Data Processing Addendum
Effective date: 2026-09-20.
This Addendum forms part of the Loglune Terms of Service and governs Loglune's processing of personal data contained in Customer Data. Where this Addendum and the Terms of Service conflict on the processing of Customer Personal Data, this Addendum controls. The Privacy Notice describes Loglune's own processing as a controller and is not replaced by this Addendum.
Navigation
| Part | Clauses | Purpose |
|---|---|---|
| A. Scope and roles | 1–3 | identify the parties, incorporate this Addendum, and fix the controller and processor roles |
| B. Processing obligations | 4–10 | limit processing to instructions and state confidentiality, security, subprocessors, assistance, and deletion |
| C. Transfers, evidence, and term | 11–13 | state transfer mechanisms, audit evidence, liability order, and duration |
| Annexes | A–C | describe the processing, list every subprocessor with the country its processing runs in, and state the security measures |
Part A — Scope and roles
1. Parties and incorporation
This Addendum is between the customer that accepted the Terms of Service (the "Customer") and Loglune (the "Processor"). It is incorporated into the Terms of Service on acceptance and needs no separate signature. A countersigned copy is issued on request to support@loglune.com.
2. Definitions
"Customer Personal Data" means personal data that the Customer places in flag definitions, targeting rules, segments, evaluation context, or the request input of an AI-assisted operation, and that Loglune processes on the Customer's behalf. "Controller", "processor", "subprocessor", "personal data", "processing", and "personal data breach" carry the meanings given in Article 4 of the General Data Protection Regulation, read for the United Kingdom under the UK General Data Protection Regulation, for Japan as an entrustment of handling under the Act on the Protection of Personal Information, and for Brazil as the relationship between controller and operator under the Lei Geral de Proteção de Dados.
3. Roles
| Data | Customer role | Loglune role |
|---|---|---|
| personal data inside flag definitions, targeting rules, segments, and evaluation context | controller | processor |
| the request input of an AI-assisted operation the Customer starts | controller | processor |
| account, authentication, billing, support, and usage data about the Customer's own personnel | data subject's employer | independent controller, governed by the Privacy Notice |
Loglune does not determine the purposes or means of processing Customer Personal Data, does not use it for its own purposes, and does not sell or share it.
Part B — Processing obligations
4. Instructions
Loglune processes Customer Personal Data only on the Customer's documented instructions. The Terms of Service, this Addendum, and the Customer's own configuration and requests in the Service are the complete documented instructions. Loglune informs the Customer if an instruction appears to infringe applicable data protection law and may suspend the affected processing until the instruction is corrected. Where law requires Loglune to process without the Customer's instruction, Loglune informs the Customer before processing unless that law forbids the notice.
5. Purpose limitation
Customer Personal Data is used to operate the platform, to deliver and reproduce the Customer's own configuration, and to run an AI-assisted operation that the Customer started. It is not used for any other purpose, is not disclosed to another customer, and is not used to train, fine-tune, evaluate, or improve any model. Loglune requires the same of every subprocessor listed in Annex B and configures the model routing described in Annex A so that a request fails rather than reaching an endpoint that retains the input or collects it for training.
6. Confidentiality
Access is limited to personnel who need it to perform this Addendum. Those personnel are bound by a written confidentiality obligation that survives the end of their engagement.
7. Security
Loglune applies the technical and organisational measures in Annex C and maintains a level of security appropriate to the risk. Measures may change, and a change may not reduce the level of security.
8. Subprocessors
The Customer gives a general authorisation for the subprocessors listed in Annex B. Loglune imposes data protection obligations on each subprocessor that are no less protective than this Addendum, and remains responsible to the Customer for each subprocessor's performance. Before a new subprocessor begins processing Customer Personal Data, Loglune updates Annex B and the Third-party Services List in the Privacy Notice and gives notice through the registered email address or the Service. The Customer may object on reasonable data protection grounds within 30 days of the notice by writing to support@loglune.com; if the objection cannot be resolved, the Customer may terminate the affected subscription and receive a refund of the unused prepaid period.
9. Assistance
Loglune assists the Customer, taking into account the nature of the processing and the information available to it, with responses to data subject requests, with data protection impact assessments and prior consultations, and with the security obligations in Articles 32 to 36 of the General Data Protection Regulation. Loglune forwards a data subject request it receives directly to the Customer without responding to its substance. On becoming aware of a personal data breach affecting Customer Personal Data, Loglune notifies the Customer without undue delay and provides the nature of the breach, the categories and approximate volume affected, the likely consequences, and the measures taken.
10. Deletion and return
On the Customer's request, and on termination of the subscription, Loglune deletes or returns Customer Personal Data and deletes the Customer's delivery keys, following the account deletion procedure in the Privacy Notice. Copies required by law are isolated from normal processing and deleted when the retention requirement ends. Pinning a version excludes it from automatic deletion and is not a refusal to delete on request.
Part C — Transfers, evidence, and term
11. International transfers
Annex B states the country in which each subprocessor's processing runs. Where a transfer from the European Economic Area, the United Kingdom, or Switzerland is not covered by an adequacy decision, the Standard Contractual Clauses approved by the European Commission apply in the controller-to-processor module, with the United Kingdom International Data Transfer Addendum for the United Kingdom and the Swiss amendments for Switzerland. Annex A supplies the information those clauses require. For a transfer subject to the Act on the Protection of Personal Information, Loglune identifies the receiving country and the measures the recipient takes; for Brazil, the transfer relies on the standard contractual mechanisms recognised under the Lei Geral de Proteção de Dados.
