Legal
Data Processing Addendum
Effective: 19 August 2026
This Data Processing Addendum ("DPA") forms part of the agreement governing a customer's use of Discrezo's Business Services, including the Discrezo Terms of Use, Service Terms, applicable order form, subscription agreement or other written agreement between the parties (together, the "Agreement").
This DPA is entered into between:
Discrezo 333 West San Carlos Street San Jose, CA 95110 United States
("Discrezo")
and the customer that has entered into the Agreement ("Customer").
Discrezo and Customer are each a "Party" and together the "Parties".
This DPA applies where Discrezo Processes Personal Data on behalf of Customer in connection with the Services. Capitalised terms not defined in this DPA have the meanings given to them in the Agreement.
Scope and roles
Customer Data
For the purposes of this DPA, "Customer Data" means Personal Data Processed by Discrezo on behalf of Customer in connection with the Services.
Customer Data may include Personal Data contained in:
- prompts;
- files;
- documents;
- instructions;
- conversation context;
- Customer-configured memory;
- other Input submitted by Customer or its End Users; and
- information obtained through Customer-authorised features.
Customer Data does not include Personal Data that Discrezo Processes independently as a Controller for its own legitimate business purposes, as described below.
Customer as Controller
Where Customer determines the purposes and means of Processing Customer Data, Customer acts as the:
Controller
and Discrezo acts as the:
Processor
for that Customer Data.
Customer as Processor
Where Customer itself Processes Personal Data on behalf of another Controller and provides that Personal Data to Discrezo, Customer acts as a Processor and Discrezo acts as its:
Sub-processor
for that Customer Data.
Customer confirms that it is authorised by the relevant Controller to appoint Discrezo as a Sub-processor.
Discrezo as independent Controller
This DPA does not apply to Personal Data that Discrezo Processes as an independent Controller for its own purposes.
This may include limited information relating to:
- Customer's commercial relationship with Discrezo;
- account administration;
- billing;
- subscription records;
- fraud prevention;
- security;
- service entitlement;
- legal compliance;
- communications with Discrezo; and
- operation of Discrezo's own business.
Discrezo's Privacy Policy governs that Processing.
Processing instructions
Documented instructions
Discrezo will Process Customer Data only:
- to provide the Services;
- in accordance with the Agreement;
- in accordance with this DPA;
- according to Customer's configuration of the Services;
- according to Customer's use of Standard Mode or Private Mode;
- according to other documented instructions agreed between the Parties; or
- where required by applicable law.
Together, these constitute Customer's documented instructions.
Legal requirements
If applicable law requires Discrezo to Process Customer Data other than in accordance with Customer's documented instructions, Discrezo will inform Customer before carrying out that Processing unless applicable law prohibits Discrezo from doing so.
Unlawful instructions
If Discrezo reasonably believes that a Customer instruction infringes applicable Data Protection Law, Discrezo will inform Customer.
Discrezo may suspend the affected Processing while the Parties attempt to resolve the issue where reasonably necessary.
Discrezo's privacy architecture
The Parties acknowledge that Discrezo is designed around separation between:
account identity
and:
AI inference.
Customer account systems and inference systems have different responsibilities.
Account information
Account systems may Process information required for:
- authentication;
- subscription administration;
- billing;
- plan entitlement;
- account configuration; and
- Customer relationship management.
Inference information
Inference systems may Process:
- prompts;
- relevant conversation context;
- model instructions;
- routing information; and
- generated responses.
The inference path is designed not to require ordinary Customer or End User account identity in order to generate a response.
Identity separation
Where technically applicable to the Service being used, Discrezo is designed not to send an AI provider the End User's:
- Discrezo account identifier;
- account email;
- payment identity; or
- originating network identity
merely in order for that provider to answer the request.
This does not remove Personal Data that an End User voluntarily includes within the content of a prompt.
If a prompt itself contains a person's name, employer, address, health information or other identifying information, the AI provider Processing that prompt may be able to read that information.
Automatic AI routing
Customer instructs Discrezo to Process Customer Data as reasonably necessary to automatically select and use an eligible AI model to provide the Services.
The routing process may consider characteristics of the request and operational factors including:
- type of task;
- complexity;
- context requirements;
- model capability;
- Customer-selected privacy mode;
- provider eligibility;
- availability;
- reliability; and
- service health.
