Skip to content
Prerun
Legal

Data Privacy Addendum

Effective January 1, 2026

This Data Processing Addendum ("DPA") forms part of and is incorporated into the Prerun Terms of Service, Enterprise Agreement, Order Form, or other written agreement governing Customer's use of the Services (collectively, the "Agreement").

This DPA applies where Prerun AI, LLC ("Prerun," "Processor," "Service Provider," "we," "our," or "us") Processes Personal Data on behalf of a customer acting as a Controller, Business, or equivalent designation under applicable Data Protection Laws ("Customer," "Controller," or "Business").

To the extent of any conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA shall control.

1. DEFINITIONS

1.1 Applicable Data Protection Laws

"Applicable Data Protection Laws" means all laws, regulations, directives, and governmental requirements applicable to the Processing of Personal Data, including where applicable:

(a) Regulation (EU) 2016/679 ("GDPR");

(b) UK GDPR;

(c) the UK Data Protection Act 2018;

(d) the California Consumer Privacy Act ("CCPA");

(e) the California Privacy Rights Act ("CPRA");

(f) applicable U.S. state privacy laws; and

(g) other applicable privacy and data protection laws.

1.2 Controller

"Controller" shall have the meaning assigned under Applicable Data Protection Laws and includes "Business" where applicable.

1.3 Processor

"Processor" shall have the meaning assigned under Applicable Data Protection Laws and includes "Service Provider" where applicable.

1.4 Personal Data

"Personal Data" means information relating to an identified or identifiable natural person that is processed under the Agreement and subject to Applicable Data Protection Laws.

1.5 Personal Data Breach

"Personal Data Breach" means a breach of security leading to accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to Personal Data.

1.6 Processing

"Processing" shall have the meaning assigned under Applicable Data Protection Laws and includes collection, storage, organization, use, disclosure, transmission, deletion, and related operations.

1.7 Subprocessor

"Subprocessor" means any third party engaged by Prerun to Process Personal Data on behalf of Customer in connection with providing the Services.

1.8 Standard Contractual Clauses

"Standard Contractual Clauses" or "SCCs" means any approved transfer mechanism adopted by the European Commission, UK authorities, or other competent regulatory authorities for international transfers of Personal Data.

2. SCOPE OF PROCESSING

2.1 Subject Matter

Prerun shall Process Personal Data solely as necessary to provide the Services under the Agreement.

2.2 Nature of Processing

Processing activities may include:

(a) collection;

(b) storage;

(c) organization;

(d) retrieval;

(e) transmission;

(f) analysis;

(g) security monitoring;

(h) backup and disaster recovery;

(i) support services;

(j) authentication;

(k) API operations;

(l) MCP services;

(m) AI-assisted functionality;

(n) certification services; and

(o) related operational activities.

2.3 Purpose of Processing

Prerun shall Process Personal Data solely for purposes of:

(a) providing the Services;

(b) maintaining the Services;

(c) securing the Services;

(d) supporting customers;

(e) complying with documented customer instructions;

(f) complying with legal obligations; and

(g) activities otherwise permitted by the Agreement.

2.4 Duration of Processing

Prerun shall Process Personal Data for the duration of the Agreement and thereafter only as required by applicable law, legal obligations, security requirements, backup retention schedules, or documented customer instructions.

3. CUSTOMER INSTRUCTIONS

3.1 Documented Instructions

Prerun shall Process Personal Data only on documented instructions from Customer unless otherwise required by applicable law. GDPR Article 28 requires processors to act only on documented controller instructions.

3.2 Agreement as Instructions

The Agreement, this DPA, customer configurations, account settings, API instructions, MCP configurations, and customer use of the Services collectively constitute Customer's documented instructions.

3.3 Unlawful Instructions

If Prerun reasonably believes that a Customer instruction violates Applicable Data Protection Laws, Prerun may notify Customer and suspend the affected Processing activity until the issue is resolved.

4. CONFIDENTIALITY

4.1 Personnel Confidentiality

Prerun shall ensure that individuals authorized to Process Personal Data are subject to appropriate confidentiality obligations.

4.2 Access Limitation

Access to Personal Data shall be limited to individuals who require such access to perform their duties relating to the Services.

4.3 Continuing Obligation

Confidentiality obligations shall survive termination of employment, engagement, or contractual relationships.

5. SECURITY OF PROCESSING

5.1 Security Measures

Taking into account the nature, scope, context, purposes, and risks of Processing, Prerun shall maintain appropriate technical and organizational measures designed to protect Personal Data. GDPR requires processors to implement appropriate technical and organizational measures and assist controllers with security obligations.

5.2 Security Controls

Such measures may include:

(a) encryption in transit;

(b) authentication controls;

(c) authorization controls;

(d) access management;

(e) audit logging;

(f) monitoring systems;

(g) vulnerability management;

(h) incident response procedures;

(i) backup systems;

(j) infrastructure protections; and

(k) security review processes.

5.3 Security Evolution

Customer acknowledges that security measures may evolve over time provided such changes do not materially reduce the overall level of protection provided to Personal Data.

