Compute Terms aria-hidden="true"bservatory

The published contract terms of cloud infrastructure and AI model providers, archived twice daily and laid out side by side. Every value links to the source document.

ai-generated summaries · documented methodology · not legal advice

Runpod: Runpod Data Processing Agreement

Full side-by-side comparison of both captured documents.

← Back to the change feed

Both captured versions of this document, in full. Deleted text is struck through on the left; inserted text is underlined on the right.

Runpod · Runpod Data Processing Agreement dpa Detected 2026-07-23
direct captureBefore
Captured 2026-07-18 17:26:21 UTCMethod directHash 4d9eceb54fd604c8
direct captureAfter
Captured 2026-07-23 04:19:10 UTCMethod directHash f77501f2c28b1111
22 changes
BeforeAfter
Legal
Data Processing Agreement
Legal
Data Processing Agreement
THIS DATA PROCESSING AGREEMENT
(“
Introduction & Scope
This Runpod Data Processing Agreement (“
DPA
DPA
”) is entered into as of the Agreement Effective Date by and between: (1) Runpod, Inc. (“
Runpod
”); and (2) the entity or other person who is a counterparty to the Agreement (as defined below) into which this DPA is incorporated and forms a part (
”) forms part of the Runpod Master Services Agreement (“
Agreement
”) between Runpod Inc. (collectively “
Runpod”
or the “
Processor
”) and (“
Customer
Customer
), together the
or
Controller”
). Customer and Runpod are separately referred to as “
Party
” and collectively as “
Parties
Parties
” and each a “
Party
”.
”.
INTERPRETATION
In this DPA, the following terms shall have the meanings set out in this Section 1, unless expressly stated otherwise:
“
Aggregate Data
” means anonymized sets of data derived from the data of a single Runpod Customer or multiple Runpod Customers. Aggregate Data does not include any Personal Data.
“
Agreement
” means the agreement under which Runpod has agreed to provide services to Customer entered into by and between the Parties.
“
Applicable Data Protection Laws
“means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to Runpod’s Processing of Customer Personal Data under the Agreement (including, as and where applicable, the GDPR and or State Privacy Laws).
“
Controller
” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
In the course of providing the Services (as defined herein), the Processor may obtain access to Personal Data on behalf of the Controller. The Parties acknowledge that it is necessary to enter into this DPA to establish the respective rights and obligations of the Controller and the Processor with respect to the collection, Processing, and use of Personal Data, and to ensure that such Personal Data is afforded a level of protection no less than that maintained by the Controller. This DPA sets forth the subject matter and duration of the Processing, the nature and purpose of the Processing, the types of Personal Data to be Processed, the categories of Data Subjects concerned, and the obligations and rights of the Controller and the Processor in relation thereto.
To execute this DPA, Customer must complete the signature block and required information and submit the signed DPA to Runpod via email to
chris.love@runpod.io
. This DPA shall become legally binding only upon completion of all such steps. Any modifications, alterations, or amendments to the content of this DPA by Customer shall prevent the formation of a binding agreement between the Parties, and Runpod shall not be liable for any amounts claimed under a DPA that has not strictly met all requirements for formation or that has been modified by Customer.
Definitions
Capitalized
terms not defined in this DPA shall have the meaning given to them in the Agreement and in the applicable laws.
“
Customer Personal Data
“
Customer Personal Data
” means any Personal Data Processed by Runpod or its Sub-Processor on behalf of Customer to perform the Services under the Agreement (including, for the avoidance of doubt, any such Personal Data comprised within Customer Data).
” means any Personal Data Processed by Processor or its Sub-Processor on behalf of Customer to perform the Services under the Agreement (including, for the avoidance of doubt, any such Personal Data comprised within Customer Data).
“
Data Protection Laws
” means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of Customer Personal Data under the Agreement, including, without limitation, GDPR and FADP.
“
GDPR
” means, as and where applicable to Processing concerned: (i) the General Data Protection Regulation (EU) 2016/679 (“
EU GDPR
”); and/or (ii) the UK General Data Protection Regulation (“
UK GDPR
”); each as amended.
“
Data Subject
“
Data Subject
” means the identified or identifiable natural person to whom Customer Personal Data relates.
” means an identified or identifiable natural person to whom Customer Personal Data relates.
“
Data Subject Request
“
Data Subject Request
” means the exercise by a Data Subject of its rights in accordance with Applicable Data Protection Laws in respect of Customer Personal Data and the Processing thereof.
“Effective Date”
means the effective date of the Agreement.
” means the exercise by a Data Subject of its rights in accordance with Data Protection Laws in respect of Customer Personal Data and the Processing thereof.
GDPR
” means, as and where applicable to Processing concerned: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“
EU GDPR
”); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended, including by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) (“
UK GDPR
”), including, in each case (i) and (ii) any applicable national implementing or supplementary legislation (e.g., the UK Data Protection Act 2018 and the UK Data Use and Access Act 2025), and any successor, amendment or re-enactment, to or of the foregoing. References to “
Articles
” and “
Chapters
” of, and other relevant defined terms in, the GDPR shall be construed accordingly.
EEA
” means the European Economic Area.
Personal
Data
” means “personal data,“personal information, “personally identifiable information” or similar term defined in Applicable Data Protection Laws.
Effective Date
” means the effective date of the Agreement.
“
FADP
” means, as and where applicable to Processing concerned, the Federal Act on Data Protection of 19 June 1992 in its revised version of 25 September 2020, as amended.
“
FDPIC
” means the Swiss Federal Data Protection and Information Commissioner.
“
ICO
” means the United Kingdom’s Information Commissioner’s Office (or its successor).
“
Performance Data
” means any log files, metadata, telemetry data, and other technical performance data automatically generated by the Service relating to the use, performance, efficacy, reliability, and/or accuracy of the Runpod Services (certain of which may constitute Personal Data).
“
Personal Data
” or “personal data” means any information about, or relating to an identified or identifiable natural person as defined by Data Protection Laws.
"Special Categories of Personal Data"
means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or a natural person's sex life or sexual orientation, as defined in Article 9(1) of the GDPR and any equivalent provision under applicable Data Protection Laws.
“
Personal Data Breach
“
Personal Data Breach
” means a breach of Runpod’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in Runpod’s possession, custody or control. For clarity, Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data (such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems).
” means a breach of security leading to accidental or unlawful destruction, loss, or alteration, unauthorized disclosure of, or access to, Personal Data processed for Customer by Processor. For clarity, Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data (such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems).
“
Personnel
“
Personnel
” means a person’s employees, agents, consultants, contractors or other staff.
” means a person’s employees, agents, consultants or contractors.
“
Privacy Statement
” means the privacy statement adhered to by Runpod in provision of all Runpod Offerings, as published and updated from time to time on Runpod’s Website
Privacy policy
.
“
Process
“
Process
, and grammatical inflections thereof, means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“
Processor
” means a natural or legal person, public authority, agency or other body that Processes Personal Data on behalf of a Controller.
(and its inflections) shall have the meaning given to that term under applicable Data Protection Laws.
“
Restricted Transfer
“
Restricted Transfer
” means the disclosure, grant of access or other transfer of Customer Personal Data to any person located in: (i) in the context of the EU GDPR, any country or territory outside the European Economic Area (“
EEA
”) which does not benefit from an adequacy decision from the European Commission (an “
EU Restricted Transfer
”); and (ii) in the context of the UK GDPR, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “
UK Restricted Transfer
”), which would be prohibited without a legal basis under Chapter V of the GDPR.
“
SCCs
” means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914.
