Legal
Data processing addendum
For customer personal data, the customer acts as controller and Halvr acts as processor, except where Halvr processes account or billing data for its own legitimate business obligations.
Effective July 14, 2026
Scope and roles
This addendum forms part of the Halvr terms or applicable order when Halvr processes personal data on the customer's behalf. The customer is the controller or business; Halvr is the processor or service provider. Each party remains responsible for the legal duties that apply to its role.
Processing instructions
Halvr will process customer personal data only to provide, secure, support, and improve the contracted service; comply with documented customer settings and instructions; or meet law. Halvr will notify the customer if an instruction appears unlawful unless prohibited from doing so.
- Subject matter: account administration and proxying, metering, controlling, storing, and reporting model traffic.
- Data subjects: the customer's users, personnel, end users, and other people represented in submitted content or metadata.
- Data types: identifiers, account data, request metadata, optional prompt and response content, usage, cost, and security records.
- Duration: the subscription term plus the deletion and backup-retention periods described in the privacy notice or order.
Confidentiality and security
Halvr limits personal-data access to people and service providers who need it for their work and who are bound by confidentiality duties. Halvr maintains technical and organizational measures appropriate to the service, including access control, encrypted transport, encrypted provider credentials, tenant authorization, logging, backups, retention controls, and vulnerability management.
Subprocessors
The customer authorizes Halvr to use subprocessors for infrastructure, databases, analytics storage, object storage, communications, and payments. Halvr will impose data-protection obligations appropriate to the service supplied by each subprocessor and remains responsible for its processing obligations under this addendum.
A customer with a contractual notification requirement may request the current subprocessor list at privacy@halvr.io and object to a new subprocessor on reasonable data-protection grounds.
Security incidents
Halvr will notify the customer without undue delay after confirming a breach of customer personal data and will provide information reasonably available to support the customer's legal assessment and notices. Notification does not admit fault or liability. The customer is responsible for maintaining current security contacts.
Assistance, deletion, and audits
Taking into account the nature of the service, Halvr will provide reasonable assistance with data-subject requests, security assessments, impact assessments, and regulator inquiries. On termination or documented request, Halvr will delete or return customer personal data unless law requires retention. Halvr may satisfy audit requests with current security documentation, written responses, or an independent report before agreeing to an on-site review.
International transfers
Where a restricted transfer requires additional safeguards, the parties will use the applicable standard contractual clauses or another valid transfer mechanism. The customer authorizes transfers needed to use approved subprocessors and selected model providers, subject to those safeguards.
Order of precedence
If this addendum conflicts with the Halvr terms on the processing of customer personal data, this addendum controls. A signed order or negotiated data-processing agreement controls over this online version for the same subject matter.