Legal
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service and applies whenever Laya Studio processes personal data on your behalf.
Last updated ·
1. Parties, scope and precedence
This DPA is between you, the customer (“Customer”), and Laya Studio (“Laya Studio”). It applies to personal data contained in content the Customer (or its end users) sends to the Service (“Customer Personal Data”), which Laya Studio processes as processor (Auftragsbearbeiter under the Swiss nFADP) for the Customer as controller. It is concluded when the Customer accepts the Terms; a countersigned copy is available on request from privacy@laya.studio. If this DPA conflicts with the Terms, this DPA prevails for data protection matters; if the Standard Contractual Clauses apply, they prevail over both.
Account, billing and usage-metadata data, for which Laya Studio is controller, is governed by the Privacy Policy, not this DPA.
2. Details of the processing
- Subject matter and nature: hosted inference: receiving request content, running the Laya model (and, for the chat agent, a language model that plans questions), and returning answers.
- Purpose: providing the Service to the Customer under the Terms.
- Duration: for each request, only as long as needed to return the answer; the DPA lasts as long as the Terms.
- Categories of data subjects: determined by the Customer; typically the Customer’s end users, customers, employees, patients or other persons mentioned in the text sent.
- Categories of personal data: determined by the Customer; any personal data contained in text and questions, which may include special categories (such as health data) if the Customer chooses to send them.
- Retention: request content is not stored. Request metadata (which contains no content) is kept 30 days.
3. Customer instructions and responsibilities
Laya Studio processes Customer Personal Data only on the Customer’s documented instructions, which are these Terms and DPA and the Customer’s API calls and settings (including Swiss-only mode), unless Union, Member State or Swiss law requires otherwise; in that case Laya Studio informs the Customer first unless the law prohibits it. Laya Studio informs the Customer if it believes an instruction infringes data protection law. The Customer is responsible for the lawfulness of the data it sends, for having a legal basis, and for informing data subjects.
4. Confidentiality and security
Laya Studio ensures that anyone authorised to process Customer Personal Data is bound by confidentiality, and implements appropriate technical and organisational measures under Art. 32 GDPR and Art. 8 nFADP, in particular:
- No persistence of request content: processed in memory only, never written to a database, log or training set.
- TLS encryption on every connection; GPU servers not reachable from the public internet and accepting requests only from the gateway, authenticated with a shared secret.
- API keys stored only as SHA-256 hashes; tenant isolation derived from the key; database row-level security; privileged operations server-side only.
- Least-privilege access to production systems, with secrets held in the hosting provider’s secret store.
- Residency controls: Swiss-only mode restricts processing of request content to Switzerland and fails closed.
Laya Studio may update these measures provided the overall level of protection is not reduced.
5. Assistance
Taking into account the nature of the processing, Laya Studio assists the Customer with responding to data subject requests, with security, breach notification, data protection impact assessments and prior consultations (Art. 32–36 GDPR; Art. 22–24 nFADP). Because request content is not stored, Laya Studio will generally hold no Customer Personal Data to which such a request could apply.
6. Subprocessors
The Customer gives general authorisation for Laya Studio to engage the subprocessors listed on the Subprocessors page. Laya Studio will notify the Customer by email and on that page at least 30 days before adding or replacing a subprocessor that receives Customer Personal Data. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a refund of unused prepaid credits. Laya Studio imposes data protection obligations on each subprocessor equivalent in substance to this DPA and remains responsible to the Customer for its subprocessors’ performance.
7. International transfers
Customer Personal Data may be processed in Switzerland, the EU/EEA and, as described on the Subprocessors page, the United States (for the chat agent outside Swiss-only mode) and in transit on Cloudflare’s global network. Where Customer Personal Data is transferred to a country without an adequacy decision recognised under the GDPR or the nFADP, the transfer is based on the recipient’s certification under the EU-U.S. or Swiss-U.S. Data Privacy Framework or on the European Commission’s Standard Contractual Clauses (Module 2 or 3 as applicable), with the adaptations required by the FDPIC for transfers subject to Swiss law, which are incorporated by reference where required. The Customer can avoid such transfers of request content for processing by enabling Swiss-only mode.
8. Personal data breaches
Laya Studio notifies the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to help the Customer meet its own notification duties, and takes reasonable steps to contain it.
9. Deletion and return
Request content is deleted from memory as soon as each answer is returned, so nothing remains to be returned or deleted at the end of the Service. Any Customer Personal Data that nonetheless exists is deleted on termination unless law requires storage.
10. Information and audits
Laya Studio makes available the information reasonably necessary to demonstrate compliance with this DPA and Art. 28 GDPR, primarily through written answers and documentation. Where that is insufficient, the Customer (or an auditor bound by confidentiality) may audit once per year on at least 30 days’ written notice, during business hours, at the Customer’s cost and without access to other customers’ data or to subprocessors’ facilities beyond their own audit reports. Laya Studio holds no formal certification (such as ISO 27001) today.
11. Liability and term
Liability under this DPA is subject to the limitations in the Terms, except where the law or the Standard Contractual Clauses do not allow it. This DPA ends when the Terms end; obligations about deletion and confidentiality survive. Swiss law and the jurisdiction in the Terms apply, except where the Standard Contractual Clauses require otherwise.