” means any transfer of Personal Data to a third country not benefiting from an adequacy decision under applicable Data Protection Laws (whether from Customer to Runpod, from Runpod to a Sub-Processor, or between establishments of Runpod or a Sub-Processor) that would be prohibited by Data Protection Laws absent appropriate authorization mechanisms.
“
Services
“
Services
” means those services and activities to be supplied to or carried out by or on behalf of Runpod for Customer pursuant to the Agreement.
” means Runpod services and products ordered or subscribed to by the Customer in the Agreement.
State Privacy Laws
” means, collectively, the comprehensive U.S. state data privacy laws currently in effect and applicable to Provider’s Processing of Personal Data under the Agreement.
Standard Contractual Clauses
” means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council approved by implementing decision (EU) 2021/914 of the European Commission of 4.6.2021, as may be amended, superseded, or replaced.
“
Sub-Processor
“
Sub-Processor
” means any third party appointed by or on behalf of Runpod to Process Customer Personal Data.
” means any person or entity appointed by or on behalf of Runpod to process Personal Data on behalf of Runpod in connection with the Services and shall include any Sub-Processor rightfully appointed by a Sub-Processor (a Sub-Sub-Processor) to process Personal Data on behalf of Runpod in connection with the Services, but shall not include any individual employee of Runpod or a Sub-Processor.
“
Supervisory Authority
“
Supervisory Authority
: (i) in the context of the EEA and the EU GDPR, shall have the meaning given to that term in the EU GDPR; and (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner’s Office.
means, in the context of the EU GDPR, the authority as defined in Article 4(21) thereof, in the context of the UK GDPR, the ICO, and in the context of the FADP, the FDPIC.
UK Transfer Addendum
” means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section ‎‎18 of the UK Mandatory Clauses included in Part 2 thereof (the “
UK Mandatory Clauses
”).
Unless otherwise defined in this DPA, all capitalized terms in this DPA shall have the meaning given to them in the Agreement.
PROCESSING OF CUSTOMER PERSONAL DATA
Details and roles. The Parties acknowledge and agree that the details of Runpod’s Processing of Customer Personal Data (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to the DPA. Runpod may create, generate, use and disclose Aggregate Data for any lawful purpose. Runpod will not, and will not allow third parties to which it discloses Aggregate Data, re-identify Aggregate Data such that it becomes identifiable to Data Subjects.
This DPA does not apply to Personal Data relating to an employee or other authorized representative of Customer that is collected or received by Runpod in connection with the procurement or use of, or payment for, the Services (for example, the names and email addresses of Customer’s account representatives and accounting personnel). Runpod’s use of Personal Data of such an employee or other representative is governed by the Runpod Privacy Policy, which describes how to manage individual communication preferences. The Parties shall be responsible for informing its own Authorized Users of the processing of their Personal Data as provided in the Agreement.
General. Runpod shall not Process Customer Personal Data other than: (a) on Customer’s instructions set out in the Agreement and this DPA; or (b) as required by applicable laws. Customer instructs and authorizes Runpod to Process Customer Personal Data for the purposes set out in the Agreement (as further described in Annex 1 (Data Processing Details) to the DPA). This includes (i) to provide the Services; (ii) to provide customer support; and (iii) to improve and enhance the Services. The Agreement is a complete expression of such instructions, and Customer’s additional instructions will be binding on Runpod only pursuant to any written amendment to this DPA signed by both Parties. Customer acknowledges and agrees that any instructions issued by Customer with regards to the Processing of Customer Personal Data by or on behalf of Runpod pursuant to or in connection with the Agreement shall be in strict compliance with Applicable Data Protection Laws. Where required by Applicable Data Protection Laws, if Runpod receives an instruction from Customer that, in its reasonable opinion, infringes Applicable Data Protection Laws, Runpod shall notify Customer.
TECHNICAL AND ORGANIZATIONAL MEASURES; ASSISTANCE
Personnel. Runpod shall take commercially reasonable steps designed to ascertain the reliability of any Runpod Personnel who Process Customer Personal Data, and shall enter into written confidentiality agreements with all Runpod Personnel who Process Customer Personal Data that are not subject to professional or statutory obligations of confidentiality.
Security. Runpod shall implement and maintain technical and organizational measures in relation to Customer Personal Data designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access as described in Annex 3 (Security Measures) (the “
Security Measures
”). Runpod may modify these Security Measures from time to time to reflect its then-current security standards and practices; provided that such modifications do not materially decrease the overall security of Services and/or relevant Customer Personal Data.
Data Subject Rights. Runpod, taking into account the nature of the Processing of Customer Personal Data, shall provide Customer with such assistance as may be reasonably necessary and technically feasible to assist Customer in fulfilling its obligations to respond to Data Subject Requests. If Runpod receives a Data Subject Request, Customer will be responsible for responding to any such request. Runpod shall: (a) promptly notify Customer if it receives a Data Subject Request; and (b) not respond to any Data Subject Request, other than to advise the Data Subject to submit the request to Customer, except as required by Applicable Data Protection Laws.
DPIAs and Consultations. If and to the extent the GDPR applies to the given Processing of Customer Personal Data, Runpod shall, taking into account the nature of the Processing and the information available to it, provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with Supervisory Authorities, which are required by Article 35 or Article 36 of the GDPR (as applicable), in each case solely in relation to such Processing of Customer Personal Data by Runpod.
PERSONAL DATA BREACHES
Notifications. Runpod shall notify Customer without undue delay upon Runpod’s confirmation of a Personal Data Breach affecting Customer Personal Data. Runpod shall reasonably co-operate with Customer and take such commercially reasonable steps as may be directed by Customer to assist in the investigation of any Personal Data Breach. Runpod shall provide Customer with information (insofar as such information is within Runpod’s possession and knowledge and does not otherwise compromise the security of any Personal Data Processed by Runpod) to allow Customer to meet its obligations under the Applicable Data Protection Laws to report the Personal Data Breach. Runpod’s notification of or response to a Personal Data Breach shall not be construed as Runpod’s acknowledgement of any fault or liability with respect to the Personal Data Breach. As between the Parties, Customer is solely responsible for complying with applicable laws (including notification laws), and fulfilling any third-party notification obligations, related to any Personal Data Breaches.
Consultation with Runpod. If Customer determines that a Personal Data Breach suffered by Runpod or a Sub-Processor affecting Customer Personal Data must be notified to any Supervisory Authority, any other governmental authority, any Data Subject(s), the public or others under Applicable Data Protection Laws or otherwise, to the extent such notice directly or indirectly refers to or identifies Runpod, where permitted by applicable laws, Customer agrees to: (a) notify Runpod in advance; and (b) in good faith, consult with Runpod and consider any clarifications or corrections Runpod may reasonably recommend or request to any such notice, which: (i) relate to Runpod’s involvement in or relevance to such Personal Data Breach; and (ii) are consistent with applicable laws.
SUB-PROCESSING
General authorization. Customer generally authorizes Runpod to appoint Sub-Processors in accordance with this Section 5. Information about Runpod’s Sub-Processors, including their functions and locations, is as shown in [INSERT] (as may be updated from time-to-time) or such other website address or Sub-Processor document as Runpod may provide to Customer from time-to-time (the “
Sub-Processor List
”). Without limitation, Customer authorizes Runpod engagement of the Sub-Processors listed on the Sub-Processor List as of the Effective Date.
