Skip to main content
Binding text: the Valar Customer Data Processing Addendum is incorporated by reference into the Valar Terms of Use and prevails over this page. This page summarizes it so you can find the terms you need quickly.
Applies to: every customer using the Services under the Agreement
Contact: [email protected] for questions or a countersigned copy
The DPA governs how Valar Ltd. (Hasolelim Street 17, Tel Aviv, Israel) processes personal data solely on your behalf when you use the Services. By using the Services you accept it. Where it conflicts with the Agreement, the DPA prevails for the processing of personal data; its Schedules prevail over its main body for the matters they cover.

Definitions

  • Prompt - the content you submit to the Services for execution against a Model.
  • Output - the content a Model generates in response to a Prompt and returns to you.
  • Model - a third-party AI model made available through the Services and selected by you for a Prompt.
  • Completion Window - the maximum period within which Valar undertakes to return the first token, chosen per request through the API’s completion window parameter, from real-time execution up to twelve (12) hours.
  • Zero Data Retention - the standing configuration under which Prompts and Outputs are not retained after the request they relate to has been executed.
  • Self-Managed Deployment - a deployment of the Services inside your own infrastructure or a cloud environment you control, where Prompts and Outputs are processed within that environment.
  • Customer Personal Data - personal data Valar processes solely on your behalf under the DPA and the Agreement.
  • Data Incident - accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Valar on your behalf.
  • Security Documentation - the technical and organizational measures for the Services, detailed in the Valar Trust Center. Valar grants access on request.
  • Data Protection Laws - the GDPR, UK GDPR, CCPA, Israel’s PPL (including Amendment 13, in force from 14 August 2025) and the Swiss FADP, as applicable to the processing.

1. Roles

You are the controller of Customer Personal Data and Valar is the processor. Where you act as a processor for your own customers, Valar acts as your sub-processor. You are responsible for complying with Data Protection Laws in your use of the Services and for the lawful bases, notices and consents needed to send personal data to Valar.

2. What Valar may do with your data

Valar processes Customer Personal Data only for the Permitted Purposes: processing in accordance with the Agreement and the DPA, providing the Services, following your reasonable documented instructions consistent with the Agreement, and complying with applicable law under a court order or a competent authority (with notice to you unless legally prohibited). If Valar believes an instruction infringes Data Protection Laws, it tells you without undue delay and may temporarily cease the affected processing. Valar will not, and will not permit any sub-processor to, use Customer Personal Data to train, fine-tune, or otherwise develop or improve artificial intelligence or machine learning systems.

3. Zero data retention

Prompts and Outputs are not retained after the request they relate to has been executed:
  • Prompts submitted for real-time execution are not written to persistent storage.
  • Prompts submitted with a deferred Completion Window are held in queue storage only until the request has been executed, and in no case for more than twelve (12) hours from receipt, after which they are deleted.
  • Outputs are returned to you and are not retained after delivery.
Because of this, no personal data from Prompts or Outputs remains in Valar’s possession on termination, and no deletion request is needed for it. For a Self-Managed Deployment, Valar does not receive, store or process Prompts or Outputs at all. The DPA then applies only to account administration, support, and the operational telemetry described in Schedule 1.

4. Data subject requests

If Valar receives a request from a data subject about Customer Personal Data, it notifies you or refers the data subject to you, to the extent legally permitted. Valar assists you in responding, insofar as possible and reasonable, limited to the information and means reasonably available to it.

5. Confidentiality

Personnel, contractors and advisors who process Customer Personal Data are bound by confidentiality obligations at least as protective as the DPA and the Agreement, or by a statutory duty of confidentiality, and access is granted on a need-to-know basis.

6. Sub-processors

  • You give Valar general written authorization to engage sub-processors, subject to the conditions below.
  • The current Sub-processor List, with identities, locations and the service each provides, is published at trust.valarhq.ai.
  • Valar gives at least fourteen (14) days’ notice before adding or replacing a sub-processor, by updating the list and by email.
  • You may object in writing, for reasons relating to the protection of Customer Personal Data, within thirty (30) days of the notice. Silence is deemed acceptance. If you object, Valar uses reasonable efforts to offer a change that avoids the sub-processor within thirty (30) days; if it cannot, you may terminate the affected Services and pay only for Services provided.
  • Every sub-processor is bound by a written agreement with data-protection obligations that are the same or materially similar to the DPA. Valar remains responsible for its sub-processors, and none may use Customer Personal Data for training or model development or for any purpose beyond providing the Services.

