NoThirdParty AI
  • How it works
  • Pricing
  • FAQ
  • Contact →
How it works Pricing FAQ Contact →

Data Processing Agreement

Effective date: July 8, 2026

This Data Processing Agreement ("DPA") is entered into between the subscribing organization identified in the applicable order or subscription agreement ("Client" or "Data Controller") and NoThirdParty AI, LLC ("NoThirdParty AI" or "Data Processor").

This DPA supplements the NoThirdParty AI Terms of Service and governs the processing of Personal Data by NoThirdParty AI on behalf of the Client in connection with the Service.

1. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person that is input into the Service by the Client or Client's authorized users.
  • Processing — any operation performed on Personal Data, including collection, storage, retrieval, transmission, or deletion.
  • Sub-processor — any third party engaged by NoThirdParty AI to process Personal Data on behalf of the Client.
  • Service — the private AI platform and associated services provided by NoThirdParty AI under the Terms of Service.

2. Scope and Purpose of Processing

NoThirdParty AI processes Personal Data solely for the purpose of providing the Service as described in the Terms of Service. The nature of Processing includes storage of conversation history, retrieval of conversation history for authorized users, and transmission of conversation content to the AI model running on NoThirdParty AI's own hardware. NoThirdParty AI processes Personal Data only on the documented instructions of the Client.

3. Client Obligations as Data Controller

The Client is responsible for:

  • Ensuring it has a lawful basis under applicable law for providing Personal Data to NoThirdParty AI
  • Informing its users about how their data is processed, including by providing a copy of or link to this DPA where required
  • Ensuring that Personal Data submitted to the Service complies with applicable data protection laws
  • Obtaining any necessary consents from data subjects prior to submitting their data to the Service

4. NoThirdParty AI Obligations as Data Processor

NoThirdParty AI will:

  • Process Personal Data only on the Client's documented instructions and not for any other purpose
  • Ensure that personnel with access to Personal Data are bound by appropriate confidentiality obligations
  • Implement and maintain the technical and organizational security measures described in Section 5
  • Not transmit Personal Data to third-party AI model providers or use it to train AI models
  • Notify the Client without undue delay (and in no event more than 72 hours) upon becoming aware of a confirmed Personal Data breach
  • Assist the Client in fulfilling data subject rights requests as described in Section 7
  • Delete or return all Personal Data upon termination as described in Section 8

5. Security Measures

NoThirdParty AI implements the following technical and organizational measures to protect Personal Data:

  • Encryption in transit — communications between Client users and our servers are encrypted using TLS at each hop. Traffic passes through Cloudflare's network for routing purposes; Cloudflare's edge servers decrypt and re-encrypt traffic at this hop but do not log, cache, or retain the decrypted content. NoThirdParty AI does not enable Cloudflare's caching, WAF content inspection logging, or AI-related products on this traffic
  • Client isolation — each Client's data is stored in a separate database instance, inaccessible to other clients
  • Access controls — access to Personal Data is limited to personnel who require it to provide the Service
  • No external AI transmission — Personal Data is never transmitted to third-party AI model providers; the AI model runs on NoThirdParty AI's own hardware
  • Infrastructure security — servers are operated in a physically controlled environment with network-level access controls

6. Sub-processors

NoThirdParty AI uses the following sub-processors in connection with the Service. All sub-processors are bound by data protection obligations no less protective than those in this DPA.

Sub-processor Role Location
Cloudflare, Inc. Network infrastructure and traffic routing, including TLS termination, between Client users and NoThirdParty AI servers. Cloudflare does not retain, log, or use decrypted content United States
Google LLC (Google Drive) Encrypted remote backup storage of Client data. Data is encrypted client-side before transmission; Google does not have access to unencrypted Personal Data United States

NoThirdParty AI will notify the Client at least 14 days in advance of any intended addition or replacement of a sub-processor. The Client may object to a new sub-processor by notifying NoThirdParty AI in writing within 14 days of receiving such notice. If the parties cannot reach a mutually acceptable resolution within 30 days, either party may terminate the subscription with a pro-rata refund for the unused portion.

7. Data Subject Rights

NoThirdParty AI will assist the Client in responding to requests from data subjects exercising their rights (access, correction, deletion, restriction, portability) to the extent that NoThirdParty AI has access to the relevant Personal Data and the right is applicable under the law governing the Client's operations.

Data subject rights requests should be submitted by the Client to [email protected]. NoThirdParty AI will respond within 30 days.

8. International Data Transfers

Where Personal Data is transferred from the European Economic Area, United Kingdom, or Switzerland to the United States, the parties agree that the Standard Contractual Clauses (Module 2: Controller to Processor), as approved by the European Commission, are incorporated into this DPA by reference and apply to such transfers.

9. Health Information

This DPA does not constitute a Business Associate Agreement under HIPAA. Client shall not submit Protected Health Information (PHI) to the Service unless a separate, executed Business Associate Agreement is in place between the parties.

10. Data Retention and Deletion

Personal Data is retained for the duration of the active service agreement. Upon termination of the agreement:

  • The Client may request a data export prior to the termination date
  • NoThirdParty AI will delete all Personal Data within 30 days of termination
  • NoThirdParty AI will provide written confirmation of deletion upon request

11. Audit Rights

The Client may request written confirmation of NoThirdParty AI's compliance with this DPA no more than once per calendar year, with reasonable advance notice. NoThirdParty AI will respond within 30 days. If the Client requires a third-party audit, the parties will agree in advance on the scope, timing, and cost allocation.

12. Confidentiality

Both parties agree to keep the terms of this DPA and any Personal Data disclosed under it confidential, except as required by law or as necessary to perform obligations under this DPA.

13. Governing Law

This DPA is governed by the laws of the State of Nebraska, United States. Disputes arising under this DPA shall be resolved in the same manner as disputes under the Terms of Service.

14. Order of Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to data processing matters, this DPA takes precedence. In all other matters, the Terms of Service govern.

Questions about this agreement? Contact us at [email protected].

© 2026 NoThirdParty AI
Privacy Terms DPA AUP SLA Contact →