The routing system does not require Customer's billing identity or payment information to determine which AI model should answer a request.
Standard Mode
Where Customer or an End User uses Standard Mode, Customer instructs Discrezo to disclose the prompt and relevant context to an eligible AI or inference Sub-processor as necessary to generate a response.
Depending on the route, eligible Sub-processors may include providers operating:
- proprietary AI models;
- frontier AI models;
- open models; or
- supporting inference infrastructure.
Standard Mode provides identity separation as described in the Agreement.
It does not mean that the AI Sub-processor cannot see the Customer Data contained within the prompt it must Process.
Private Mode
Where Customer or an End User enables Private Mode, Discrezo will apply the provider restrictions associated with Private Mode before ordinary model selection.
Private Mode is designed to prevent Customer prompts from being routed to:
- OpenAI;
- Anthropic; or
- Google.
Private Mode requests may still be Processed by Sub-processors providing infrastructure or inference required to operate supported open models.
Private Mode restrictions take precedence over ordinary model preference.
If no eligible Private Mode route is available, Discrezo may return an error or limit functionality rather than intentionally route the request through an excluded provider.
Purpose limitation
Discrezo will Process Customer Data only for the purposes permitted by the Agreement and this DPA.
Discrezo will not use Customer Data Processed on behalf of Customer to create advertising profiles about individual End Users.
Discrezo will not sell Customer Data.
Discrezo will not use readable Customer conversation content to target advertising to Customer's End Users.
Model training
Discrezo will not use Customer's readable saved conversation history to train foundation AI models.
Discrezo will not intentionally instruct AI Sub-processors to use Customer Data to train general-purpose models where the applicable Discrezo provider arrangement or configuration prohibits such use.
Customer acknowledges that AI providers remain independent third-party technology providers and may be subject to their own legal obligations.
Discrezo will use provider arrangements and configurations consistent with the privacy commitments applicable to the relevant Discrezo Service.
Confidentiality
Discrezo will ensure that persons authorised to Process Customer Data are:
- subject to appropriate confidentiality obligations;
- authorised to Process Customer Data only as necessary for their responsibilities; and
- provided access according to appropriate access controls.
Authorised personnel must Process Customer Data only in accordance with Discrezo's obligations under this DPA.
Security
Discrezo will maintain appropriate technical and organisational measures designed to protect Customer Data against:
- accidental destruction;
- unlawful destruction;
- loss;
- alteration;
- unauthorised disclosure;
- unauthorised access; and
- other unlawful Processing.
Discrezo operates an ISO/IEC 27001-certified information security management system.
Additional information about relevant security measures is set out in Schedule 2.
Saved conversations and encrypted Customer Data
Where the Services provide encrypted conversation history, memory or synchronisation, readable saved content is designed to be encrypted on a trusted End User device before sync.
Discrezo's backend is designed not to possess the key required to decrypt that saved content.
Accordingly, Customer Data stored by Discrezo may include encrypted content that Discrezo does not have the technical ability to read.
Customer understands this limitation
Customer acknowledges that these security properties may limit Discrezo's ability to:
- inspect encrypted Customer Data;
- search within encrypted Customer Data;
- recover lost encrypted Customer Data;
- provide plaintext copies of encrypted Customer Data; or
- respond to requests that require Discrezo itself to decrypt Customer Data.
This limitation is an intended consequence of the privacy architecture rather than a limitation arising from administrative access restrictions.
Logging and telemetry
Discrezo may Process operational information necessary to operate, secure and improve the Services.
This may include information relating to:
- route;
- provider;
- latency;
- token or compute usage;
- error category;
- service availability; and
- similar operational measurements.
Discrezo designs its ordinary inference logging so that readable prompt and response bodies do not have a legitimate place in operational logs.
Discrezo also designs ordinary inference logs so they do not require Customer or End User account identity.
Sub-processors
Customer provides Discrezo with general authorisation to engage Sub-processors to Process Customer Data where necessary to provide the Services.
Sub-processors may include providers of:
- AI models;
- open-model inference;
- computing infrastructure;
- hosting;
- authentication;
- security;
- encrypted storage;
- support systems;
- communications;
- monitoring; and
- other infrastructure necessary to operate the Services.
