Data Processing Agreement (DPA)

Processor: ELVARON LIMITED, Registration No. 79402144, 14/F, China Building, 29 Queen's Road Central, Central, Hong Kong (“Processor”, “ModelStation”). Controller: the organization or other person that has entered into an agreement with the Processor for the use of ModelStation (“Customer”). Contact: support@modelstation.org

Version: 2.0


Manner of conclusion

This DPA applies to the processing of personal data carried out by the Processor on the Customer’s instructions in the provision of ModelStation, and constitutes an integral part of the Terms of Use.

The DPA is deemed concluded: (a) from the moment the Customer begins to use the Service to process personal data for commercial purposes; or (b) from the moment the parties sign a separate counterpart of the DPA. A signed counterpart, as well as annexes on technical measures and, where necessary, standard contractual clauses, are provided upon request to support@modelstation.org.

In the event of a conflict between the DPA and the Terms of Use on matters of personal-data processing, the DPA prevails. In the event of a conflict between the DPA and the standard contractual clauses (SCC), the SCC prevail to the extent required by applicable law.


1. Definitions

“Data Protection Legislation” — the rules applicable to the processing, including the PDPO (Cap. 486) of Hong Kong, the GDPR (Regulation (EU) 2016/679), the UK GDPR and the Data Protection Act 2018, Swiss data-protection legislation, the CCPA/CPRA, and other applicable rules.

“Customer Data” — personal data that the Processor processes on behalf of the Customer in the provision of the Service.

“Data Subject” — a natural person to whom Customer Data relate.

“Security Incident” — a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data.

“Sub-processor” — a third party engaged by the Processor to process Customer Data.

“SCC” — the standard contractual clauses approved by European Commission Decision 2021/914, and for the United Kingdom — the International Data Transfer Addendum to the SCC issued by the ICO.

Other terms are used in the meanings defined in the Terms of Use and the Data Protection Legislation.


2. Roles of the parties

2.1. In respect of Customer Data processed for the provision of the Service, the Customer acts as controller (data user in the terminology of the PDPO), and the Processor acts as processor (data processor).

2.2. In respect of data that the Processor processes for its own purposes — account maintenance, authentication, billing and accounting, ensuring security and preventing abuse, compliance with sanctions requirements, compliance with legal requirements, protection of legal position — the Processor acts as an independent controller. Such processing is governed by the Privacy Policy, and not by this DPA.

2.3. Each party independently is responsible for compliance with the Data Protection Legislation in respect of its role.

2.4. The parties are not joint controllers unless this is expressly agreed in writing.


3. Customer obligations and representations

3.1. The Customer represents and warrants that:

  1. it has a lawful basis for transmitting Customer Data to the Service and for their processing by the Processor and Sub-processors, including transfer outside the Customer’s country;
  2. it has provided Data Subjects with the required information and, where necessary, has obtained valid consent, including for the use of third-party AI Providers and cross-border transfer;
  3. it complies with the principle of minimization and does not transmit data not required for its task;
  4. it does not transmit to the Service special categories of data (health data, biometric data, genetic data, data concerning criminal convictions, children’s data, payment details, government identifiers), unless the parties have expressly agreed additional measures in writing;
  5. its instructions do not violate the Data Protection Legislation;
  6. it does not use the Service for use cases prohibited by §7 of the Acceptable Use Policy.

3.2. The Customer is responsible for configuring features that affect processing: history and memory retention, the composition of invited users, administrator rights, the volume of uploaded files, the selection of an AI Provider, and the acceptability of its jurisdiction.

3.3. The Customer acknowledges that the Processor has no practical ability to detect in advance, within the contents of requests, impermissible categories of data, and assumes the associated risk.


4. Processing on instructions

4.1. The Processor processes Customer Data only on the Customer’s documented instructions. Documented instructions are deemed to be: the Terms of Use, this DPA, account settings, the actions of the Customer’s users in the interface, and requests sent through support.

4.2. The Processor does not use Customer Data for its own purposes, except in the cases specified in §2.2, and does not use them to train models.

4.3. If the Processor is obliged to process data by reason of a requirement of applicable law, it informs the Customer, if such information is not prohibited by law.

4.4. If the Processor considers that a Customer instruction violates the Data Protection Legislation, it notifies the Customer and may suspend performance of the corresponding instruction until it is clarified.

4.5. The Processor is not responsible for the lawfulness of the processing purposes determined by the Customer, for the existence of a legal basis, or for the content of data sent to the Service.


5. Personnel confidentiality

Access to Customer Data is granted only to those employees and contractors of the Processor for whom it is necessary to perform their duties; such persons are bound by confidentiality obligations that survive termination of cooperation, and have been informed of the processing requirements.


6. Security

6.1. The Processor applies technical and organizational measures appropriate to the risk, taking into account the state of the art and the nature of the processing. The list of measures is set out in Annex 2.

6.2. Measures may be updated provided that the level of protection is not reduced.

6.3. The Customer independently assesses the sufficiency of the measures for its purposes and is responsible for the protection of its own environment, devices, and the credentials of its users.