6. PERSONAL DATA BREACHES

6.1 Notification

Prerun shall notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data where notification is required by Applicable Data Protection Laws.

6.2 Information Provided

To the extent reasonably available, such notification may include:

(a) the nature of the incident;

(b) categories of affected information;

(c) known or anticipated consequences;

(d) mitigation actions taken; and

(e) recommended response actions.

6.3 No Admission

Notification of a Personal Data Breach shall not constitute an admission of fault, liability, wrongdoing, or legal responsibility.

7. ASSISTANCE TO CUSTOMER

7.1 Data Subject Requests

Taking into account the nature of Processing, Prerun shall provide reasonable assistance to Customer in responding to requests from Data Subjects where required by Applicable Data Protection Laws.

7.2 Compliance Assistance

Prerun shall provide reasonable assistance to Customer regarding:

(a) security obligations;

(b) breach notification obligations;

(c) impact assessments;

(d) regulatory inquiries; and

(e) other obligations imposed by Applicable Data Protection Laws.

7.3 Reasonableness

Assistance obligations shall be limited to information and resources reasonably available to Prerun and may be subject to reimbursement where substantial effort is required.

8. SUBPROCESSORS

8.1 General Authorization

Customer generally authorizes Prerun to engage Subprocessors in connection with providing the Services.

8.2 Use of Subprocessors

Prerun may engage Subprocessors to provide services including:

(a) cloud infrastructure;

(b) hosting services;

(c) content delivery services;

(d) analytics services;

(e) monitoring services;

(f) customer support services;

(g) payment processing services;

(h) authentication services;

(i) security services;

(j) email delivery services;

(k) artificial intelligence services; and

(l) operational support services.

8.3 Subprocessor Obligations

Prerun shall require Subprocessors to maintain privacy, confidentiality, and security obligations that are substantially similar to those applicable to Prerun under this DPA where required by applicable law.

8.4 Responsibility for Subprocessors

Prerun shall remain responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Laws and contractual obligations.

8.5 Subprocessor List

Prerun shall maintain a current Subprocessor List available at:

https://www.prerun.ai/legal/subprocessors

8.6 Changes to Subprocessors

Prerun may update its Subprocessor List from time to time as vendors, infrastructure providers, and service providers are added, removed, or modified.

9. AUDITS AND INFORMATION RIGHTS

9.1 Information Availability

Prerun shall make available information reasonably necessary to demonstrate compliance with this DPA.

9.2 Audit Alternatives

Customer acknowledges that security documentation, certifications, audit reports, questionnaires, Trust Center materials, and similar compliance documentation may satisfy audit requests where appropriate.

9.3 Audit Limitations

Any audit rights shall:

(a) occur during normal business hours;

(b) be subject to reasonable advance notice;

(c) avoid disruption to Prerun operations;

(d) protect confidential information of other customers; and

(e) be subject to reasonable confidentiality obligations.

9.4 Frequency

Unless otherwise required by law, audits shall not occur more than once during any twelve (12) month period.

10. INTERNATIONAL DATA TRANSFERS

10.1 Transfer Authorization

Customer authorizes Prerun to transfer Personal Data internationally where necessary to provide the Services.

10.2 Transfer Mechanisms

Where required by Applicable Data Protection Laws, Prerun shall implement appropriate safeguards for international transfers of Personal Data.

Such safeguards may include:

(a) Standard Contractual Clauses;

(b) UK International Data Transfer Addendums;

(c) adequacy decisions;

(d) approved transfer mechanisms; and

(e) other lawful transfer frameworks.

10.3 Supplementary Measures

Where appropriate, Prerun may implement supplementary safeguards including:

(a) encryption;

(b) access controls;

(c) contractual commitments;

(d) transfer assessments; and

(e) technical protections.

10.4 Customer Acknowledgement

Customer acknowledges that Personal Data may be processed in jurisdictions where Prerun, its Affiliates, service providers, or Subprocessors operate.

11. RETURN AND DELETION OF PERSONAL DATA

11.1 Customer Options

Upon termination or expiration of the Agreement, Customer may request:

(a) return of Personal Data;

(b) export of Personal Data; or

(c) deletion of Personal Data.

11.2 Deletion Timeline

Subject to applicable law, operational requirements, backup schedules, security obligations, and legal retention requirements, Prerun shall delete or return Personal Data within a commercially reasonable period following termination.

11.3 Exceptions

Prerun may retain Personal Data where required to:

(a) comply with law;

(b) comply with regulatory obligations;

(c) resolve disputes;

(d) maintain security records;

(e) prevent fraud; or

(f) enforce contractual rights.

11.4 Backup Systems

Customer acknowledges that residual copies may remain within backup systems, archives, audit logs, disaster recovery systems, and security records for a limited period following deletion from active systems.

12. CCPA AND CPRA TERMS

12.1 Service Provider Status

To the extent applicable, Prerun acts as a Service Provider under the CCPA and CPRA with respect to Personal Information processed on behalf of Customer.