AI providers are Sub-processors where applicable
Where an AI or inference provider Processes Personal Data contained in Customer Data on behalf of Customer through Discrezo, Discrezo will treat that provider as a Sub-processor for the purposes of this DPA where Data Protection Law requires that relationship.
The fact that Discrezo separates account identity from the inference request does not change the fact that the prompt itself may contain Personal Data.
Sub-processor obligations
Discrezo will enter into appropriate contractual arrangements with Sub-processors requiring them to protect Customer Data to a standard consistent with Discrezo's applicable obligations under this DPA.
Discrezo remains responsible for its Sub-processors to the extent required by applicable Data Protection Law and the Agreement.
Sub-processor list
Discrezo will make information about its current material Sub-processors available to Business customers either:
- through the Discrezo website;
- through the Business Service; or
- on request to support@discrezo.com.
Changes to Sub-processors
Discrezo will provide reasonable notice of a new material Sub-processor where required by applicable Data Protection Law.
Customer may object to the appointment of a new Sub-processor on reasonable data-protection grounds.
The Parties will work in good faith to address the objection.
If the objection cannot reasonably be resolved and Discrezo cannot provide the affected Service without the Sub-processor, either Party may terminate the affected portion of the Services in accordance with the Agreement.
Data Subject requests
Taking into account the nature of Processing, Discrezo will provide reasonable assistance to Customer in responding to requests from Data Subjects exercising rights under applicable Data Protection Law.
These may include requests relating to:
- access;
- correction;
- deletion;
- restriction;
- objection; and
- portability.
Requests received directly by Discrezo
If Discrezo receives a Data Subject request relating principally to Customer Data that Discrezo Processes on Customer's behalf, Discrezo may:
- direct the Data Subject to Customer;
- notify Customer; or
- respond as authorised by Customer.
Discrezo will not independently determine Customer's obligations to the Data Subject unless required by law.
Architecture limitations
Customer acknowledges that Discrezo's privacy architecture intentionally limits the relationship between account identity and readable inference content.
Accordingly, Discrezo may not be technically capable of locating readable prompts by searching for an End User's account identity.
Where saved content is end-to-end encrypted, Discrezo may also be unable to provide the readable content itself.
Discrezo will provide assistance that is technically possible taking into account the nature of the Processing.
Assistance with compliance
Taking into account:
- the nature of the Processing; and
- the information reasonably available to Discrezo,
Discrezo will provide reasonable assistance to Customer where required under applicable Data Protection Law concerning:
- security of Processing;
- Personal Data Breach obligations;
- data-protection impact assessments;
- prior consultation with a supervisory authority; and
- Data Subject rights.
Customer remains responsible for determining whether its intended use of Discrezo requires a data-protection impact assessment or other regulatory assessment.
Personal Data Breaches
Discrezo will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data for which Discrezo acts as Processor.
To the extent reasonably available, the notification will include information concerning:
- the nature of the Personal Data Breach;
- categories of affected Customer Data;
- categories of affected Data Subjects;
- likely consequences;
- measures taken or proposed to address the incident; and
- information reasonably necessary for Customer to meet its own legal obligations.
Information may be supplied in phases where all relevant information is not immediately available.
No admission
Notification of a Personal Data Breach does not constitute an admission by Discrezo of fault or liability.
Customer obligations
Customer remains responsible for determining whether it must:
- notify a supervisory authority;
- notify affected individuals; or
- take other action
under applicable law.
Discrezo will provide reasonable assistance where legally required.
Audits and compliance information
Discrezo will make information reasonably necessary to demonstrate compliance with this DPA available to Customer as required by applicable Data Protection Law.
This may include relevant:
- security documentation;
- certification information;
- audit summaries;
- policies; and
- responses to reasonable security assessments.
ISO 27001
Discrezo's current ISO/IEC 27001 certification may be used as part of Customer's assessment of Discrezo's information-security controls.
Certification does not prevent Customer from exercising audit rights that cannot legally be excluded.
Customer audits
Where applicable Data Protection Law requires an audit and available third-party assurance is not reasonably sufficient, Customer may request an audit of Discrezo's compliance with this DPA.
