Data Processing Addendum
Last updated: 2026-09-15
This Data Processing Addendum ("DPA") is between the customer that accepts the Agreement ("Customer") and Robot Networks Inc. ("Robot Networks"). It supplements and forms part of the Terms of Service, an order form, or another written agreement governing Customer's use of Boardwalk (the "Agreement"). It applies when Robot Networks processes Customer Personal Data on Customer's behalf and applicable Data Protection Law requires processor terms. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls.
Customer enters this DPA for itself and its Authorized Affiliates. It is effective when Customer accepts the Agreement or first uses the Service to process Customer Personal Data, whichever is later. No separate signature is required, but either party may request a countersigned copy.
1. Definitions
- "Authorized Affiliate" means a Customer affiliate permitted to use the Service under the Agreement.
- "Customer Personal Data"means Personal Data in Customer Content that Robot Networks processes on Customer's behalf through the Service.
- "Data Protection Law"means privacy and data-protection law applicable to a party's processing under this DPA, including the EU GDPR, UK GDPR, Swiss FADP, the California Consumer Privacy Act as amended, and other applicable comprehensive U.S. state privacy laws.
- "EU SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
- "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- "Personal Data", "Controller", "Processor", "Data Subject", "Process", "Subprocessor", and "Personal Data Breach" have the meanings given by applicable Data Protection Law.
- "Service" means Boardwalk and related services covered by the Agreement.
2. Roles and instructions
Customer is a Controller or Processor, as applicable, and Robot Networks is its Processor or Subprocessor for Customer Personal Data. Robot Networks will process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, Customer's API requests, model deployments, account configuration, and other use of the Service, unless law requires otherwise. If legally permitted, we will notify Customer before processing required by law. We will inform Customer if we believe an instruction violates Data Protection Law.
Robot Networks is an independent Controller for account, billing, security, service analytics, and business-operations information that it determines how and why to process. That processing is described in our Privacy Policy and is not Customer Personal Data under this DPA.
3. Customer responsibilities
Customer is responsible for the lawfulness of Customer Personal Data and its instructions. Customer will provide required notices, obtain required rights and consents, respond to Data Subjects, and configure and use the Service consistently with Data Protection Law. Customer will not submit protected health information subject to HIPAA, payment-card account data, government identification numbers, biometric identifiers, children's data, or other specially regulated data unless a written agreement with Robot Networks expressly supports it and Customer has implemented all legally required safeguards.
4. Confidentiality
Robot Networks limits access to Customer Personal Data to personnel who need it to perform the Agreement. Authorized personnel are bound by confidentiality obligations and receive appropriate privacy and security guidance.
5. Security
Robot Networks will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Annex II describes the current measures. We may update them without materially decreasing the overall level of protection during the Agreement.
6. Subprocessors
Customer gives Robot Networks general written authorization to engage Subprocessors. We will impose data-protection obligations appropriate to the processing on each Subprocessor and remain responsible for its performance to the extent required by Data Protection Law. The current list is in Annex III through our Subprocessor List.
We will give at least 30 days' notice before a new or replacement Subprocessor begins processing Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. We will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate the affected Service, and we will refund prepaid fees allocable to the unused terminated portion. Customer-directed third-party services, including Hugging Face, are not Subprocessors when Customer independently directs the interaction under its own account or arrangement.
7. International transfers
Customer Personal Data is processed primarily in the United States. For a transfer from the European Economic Area to Robot Networks in a country without an adequacy decision, the EU SCCs are incorporated into this DPA and apply as follows:
- Module 2 applies when Customer is a Controller; Module 3 when it is a Processor.
- The optional docking clause in Clause 7 applies.
- Clause 9(a), Option 2 applies with general authorization and the 30-day notice period in Section 6.
- The optional independent dispute-resolution wording in Clause 11(a) does not apply.
- Under Clause 17, Option 1 applies and the governing law is Ireland.
- Under Clause 18(b), disputes are resolved by the courts of Ireland.
- The information in Annexes I, II, and III below completes the SCC appendices.
The UK Addendum is incorporated for restricted transfers from the United Kingdom, with the following selections: Table 1 uses the parties, contacts, roles, and acceptance date in the Agreement and Annex I; Table 2 uses the EU SCC modules and selections in this Section; Table 3 uses Annexes I–III; in Table 4, both the exporter and importer may end the Addendum in accordance with Section 19. The mandatory clauses in Part 2 apply. For transfers from Switzerland, the EU SCCs apply with references to the GDPR and EU law interpreted to include the Swiss FADP and with Data Subjects able to enforce their rights in Switzerland. If a valid successor transfer mechanism becomes available, we may rely on it as permitted by law.
8. Data Subject requests
Taking into account the nature of processing, Robot Networks will provide reasonable assistance through available product controls and other appropriate measures so Customer can respond to requests to access, correct, delete, restrict, object to, or export Customer Personal Data. If we receive a request relating to Customer Personal Data directly from a Data Subject, we will forward it to Customer unless prohibited by law and will not respond substantively except on Customer's instructions or as required by law.
9. Personal Data Breaches
Robot Networks will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. To the extent available, notice will describe the nature of the breach, likely consequences, affected categories and approximate numbers, and measures taken or proposed. We will provide reasonable updates and assistance so Customer can meet its notification obligations. Notice is not an admission of fault or liability.
10. Assessments and regulatory assistance
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with Customer's data-protection impact assessments, prior consultations, security-of-processing duties, and regulator inquiries relating to Customer Personal Data.
