Mizan

Data Processing Addendum

Last updated: August 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies where the GDPR or other data protection law requires it. Where the DPA conflicts with the Terms, the DPA governs with respect to the processing of personal data.

Scope

You (the controller) use the Service to track AI spend and, where applicable, to route model requests. This DPA covers any personal data you submit to the Service or that we process on your behalf in providing it — for example, content contained in prompts routed through the gateway, or data we process to operate your account. Where we process personal data for our own purposes (for example, account and billing administration), we act as an independent controller and that processing is governed by the Privacy Policy, not this DPA.

Definitions

“Personal data”, “processing”, “controller”, “processor”, “data subject”, and “supervisory authority” have the meanings given in the GDPR (Regulation (EU) 2016/679) or, where it applies, the UK GDPR or other applicable data protection law. “Subprocessor” means any third party engaged by us who processes personal data covered by this DPA.

Processing instructions

We process personal data only on your documented instructions, as set out in the Terms, this DPA, and the Service's configuration. You instruct us to: (1) provide the Service to you, including routing model requests to the providers you select and reading usage data from providers you connect; (2) bill, secure, and support your account; and (3) comply with legal obligations. We will notify you if we believe an instruction infringes applicable law. We will not process personal data for any other purpose, sell it, or use it for our own profiling or advertising.

Confidentiality

We require all personnel and subprocessors who access personal data covered by this DPA to be bound by confidentiality obligations and to access it only as needed to perform the Service. We do not disclose personal data covered by this DPA except: to you; to subprocessors listed on our Subprocessors page; where you route traffic to a provider you select (BYOK); or where compelled by law with reasonable prior notice to you where permitted.

Security

We implement and maintain appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and accidental loss, destruction, or damage, as described on our Security page: TLS in transit, AES-256-GCM encryption at rest for credentials, hashed gateway keys, per-owner access control, and a data model that avoids storing prompt and completion content. We will notify you without undue delay of any personal data breach affecting personal data you process through the Service.

Subprocessors

You grant us a general authorization to engage the subprocessors listed on our Subprocessors page. We will provide at least 30 days' notice of any material addition or replacement of a subprocessor and post the change on that page. If you object on reasonable data-protection grounds within 30 days, you may terminate the affected Service, and we will cooperate in an orderly transition. Each subprocessor is bound by written terms that provide at least the same level of protection as this DPA.

Data subject rights

Where personal data is processed on your behalf, we will, to the extent permitted by law, assist you in responding to data subject requests. Where you are unable to access, correct, or delete personal data directly in the product, contact us at naim@app-mizan.com and we will provide reasonable assistance, at your cost where applicable.

Deletion & return

On termination of the Service, we will, at your election, delete or return the personal data processed on your behalf, unless applicable law requires us to retain it. Prompt and completion content routed through the gateway is not stored and therefore requires no deletion. Data governed by this DPA is deleted in accordance with our Data Retention policy.

Liability

Each party is liable for damages arising from its own failure to comply with applicable data protection law and the terms of this DPA. Our aggregate liability under the DPA is subject to the limitation of liability in the Terms of Service. The DPA's liability provisions take precedence where they conflict with the Terms.

Contact

DPA and compliance requests: naim@app-mizan.com.