Skip to content
codaicodai
ResolveBenchmarksPricingChangelogDocs
RO
Sign inGet started

Legal · DPA

Data Processing Addendum

The terms under which Interactive Media Solutions S.R.L. (IMS SRL) processes personal data on behalf of business customers who use codai, as required by Article 28 GDPR. It forms part of the Terms of Service.

Version 1.0 · Updated September 25, 2026

This document is also available in Romanian.

Summary in plain words

  • When your organisation sends personal data through codai (in prompts, files or tool results), you are the controller and we are your processor.
  • We process that data only to provide the Service, only on your documented instructions, and only in the EU unless a listed subprocessor needs otherwise.
  • We tell you 30 days before adding or replacing a subprocessor, and you may object.
  • We notify you of a personal data breach without undue delay and in any case within 72 hours of becoming aware of it.
  • When the contract ends we delete your data within 30 days (backups included), unless the law requires us to keep it.

Contents

  1. 01 Parties and scope
  2. 02 Subject matter, duration, nature and purpose
  3. 03 Categories of data and data subjects
  4. 04 Your obligations as controller
  5. 05 Our obligations as processor
  6. 06 Subprocessors
  7. 07 Security measures
  8. 08 Personal data breaches
  9. 09 Deletion and return
  10. 10 Audits
  11. 11 International transfers
  12. 12 Term, liability and law

01Parties and scope

Processor: Interactive Media Solutions S.R.L. (IMS SRL), CUI 37237457, Reg. Com. J18/241/2017, Str. 23 August nr. 1B, Et. 1, Ap. 8, Târgu Jiu, jud. Gorj, România, e-mail [email protected], [email protected] ("we").

Controller: the customer — the organisation or professional that accepted the Terms of Service and uses the Service for its own business purposes ("you").

This Addendum applies whenever we process personal data on your behalf as part of the Service. It does not cover data we process as an independent controller (your account, billing and security records), which the Privacy Policy describes. If this Addendum and the Terms conflict on data protection, this Addendum prevails.

02Subject matter, duration, nature and purpose

  • Subject matter: personal data contained in the content you or your users submit to the Service — prompts, messages, files, tool calls and tool results, session transcripts and the model outputs generated from them.
  • Duration: for as long as you use the Service, plus the deletion period in "Deletion and return".
  • Nature: storage, transmission, routing to AI model providers, generation of outputs, synchronisation between your devices, and deletion.
  • Purpose: providing the codai gateway, console, apps and APIs to you, as described in the Terms of Service — and nothing else. We do not use your data to train models unless you opt in, and never for advertising.

03Categories of data and data subjects

  • Data categories: identification and contact data, professional data, communications content, source code and documents containing personal data, device and technical data (IP address, user agent, identifiers), and any other data you choose to include in your content.
  • Special categories (Art. 9 GDPR) and criminal-offence data: not required by the Service. Do not submit them unless you have a lawful basis and have assessed the risk; if you do, the same safeguards apply.
  • Data subjects: your employees, contractors and authorised users; your customers, prospects and correspondents; and any other individuals whose data appears in the content you submit.

04Your obligations as controller

  • You have a lawful basis for the processing and have given the required information to data subjects.
  • Your instructions comply with the law. The Terms, this Addendum and your configuration of the Service (keys, retention, session sync, BYOK) are your complete instructions; further instructions must be agreed in writing.
  • You are responsible for the content you submit and for configuring access to your account securely.

05Our obligations as processor

  • We process personal data only on your documented instructions, including for transfers, unless EU or Romanian law requires otherwise — in which case we tell you first, unless the law forbids it.
  • We tell you promptly if we believe an instruction infringes the GDPR.
  • Everyone authorised to process the data is bound by confidentiality.
  • We implement the security measures described below (Art. 32 GDPR).
  • We assist you, taking into account the nature of the processing, in answering data-subject requests (Arts. 12–23) and with security, breach notification, impact assessments and prior consultation (Arts. 32–36). Most requests can be handled self-service in the console.
  • We make available the information needed to demonstrate compliance with Art. 28 and allow audits as described below.

06Subprocessors

You give general authorisation for the subprocessors listed at codai.ro/subprocessors. We impose on each of them data-protection obligations equivalent to this Addendum and remain liable to you for their performance.

We announce any intended addition or replacement at least 30 days in advance, on the subprocessors page and by e-mail to the account owner. You may object on reasonable data-protection grounds within that period; if we cannot address the objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid, unused fees.

07Security measures

  • Hosting in the EU on Google Cloud (europe-west1, Belgium); encryption in transit (TLS 1.2+) and at rest; secrets and provider credentials managed in Cloud KMS / Secret Manager.
  • API keys stored only as hashes; sign-in through a dedicated OpenID Connect identity service with passkeys and TOTP; per-device session revocation.
  • Least-privilege access to production, limited to the controller’s authorised personnel; audit logging of administrative actions.
  • Isolation of customer data by account; spend caps and rate limits against abuse.
  • Database backups with point-in-time recovery, retained for 30 days; tested disaster-recovery procedures.
  • Responsible-disclosure programme ([email protected]) and prompt patching of dependencies.

08Personal data breaches

We notify you without undue delay, and in any case within 72 hours after becoming aware of a personal data breach affecting your data. The notice describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken or proposed. We provide further information in phases as it becomes available.

09Deletion and return

You can export your data from the console at any time. When the Service ends, or when you delete your account, we delete personal data processed on your behalf within 30 days, including from backups, unless EU or Romanian law requires us to retain it; retained data stays protected by this Addendum.

10Audits

On request we provide the information necessary to demonstrate compliance, including answers to reasonable security questionnaires. If that is not sufficient, or a supervisory authority requires it, you (or an independent auditor bound by confidentiality) may audit our compliance once per year with 30 days’ written notice, during business hours and without disrupting the Service. Each party bears its own costs unless the audit reveals a material breach by us.

11International transfers

We process your data in the EU/EEA. Where a subprocessor processes data outside the EU/EEA in a country without an adequacy decision, the transfer is covered by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914, module 3 processor-to-processor) or the subprocessor’s certification under the EU-US Data Privacy Framework, together with supplementary measures where needed.

Bring-your-own-key traffic goes directly from your apps to the provider you configured and is not processed by us.

12Term, liability and law

This Addendum applies for as long as we process personal data on your behalf. The limitation of liability in the Terms of Service applies, except where the GDPR provides otherwise. Romanian law governs this Addendum. Questions: [email protected].

↑ Back to top

codaicodai

One model name. Every frontier model.

All systems operational

Product

ResolveBenchmarksPricingChangelogDownloadWeb app

Developers

DocsAPI referenceSDKsStatusGitHub

Company

AccountSecurityContact

Legal

PrivacyTermsDPASubprocessorsImprint

© 2026 codai · Built in Romania 🇷🇴 · Cloud Run · EU data

RO
ResolveBenchmarksPricingChangelog