures;
(e) audit logging;
(f) infrastructure monitoring;
(g) vulnerability management;
(h) incident response procedures;
(i) backup systems;
(j) disaster recovery processes;
(k) workforce confidentiality obligations;
(l) vendor management procedures; and
(m) security review processes.
Security measures may evolve over time provided that the overall level of protection is not materially reduced.
18. ANNEX III – SUBPROCESSOR CATEGORIES
Prerun may utilize Subprocessors within the following categories:
(a) cloud hosting providers;
(b) infrastructure providers;
(c) content delivery providers;
(d) monitoring providers;
(e) analytics providers;
(f) customer support providers;
(g) payment processors;
(h) authentication providers;
(i) security providers;
(j) email delivery providers;
(k) artificial intelligence providers; and
(l) operational service providers.
Current Subprocessors are listed at:
https://www.prerun.ai/legal/subprocessors
19. CONTACT INFORMATION
Prerun AI, LLC
State of Maine, United States
Privacy Requests:
privacy@prerun.ai
Legal Notices:
legal@prerun.ai
Support:
support@prerun.ai
Website:
https://www.prerun.ai
20. EXECUTION
This DPA is incorporated into and forms part of the Agreement governing Customer's use of the Services.
By executing or accepting the Agreement, Customer acknowledges and agrees to this DPA and authorizes the Processing activities described herein.