Unless required following a Personal Data Breach, by a regulator, or by applicable law:
- audits may occur no more than once in any twelve-month period;
- Customer must provide reasonable advance written notice;
- the audit must take place during normal business hours;
- the audit must avoid unreasonable disruption;
- auditors must be bound by appropriate confidentiality obligations;
- the audit must not compromise another customer's security or confidentiality; and
- Customer will bear its own audit costs.
Discrezo may satisfy a reasonable audit request by providing relevant independent audit or certification materials where legally permissible and reasonably sufficient.
Return and deletion
Following termination or expiry of the Services, Discrezo will, at Customer's instruction and subject to applicable law:
- return Customer Data;
- delete Customer Data; or
- permit Customer to retrieve Customer Data through functionality made available within the Services.
Encrypted content
Where Customer Data is stored in end-to-end encrypted form and Discrezo does not hold the relevant decryption key, Discrezo may only be technically capable of:
- providing encrypted data;
- making encrypted data available for Customer-controlled decryption; or
- deleting the encrypted data.
Discrezo is not required to decrypt information where the architecture intentionally prevents Discrezo from doing so.
Legal retention
Discrezo may retain Customer Data where required by applicable law.
Where legally required retention applies, Discrezo will limit further Processing to the purpose requiring retention and continue to protect the information under this DPA.
Backups
Residual copies may remain temporarily in backups or disaster-recovery systems until they are overwritten through ordinary retention cycles, provided they remain protected and are not restored for ordinary Processing except where necessary for recovery.
Customer obligations
Customer represents and warrants that it:
- has complied with applicable Data Protection Law;
- has provided all notices required to Data Subjects;
- has an appropriate lawful basis for the Processing;
- has obtained any required consents;
- has authority to provide Customer Data to Discrezo;
- has authority to instruct Discrezo to Process Customer Data;
- will only provide instructions that comply with applicable law; and
- will configure and use the Services in a manner consistent with its own data-protection obligations.
Customer responsibility for prompts
Customer controls the information that its End Users submit through Discrezo.
Customer is responsible for determining whether its End Users are permitted to submit particular categories of Personal Data.
This includes considering whether Customer Data contains:
- health information;
- financial information;
- children's data;
- biometric data;
- government identifiers;
- criminal-offence data;
- confidential business information;
- special-category Personal Data; or
- other sensitive information.
Discrezo's identity-separation architecture does not remove Personal Data that a user deliberately places inside a prompt.
Sensitive Personal Data
Discrezo does not require sensitive Personal Data to establish an ordinary Business account.
However, End Users may include sensitive Personal Data within unstructured prompts or files.
Where Customer permits this, Customer is responsible for ensuring that:
- the Processing is lawful;
- appropriate notices have been provided;
- any necessary consent or other lawful basis exists;
- use of the relevant Discrezo mode is appropriate; and
- any additional regulatory requirements applicable to Customer have been satisfied.
Regulated data
Unless Discrezo enters into a separate written agreement expressly covering a particular regulated use, Customer must not assume that the Services are contractually authorised for processing subject to specialised regimes merely because Discrezo maintains general privacy and security controls.
For example, where a Business Customer requires:
- a Business Associate Agreement;
- specialised healthcare terms;
- financial-services obligations;
- government-security requirements; or
- other sector-specific contractual commitments,
those requirements must be agreed separately where applicable.
International transfers
Customer acknowledges that Discrezo and its Sub-processors may Process Customer Data in countries other than the country in which Customer or the relevant Data Subject is located.
Where applicable Data Protection Law requires a transfer mechanism, the provisions below apply.
EEA transfers
Where Customer Data protected by the GDPR is transferred to Discrezo in a country that does not benefit from an applicable adequacy decision and another lawful transfer mechanism does not apply, the European Commission Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated into this DPA.
Applicable module
Where Customer is a Controller and Discrezo is a Processor:
Module Two — Controller to Processor
applies.
Where Customer is a Processor and Discrezo is a Sub-processor:
Module Three — Processor to Processor
applies.
Completion of EU SCCs
For purposes of the EU SCCs:
- Customer is the data exporter;
- Discrezo is the data importer;
- the Parties' contact information is as set out in the Agreement and this DPA;
- Clause 7, the optional docking clause, does not apply unless the Parties agree otherwise;
- Clause 9, Option 2, general written authorisation for Sub-processors applies;
- the Sub-processor notification mechanism is the mechanism described in Section 13 of this DPA;
- the optional language in Clause 11 does not apply;
- for Clause 17, the governing law will be the law of Ireland, where permissible;
- for Clause 18, disputes under the SCCs will be resolved by the courts of Ireland, where permissible;
- Schedule 1 of this DPA supplies the relevant information for Annex I;
- Schedule 2 supplies the relevant information for Annex II; and
- the applicable Sub-processor information made available under Section 13 supplies the relevant information for Annex III.