12. Evidence and audit
Loglune makes available the information needed to demonstrate compliance with this Addendum, including the current Annex B, the measures in Annex C, and any third-party audit report it holds. Where an on-site audit is required by law, it takes place on reasonable notice, no more than once in a twelve-month period unless a regulator or a breach requires otherwise, during business hours, without disrupting the Service, and subject to confidentiality. Loglune does not claim a certification, an audit report, a storage region, or a transfer safeguard that is not in place; the Third-party Services List in the Privacy Notice carries the same rule.
13. Liability, term, and changes
This Addendum takes effect when the Customer accepts the Terms of Service and ends when Loglune has completed its obligations under Clause 10. The liability limits in the Terms of Service apply to this Addendum, except where mandatory law provides otherwise. Loglune updates this Addendum when the processing, the subprocessors, or the transfer mechanisms change, and gives notice of a material change through the registered email address or the Service.
Annex A — Description of the processing
| Item | Content |
|---|---|
| Subject matter | provision of the Loglune feature-flag and configuration platform, its append-only change history, the reconstruction of a past version for reproduction, and the optional AI-assisted operations |
| Duration | the term of the subscription, plus the period needed to complete Clause 10 |
| Nature and purpose | storage, retrieval, evaluation, reconstruction, delivery to the Customer's authorised runtime, and, when the Customer starts a named request, transmission to a model host for analysis and a draft code change |
| Categories of data subjects | the Customer's authorised users, and the Customer's own end users to the extent the Customer places their identifiers or attributes in targeting rules, segments, or evaluation context |
| Categories of personal data | user keys and attribute-set keys chosen by the Customer, targeting rules and segment membership, the report text supplied with an AI-assisted operation, and the authorised users' business email and identity-provider account identifier |
| Special categories | none requested; Loglune asks the Customer not to place special-category data in flag definitions or request text |
| Frequency | continuous for storage and evaluation; per request for an AI-assisted operation |
| Model routing for an AI-assisted operation | the request input is sent to the routing intermediary in Annex B, which is configured to allow only the two named zero-retention endpoints, to refuse an endpoint that collects data for training, and to fail the request rather than fall back to any other endpoint, provider, or region |
Annex B — Subprocessors and the country each one processes in
Last updated: 2026-09-20. Every subprocessor below may receive Customer Personal Data. Providers that process only Loglune's own controller data, including the payment processor and the support mailbox, are listed in the Third-party Services List in the Privacy Notice and are not subprocessors of Customer Personal Data.
| Subprocessor | Entity and country of establishment | Function | Customer Personal Data reached | Country the processing runs in |
|---|---|---|---|---|
| Cloudflare | Cloudflare, Inc., United States | hosting, content delivery, application execution, the per-customer database that holds flag and configuration history, the control database, ruleset storage, and sign-in session verification | all Customer Personal Data held in flag definitions, targeting rules, segments, and evaluation context, and session and authentication tokens | Cloudflare's global network. Loglune sets no jurisdiction restriction on the per-customer database, so it is created in the Cloudflare location nearest the first request and the processing follows Cloudflare's disclosed locations |
| Identity provider chosen by the Customer | the provider's own entity and country | authenticates an authorised user and returns a verified identity to the sign-in check | business email, account identifier, authentication result | the locations disclosed by that identity provider; the Customer selects the provider and holds the relationship with it |
| OpenRouter | OpenRouter, Inc., United States | routing intermediary for an AI-assisted operation: receives the request input and forwards it to one of the two model hosts below, applying the zero-retention, no-training, no-fallback, and region restrictions in Annex A | the report text supplied with the request, flag keys, environment names, timestamps, version identifiers, and the source files read from the repository the Customer approved | United States |
| Amazon Bedrock | Amazon Web Services, Inc., United States | model host that runs the model for an AI-assisted operation, reached only through the region-pinned endpoint amazon-bedrock/us-east-1 |
the request input described in the OpenRouter row | United States, in the AWS Region US East (N. Virginia) |
| Google Vertex AI | Google LLC, United States | model host that runs the model for an AI-assisted operation, reached only through the region-pinned endpoint google-vertex/us |
the request input described in the OpenRouter row | United States; the Vertex AI multi-region endpoint us keeps processing inside United States regions |
The model is authored by Anthropic PBC. On the two endpoints above, Anthropic does not receive the request input: the model runs inside the model host's own infrastructure. Loglune does not send an AI-assisted operation to Anthropic's own service, to any other provider, or to any endpoint outside the two listed here; a request that cannot be served by them fails instead of moving elsewhere.
Annex C — Technical and organisational measures
| Measure | Content |
|---|---|
| Tenant separation | each customer's flag and configuration history is held in a database of its own, and a delivery or reproduction reads only the customer it is authorised for |
| Access control | administrative access requires an identity-provider sign-in verified by the access layer, and a change to a spending limit requires a second authentication factor |
| Transport and storage | encrypted transport for every request, and storage encrypted by the hosting provider |
| Credentials | delivery keys and operator tokens are stored only as a hash, are never written to a URL or a log, and are revocable by the Customer |
| Identifier handling | user keys and attribute-set keys are kept out of request URLs and logs and are not included in the model input of an AI-assisted operation |
| Integrity of the record | the change history is append-only apart from retention deletion, versions increase monotonically within a customer, and an audit chain is anchored daily |
| Review of output | an AI-assisted operation changes no state; its conclusions are checked against the rule-based engine and a code change is delivered only as a draft pull request for a person on the Customer's side to review |
| Incident response | detection, containment, risk assessment, notification under Clause 9, remediation, and closure are recorded for each incident |
| Deletion | deletion on request and at termination follows Clause 10 and the account deletion procedure in the Privacy Notice |