Legal
Data processing agreement
Draft outline of the agreement under which request content is processed on the customer's behalf.
This is a draft outline. The final text is pending counsel review and will be published before the API opens.
The final agreement will cover the headings below. Where we already know a commitment, it is listed.
Roles
- For the content of API requests (state, questions, labels and answers), the customer is the controller and Thinqit B.V. is the processor.
- For account and billing data, Thinqit B.V. is the controller. See the privacy policy.
Subject and purpose
- Processing request content only to answer the customer's API requests, and to keep opt-in content logs when the customer turns them on.
Location
- All processing takes place in the EU: Azure West Europe for the platform, Dex's own inference nodes on dedicated hardware operated by thinQit in the Netherlands, and Azure OpenAI in the EU data zone for the fallback path. See Data handling and residency.
Retention and deletion
- By default, request content exists only in memory while a request runs and is never written to disk, logs or error reports.
- Opt-in content logs are encrypted, kept for 1 to 30 days as the customer chooses, and deleted within 1 hour when logging is turned off.
- Request metadata without content is kept for 30 days.
No training
- Customer content is never used to train, tune or calibrate any model.
Azure OpenAI abuse monitoring exception
- On the fallback path, Azure OpenAI abuse monitoring may by default store prompts its classifiers flag for up to 30 days, inside the EU data zone.
- We apply to Microsoft for modified abuse monitoring before launch. Until it is approved, this exception applies.
- Customers can avoid it by sending
"fallback": "never"or by pinning an exact model version.
Subprocessors
- The current list is on the subprocessors page.
- How we tell customers about a new subprocessor, and how customers can object.
Security measures
- The measures summarized in Data handling and residency, in full.
Personal data breaches
- How and when we notify customers.
Assistance and audits
- How we help customers answer data subject requests, and how customers can verify compliance.
Provider: Thinqit B.V., Vanadiumweg 25, 3812PX Amersfoort, the Netherlands. KvK 99883813. Tax ID 869172335. hello@thinqit.io, legal@thinqit.io.