Skip to main content
1API Club

Data Processing Addendum

Data Processing Addendum

This DPA forms part of the applicable service agreement between 1API Cluband a customer when we process Customer Personal Data on that customer's behalf.

Last updated: August 13, 2026.

Customer content
Not written to 1API Club application databases or long-term logs; a private continuation cache is the limited exception.
Gateway API keys
Verified with a one-way digest, not retained in plaintext.
Independent processing
Upstream AI providers apply their own terms and data controls.

Processor and service provider boundary

The customer determines the purposes and means of processing in its application. We act as a processor under GDPR and UK GDPR, or a service provider or contractor under CCPA/CPRA, when those roles apply to Customer Personal Data routed through the Service.

We process Customer Personal Data only to provide the Service, including transient routing of API requests, delivery of responses, credential verification, usage metering, service security, abuse prevention, customer-requested support, and compliance with applicable law.

We act independently for our account, billing, fraud-prevention, security, support, and legal-compliance records. The related boundary is described in Privacy.

Content and credentials

Customer Personal Data may include personal data in routed prompts, instructions, messages, files, tool inputs, outputs, model responses, limited API usage metadata, and account or support data that the customer provides.

Routed API prompts and responses are not written to 1api's application databases or long-term logs. To support response continuation and one bounded recovery attempt, 1api may temporarily retain the minimum required conversation content in an isolated, idle-expiring continuation cache. Each successful cache write starts a rolling one-hour retention period. A successful continuation refreshes that period; cache reads, failed requests, and retries do not. The one-hour period can continue to refresh for an active conversation; there is no separate maximum lifetime. One hour after the last successful cache write, the content becomes unavailable to the Gateway and is scheduled for automatic deletion.

The cache is operationally separate from 1api's application databases and long-term logging systems. It is not exposed through customer or administrator consoles, is not a customer-accessible response archive, and is not used for training, analytics, or debugging. Usage, billing, security, and audit records may retain metadata that does not include prompt or response content. Upstream AI and infrastructure providers process and may retain content under their own terms, retention settings, and data controls.

Gateway API keys are not stored in plaintext. The complete key is shown only at creation; a one-way digest and limited lifecycle metadata support verification, rotation, revocation, security, and audit.

Usage, account, billing, support, and security records are retained only for the purposes and periods described in Privacy. Platform archives exclude raw request and response bodies, messages, tool payloads, and file contents.

Documented instructions

The customer instructs us to process Customer Personal Data as necessary to provide the Service and as described in the applicable agreement, this DPA, the customer's use of the Service, and the customer's documented lawful instructions.

If we believe an instruction infringes applicable data-protection law, we will inform Customer unless prohibited by law. We may process Customer Personal Data where required by applicable law and will notify Customer where permitted to do so.

Confidentiality and security

We limit access to Customer Personal Data to personnel and authorized service providers who need it to provide, secure, or support the Service and who are subject to confidentiality obligations.

We maintain technical and organizational measures appropriate to the Service, including access controls, least-privilege practices, credential lifecycle controls, operational monitoring, and measures designed to protect Customer Personal Data from unauthorized or unlawful processing and accidental loss, destruction, or damage.

Subprocessors and international transfers

We may use subprocessors for hosting, authentication, payments, communications, security, analytics, and operations. The public categories and objection path are listed in Subprocessors. We remain responsible for a subprocessor's processing of Customer Personal Data to the extent required by applicable law and the applicable agreement.

An upstream AI provider receives the content needed to fulfil a selected request and processes it under its own terms, retention settings, abuse controls, and data controls. Where an upstream AI provider determines its own purposes or means, it acts independently and its processing is not changed by this DPA.

We publish material changes to the Subprocessor List. A customer with a reasonable, documented data-protection objection may contact us before or promptly after a change takes effect. We will work in good faith to address a substantiated objection. If we cannot do so, Customer may stop using the affected part of the Service in accordance with the applicable agreement.

We and our service providers may process Customer Personal Data outside the country where a customer or data subject is located. Where an international transfer mechanism is required by applicable law, we use the contractual, statutory, or other lawful safeguard applicable to the transfer.

Customer assistance

  • We provide reasonable information and assistance for applicable data subject requests, security obligations, impact assessments, and consultations.
  • Because routed content is not persisted, it is not available for later return or deletion from platform storage.
  • Records may be retained when needed for billing, accounting, fraud prevention, security, disputes, legal claims, or another lawful obligation.

Deletion and return

Because we do not persist routed API prompts, responses, or other routed customer content, those data are not available for later return or deletion from platform storage. Customers can use available Service controls to manage their account, credentials, and customer-visible usage records.

At the end of the Service relationship, we delete or return Customer Personal Data we still process where required by applicable law and the applicable agreement, unless retention is required for billing, accounting, fraud prevention, security, dispute resolution, legal claims, or another lawful obligation.

Audit information

We make reasonable information available to demonstrate this DPA. A documented audit request must be scoped to Customer Personal Data and arranged to protect other customers, platform security, and confidential information. The parties agree the scope, timing, and safeguards for any audit in advance.

Precedence and contact

If this DPA conflicts with the applicable agreement on a matter of data processing, this DPA controls to the extent of that conflict. This DPA does not amend the independent terms or data controls of an upstream AI provider, a customer application, or another independent party.

Contact [email protected] for a DPA question or documented subprocessor objection. Read Privacy, Subprocessors, Terms, and Refunds for the related public policies.