LLM Hangar / Data processing agreement
Data processing agreement
This page is a plain-language summary of the processing facts the agreement records. It is not the agreement itself. The signed agreement governs.
We work from the Common Paper standard data processing agreement, with the cover page filled in with the facts below. If your procurement process needs a signed copy, email us and we will send one.
The parties
The service is operated by Strix Technology (Pty) Ltd, 581 Opstal Street, Pretoria, 0184, South Africa. For your account data we act as the controller; for data you ask us to process on your behalf, such as deployment metadata you enter, we act as your processor.
What is processed
- Account data: the email address and organization details you give us.
- Deployment metadata: which model, shape, region, budget cap and timer you chose, and the state of each deployment.
- The audit log: every action we took in your cloud account, timestamped, including the pre-flight plan and the teardown sweep.
What is not processed
- Prompts and responses. They travel between your client and the instance in your own cloud account and never pass through our systems.
- Model weights and files on your instances. They live on your infrastructure.
- Your cloud provider's invoice. They bill you directly.
Where
Platform data is hosted in Germany. Deployment infrastructure is created in the regions you choose; the EU-only option pins it to EU member-state regions. See the EU hosting comparison.
Sub-processors
None for prompt and response content. For account and platform data, the dated list is at /sub-processors. Changes are announced by email to account holders.
Retention and deletion
- Deployment history, including the audit log, is kept after teardown for the period your plan includes: 30 days on the Lab plan.
- Deleting a deployment tears everything down in your account, and the teardown is verified against your provider before it is reported destroyed.
- You can delete any deployment, or your whole organization, at any time on any plan.
International transfers
Strix Technology operates from South Africa, so our staff access EU-hosted data from there under appropriate contractual safeguards. South Africa's POPIA provides data protection comparable in structure to the GDPR. The privacy policy describes this in full.
Security measures
Access scoping per provider, credential storage, endpoint keys, the audit log and verified teardown are described at /security.