12.2 Processing Restrictions

Prerun shall not:

(a) sell Customer Personal Information;

(b) share Customer Personal Information for cross-context behavioral advertising;

(c) retain Customer Personal Information except as permitted by the Agreement;

(d) use Customer Personal Information outside the direct business relationship between the parties; or

(e) combine Customer Personal Information with information obtained from other customers except as permitted by law.

12.3 Business Purposes

Prerun may Process Personal Information for business purposes consistent with:

(a) the Agreement;

(b) this DPA;

(c) customer instructions; and

(d) Applicable Data Protection Laws.

12.4 Customer Rights

Customer retains responsibility for responding to requests from consumers exercising rights under applicable privacy laws.

13. AI PROCESSING TERMS

13.1 AI Services

Customer acknowledges that the Services may utilize artificial intelligence systems, machine learning systems, retrieval systems, and large language models.

13.2 Customer Authorization

Customer authorizes Prerun to process Personal Data through AI systems where reasonably necessary to provide requested functionality.

13.3 Third-Party AI Providers

Prerun may utilize third-party AI providers as Subprocessors or service providers in connection with the Services.

13.4 AI Training Restrictions

Except where expressly authorized by Customer, Prerun does not use Customer Content to train proprietary foundation models.

13.5 Public Model Training

Prerun does not intentionally contribute Customer Content to publicly available foundation model training datasets.

13.6 Enterprise AI Providers

Where commercially reasonable, Prerun seeks to utilize enterprise-grade arrangements that restrict use of Customer Content for model training purposes.

13.7 AI Outputs

Customer acknowledges that AI-generated outputs may contain inaccuracies, omissions, incomplete information, or unexpected results.

Customer remains responsible for reviewing and validating outputs before relying upon them.

14. LIABILITY

14.1 Agreement Controls

The liability limitations contained within the Agreement shall apply to this DPA.

14.2 No Expansion of Liability

Nothing within this DPA shall increase or expand either party's liability beyond the liability limitations expressly set forth in the Agreement.

15. ORDER OF PRECEDENCE

15.1 DPA Priority

To the extent of any conflict relating to Personal Data Processing obligations, this DPA shall control over the Agreement.

15.2 Remaining Terms

Except as expressly modified by this DPA, all provisions of the Agreement shall remain in full force and effect.

16. ANNEX I – DESCRIPTION OF PROCESSING

Controller

Customer and its Affiliates utilizing the Services.

Processor

Prerun AI, LLC

Categories of Data Subjects

Personal Data may relate to:

(a) customer employees;

(b) customer contractors;

(c) customer representatives;

(d) customer end users;

(e) customer clients;

(f) prospective customers;

(g) website visitors;

(h) API users;

(i) MCP users; and

(j) other individuals whose information is submitted to the Services.

Categories of Personal Data

Personal Data may include:

(a) names;

(b) email addresses;

(c) company information;

(d) account information;

(e) authentication information;

(f) technical information;

(g) device information;

(h) usage information;

(i) support information;

(j) billing information; and

(k) Customer Content containing Personal Data.

Sensitive Data

Processing of sensitive categories of Personal Data shall occur only where submitted by Customer and authorized under Applicable Data Protection Laws.

Frequency of Processing

Continuous and as necessary to provide the Services.

Purpose of Processing

Provision, maintenance, support, security, operation, and improvement of the Services.

17. ANNEX II – TECHNICAL AND ORGANIZATIONAL MEASURES

Prerun maintains security measures designed to protect Personal Data, including where appropriate:

(a) encryption in transit;

(b) authentication controls;

(c) authorization controls;

(d) access management procedures;

(e) audit logging;

(f) infrastructure monitoring;

(g) vulnerability management;

(h) incident response procedures;

(i) backup systems;

(j) disaster recovery processes;

(k) workforce confidentiality obligations;

(l) vendor management procedures; and

(m) security review processes.

Security measures may evolve over time provided that the overall level of protection is not materially reduced.

18. ANNEX III – SUBPROCESSOR CATEGORIES

Prerun may utilize Subprocessors within the following categories:

(a) cloud hosting providers;

(b) infrastructure providers;

(c) content delivery providers;

(d) monitoring providers;

(e) analytics providers;

(f) customer support providers;

(g) payment processors;

(h) authentication providers;

(i) security providers;

(j) email delivery providers;

(k) artificial intelligence providers; and

(l) operational service providers.

Current Subprocessors are listed at:

https://www.prerun.ai/legal/subprocessors

19. CONTACT INFORMATION

Prerun AI, LLC

State of Maine, United States

Privacy Requests:
privacy@prerun.ai

Legal Notices:
legal@prerun.ai

Support:
support@prerun.ai

Website:
https://www.prerun.ai

20. EXECUTION

This DPA is incorporated into and forms part of the Agreement governing Customer's use of the Services.

By executing or accepting the Agreement, Customer acknowledges and agrees to this DPA and authorizes the Processing activities described herein.