7. Sub-processors

7.1. The Customer grants a general authorization to engage the Sub-processors disclosed in the “Sub-processors” document and in Annex 3.

7.2. The Processor: enters into with each Sub-processor a contract containing data-protection obligations no less strict than those in this DPA, to the extent applicable to its service; is responsible for the Sub-processor’s performance of such obligations to the extent of §12.

7.3. The Processor informs of a change in the composition of Sub-processors through the “Sub-processors” page, where possible before the new processing begins. A Customer that has subscribed to notices may, within 30 days, raise a reasoned objection. The parties in good faith seek an alternative; in its absence the Customer may discontinue use of the affected feature or terminate the contract in respect of it. Other remedies do not apply.

7.4. Replacement of a Sub-processor for the purpose of eliminating a security threat, ensuring continuity, or complying with a legal requirement is permitted without prior notice, with subsequent disclosure.


8. International data transfers

8.1. The Customer confirms that processing involves transfer of data outside Hong Kong and the Customer’s country, including to the United States, the EEA, Singapore, and mainland China — depending on the Models selected and the infrastructure.

8.2. For transfers subject to the GDPR, the SCC, Module 2 (controller — processor) apply, incorporated into the DPA by reference, with the following particulars: place — Hong Kong; governing law of the SCC — the law of an EU Member State as determined by the SCC; the SCC annexes are deemed completed with the information from Annexes 1–3 of this DPA; frequency of transfer — continuously, as requests are sent.

8.3. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCC applies.

8.4. The Processor conducts a reasonable assessment of the transfer circumstances and applies supplementary measures: minimization of data transferred, channel encryption, access restriction, contractual obligations to notify of lawful requests of authorities to the extent permitted by law.

8.5. Section 33 of the PDPO is not in force as of the date of this version; independently of that, the Processor applies contractual measures recommended by the PCPD.

8.6. The Processor cannot guarantee the impossibility of access by competent authorities of foreign states to data located in their jurisdiction. The Customer accepts this risk and must take it into account when selecting Models.


9. Data Subject requests

9.1. The Customer is responsible for considering Data Subject requests.

9.2. The Processor provides reasonable assistance taking into account the nature of the processing and the available functionality: provision of information about categories of processing, export of available data, deletion or rectification of data at the Customer’s direction.

9.3. If a Data Subject request is received directly by the Processor, it does not respond on the merits (other than acknowledging receipt) and, where it is possible to identify the Customer, forwards the request to the Customer.

9.4. Assistance requiring substantial labor and going beyond standard functionality may be provided on a fee basis upon prior agreement.


10. Security Incidents

10.1. The Processor notifies the Customer of a confirmed Security Incident affecting Customer Data without undue delay after the incident became known to it, and, as a rule, no later than 72 hours.

10.2. The notice contains the information available at the time of sending: the nature of the incident, the categories and approximate volume of data affected, the likely consequences, the measures taken and planned, a contact person. Information may be supplemented as the investigation proceeds.

10.3. The duty to notify supervisory authorities and Data Subjects rests with the Customer as controller; the Processor provides reasonable assistance.

10.4. A notice is not an admission of fault or liability of the Processor.

10.5. The Processor is not obliged to notify of incidents that do not affect Customer Data, or of unsuccessful attack attempts blocked by standard protective means.


11. Audit and confirmation of compliance

11.1. Upon a reasoned written request, no more than once in 12 months, the Processor provides: a description of technical and organizational measures; responses to a reasonable security questionnaire; available reports and confirmations.

11.2. On-site review is possible upon a reasoned necessity, provided that: the scope, date, and procedure are agreed in advance at least 30 days beforehand; a confidentiality agreement is signed; the review is conducted during business hours, without impairing the operation of the Service and without access to other customers’ data; an independent auditor who is not a competitor of the Processor is engaged; expenses are borne by the Customer.

11.3. The Processor may refuse to provide information the disclosure of which would violate obligations to third parties, legislation, or create a risk to the security of the infrastructure.


12. Liability

12.1. The liability of the parties under this DPA is subject to the limitations established by §17 of the Terms of Use, except in cases where such limitation is not permitted by the Data Protection Legislation.

12.2. Limitations of liability do not affect the rights of Data Subjects provided by the Data Protection Legislation, including the rights provided by the SCC.

12.3. The Customer indemnifies the Processor for losses arising from: the absence of a legal basis for processing; unlawful instructions; transmission to the Service of impermissible categories of data; a breach of the representations in §3.


13. Deletion and return of data

13.1. Upon cessation of the provision of services, the Processor, at the Customer’s choice, deletes or returns Customer Data within a reasonable time, but no later than 90 calendar days, unless applicable law requires retention.

13.2. Deletion from backups is performed as they naturally rotate.

13.3. The Processor may retain data to the extent and for the period required by applicable law, as well as de-identified and aggregated consumption information that does not permit identification of Data Subjects.

13.4. Upon request, the Processor confirms deletion in writing.


14. Term and other conditions

14.1. The DPA remains in force during the period of processing of Customer Data and terminates together with termination of the contract and completion of data deletion.

