funkshin
GDPR

Data Processing Agreement

Last updated: August 17, 2026

This Data Processing Agreement applies when Funkshin processes personal data for a business customer. It should be reviewed and completed with the parties' legal names, addresses, and transfer arrangements before signature.

1. Roles and scope

The customer is the controller and Funkshin is the processor for personal data submitted to a customer workspace or processed through a customer-configured workflow. Funkshin processes that data only on the customer's documented instructions, including instructions given through the service configuration, these terms, and this Agreement. Funkshin remains an independent controller for its own account, billing, security, and legal-compliance processing.

2. Processing details

The subject matter is the provision of AI automation, agent orchestration, hosting, storage, integrations, logging, support, usage accounting, and related services. The duration is the customer subscription term plus the deletion period described below. Data categories may include account identifiers, contact details, prompts, files, knowledge-base data, workflow data, credentials, logs, usage data, and AI inputs and outputs. Data subjects may include the customer's users, employees, customers, suppliers, and other people described in the customer's content.

3. Customer obligations

The customer will provide lawful instructions, establish a legal basis, give required notices, honor data-subject rights, and avoid sending special-category data, children's data, or regulated data unless the customer has implemented appropriate safeguards and Funkshin has agreed in writing. The customer will configure access controls, provider routes, retention, and human review appropriate to its risk.

4. Funkshin obligations

Funkshin will keep personal data confidential, process it only for the services and documented instructions, maintain reasonable technical and organizational measures, and ensure that personnel authorized to process it are bound by confidentiality. Funkshin will assist with reasonable requests concerning data-subject rights, security, breach notification, impact assessments, and regulator consultations, taking into account the nature of the processing.

5. Subprocessors and AI providers

The customer authorizes the subprocessors listed in the Subprocessor List, including Netcup and, where selected, OpenRouter, direct model providers, and customer-connected infrastructure. Funkshin will maintain the list and provide notice of intended material changes where required. The customer may object on reasonable data-protection grounds within the stated notice period. If the parties cannot resolve an objection, Funkshin may offer a commercially reasonable alternative or either party may terminate the affected service.

OpenRouter and direct model providers may receive prompts, files, instructions, metadata, and outputs. The customer is responsible for selecting a compliant route. A customer-owned inference server is not a Funkshin subprocessor; the customer is responsible for that server and its provider agreements.

6. Security incidents

Funkshin will notify the customer without undue delay after becoming aware of a personal-data breach affecting the customer's data, and will provide reasonably available information about the nature, scope, likely consequences, and response measures. The customer remains responsible for notifying its supervisory authority and affected data subjects where required.

7. International transfers

Funkshin will use a lawful transfer mechanism for restricted transfers, such as an adequacy decision, Standard Contractual Clauses, or another approved safeguard. The customer acknowledges that provider routing can change based on its selected model and must review the applicable provider and location before processing personal data.

8. Return and deletion

At the customer's request or termination, Funkshin will make customer data available for export through available functionality and delete or return it, unless retention is required by law. Backups and security records may persist for a limited period and remain protected until deletion in the normal cycle.

9. Audit and precedence

Funkshin will make available information reasonably necessary to demonstrate compliance and will support reasonable audits, subject to confidentiality, security, and cost controls. If this Agreement conflicts with the Privacy Policy or Terms for customer workspace processing, this Agreement controls.

10. Contact

Data-protection requests and subprocessors objections can be sent to legal@funkshin.com.