Notification. Runpod shall give Customer prior written notice of the appointment of any proposed Sub-Processor, including reasonable details of the Processing to be undertaken by the Sub-Processor by updating the Sub-Processor List and notifying the Customer of such intended change, no later than thirty (30) days before the appointment of new Sub-Processors. If, within thirty (10) days of receipt of that notice, Customer notifies Runpod in writing of any objections to the proposed appointment (made in good faith based upon evidenced concerns that the use of that proposed Sub-Processor would cause Customer to be in material and unavoidable breach of Applicable Data Protection Laws): (a) Runpod shall use reasonable efforts to make available a commercially reasonable change in the provision of the Services, which avoids the use of that proposed Sub-Processor; and (b) where: (i) such a change cannot be made within thirty (30) days from Runpod’s receipt of Customer’s notice; (ii) no commercially reasonable change is available; and/or (iii) Customer declines to bear the cost of the proposed change, then Runpod may terminate the Agreement without liability to Customer beyond reimbursing any pre-paid fees on a pro-rated basis. If Customer does not object to Runpod’s appointment of a Sub-Processor during the objection period referred to in this Section 5.2, Customer shall be deemed to have approved the engagement and ongoing use of that Sub-Processor.
Runpod Responsibilities. With respect to each Sub-Processor, Runpod shall maintain a written contract between Runpod and the Sub-Processor that includes terms which offer at least an equivalent level of protection for Customer Personal Data as those set out in this DPA. Runpod shall remain liable for any breach of this DPA caused by a Sub-Processor.
DATA TRANSFERS
Entry into SCCs. In respect of any Restricted Transfer of Customer Personal Data from Customer to Runpod under this DPA: (a) that is an EU Restricted Transfer, the Parties hereby enter into and agree to comply with their respective obligations set out in the SCCs as populated in accordance to clause 6.2 below; and/or (b) that is a UK Restricted Transfer, the Parties hereby enter into and agree to comply with their respective obligations set out in the SCCs as varied by the UK Transfer Addendum as populated in accordance to clause 6.3 below.
Population of SCCs. In respect of any SCCs entered into pursuant to Section 6.1, the Parties agree as follows: (a) each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs; (b) as applicable: (i) Module Two of the SCCs applies to any relevant EU Restricted Transfer involving Processing of Customer Personal Data in respect of which Customer is a Controller in its own right; and (ii) Module Three of the SCCs applies to any relevant EU Restricted Transfer involving Processing of Customer Personal Data in respect of which Customer is itself a Processor; (c) as and where applicable to the relevant Module of the SCCs and the Clauses thereof: (i) in Clause 7: the optional ‘Docking Clause’ is not used; (ii) in Clause 9: ‘OPTION 2: GENERAL WRITTEN AUTHORISATION’ applies, and the minimum time period for advance notice of the addition or replacement of Sub-Processors shall be the advance notice period set out in Section 5.2; (iii) in Clause 11: the optional language is not used; (iv) in Clause 13: all square brackets are removed and all text therein is retained; (v) in Clause 17: ‘OPTION 1’ applies, and the Parties agree that the SCCs shall be governed by the law of: (A) Ireland in relation to any EU Restricted Transfer; (vi) in Clause 18(b): the Parties agree that any dispute arising from the SCCs shall be resolved by the courts of Ireland.
In respect of the Annexes to the Appendix to the SCCs: (i) Annex I is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA with Customer being the ‘data exporter’ and Runpod being the ‘data importer’; (ii) part C of Annex I is populated with the following “Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, Ireland; and (iii) Annex II is populated with reference to the information contained in and determined by Section 3.2 of the DPA (including the Security Measures).
Population of UK Transfer Addendum. Where relevant in accordance with Section 6.1(b), the SCCs apply to any UK Restricted Transfers as varied by the UK Transfer Addendum in the following manner: (i) ’Part 1 to the UK Transfer Addendum’: (A) Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) to the DPA and Section 6.2; and (B) Table 4 to the UK Transfer Addendum is completed by the box labelled ‘Data Importer’ being deemed to have been ticked; and (ii) ‘Part 2 to the UK Transfer Addendum’: the Parties agree to be bound by the UK Mandatory Clauses and that the SCCs shall apply to any UK Restricted Transfers as varied in accordance with those Mandatory Clauses.
As permitted by Section 17 of the UK Mandatory Clauses, the Parties agree to the presentation of the information required by ‘Part 1: Tables’ of the UK Transfer Addendum in the manner set out in clause 6.3; provided that the Parties further agree that nothing in the manner of that presentation shall operate or be construed so as to reduce the Appropriate Safeguards (as defined in Section 3 of the UK Mandatory Clauses). In relation to any UK Restricted Transfer to which they apply, where the context permits and requires any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in clause 6.3 above.
Adoption of new transfer mechanism. Runpod may on notice vary this DPA and replace the relevant SCCs with: (i) any new form of the relevant SCCs or any replacement therefor prepared and populated accordingly (e.g. standard data protection clauses adopted by the European Commission for use specifically in respect of transfer to data importers subject to Article 3(2) of the EU GDPR); or (ii) another transfer mechanisms, other than the SCCs, that enables the lawful transfer of Customer Personal Data to Vendor under this DPA in compliance with Chapter V of the GDPR.
Provision of the full-form SCCs. In respect of any given Restricted Transfer, if requested of Customer by a Supervisory Authority or Data Subject – on specific written request and accompanied by suitable supporting evidence of the relevant request - Runpod shall provide Customer with an executed version of the relevant set(s) of SCCs responsive to the request made of Customer (amended and populated in accordance with clause 6.2) for countersignature by Customer, onward provision to the relevant requestor and/or storage to evidence Customer’s compliance with Applicable Data Protection Laws.
AUDITS
Information provision and audits. Runpod shall make available to Customer on request, such information as Runpod (acting reasonably) considers appropriate in the circumstances to demonstrate its compliance with this DPA. Subject to Sections 7.2 to 7.4, in the event that Customer (acting reasonably) is able to provide documentary evidence that such information is not sufficient in the circumstances to demonstrate Runpod’s compliance with this DPA, at Customer’s expense, Runpod shall allow for and contribute to audits by Customer or an auditor mandated by Customer in relation to the Processing of Customer Personal Data by Runpod up to once per year.
Customer responsibilities. Customer shall give Runpod reasonable notice of any audit to be conducted under Section 7.1 (which shall in no event be less than thirty (30) days’ notice, unless a shorter notice period is specifically required under Applicable Data Protection Laws relevant to the audit concerned) and shall use its best efforts (and ensure that each of its mandated auditors uses its best efforts) to avoid causing any destruction, damage, injury or disruption to Runpod’s premises, equipment, Personnel, data, and business (including any interference with the confidentiality or security of the data of Runpod’s other customers or the availability of Runpod’s services to such other customers).
Audit plans. Prior to conducting any audit, Customer must submit a detailed proposed audit plan providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Runpod will review the proposed audit plan and provide Customer with any feedback, concerns or questions (for example, any request for information that could compromise Runpod security, privacy, employment or other relevant policies). Runpod will work cooperatively with Customer to agree on a final audit plan.
Limitations. Runpod need not give access to its premises for the purposes of any audit under this Section 7: (a) where a third-party audit report or certification (e.g., SOC 2 Type 2, ISO 2700x, NIST or similar audit report or certification) is provided in lieu of such access (acceptance of which for this purpose not to be unreasonably withheld, delayed or conditioned by Customer); (b) to any individual unless they produce reasonable evidence of their identity; (c) to any auditor whom Runpod has not approved in advance (acting reasonably); (d) to any individual who has not entered into a non-disclosure agreement with Runpod on terms acceptable to Runpod (acting reasonably); (e) outside normal business hours at those premises; or (f) on more than one occasion in any calendar year during the term of the Agreement, except for any audits which Customer is required to carry out under Applicable Data Protection Laws or by a Supervisory Authority. Nothing in this DPA shall require Runpod to furnish more information about its Sub-Processors in connection with such audits than such Sub-Processors make generally available to their customers. Nothing in this Section 7 shall be construed to obligate Runpod to breach any duty of confidentiality.