If these terms conflict with the mandatory provisions of the EU SCCs, the EU SCCs control.
United Kingdom transfers
Where Customer Data protected by the UK GDPR is subject to a restricted transfer to Discrezo and an alternative lawful mechanism does not apply, the Parties incorporate:
the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses
as issued by the UK Information Commissioner's Office and amended, replaced or superseded from time to time.
For purposes of the UK Addendum:
- the EU SCCs incorporated under this DPA form the Approved EU SCCs;
- Customer acts as exporter;
- Discrezo acts as importer;
- the relevant information in this DPA completes the applicable tables;
- the Parties may end the Addendum where permitted by its mandatory provisions; and
- the Information Commissioner's Office is the competent supervisory authority where applicable.
Switzerland
Where Swiss data-protection law applies to a transfer and the EU SCCs are used as the transfer mechanism, the EU SCCs will apply with adaptations necessary to give effect to applicable Swiss law.
References to the GDPR will include applicable Swiss data-protection law where appropriate.
References to EU Member States or supervisory authorities will be interpreted to include Switzerland and the competent Swiss authority where required.
Transfer assessments
Where required by applicable Data Protection Law, the Parties will reasonably cooperate in connection with a transfer impact or transfer risk assessment relating to Discrezo's Processing of Customer Data.
Discrezo will make reasonably available information regarding:
- the nature of the Processing;
- relevant technical measures;
- relevant contractual protections; and
- Sub-processor locations or transfers
to the extent necessary and legally permitted.
Government access requests
Where legally permitted, Discrezo will notify Customer if it receives a legally binding government or law-enforcement demand specifically requiring disclosure of Customer Data.
Discrezo will evaluate requests it receives in accordance with applicable law.
Discrezo will not voluntarily provide Customer Data to a government authority merely because the authority requests it informally where legal process is required.
Nothing in this section requires Discrezo to:
- violate applicable law;
- obstruct lawful process; or
- disclose information it does not possess or cannot technically decrypt.
United States privacy laws
To the extent Discrezo Processes Personal Data on behalf of Customer and applicable U.S. state privacy law treats Discrezo as a service provider, contractor, processor or analogous role, Discrezo agrees to the obligations applicable to that role.
California
To the extent the California Consumer Privacy Act, as amended ("CCPA"), applies to Personal Information Processed under this DPA:
Customer discloses Personal Information to Discrezo solely for the limited and specified business purposes described in the Agreement and this DPA.
Discrezo will:
- Process the Personal Information only for those specified business purposes and other purposes permitted by the CCPA;
- not sell the Personal Information;
- not share the Personal Information for cross-context behavioural advertising;
- not retain, use or disclose Personal Information outside the direct business relationship between Customer and Discrezo except as permitted by the CCPA;
- not retain, use or disclose Personal Information for purposes other than those specified in the Agreement, this DPA or otherwise permitted by the CCPA;
- provide the level of privacy protection required of service providers or contractors under applicable CCPA requirements;
- notify Customer if Discrezo determines that it can no longer meet its applicable CCPA obligations;
- permit Customer to take reasonable and appropriate steps to help ensure Discrezo uses Personal Information consistently with Customer's CCPA obligations; and
- cooperate with Customer to stop and remediate unauthorised use of Personal Information where reasonably required.
Combining Personal Information
Discrezo will not combine Personal Information Processed on behalf of Customer with Personal Information obtained from another person or from Discrezo's own independent interaction with a consumer except where permitted by applicable law.
Nothing in this provision prevents Discrezo from separately Processing its own Controller information as described in Section 1.4.
Consumer requests
Discrezo will provide reasonable assistance necessary for Customer to respond to applicable consumer requests where required by the CCPA and technically possible.
