Current status
These data processing terms describe the private-preview operating model and are not a signed enterprise data processing addendum. A countersigned DPA with the legal entity, governing law, transfer mechanism, and customer instructions will be provided before paid processing.
Roles
For customer repository and account data, the customer determines the purpose of processing and Ontoly processes data only to provide, secure, support, and improve the configured service.
Security
Access is restricted by approved identity, repository authorization, and service role. Data in transit must use encryption. Production retention, backup, incident-response, and deletion schedules will be documented before general availability.
Subprocessors
Ontoly may use infrastructure, authentication, email, source-control, and model providers for narrowly defined processing. The current provider categories are listed on the Subprocessors page.
Requests
Privacy, security, deletion, export, and enterprise DPA requests can be sent to hello@sarwagya.wtf.