Version 1.0 — August 11, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Human Frontier Labs Inc. (“Sontara,” “we”) and the customer identified in the applicable subscription (“Customer”) governing Customer’s use of the Sontara service (the “Agreement”). It applies whenever we process Customer Data on Customer’s behalf.
We process Customer Data onlyto provide, maintain, secure, and support the Service, at Customer’s documented instructions (the Agreement, this DPA, and Customer’s configuration of the Service are those instructions).
We do not: sell Customer Data; share it for advertising; use it to train AI or machine-learning models; or combine it with other customers’ data. Our AI infrastructure provider (Google Cloud Vertex AI) is contractually prohibited from using Customer Data to train its models under Google Cloud’s enterprise terms.
If a law requires us to process Customer Data otherwise, we will tell Customer before we do, unless the law forbids that notice.
If Customer uses the Service to process data belonging to its own clients, Customer represents that it has the rights and notices needed to submit that data, and Sontara acts as Customer’s subprocessor. The commitments in this DPA are designed to flow down: Customer may share this DPA and the Security Annex with its clients to document Sontara’s role.
Everyone we authorize to process Customer Data is bound by confidentiality obligations. Human access to Customer Data is restricted to what is necessary for security, support Customer requests, or legal compliance — our systems are built so that operating the Service does not require humans to read Customer content.
We maintain the technical and organizational measures described in the Security Annex below. The headline, because it is architectural rather than aspirational: every customer agent runs in its own isolated runtime with its own dedicated storage and its own service identity. We will not materially weaken the Annex during a subscription term.
Customer authorizes the subprocessors listed in the Subprocessor Annex. We bind each to data-protection obligations no less protective than this DPA. We will give notice (email or in-product) at least 15 days before adding a subprocessor that will touch Customer Data; if Customer reasonably objects on data-protection grounds and we cannot resolve it, Customer may terminate the affected subscription and receive a prorated refund of prepaid fees — our only obligation for such an objection.
Taking into account the nature of the Service, we will reasonably assist Customer with: (a) responding to data-subject/consumer requests (access, correction, deletion, portability) concerning Customer Data — much of this Customer can do directly in-product; (b) security-incident notifications; and (c) reasonable information requests needed for Customer’s privacy assessments (see Section 9).
If we confirm a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data, we will notify Customer without undue delay and no later than 72 hours after confirmation, with what we know: nature of the incident, data categories affected, measures taken. We will keep Customer informed as remediation proceeds. Our notice is not an admission of fault.
Once per year on request, we will provide: this DPA’s current annexes, a written summary of our security measures, and written responses to a reasonable security questionnaire. This documentation route is the audit mechanism under this DPA. (We are a small company with a genuinely isolated architecture; we put our effort into the isolation, and we document it honestly. We do not offer on-site audits at this tier.)
Customer can export Customer Data during the term. Upon account deletion or termination, we delete Customer Data — including agent memory, files, and the dedicated storage bucket — with deletion beginning immediately and completing within 30 days, except records we must retain for legal, tax, or fraud-prevention purposes (which stay protected under this DPA until deleted). Details: sontara.ai/data-deletion.
The Service is operated from the United States; Customer Data is processed in the United States on Google Cloud infrastructure. Customer instructs this processing location.
This DPA is part of the Agreement. Liability under this DPA is subject to the Agreement’s limitations of liability (they apply once, across the Agreement and this DPA together). If this DPA conflicts with the Agreement on data protection, this DPA controls. This DPA terminates with the Agreement, surviving as long as we hold Customer Data.
Architecture (the important part):
Organizational: confidentiality obligations for all personnel; security-incident response with the 72-hour customer notice above; subprocessors bound in writing; no advertising or analytics SDKs in mobile apps; privacy-preserving, cookieless web analytics.
| Subprocessor | Role | Location |
|---|---|---|
| Google Cloud (Cloud Run, GCS, Vertex AI, Secret Manager) | Infrastructure, storage, AI inference | US |
| Clerk | Authentication & identity | US |
| Stripe | Payments (and partner payouts/KYC) | US |
| Neon | Database (Postgres) | US (AWS us-east-2) |
| Vercel | Web hosting; cookieless analytics | US |
| Resend | Transactional email | US |
| RevenueCat | Mobile app-store billing (not used for Teams/org subscriptions) | US |
| ImprovMX | Inbound email forwarding for sontara.ai mailboxes | EU/US |
Current list also available on request via privacy@sontara.ai.
Download the signable PDF and countersign, or email legal@sontara.ai.