11. Demonstrating compliance and audits
We will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. No more than once per year, except after a Personal Data Breach, where there are indications of non-compliance, or when a regulator or applicable law requires otherwise, Customer may request an audit by itself or an independent auditor appointed by Customer. Audits require reasonable advance notice, confidentiality, normal business hours, protection of other customers' data, and minimal disruption. Customer bears its audit costs. We may satisfy a request with current third-party reports, certifications, or questionnaires where sufficient for the request, without limiting audit and inspection rights under applicable law or the EU SCCs.
12. Return and deletion
During the Agreement, Customer can retrieve data through available Service interfaces. At termination, we will delete or return Customer Personal Data at Customer's choice, including existing copies, unless applicable law requires retention. For data subject to the EU SCCs, any retained data remains protected under those clauses and is processed only for the purpose and duration required by that law. We will certify deletion on request. If Customer makes no timely return request, Customer instructs us to delete. Deletion from active systems and rolling backups follows our Data Retention Policy. Metering, receipt, and financial records processed in our independent-controller role may remain where necessary and lawful under the Privacy Policy. Describing a record as operational or financial does not change our role for Customer Personal Data or override the SCC deletion duties.
13. U.S. state privacy terms
Where applicable U.S. state privacy law treats Robot Networks as a service provider, contractor, or processor, we will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship or for a purpose other than the Agreement; or combine it with personal information obtained from another source, except as permitted by applicable law to provide and secure the Service. We certify that we understand and will comply with these restrictions. Customer may take reasonable steps to verify our compliance and require us to stop and remediate unauthorized use. We will notify Customer if we determine that we can no longer meet our obligations under applicable U.S. state privacy law and provide the level of privacy protection that law requires.
14. Liability
Each party's liability arising from this DPA is subject to the Agreement's exclusions and limits, except where Data Protection Law prohibits that limitation. The EU SCCs control to the extent their liability terms conflict with the Agreement or this DPA.
15. Duration and precedence
This DPA remains effective while Robot Networks processes Customer Personal Data. Provisions that must survive to protect the data continue after termination. For restricted transfers, the UK Addendum controls where it applies; otherwise the order of precedence is the EU SCCs, this DPA, and then the Agreement.
16. Signed copies and contact
To request a signed copy or ask a data-protection question, email legal@boardwalk.cloudwith your organization name and the email address on your Boardwalk account.
Annex I. Details of processing
A. Parties
Data exporter: Customer and its Authorized Affiliates, acting as Controller or Processor. Contact details are the account and agreement contacts supplied to Robot Networks.
Data importer: Robot Networks Inc., a Delaware corporation, acting as Processor. Contact: Legal and Privacy, legal@boardwalk.cloud, c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
B. Description
- Data Subjects:Customer's users, personnel, customers, end users, and other people whose Personal Data Customer submits in prompts, generated outputs, model artifacts, support requests, or related use of the Service.
- Personal Data: text and other information in prompts and generated outputs; identifiers and other information contained in model artifacts; request and model identifiers; token counts; timing, status, and technical metadata; and support or operational information Customer provides.
- Sensitive data: none authorized under the ordinary Service. Specially regulated data requires the separate written agreement and safeguards in Section 3.
- Nature and purpose:receiving, routing, and serving inference requests; generating and returning output; discovering, validating, storing, ingesting, qualifying, and serving Customer-directed model artifacts; security; support; and related operations on Customer's instructions.
- Frequency:intermittent or continuous, according to Customer's use.
- Duration: the Agreement plus the deletion and backup periods in the Data Retention Policy and any lawful hold.
C. Supervisory authority
The competent authority is determined under Clause 13 of the EU SCCs. For UK transfers it is the UK Information Commissioner's Office, and for Swiss transfers the Swiss Federal Data Protection and Information Commissioner.
Annex II. Technical and organizational measures
- Data minimization. Boardwalk does not create prompt or completion histories in its metering or receipt database or send this content to analytics. GPU providers process request content and may buffer requests and results as described in the Data Retention Policy.
- Encryption. Encrypted transport for Service traffic and provider-managed encryption at rest for primary databases, object stores, secret stores, and backups.
- Credentials. API keys are stored as one-way hashes. Payment-card details go directly to Stripe. Hugging Face OAuth tokens are held in AWS Secrets Manager and are not placed on serving endpoints.
- Access control. Role-based organization authorization, separate authentication paths for inference, console, and administration, least-privilege cloud permissions, multi-factor protection for production administration, and access logging.
- Tenant and workload isolation.Organization-scoped data access and containerized GPU workers operated through RunPod's multi-tenant service.
- Logging and monitoring. Structured, access-controlled logs; credential redaction; service-health monitoring; alarms; audit events; and bounded retention.
- Resilience. Managed backups or point-in-time recovery for primary data, health checks, documented operational runbooks, and independently hosted status reporting.
- Development practices. Code review through version control, automated formatting, linting, type checking, tests, dependency review, and controlled CI-based deployment.
- Incident response and deletion. Incident investigation and notification procedures, account and organization lifecycle controls, artifact reaping, and rolling expiration of logs and backups.
- Vendor management. Contractual data-protection requirements and review of providers that process Customer Personal Data.
Annex III. Subprocessors
The current Subprocessor Listis incorporated into this Annex III. It identifies each provider's purpose, processing location, and data categories. To receive change notices, email legal@boardwalk.cloud with the subject "Subprocessor notifications".