# Data Processing Addendum This addendum is part of the [Terms of Service](/legal/terms) between the customer ("you") and Runtime LLC ("Runtime", "we"). It applies automatically, with no signature, whenever we process personal data for you that is covered by data protection law, including the GDPR, the UK GDPR, the Swiss FADP and United States state privacy laws. Where it conflicts with the rest of the terms about personal data, this addendum wins. ## 1. Roles For personal data inside Your Content ("Customer Personal Data"), you are the controller, or a processor for your own customers, and we are your processor. You are responsible for having a lawful basis and for your instructions to us being lawful. The [Privacy Policy](/legal/privacy), not this addendum, covers data where we are the controller, such as your account. ## 2. What we do with it We process Customer Personal Data only on your documented instructions. The terms, this addendum and your use of the Services are those instructions. We will tell you if we think an instruction breaks the law. If the law compels us to process Customer Personal Data otherwise than on your instructions, we tell you before we do, unless that law forbids it. We do not sell Customer Personal Data, do not share it for advertising, and do not use it for any purpose but providing, securing and supporting the Services and meeting our legal obligations. We do not retain, use, disclose or combine it outside our direct business relationship with you, and we will tell you if we can no longer meet these obligations. The subject matter, duration, nature and purpose of the processing, and the types of data and people concerned, are in Annex 1. ## 3. Data you must not send The Services are general-purpose compute and we do not know what you put in them. As the [Acceptable Use Policy](/legal/acceptable-use) says, you must not use them for protected health information, ever, and not for payment card numbers, government identifiers or special categories of personal data unless you encrypt the data and we have agreed in writing first. ## 4. People and security Everyone we authorize to handle Customer Personal Data is bound to keep it confidential. We maintain the security measures in Annex 2 and may improve them, but will not materially weaken them. You are responsible for using the Services securely: your keys, your code, what you expose, and your own backups. ## 5. Subprocessors You authorize us to use the subprocessors listed at [/legal/subprocessors](/legal/subprocessors). We hold each of them to data protection terms no weaker than these and remain responsible for what they do. We update that page before a new subprocessor starts handling Customer Personal Data. If you object to one on reasonable data protection grounds and we cannot resolve it, your remedy is to close your account, and we will refund purchased credit you have not spent, unless it has expired under section 6 of the terms. ## 6. Helping you Taking the nature of the Services into account, we give you reasonable help to answer requests from people exercising their rights, and with impact assessments and consultations with regulators that the law requires of you. The Services let you read, export and delete Your Content yourself. If a person sends a request about your data to us, we point them to you. ## 7. Breaches If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, disclosure of or access to Customer Personal Data, we tell you without undue delay. We tell you what we know, what we are doing about it, and update you as we learn more. Telling you is not an admission of fault. ## 8. Return and deletion You can export and delete Your Content at any time while your account is open. When the agreement ends, or a retention period under the terms runs out, we delete Customer Personal Data. Exporting it before then is how it is returned to you. We keep only copies the law requires us to keep, which stay protected by this addendum. ## 9. Audits Once a year, on written request, we give you the information reasonably needed to show that we comply with this addendum. If the law requires more, you may audit us on at least 30 days' notice, during business hours, under a confidentiality agreement, without access to other customers' data, and at your cost. ## 10. Transfers We process Customer Personal Data in the United States. Where a transfer of personal data from the European Economic Area to us is restricted by law, the European Commission's standard contractual clauses of 4 June 2021 (Decision 2021/914) are incorporated into this addendum: Module Two where you are a controller, Module Three where you are a processor. For those clauses: you are the exporter and we are the importer; Clause 7 does not apply; Clause 9 uses general written authorization with the notice period in section 5; the optional paragraph of Clause 11 does not apply; Irish law governs and the Irish courts have jurisdiction; Annexes 1 and 2 below complete the clauses' annexes; and the competent supervisory authority is the one for your place of establishment. For transfers from the United Kingdom, the Information Commissioner's International Data Transfer Addendum to those clauses applies, completed with the same information, and either party may end it under its Table 4. For transfers from Switzerland, the clauses apply with references to the GDPR read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as the authority. Where the clauses and this addendum conflict, the clauses win. ## 11. Liability Each party's liability under this addendum, including under the standard contractual clauses as between the parties, is subject to the limits in the Terms of Service. Nothing here limits what either party owes directly to an individual under data protection law. ## Annex 1: the processing - **Exporter:** the customer named on the account, contact as given on the account. - **Importer:** Runtime LLC, 1500 N Grant St Ste N, Denver, CO 80203, United States; marc@heyruntime.com. Role: processor. - **Subject matter and nature:** hosting, running, storing and transmitting Your Content to provide the Services. - **Purpose:** providing, securing and supporting the Services. - **Duration:** while your account is open, and then until deletion under the terms. - **Frequency:** continuous. - **People concerned:** whoever you decide, typically your staff, your customers and your users. - **Types of data:** whatever you decide to put in the Services, within the limits of section 3, including the output of scheduled jobs and the secrets you store, which are sealed. For resources that serve the internet, the connection records our ingress keeps: client IP address, time and request line, for a bounded period. No special categories. - **Subprocessors:** as listed at /legal/subprocessors, for the same subject matter, nature and duration. ## Annex 2: security measures - Every sandbox runs in its own Firecracker virtual machine with its own guest environment, on servers we operate. Host credentials and control interfaces are not reachable from a sandbox. - Sandboxes reach the public web only. Private and internal addresses are refused, connections are limited per sandbox, and any sandbox's network access can be cut at once. - Data is encrypted in transit, and connections to the database verify the server's certificate. - Customers are separated in the database by row-level rules tied to the organization, and each part of the system connects with its own database role, holding only the permissions that part needs. - API keys are scoped to named operations and can be revoked at any time. - Access to production systems is limited to authorized people, and actions on customer resources are recorded. - Outbound connections are attributable to one sandbox and one organization, so that abuse can be traced and stopped. - We handle security incidents under a written procedure that includes preserving evidence and notifying affected customers.