RETURN AND DELETION
General. Upon expiration or earlier termination of the Agreement, Runpod shall return and/or delete all Customer Personal Data in Runpod’s care, custody or control. To the extent that deletion of any Customer Personal Data contained in any back-ups’ maintained by or on behalf of Runpod is not technically feasible within the timeframe set out in Customer’s instructions, Runpod shall (a) securely delete such Customer Personal Data in accordance with any relevant scheduled back-up deletion routines (e.g., those contained within Runpod’s relevant business continuity and disaster recovery procedures); and (b) pending such deletion, irreversibly render anonymous all such Customer Personal Data and put such Customer Personal Data beyond use.
Permitted retention. Notwithstanding the foregoing, Runpod may retain Customer Personal Data where required by applicable laws, provided that Runpod shall (a) maintain the confidentiality of all such Customer Personal Data and (b) Process the Customer Personal Data only as necessary for the purpose(s) and duration specified in the applicable law requiring such retention.
CUSTOMER’S RESPONSIBILITIES
Security. Customer agrees that, without limiting Runpod’s obligations under Section 5 (Security), Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to maintain a level of security appropriate to the risk in respect of the Customer Personal Data; (b) securing the account authentication credentials, systems and devices Customer uses to access the Services; (c) securing Customer’s systems and devices that Runpod uses to provide the Services; and (d) backing up Customer Personal Data.
Compliance. Customer shall ensure: (a) that there is, and will be throughout the term of the Agreement, a valid legal basis for the Processing by Runpod of Customer Personal Data in accordance with this DPA and the Agreement (including, any and all instructions issued by Customer from time to time in respect of such Processing) for the purposes of all Applicable Data Protection Laws (including Article 6, Article 9(2) and/or Article 10 of the GDPR (where applicable)); and (b) that all Data Subjects have (i) been presented with all required notices and statements (including as required by Article 12-14 of the GDPR (where applicable)); and (ii) provided all required consents, in each case (i) and (ii) relating to the Processing by Runpod of Customer Personal Data.
Restricted Data. Customer shall not provide or otherwise make available to Runpod any Customer Personal Data that contains any (a) Social Security numbers or other government-issued identification numbers; (b) protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; (c) health insurance information; (d) biometric information; (e) passwords to any online accounts; (f) any payment card information subject to the Payment Card Industry Data Security Standard; (g) credentials to any financial accounts; (h) tax return data; (i) Personal Data of children under 13 years of age; or (j) any other information that falls within any special categories of personal data (as defined in GDPR) and/or data relating to criminal convictions and offences or related security measures (together, “
Restricted Data
”).
VARIOUS
Incorporation and Application. This DPA shall be incorporated into and form part of the Agreement with effect on and from the Effective Date. This DPA: (a) applies only if and to the extent Applicable Data Protection Laws govern Runpod’s Processing of Customer Personal Data in performance of the Service(s) as a ‘processor’, ‘service provider’ or similar role defined under Applicable Data Protection Laws; and (b) does not apply to Runpod’s Processing of any Personal Data for its own business/customer relationship administration purposes, its own marketing or service analytics, its own information and systems security purposes supporting the operation of the Services, nor its own legal, regulatory or compliance purposes.
State Privacy Laws. Annex 2 (State Privacy Laws Annex) applies if and to the extent Runpod’s Processing of Customer Personal Data on behalf of Customer under the Agreement is subject to any of the State Privacy Laws.
Costs. Except to the extent prohibited by Applicable Data Protection Laws, Customer shall compensate Runpod at Runpod’s then-current professional services rates for, and reimburse any costs reasonably incurred by Runpod in the course of providing, cooperation, information, or assistance requested by Customer pursuant to Sections 3.3 (Data Subject Rights), 3.4 (DPIAs and Consultations) and 7 (Audits) of this DPA (provided that Runpod shall bear its own costs in the event that any audit or inspection conducted in accordance with that Section 7 reveals any material non-compliance by Runpod with this DPA and/or Applicable Data Protection Laws. This provision applies, in each case, beyond providing self-service features included as part of, or in connection with, the Services.
LIABILITY. THE TOTAL AGGREGATE LIABILITY OF EITHER PARTY TOWARDS THE OTHER PARTY, HOWSOEVER ARISING, UNDER OR IN CONNECTION WITH THE AGREEMENT, THIS DPA AND THE SCCS (IF AND AS THEY APPLY) WILL UNDER NO CIRCUMSTANCES EXCEED ANY LIMITATIONS OR CAPS ON, AND SHALL BE SUBJECT TO ANY EXCLUSIONS OF, LIABILITY AND LOSS AGREED BY THE PARTIES IN THE AGREEMENT; PROVIDED THAT, NOTHING IN THIS SECTION 10.4 WILL AFFECT ANY PERSON’S LIABILITY TO DATA SUBJECTS UNDER THE THIRD-PARTY BENEFICIARY PROVISIONS OF THE SCCS (IF AND AS THEY APPLY).
Required Updates. Each Party shall act in good faith to agree variations to this DPA that are reasonably necessary to address the requirements of Applicable Data Protection Laws from time to time (including to apply a new transfer mechanism to comply with relevant requirements of the GDPR).
Prevail. This DPA shall be incorporated into and form part of the Agreement with effect on and from the Effective Date. In the event of any conflict or inconsistency between: (a) this DPA and the Agreement, this DPA shall prevail; or (b) any SCCs entered into pursuant to Section 6 and this DPA and/or the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.
RUNPOD / ‘DATA IMPORTER’ DETAILS
Name:
Runpod, Inc.
Address:
1181 Nixon Dr #1158, Moorestown, NJ 08057
Contact Details for Data Protection:
chris.love@Runpod.io
Runpod Activities:
Activities relevant to the data transferred under this DPA
Role:
Processor
‍
CUSTOMER / ‘DATA EXPORTER’ DETAILS
Name:
The entity or other person who is a counterparty to the Agreement
Address:
Customer’s address is:
• the address shown in the Agreement entered into by and between the Customer and Runpod; or
• if the Agreement does not include the address, the Customer’s principal business trading address unless otherwise notified to Runpod’s Contacts identified above.
Contact Details
for Data Protection:
Customer’s contact details are:
• the contact details shown in the Agreement; or
• if the Agreement does not include the contact details, Customer’s contact details submitted by Customer and associated with Customer’s account for the Services.
Customer
Activities:
Customer’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
Role:
• Controller – in respect of any Processing of Customer Personal Data in respect of which Customer is a Controller in its own right; and
• Processor – in respect of any Processing of Customer Personal Data in respect of which Customer is itself acting as a Processor on behalf of any other person (including, where applicable, its affiliates or Customer’s own customers for whom Customer is a Processor).
Categories of
Data Subjects:
Customer may submit Customer Personal Data to Runpod relating to various categories of data subjects, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to:
(i) Customer’s current, past, and prospective customers and clients;
(ii) Customer’s employees, contractors, and other personnel of the foregoing entities; and
(iii) Customer’s suppliers and service providers.
Categories of
Personal Data:
Customer may submit Customer Personal Data to Runpod, the extent of which is determined and controlled by Customer in its sole discretion and may vary depending on the Services, but which may include:
identification and contact data (name, address, title, contact details, company information);
professional information (employer, job title, geographic location, area of responsibility);
IT usage data (user ID and roles);
technical data (IP addresses, device information, browser data);
communication data (email);
and any other Personal Data elements that Customer chooses to input into or otherwise provide to the Services.
Sensitive Categories of Data,
and associated additional
restrictions/safeguards:
Categories of sensitive data:
None – as noted in Section 9.3 of the DPA, Customer agrees that Restricted Data, which includes ‘sensitive data’ (as defined in Clause 8.7 of the SCCs) must
not
be submitted to the Services.