De-identified data
Where Discrezo creates or Processes de-identified information derived from Customer Data where permitted by applicable law, Discrezo will:
- take reasonable measures to prevent the information from being associated with an individual or household;
- maintain the information in de-identified form; and
- not attempt to re-identify the information except where legally permitted, such as for legitimate security or privacy testing.
Liability
The liability of each Party arising under this DPA is subject to the exclusions and limitations of liability contained in the Agreement, except to the extent applicable law prohibits those exclusions or limitations.
Nothing in this DPA limits any rights of Data Subjects that cannot legally be limited by contract.
Term and termination
This DPA takes effect when Discrezo begins Processing Customer Data on Customer's behalf.
It remains in effect for as long as Discrezo Processes Customer Data subject to the Agreement.
Provisions that by their nature must survive termination, including confidentiality, deletion, international-transfer and data-protection obligations, will continue for so long as relevant Customer Data remains subject to those obligations.
Order of precedence
If there is a conflict concerning Processing of Customer Data:
- mandatory provisions of applicable Data Protection Law;
- applicable mandatory provisions of the EU SCCs or UK Addendum;
- this DPA;
- any applicable order form;
- the Agreement
will control in that order, unless applicable law requires another result.
Changes
Discrezo may update this DPA where necessary to:
- comply with changes to Data Protection Law;
- replace or update transfer mechanisms;
- reflect changes required by regulators;
- improve data-protection commitments; or
- reflect material changes to the Services.
Where a change materially reduces Customer's contractual data-protection rights, Discrezo will provide appropriate advance notice.
Contact
Questions about this DPA or Discrezo's Processing of Customer Data may be sent to:
support@discrezo.com
Registered address:
Discrezo 333 West San Carlos Street San Jose, CA 95110 United States
Schedule 1 — Details of Processing
1. Subject matter
Provision of the Discrezo Business Services under the Agreement.
2. Nature of Processing
Depending on Customer's use of the Services, Processing may include:
- receipt;
- transmission;
- routing;
- analysis for routing;
- inference;
- generation of AI responses;
- encrypted storage;
- encrypted synchronisation;
- retrieval;
- deletion;
- usage management;
- security Processing; and
- related operations necessary to provide the Services.
3. Purpose
To provide, secure, maintain and support the Services requested by Customer, including:
- providing AI inference;
- automatically routing requests;
- applying Customer-selected privacy modes;
- providing conversation functionality;
- synchronising encrypted history where enabled;
- enforcing plan entitlements;
- preventing abuse;
- maintaining service reliability; and
- providing Customer support.
4. Duration
For the duration of the Agreement and for such additional period as reasonably necessary to:
- return or delete Customer Data;
- complete normal backup deletion cycles; or
- comply with applicable legal obligations.
5. Categories of Data Subjects
Depending on Customer's use, Data Subjects may include:
- Customer employees;
- contractors;
- consultants;
- representatives;
- customers;
- clients;
- suppliers;
- prospective customers;
- patients where Customer independently chooses to use permitted Services in an appropriate context;
- other individuals described in Customer Input; and
- other authorised End Users.
6. Categories of Customer Data
Customer determines the Personal Data submitted to the Services.
It may include:
- names;
- contact information;
- professional information;
- employment information;
- business information;
- account information supplied within Input;
- text contained in prompts;
- documents;
- files;
- correspondence;
- information about other individuals;
- conversation context; and
- other unstructured information supplied by Customer or End Users.
7. Sensitive Personal Data
Discrezo does not require sensitive Personal Data for ordinary Business account administration.
However, because Customer controls unstructured Input, Customer Data may contain information such as:
- health information;
- financial information;
- racial or ethnic information;
- religious information;
- political information;
- biometric information;
- sexual-orientation or sex-life information;
- criminal-offence information;
- government identifiers;
- union information; or
- other sensitive or special-category Personal Data.
Customer is responsible for determining whether submission and Processing of that information is permitted.
8. Frequency
Processing occurs on a continuous or intermittent basis depending on Customer's use of the Services.
9. AI Processing
Prompts and relevant context may be transmitted to eligible AI or inference Sub-processors where necessary to generate responses.
Provider eligibility depends on the applicable Discrezo mode.
Standard Mode
May use eligible proprietary, frontier or open-model routes.
Private Mode
Restricts routes in accordance with the Private Mode requirements described in the Agreement and excludes OpenAI, Anthropic and Google from eligible prompt-processing routes.
