Legal
Data Processing Agreement
Last updated July 14, 2026
This DPA applies where Cortex processes personal data on behalf of a customer as a processor under GDPR, UK GDPR, CCPA/CPRA, or similar laws. It forms part of the agreement between Cortex and the customer.
01Roles and scope
The customer is the controller (or a processor acting for one); Cortex is a processor. Processing is limited to providing the platform per the agreement and the customer's documented instructions — including the governance configurations the customer sets in-product.
02Processing instructions
Cortex processes personal data only on documented instructions, including for transfers, unless required by law (in which case Cortex informs the customer unless prohibited). In-product configuration — policies, retention, residency, connector scopes — constitutes an instruction.
03Confidentiality & personnel
Personnel with access to customer data are bound by confidentiality and access is least-privilege, logged, and reviewed. Production access is gated and recorded in the same audit infrastructure the product exposes.
04Security measures
Encryption in transit and at rest, per-tenant logical isolation keyed on (tenantId, id), property-level access controls, DLP screening on tool calls, tamper-evident audit ledger, continuous red-teaming of the runtime, and the fail-closed governance gate chain on every run.
05Subprocessors
The customer authorizes the subprocessors in the Subprocessor Register (/legal/subprocessors). Cortex gives 30 days' notice before adding one; the customer may object on reasonable data-protection grounds. Subprocessors are bound by terms no less protective than this DPA.
06No training
Neither Cortex nor its model subprocessors use customer personal data to train or improve models. Model calls are inference-only.
07Data subject requests & assistance
Cortex routes data-subject requests it receives to the customer and provides reasonable assistance — including the audit and provenance tooling — for DSARs, DPIAs, and consultations with authorities.
08Transfers
Where personal data leaves the EEA/UK, transfers rely on adequacy decisions or Standard Contractual Clauses. VPC and air-gapped deployments keep data inside the customer's chosen boundary.
09Breach notification, deletion, audit
Cortex notifies the customer without undue delay after becoming aware of a personal-data breach. On termination, data is deleted or returned per the agreement (default: 30-day export window). Customers may audit compliance via our documentation, third-party reports, and — for Business plans — the security-review concierge.
Questions about this document: legal@cortexaios.com · See also the Trust Center