Additional safeguards for sensitive data:
N/A
Frequency of
transfer:
Ongoing – as initiated by Customer in and through its use, or use on its behalf, of the Services.
Nature of
the Processing:
Processing operations required in order to provide the Services in accordance with the Agreement.
Purpose of
the Processing:
Customer Personal Data will be Processed:
(i) to provide the Services;
(ii) to provide customer support; and
(iii) to improve and enhance the Services.
Duration of
Processing / Retention Period:
For the period determined in accordance with the Agreement and DPA, including Section 8 of the DPA.
Transfers to
(sub-)processors:
Transfers to Sub-Processors are as, and for the purposes, described from time to time in the Sub-Processor List.
‍
State Privacy Laws Annex
In this Annex 2, the terms “
UK Addendum
” means the template addendum B1.0 issued by the ICO under s119A(1) of the Data Protection Act 2018, in force from 21 March 2022, as may be amended in accordance with its terms.
Details of the Processing, Data Categories, and Data Subjects
Runpod collects, uses, and discloses Customer Personal Data solely for the purposes of providing the Services and for such other ancillary purposes consented to by the Customer or as required by law. Processing operations are limited to those required to perform the Services in accordance with the Agreement. Runpod shall not determine the purposes for which or the manner in which Customer Personal Data is processed, and neither Runpod nor its Sub-Processors shall process Customer Personal Data for their own purposes. The following categories of Personal Data may be processed: (i) personal data (e.g., last name, first name, and address); (ii) communication data (e.g., email); (iii) IT usage data (e.g., user ID, and roles); and/or (iv) any other category named in Runpod's Privacy Statement. Customer Personal Data may relate to the following categories of Data Subjects: (a) the Customer's clients/service recipients; (b) the Customer's employees; and/or (c) the Customer's suppliers/service providers.
Where Customer Personal Data includes Special Categories of Personal Data, Customer warrants that: (i) it has identified and documented a valid legal basis under Article 9(2) of the GDPR (or equivalent provision under applicable Data Protection Laws) for such processing prior to transmitting such data to Runpod; (ii) it will promptly provide evidence of such legal basis to Runpod upon request; and (iii) it will notify Runpod in writing before adding any new Special Categories of Personal Data to the scope of processing under this DPA.
Place of Data Processing
Runpod uses third-party data hosting providers (as identified in Attachment 2) to host the Services on servers located throughout the world, including in the United States. Where a region is specified by Customer during service instantiation, Runpod will use reasonable efforts to allocate a server in a geographically proximate location. Where cross-border transfer cannot be avoided, legally required authorization mechanisms shall be applied.
Instructions
Runpod shall process Personal Data for the purposes of: (i) processing as required by Customer in its use of the Services; (ii) processing in accordance with the Agreement, this DPA and any other agreements between the Parties, (iii) processing to comply with other reasonable instructions provided by Customer where such instructions are consistent with the terms of the Agreement, applicable laws and DPA.
Runpod will inform Customer if, in Runpod’s opinion, the Customer’s instructions or requests are contrary to Data Protection Laws, with reasons thereof in writing via email.
Where Customer's instructions require the processing of Special Categories of Personal Data, Customer confirms that such processing is permitted under applicable Data Protection Laws and that the relevant conditions under Article 9(2) of the GDPR (or equivalent provision under applicable Data Protection Laws) are satisfied. Runpod shall process such data solely in accordance with Customer's documented instructions and shall not process it for any other purpose. If Runpod becomes aware that Customer Personal Data being processed includes Special Categories of Personal Data not previously identified by Customer, Runpod shall notify Customer promptly in writing.
Confidentiality
Runpod shall take commercially reasonable steps to ascertain the reliability of any Processor Personnel who Process Customer Personal Data, and shall enter into written confidentiality agreements with all Processor Personnel who Process Customer Personal Data that are not subject to professional or statutory obligations of confidentiality.
Technical & Organizational Measures
Runpod shall implement reasonably necessary technical and organizational measures (“
TOMs
”) designed to protect Customer Personal Data against accidental or unlawful destruction, including, as appropriate: (i) anonymization, pseudonymization, and encryption of Personal Data; (ii) security controls designed to ensure the availability and protect the confidentiality of Personal Data; and (iii) regular testing, assessing, and evaluating the effectiveness of such measures for the duration of the Agreement. The TOMs implemented by Runpod are specified in Attachment 1. Runpod reserves the right to modify the TOMs at any time, provided that any modifications shall not materially decrease the security of Customer Personal Data.
Runpod engages approved Sub-Processors to provide or support parts of the Services, and the TOMs depend partially on such Sub-Processors as described in
Attachment 1;
provided that Runpod remains responsible for its compliance with the TOMs regardless of its reliance on Sub-Processors
.
Sub-Processors
Customer acknowledges and agrees that Runpod may engage Sub-Processors in the provision of Services, subject to this DPA, and that (i) a Runpod affiliate may be retained as a Sub-Processor; and (ii) Runpod or a Runpod affiliate may engage third-party Sub-Processors.
Where Runpod engages a Sub-Processor in the provision of Services, a data processing agreement will be entered into with the Sub-Processor. A list of Runpod’s Sub-Processors is available in
Attachment 2
.
Customer further acknowledges that Runpod may, for commercial or security reasons, maintain certain Sub-Processors as confidential (“
Confidential Sub-Processors
”). Disclosure of any information related to Confidential Sub-Processors shall be subject to the execution of a non-disclosure agreement proposed by Runpod, and such disclosure will only occur once that agreement has been fully executed by the Parties.
Upon authorizing any new Sub-Processor to access Personal Data, Runpod will update the list of Runpod's Sub-Processors. Where a new Confidential Sub-Processor is appointed, Runpod’s notification to Customer will not identify the Sub-Processor but will state the type of services or operations it supports and the geographic location of such processing. If Customer wishes to receive additional information regarding such Confidential Sub-Processor, Customer must first execute a non-disclosure agreement proposed by Runpod, after which Runpod may disclose further details.
Within ten (10) business days of an update to the list of Sub-Processors, Customer shall inform Runpod, in writing, of objections to any new Sub-Processors, if any. If Customer objections are not unreasonable, Runpod will use reasonable efforts to change the Services provided to Customer or recommend a commercially reasonable change to Customer’s Services to avoid processing of Personal Data by the objected-to new Sub-Processor without unreasonably burdening the Customer.
If Customer objects to a new Sub-Processor, Customer may terminate any subscription for the affected Runpod Services without penalty by providing written notice of termination before the end of the notice period, unless the new Sub-Processor is necessary for Runpod to provide the Services, in which case the standard termination provisions of this DPA shall apply.
If use of a Sub-Processor involves a Restricted Transfer, Runpod shall ensure that the authorizations required under applicable Data Protection Laws are at all relevant times incorporated into an agreement between Runpod and the Sub-Processor and between the Sub-Processor and any Sub-Sub-Processor.
Data Subject Requests
Runpod shall reasonably support the Customer in the case of a Data Subject Request, insofar as Customer cannot fulfill such a request on its own, to the extent legally permitted and technically possible. Customer shall pay Runpod for the costs for such support, to the extent legally permitted.
If a Data Subject Request is received by Runpod that relates to Personal Data transferred by the Customer, Runpod will refer the request to the Customer. Runpod will not respond to such a request but shall instead support Customer as provided in this Section.
Personal Data Breach Notification
Runpod shall inform Customer without undue delay after becoming aware of a Personal Data Breach and shall, at Customer’s request, provide reasonable assistance in obtaining information within Runpod’s control to enable Customer to meet its obligations under Data Protection Laws to report the Personal Data Breach. Runpod's notification of or response to a Personal Data Breach shall not be construed as an acknowledgement of any fault or liability on the part of Runpod with respect to such Personal Data Breach.