10. Saved content
Where encrypted history or memory is enabled:
- readable content is designed to be encrypted on a trusted End User device before synchronisation;
- Discrezo may Process or store encrypted Customer Data; and
- Discrezo's backend is designed not to possess the key required to read that saved Customer Data.
11. Return and deletion
Customer Data will be returned or deleted in accordance with Section 18.
For encrypted data, return may consist of encrypted information or Customer-controlled export where Discrezo does not possess the key required to produce plaintext.
Schedule 2 — Technical and Organisational Measures
Discrezo maintains technical and organisational measures appropriate to the nature of the Services and risks associated with the Processing.
These measures include, as applicable:
1. Information security management
Discrezo operates an:
ISO/IEC 27001-certified information security management system.
Security risks and controls are managed through formal information-security processes.
2. Architectural separation
Discrezo is designed to separate account administration from AI inference.
Inference systems are designed not to require ordinary account identity to generate an AI response.
3. Data minimisation
Systems and services are designed to receive only information reasonably necessary for the function they perform.
4. Encrypted saved content
Where encrypted history and memory are enabled, saved content is designed to be encrypted on a trusted device before synchronisation.
Discrezo's backend is designed not to hold the key required to decrypt that saved content.
5. Communications security
Discrezo uses appropriate protections for transmission of information between user devices, Discrezo systems and authorised service providers.
6. Credential security
AI provider credentials and similar privileged service credentials are maintained within protected server-side systems and are not intended to be exposed to ordinary End User browsers.
Credentials can be rotated or disabled where necessary.
7. Access controls
Access to production systems and information is restricted according to role and operational need.
Personnel authorised to access Customer-related systems are subject to appropriate confidentiality obligations.
8. Logging controls
Operational logging is designed to support:
- reliability;
- diagnostics;
- security;
- capacity management; and
- service monitoring
without intentionally creating a readable copy of Customer conversations in ordinary operational logs.
Prompt and response bodies are designed to be excluded from ordinary inference logging.
9. Identity controls
AI provider-bound inference requests are designed not to require unnecessary Customer or End User account identity.
10. Software security
Security practices include controls relating to:
- software changes;
- secrets;
- dependencies;
- privacy-boundary testing; and
- security review.
11. Provider security
AI and infrastructure providers are subject to provider eligibility and privacy requirements appropriate to the relevant Discrezo mode.
Private Mode applies additional provider restrictions.
12. Threat modelling
Discrezo's security programme considers threats including:
- account-to-inference correlation;
- logging leakage;
- metadata leakage;
- credential compromise;
- provider compromise;
- router manipulation;
- client compromise;
- abuse;
- fraud; and
- software supply-chain risks.
13. Incident response
Discrezo maintains incident-management processes designed to:
- identify;
- investigate;
- contain;
- remediate; and
- communicate
material security incidents.
14. Service protection
Discrezo may use technical controls designed to protect against:
- account abuse;
- excessive automated use;
- credential misuse;
- unauthorised access; and
- service exhaustion.
15. Security review
Discrezo uses a combination of:
- technical controls;
- automated checks;
- human review;
- information-security management; and
- independent assurance
to assess important security boundaries.
Schedule 3 — International Transfer Information
Where the EU SCCs or UK Addendum apply:
Data exporter
Customer, as identified in the Agreement.
Data importer
Discrezo 333 West San Carlos Street San Jose, CA 95110 United States
Contact:
support@discrezo.com
Data subjects
As described in Schedule 1.
Categories of Personal Data
As described in Schedule 1.
Sensitive Personal Data
As described in Schedule 1.
Frequency
Continuous or intermittent according to Customer's use.
Nature and purpose
Provision of the Discrezo Services as described in Schedule 1.
Retention
As described in Section 18 and Schedule 1.
Sub-processors
As described in Section 13 and the then-current Discrezo Sub-processor List.
Technical and organisational measures
As described in Schedule 2.
Discrezo 333 West San Carlos Street San Jose, CA 95110 United States
support@discrezo.com
Effective: 19 August 2026
This Data Processing Addendum supplements the Discrezo Terms of Use and Service Terms. For general privacy practices, see the Privacy Policy.
Discrezo is not affiliated with OpenAI, Anthropic or Google.
We only claim what the architecture technically enforces.