7. Security and audits

Valar maintains appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental or unlawful destruction, loss, alteration, disclosure or access, taking into account the state of the art, implementation cost, and the nature, scope, context, purposes and risks of the processing. The measures are described in the Security Documentation and may be updated as long as the level of security is not lowered. On reasonable request and at your cost, Valar assists with your obligations under Articles 32 to 36 of the GDPR and the equivalent UK GDPR provisions. Audits. On fourteen (14) days’ prior written request, no more than once every twelve (12) months (except after a Data Incident or where a supervisory authority requires it), and subject to reasonable confidentiality undertakings, Valar makes available at its own cost the information needed to demonstrate compliance, to you or to an independent, reputable third-party auditor who is not a competitor. Valar may first offer recent third-party certifications, attestations and audit reports; you may reasonably require on-site access where those do not adequately demonstrate compliance. Audit results are used solely to assess compliance with the DPA or to meet your own contractual obligations. Where the Standard Contractual Clauses apply, their audit rights prevail.

8. Data incidents

  • Valar keeps documented incident management policies and notifies you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Data Incident, to the extent Data Protection Laws require it. This does not cover incidents caused by your own acts or omissions.
  • The notification includes, as it becomes known: the nature of the incident, including where possible the categories and approximate number of data subjects and records; the likely consequences; the measures taken or proposed; and a contact for more information.
  • You do not publish findings, notices or reports about a Data Incident that identify Valar without Valar’s prior written approval, except where Data Protection Laws or a mandatory regulatory requirement compel it, in which case you give reasonable prior notice and limit the disclosure to the minimum required. Disclosure to your advisors under confidentiality is allowed.
  • Valar promptly reimburses your reasonable costs from a Data Incident caused by Valar’s breach of the DPA, including notices to authorities and data subjects, audits and security testing, and data subject claims.

9. Return and deletion

  • Prompts and Outputs are deleted in the ordinary course under Zero Data Retention. Nothing remains to return or delete at termination.
  • Other Customer Personal Data (account, administrative and support data) is, at your written choice, deleted or returned within thirty (30) days after termination or expiry, and existing copies are deleted unless Data Protection Laws require retention. Valar may retain data for evidential purposes, to establish, exercise or defend legal claims, or to comply with law; retained data stays subject to the DPA.

10. International transfers

  • Transfers from the EEA, Switzerland and the UK to countries covered by an adequacy decision need no additional safeguards.
  • For other destinations, the transfer mechanism is the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for EEA transfers, the UK Addendum (ICO template B.1.0) for UK transfers, and the EU SCCs as adjusted for the FADP for Swiss transfers. The full terms are Schedule 2 of the binding addendum; the points below are the ones that decide how it applies to you.
  • Module Two applies when you are the controller, Module Three when you are a processor, and Module Four when Valar transfers to you as a controller outside the GDPR. Clause 9 uses general written authorization with the fourteen-day notice above. The EU SCCs are governed by the laws of Ireland, with disputes before Irish courts, and prevail over the DPA on any conflict.
  • Additional safeguards. Valar keeps encryption in transit and at rest and network protection per good industry practice, makes commercially reasonable efforts to resist bulk surveillance requests including under FISA section 702, and on a government access request, unless legally prohibited, informs the authority that Valar is a processor and directs it to you, and challenges the demand through reasonable legal mechanisms. No more than once every twelve (12) months, on your written request, Valar reports the types of binding legal demands it has received, to the extent the law permits.

11. Authorized affiliates

You enter the DPA for yourself and for your Authorized Affiliates that use the Services under your Agreement without their own contract. They are bound by your obligations, and you coordinate all communication with Valar on their behalf.

12. Other provisions

  • Impact assessments. On reasonable request and at your cost, Valar cooperates with your data protection impact assessments and prior consultations with supervisory authorities, to the extent the information is available to Valar and not to you.
  • Changes to the DPA. Either party may request variations on at least forty-five (45) calendar days’ written notice where a change in Data Protection Laws or a decision of a competent authority requires it. If no agreement is reached within thirty (30) days, either party may terminate the affected Services, paying only for Services provided.

Schedule 1: details of the processing

Schedule 3: CCPA terms

Where you are a Business under the CCPA and Valar processes Personal Information subject to it, Valar acts as your Service Provider. Valar processes Personal Information solely for the Permitted Purposes; does not receive it as consideration for the Services; does not sell or share it, and does not retain, use or disclose it outside the Permitted Purposes or the direct business relationship; does not combine it with other data in a way the CCPA prohibits for Service Providers; and notifies you if it can no longer meet these obligations. Sections 4 to 9 and 12 of this summary apply with CCPA terminology.

Schedule 4: Israel PPL supplement

Where Valar processes personal data subject to Israel’s Protection of Privacy Law on your behalf, you are the Database Controller and Valar is the Holder, with sub-processors as sub-Holders. Valar maintains the measures the Information Security Regulations require for the relevant database security level: a data security procedure, up-to-date documentation of the database structure and systems, periodic risk assessments and penetration tests with findings remediated, monitoring records, controls on portable devices and remote access, and restorable backups. Transfers out of Israel comply with the Transfer of Data to Databases Abroad regulations. Valar assists with inspection, rectification and erasure requests, performs no direct mailing under section 17C of the PPL without your written instruction, and on request reports at least annually on its performance under the supplement and supports your notifications to the Privacy Protection Authority.

Questions

For questions about the DPA or a countersigned copy, contact [email protected].