At the request of Customer, but at Customer’s sole cost, Runpod shall assist Customer in notifying the relevant Supervisory Authority and/or the Data Subjects implicated in the Personal Data Breach.
Customer is solely responsible for complying with notification requirements under Data Protection Laws and fulfilling any third-party notification obligations related to any Personal Data Breaches.
If Customer determines that a Personal Data Breach must be notified to any Supervisory Authority, any Data Subject(s), the public, or any other party under Data Protection Laws, and to the extent such notice directly or indirectly refers to or identifies Runpod, Customer agrees, where permitted by applicable Data Protection Laws, to:
notify Processor in advance; and
consult with Processor in good faith and consider any clarifications or corrections that Processor may reasonably recommend or request in respect of such notification, provided that any such clarifications or corrections: (i) relate to Processor’s involvement in or relevance to the Personal Data Breach; and (ii) are consistent with Data Protection Laws.
Data Protection Impact Assessment (DPIA)
Upon Customer's request, Runpod shall provide reasonable assistance in conducting a DPIA in relation to Runpod’s Processing of Customer Personal Data, taking into account the nature of the Processing and the information available to Runpod and its Sub-Processors. Customer shall bear all costs associated with such assistance, to the extent legally permitted.
Deletion or Returning Personal Data
Upon Customer's request, Runpod shall irretrievably delete or return all Personal Data in accordance with the Agreement, unless retention is required by applicable law.
Information & Audit Rights
Upon Customer’s written request, and no more than once per calendar year, Runpod shall make available information reasonably necessary to demonstrate Runpod's compliance with this DPA and applicable Data Protection Laws. Where Customer (acting reasonably) provides documentary evidence that such information is insufficient to demonstrate compliance, Runpod shall permit and contribute to audits, including on-premise inspections, conducted by Customer or a qualified third-party auditor appointed by Customer, in relation to the Processing of Customer Personal Data.
Prior to any audit, Customer shall submit a detailed audit plan specifying the proposed scope, duration, and start date, and providing for the confidential treatment of all information exchanged and any resulting reports. Runpod shall review the proposed plan and notify Customer of any concerns, including any request that could compromise Runpod's security, privacy, or employment policies. The Parties shall cooperate in good faith to agree on a final audit plan, including scope, timing, and duration. All costs associated with any audit shall be borne solely by Customer.
Restricted Transfers
Any Restricted Transfer shall be subject to the Standard Contractual Clauses and/or the UK Addendum, as applicable.
In respect of any Restricted Transfer between Customer and Runpod, Customer shall be deemed the "Data Exporter" and Runpod the "Data Importer" (each as defined therein), and the Parties hereby enter into, and are deemed to have signed, the Standard Contractual Clauses in accordance with
Attachment 3
and/or UK Addendum in accordance with
Attachment 4
. In addition, where a Restricted Transfer between Customer and Runpod is subject to the FADP,
Attachment 5
of this DPA shall also apply. The Standard Contractual Clauses and/or UK Addendum entered into between Customer and Runpod shall take effect upon execution of the Agreement.
Liability
Each Party's liability under this DPA shall be subject to the limitations, caps, and exclusions of liability set forth in the Agreement, and shall in no circumstances exceed such limitations.
Term & Termination
This DPA shall become effective upon execution by both Parties and shall remain in force for the duration of the Agreement or for so long as Runpod Processes Personal Data on behalf of Customer, whichever is longer.
Miscellaneous
In the event of any conflict between this DPA (or any other agreement between the Parties) and the Standard Contractual Clauses and/or UK Addendum: (a) the Standard Contractual Clauses shall prevail to the extent such conflict relates to the Processing of Personal Data under the EU GDPR; and (b) the UK Addendum shall prevail to the extent such conflict relates to the Processing of Personal Data under the UK GDPR. In the event of any conflict between this DPA and any other agreement between the Parties, this DPA shall prevail. If any provision of this DPA is or becomes invalid, the remaining provisions shall remain in full force and effect. Without prejudice to Clause 17 (Governing Law) and Clause 18 (Forum and Jurisdiction) of the Standard Contractual Clauses, and Section 12(c) of the UK Addendum, the Parties submit to the jurisdiction and venue stipulated in the Agreement.
Performance Data
Customer acknowledges that Runpod may collect, use, and disclose Performance Data for its own business purposes, including: (i) accounting, tax, billing, audit, and compliance; (ii) providing, improving, developing, optimizing, and maintaining the Services; (iii) investigating fraud, spam, or wrongful or unlawful use of the Services; and/or (iv) as otherwise permitted or required by applicable law.
In respect of such Processing, Runpod independently determines the purposes and means thereof and shall: (a) comply with applicable Data Protection Laws; (b) Process such data as described in Runpod's privacy notices (including at
https://www.runpod.io/legal/privacy-policy
, as updated from time to time); and (c) where possible, apply technical and organizational safeguards to any relevant Personal Data that are no less protective than the security measures set out in this DPA. For the avoidance of doubt, this DPA shall not apply to Runpod's Processing of Performance Data, and Performance Data does not constitute Customer Personal Data.
Attachment 1:
Technical and Organizational Measures (“TOMs”)
Action Description
Technical & Organizational Measures
Pseudonymization and Anonymization
Runpod employs tools to selectively anonymize certain data, which may include Personal Data.
Encryption
Encryption is used for data in transit and at rest, and this encryption is provided by Amazon Web Services Inc. (“
AWS
”) and Secure Cloud data centers, approved Sub-Processors (see
Attachment 2
). Runpod also encrypts data in transit.
Confidentiality
All Runpod Employees are required to sign a confidentiality agreement and accept company policies and procedures upon hire.
Integrity
The Services provide administrative controls for Customer to control who can access files within their firm. Runpod does not have these rights.
An access control policy and procedures are in place to review access control lists.
Runpod conducts periodic risk assessments to identify, rank, treat, and manage risks to an acceptable level.
Availability
Monitoring is performed through capacity management monitoring solutions.
Quality assurance processes are in place and under regular review, to mitigate against potential downtime.
Resilience of Processing Systems
The Services are hosted on AWS platform and Secure Cloud data centers. These hosting platforms are ISO 27001 and SOC 2 Type 2 certified for security, confidentiality, integrity, privacy and availability.
Restoration
Backup policy and procedures are in place, with daily automated backup reports to ensure restoration is achievable. Reports are monitored by an operational team.
An Information Security Incident Response Policy & Procedure is in place to address actual and potential Data Breaches.
Auditing/Testing
Regular audits and assessments take place for purposes of SOC 2 compliance. In addition, from time to time Runpod engages with a third party, for penetration testing services and vulnerability assessments.
Detection and monitoring
Runpod deploys firewalls and threat detection services to monitor, filter, and protect Runpod systems.
Security is incorporated into the software development lifecycle and change processes.
Additional security and compliance features related to the data center (DC) configuration for the Serverless (SLS) setup
For services utilizing Serverless (SLS) infrastructure, Runpod enables the configuration of deployments so that endpoints are isolated to specific data centers that meet defined compliance standards. This includes the ability to restrict deployments to data centers that are subject to specific regulatory requirements (e.g., HIPAA) or that otherwise satisfy applicable regulatory and contractual obligations. Customers are responsible for configuring their workloads to deploy to data centers that meet their compliance needs.
Runpod shall, upon request, advise the Controller on which data center options are available and appropriate based on the Controller’s compliance obligations.
Additional information
In addition to the measures mentioned above, Runpod implements and maintains robust technical and organizational measures to ensure a high level of data security and compliance. These include:
Certification under SOC 2 Type II;
End-to-end encryption of data in transit and at rest;
Strict role-based access controls, regular staff security training, and established incident response plans;
Real-time monitoring and automated workload management systems to maintain security and performance integrity.