14.2. Provisions necessary for the protection of Customer Data and the resolution of disputes survive termination.

14.3. The provisions of the Terms of Use on governing law, the dispute-resolution procedure, notices, severability, and language apply to the DPA, unless the Data Protection Legislation or the SCC require otherwise.


Annex 1. Particulars of processing

Subject of processing: provision of access to artificial-intelligence models of third-party providers through a unified interface, including execution of requests, operation of agents, retention of history and memory, model comparison, consumption accounting, and support.

Nature and purpose of processing: collection, recording, storage, transmission to the selected AI Provider, display, alteration at the user’s direction, deletion; the purpose is provision of the Service functionality to the Customer.

Duration: the period of the Customer’s use of the Service and the deletion period under §13.

Categories of Data Subjects: users of the Customer’s account (employees, contractors), as well as any persons whose data the Customer, by its decision, includes in the contents of requests, including the Customer’s clients and counterparties.

Categories of Customer Data:

  • identification and contact data of account users (email address, name, nickname, avatar);
  • technical data (IP address, country code, User-Agent, identifiers and session times);
  • contents of requests and responses, including text, images, files, audio transcriptions;
  • memory items and facts extracted from conversations;
  • agent settings and preferences;
  • consumption and billing data;
  • contents of support requests.

Special categories of data: not contemplated and must not be transmitted (§3.1(4)).

Frequency of transfer: continuously, as requests are sent by the Customer’s users.

Recipients: the Sub-processors specified in Annex 3.


Annex 2. Technical and organizational measures

Access control and authentication: unique accounts; passwords as a bcrypt hash (cost 12); rate-limiting of login and registration attempts; limited session lifetime (12 hours; 30 days upon express extension); storage of session tokens as hashes; a separate administrative contour with additional checks, restriction by network addresses, and a limited invitation period.

Protection in transit: TLS for all user and service traffic; redirection of unprotected connections; session cookie with the httpOnly, Secure, SameSite=Lax attributes.

Segmentation and minimization of access: separation of the public web layer, application, database, and administrative contour; absence of public access to the database; access to the production environment by keys and on the principle of least privilege.

Abuse protection: validation of input data; limitation of the size and number of attachments; limits on the frequency and parallelism of requests at the proxy and application levels; filtering of malicious traffic; blocking of suspicious operations.

Logging and monitoring: recording of login events, refusals, limit triggers, and administrative actions; minimization of the composition of logs, excluding, where possible, the full text of conversations; monitoring of anomalies.

Change management: version control; automated build and delivery; description of infrastructure as code; updating of dependencies and base images with prioritization of critical fixes.

Secrets management: storage of keys and credentials in environment variables of the production environment; exclusion of secrets from the repository; rotation upon suspicion of compromise and personnel changes.

Continuity: regular backup with restricted access; restoration procedures.

Personnel: confidentiality obligations; granting of access as needed; termination of access upon completion of the task or cooperation.

Incident response: containment, elimination of the cause, restoration, review, notification in accordance with §10.

Known limitations as of the date of this version: encryption of data at rest is being implemented in stages; two-factor authentication of user accounts is under development; independent certification against external standards has not been obtained; individual features are provided in Preview Mode.


Annex 3. Sub-processors

The current list is published on the “Sub-processors” page and includes, in particular:

Sub-processorFunctionProcessing jurisdiction
OpenAIexecution of requests to GPT modelsUnited States, EEA
Anthropicexecution of requests to Claude modelsUnited States
Googleexecution of requests to Gemini modelsUnited States, EEA
xAIexecution of requests to Grok modelsUnited States
Moonshot AIexecution of requests to Kimi modelsmainland China
Alibaba Cloudexecution of requests to Qwen modelsmainland China, Singapore
Hosting-infrastructure providerplacement of servers and databasedisclosed to the Customer upon request
Network-protection and traffic-delivery providerattack filtering, determination of request countrydisclosed to the Customer upon request
Corporate email service providersending of transactional emailsdisclosed to the Customer upon request
Licensed payment providersacceptance of payments and processing of refundsdisclosed to the Customer upon request; indicated on the payment screen
Domain-name registrar and DNS operatordomain servicingdisclosed to the Customer upon request

The contents of requests are transmitted only to the AI Provider of the selected Model.

The names and jurisdictions of specific providers of the infrastructure layer are not published on the website for security reasons and are provided to a Customer that has entered into this DPA, upon request to support@modelstation.org — to the extent necessary for a compliance assessment and a processing-impact assessment. A change in the composition of such providers is communicated to the Customer in accordance with §7.3.


Annex 4. Signing procedure

To obtain a signed counterpart of the DPA, send to support@modelstation.org a request specifying: the Customer’s full name and address; registration number; the name and position of the signatory; a description of the intended use of the Service; information about the categories of data and Data Subjects; the need to include the SCC and the applicable modules.

ELVARON LIMITED Registration No. 79402144 14/F, China Building, 29 Queen's Road Central, Central, Hong Kong support@modelstation.org