Attachment 2:
Runpod’s Sub-Processors
Sub-Processor
Purpose of Processing
Amazon Web Services Inc.
Services and Customer Data is processed with Runpod licensed software, on Amazon Web Services Inc.’s infrastructure.
Google Workspace - Google Inc.
A collection of cloud computing, productivity and collaboration tools, software and products, to enable real-time collaboration between
Runpod teams including, document creation, collection, and storage.
Google Cloud - Google Inc.
A collection of cloud computing, productivity and collaboration tools, software and products, to enable real-time collaboration between
Runpod teams and provide advance tools for scalability, security and performance.
HubSpot Inc.
A customer relationship management (CRM) platform for Runpod and its customers, prospects, and partners used by Runpod’s Sales and Marketing team to communicate with customers.
Stripe Inc.
A cloud-based business platform for invoicing and financial account management. Data collected, stored and processed is specific to fulfilling business services in performance of contracts.
BetterStack Inc.
A log monitoring platform, technical service and Runpod application logs are sent to BetterStack for search, analysis, and system monitoring. Sensitive data fields are masked such as usernames and emails, while some low sensitivity data such as IP and Host are captured directly.
Cloudflare Inc.
A content delivery platform that improves network performance, security and reliability to customers by caching static content and optimizing web traffic
PlanetScale
A cloud-based database hosting platform that has high availability, scalability, and performance for large-scale data operations managed by Runpod’s engineering team.
Docker Inc.
A containerization service that enables scalable and efficient application delivery by managing applications in an isolated environment and streamlining development workflows.
Datadog Inc.
A SIEM platform that provides application monitoring, infrastructure monitoring, log management, and alerting to ensure system reliability and operational efficiency.
Clerk Inc.
A user authentication and authorization platform that supports processes such as sign ups, logins, customer profile management, and session management.
Tinybird
A platform that provides real-time data processing and analytics services that enables the ingestion, transformation and querying of large data streams, which allows Runpod to derive actionable insights and build APIs from real-time data.
DigitalOcean LLC.
A cloud infrastructure and hosting platform that manages virtual servers, storage, and networking resources enabling Runpod to deploy, scale, manage applications and services.
Snowflake Inc.
A cloud-based data warehouse that stores, manages, and analyses structured and semi-structured data scalably and securely.
Attachment 3:
Standard Contractual Clauses
The Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (as may be amended, superseded, or replaced), are hereby incorporated by reference into this DPA as if set out in full herein.
For the purposes of the Standard Contractual Clauses:
Module Two (Controller to Processor) shall apply;
in Clause 7, the optional docking clause shall apply;
in Clause 9(a), Option 2 (general written authorization) shall apply, and the time period for prior notice of Sub-Processor changes shall be as set out in Section 8 of this DPA;
in Clause 11(a), the optional wording shall not apply;
in Clause 13, the competent Supervisory Authority shall be the authority of the EU Member State in which Customer is established in the EEA;
in Clause 17, Option 1 shall apply and the Standard Contractual Clauses shall be governed by the law of Ireland;
in Clause 18(b), disputes shall be resolved before the courts of Ireland; and
the Appendix Information shall be completed as follows:
Annex I.A (List of Parties)
as set out in the preamble and signature block of this DPA;
Annex I.B (Description of Transfer)
as set out in Section 3 of this DPA;
Annex I.C (Competent Supervisory Authority),
the Supervisory Authority of the EU Member State in which Customer is established;
Annex II (Technical and Organizational Measures)
, as set out in Attachment 1 to this DPA; and
Annex III (List of Sub-Processors),
as set out in Attachment 2 to this DPA.
Attachment 4:
International Data Transfer Addendum to the EU Commission Standard Contractual Clauses
The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0), as issued by the ICO and in force from 21 March 2022 (as may be amended, superseded, or replaced) (the "
UK Addendum
"), is hereby incorporated by reference into this DPA as if set out in full herein. For the purposes of the UK Addendum:
Table 1 (Parties)
shall be completed as follows: the start date shall be the Effective Date; the Exporter shall be Customer and the Importer shall be Runpod, with parties' details and key contacts as set out in the preamble and signature block of this DPA;
Table 2 (Selected SCCs, Modules and Selected Clauses):
the Addendum EU SCCs shall be the Standard Contractual Clauses incorporated by reference in
Attachment 3
to this DPA, including the elections specified therein;
Table 3 (Appendix Information)
shall be completed as follows: Annex 1A (List of Parties) — as set out in the preamble and signature block of this DPA; Annex 1B (Description of Transfer) — as set out in Section 3 of this DPA; Annex II (Technical and Organisational Measures) — as set out in Attachment 1 to this DPA; and Annex III (List of Sub-Processors) — as set out in Attachment 2 to this DPA;
Table 4 (Ending this Addendum when the Approved Addendum Changes)
: the Importer may end this Addendum in accordance with Section 19 of the Approved Addendum;
The UK Addendum shall be governed by the laws of England and Wales and any dispute arising from it shall be resolved by the courts of England and Wales; and
the competent supervisory authority for the purposes of the UK Addendum shall be the ICO.
Attachment 5:
Switzerland Addendum
Modified EU SCCs
. The Parties agree that Restricted Transfers from Switzerland are made pursuant to the Standard Contractual Clauses with the following modifications:
The terms “General Data Protection Regulation” or “Regulation (EU) 2016/679” as utilized in the EU SCCs shall be interpreted to include the FADP with respect to Restricted Transfers subject to the FADP.
Clause 13 of the Standard Contractual Clauses is modified to provide that the FDPIC shall have authority over the Restricted Transfers governed by the FADP and the appropriate EEA Supervisory Authority shall have authority over Restricted Transfers governed by the EU GDPR. Subject to the foregoing, all other requirements of Section 13 shall be observed.
The term “EU Member State” as utilized in the Standard Contractual Clauses shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the Standard Contractual Clauses.
Competent supervisory authority
. Where Customer is established in Switzerland or falls within the territorial scope of application of the FADP, the FDPIC shall act as competent supervisory authority insofar as the relevant Restricted Transfer is governed by the FADP.
Attachment 6:
State Privacy Laws Addendum
In this Attachment 6, the terms “
business
,” “
business purpose
business
,” “
business purpose
” shall have the respective meanings given thereto in the CCPA; and “
personal information
” shall mean Customer Personal Data that constitutes “personal information” as defined in and that is subject to the State Privacy Laws.
” shall have the respective meanings given thereto in the CCPA; and “
personal information
” shall mean Customer Personal Data that constitutes “personal information” as defined in and that is subject to the State Privacy Laws.
The business purposes and services for which Runpod is Processing personal information are for Runpod to provide the Services to and on behalf of Customer as set forth in the Agreement, as described in more detail in Annex 1 (Data Processing Details) to the DPA.
It is the Parties’ intent that with respect to any personal information, Runpod is a service provider. Runpod (a) acknowledges that personal information is disclosed by Customer only for limited and specific purposes described in the Agreement; (b) shall comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps under and subject to Section 6 (Audits) of the DPA to help ensure that Runpod’s use of personal information is consistent with Customer’s obligations under the State Privacy Laws; (d) shall notify Customer in writing of any determination made by Runpod that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
The business purposes and services for which Runpod is Processing personal information are for Runpod to provide the Services to and on behalf of Customer as set forth in the Agreement.
It is the Parties’ intent that with respect to any personal information, Runpod is a service provider. Runpod (a) acknowledges that personal information is disclosed by Customer only for limited and specific purposes described in the Agreement; (b) shall comply with applicable obligations under the State Privacy Laws and shall provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps under and subject to Section 13 (Audits) of the DPA to help ensure that Runpod’s use of personal information is consistent with Customer’s obligations under the State Privacy Laws; (d) shall notify Customer in writing of any determination made by Runpod that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
Runpod shall not (a) sell or share any personal information; (b) retain, use or disclose any personal information for any purpose other than for the business purposes specified in the Agreement, including retaining, using, or disclosing the personal information for a commercial purpose other than the business purpose specified in the Agreement, or as otherwise permitted by State Privacy Laws; (c) retain, use or disclose the personal information outside of the direct business relationship between Runpod and Customer; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Runpod’s own interaction with any consumer to whom such personal information pertains except as and to the extent necessary as part of Runpod’s provision of the Services.
Runpod shall not (a) sell or share any personal information; (b) retain, use or disclose any personal information for any purpose other than for the business purposes specified in the Agreement, including retaining, using, or disclosing the personal information for a commercial purpose other than the business purpose specified in the Agreement, or as otherwise permitted by State Privacy Laws; (c) retain, use or disclose the personal information outside of the direct business relationship between Runpod and Customer; or (d) combine personal information received pursuant to the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Runpod’s own interaction with any consumer to whom such personal information pertains except as and to the extent necessary as part of Runpod’s provision of the Services.
Runpod shall implement reasonable security procedures and practices appropriate to the nature of the personal information received from, or on behalf of, Customer, in accordance with Section 3.2 (Security Measures) of the DPA.
When Runpod engages any Sub-Processor, Runpod shall notify Customer of such Sub-Processor engagements in accordance with Section 5 (Sub-Processing) of the DPA and that such notice shall satisfy Runpod’s obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.
Runpod agrees that Customer may conduct audits, in accordance with Section 9 of the DPA, to help ensure that Runpod’s use of personal information is consistent with Runpod’s obligations under the State Privacy Laws.
Runpod shall implement reasonable security procedures and practices appropriate to the nature of the personal information received from, or on behalf of, Customer, in accordance with Section 7 (Technical & Organizational Measures) of the DPA.
When Runpod engages any Sub-Processor, Runpod shall notify Customer of such Sub-Processor engagements in accordance with Section 8 (Sub-Processing) of the DPA and that such notice shall satisfy Runpod’s obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.
Runpod agrees that Customer may conduct audits, in accordance with Section 13 of the DPA, to help ensure that Runpod’s use of personal information is consistent with Runpod’s obligations under the State Privacy Laws.
The parties acknowledge that Runpod’s retention, use and disclosure of personal information by Customer’s instructions documented in the Agreement and DPA are integral to Runpod’s provision of the Services and the business relationship between the Parties.
The parties acknowledge that Runpod’s retention, use and disclosure of personal information by Customer’s instructions documented in the Agreement and DPA are integral to Runpod’s provision of the Services and the business relationship between the Parties.
The Parties acknowledge that Runpod’s Processing of Customer Personal Data authorized by Customer under this DPA is integral to the Services and the business relationship between the Parties.
Security Measures
Action Description
Technical & Organizational Measures
Pseudonymization and Anonymization
Runpod employs tools to selectively anonymize certain data, which may include Personal Data.
Encryption
Encryption is used for data at rest, and this encryption is provided by Amazon Web Services Inc. (“AWS”) and Secure Cloud data centers, approved Sub-Processors ([INSERT]). Runpod also encrypts data in transit.
Confidentiality
All Runpod employees are required to sign a confidentiality agreement and accept company policies and procedures upon hire.
Integrity
The Services provide administrative controls for Customer to control who can access files within their firm. Runpod does not have these rights.
An access control policy and procedures are in place to review access control lists.
Runpod conducts periodic risk assessments to identify, rank, treat, and manage risks to an acceptable level.
Availability
Monitoring is performed through capacity management monitoring solutions.
Quality assurance processes are in place and under regular review, to mitigate against potential downtime.
Resilience of Processing Systems
The Services are hosted on AWS platform and Secure Cloud data centers. These hosting platforms are ISO 27001 and SOC 2 Type 2 certified for security, confidentiality, integrity, privacy and availability.
Restoration
Backup policy and procedures are in place, with daily automated backup reports to ensure restoration is achievable. Reports are monitored by an operational team.
An Information Security Incident Response Policy & Procedure is in place to address actual and potential Data Breaches.
Auditing/Testing
Regular audits and assessments take place for purposes of SOC 2 compliance. In addition, from time to time Runpod engages with a third party, for penetration testing services and vulnerability assessments.
Detection and monitoring
Runpod deploys firewalls and threat detection services to monitor, filter, and protect Runpod systems. Security is incorporated into the software development lifecycle and change processes.
‍
Runpod may update or modify these Security Measures, on written notice to Customer, from time to time; provided that such updates and modifications do not decrease the overall security of Customer Personal Data and associated technology and information systems or assets.
Attachment 7:
Brazil Addendum
1. Scope and Applicability
This Attachment 7 applies where the transfer of Customer Personal Data is subject to the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, Law No. 13.709/2018, as amended) ("
LGPD
"). For the purposes of the LGPD and this Attachment 7, references to "
Data Protection Laws
" in the DPA shall be construed to include the LGPD to the extent applicable.
2. Brazilian Standard Contractual Clauses
For any Restricted Transfer of Customer Personal Data from Brazil to a country that does not provide an equivalent level of protection as required under the LGPD, the Processor shall ensure that such transfer is protected by implementing the Brazilian Standard Contractual Clauses ("
Brazilian SCC
") issued by the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados, "
ANPD
") pursuant to Resolution CD/ANPD No. 19/2024 (as may be amended, superseded, or replaced from time to time), which are hereby incorporated by reference into this DPA as if set out in full herein. The Brazilian SCC are available at the ANPD's official website.
3. Roles of the Parties
For the purposes of the Brazilian SCC:
the Controller (Customer) shall assume the role of
Data Exporter
, as defined in the Brazilian SCC; and
the Processor (Runpod) shall assume the role of
Data Importer
, as defined in the Brazilian SCC.
4. Elections under the Brazilian SCC
The following elections apply to the Brazilian SCC incorporated herein
Clause 3 (Onward Transfers)
: Option 3.1A shall apply.
Clause 4 (Responsibilities of the Parties)
: Option 4.1A shall apply. In accordance with Option 4.1A, the Data Exporter (Controller) shall be responsible for complying with the obligations set out in the corresponding list under the Brazilian SCC.
5. Consistency with the DPA
The terms of this Attachment 7 are supplemental to, and shall be read in conjunction with, the DPA. In the event of any conflict between this Attachment 7 and the remainder of the DPA (including any other Attachment) in respect of the Processing of Customer Personal Data subject to the LGPD, this Attachment 7 shall prevail. The Annexes and Appendix Information required under the Brazilian SCC shall be completed by reference to the corresponding information set out in this DPA, including:
the parties' details as set out in the preamble and signature block of this DPA;
the description of the transfer and Processing activities as set out in Section 3 of this DPA;
the technical and organizational measures as set out in Attachment 1 to this DPA; and
the list of Sub-Processors as set out in Attachment 2 to this DPA.
6. Governing Law and Supervisory Authority
This Attachment 7 and the Brazilian SCC incorporated herein shall be governed by Brazilian law. The competent supervisory authority for the purposes of the Brazilian SCC shall be the ANPD.
‍
Build what’s next.
Build, train, and scale AI workloads on Runpod with cloud GPUs, Serverless, and Clusters.
Get started
Request a demo
‍
Build what’s next.
Build, train, and scale AI workloads on Runpod with cloud GPUs, Serverless, and Clusters.
Get started
Request a demo