Data Processing Addendum
GDPR Article 28 terms for customers who are controllers of personal data processed through Multigrid.
Last updated June 1, 2026 · Multigrid Systems, Inc., Amsterdam, Netherlands
1. Roles
You are the controller; Multigrid Systems, Inc. is the processor. Inference providers act as sub-processors under your instruction, expressed through your routing policy.
2. Instructions
We process personal data only on your documented instructions, which include your platform configuration: routing preferences, retention settings and guardrail rules.
3. Security
Technical and organisational measures are described in the Trust Center and include encryption in transit and at rest, least-privilege access and encryption of stored provider credentials. The Trust Center also sets out what is not in place, including the absence of any certification or independent penetration test; that list is part of these terms and is not a marketing summary of them.
4. Sub-processors
The current list is maintained in the Trust Center. You may object to a new sub-processor within 30 days of notice, in which case you may terminate the affected service without penalty.
5. Assistance
We assist with data-subject requests, DPIAs and breach notification. Personal-data breaches are reported to you without undue delay and in any event within 48 hours of confirmation.
6. Deletion
On termination we delete or return personal data within 30 days, except where retention is legally required. We can confirm in writing that the deletion has been carried out; we cannot supply a third-party-certified attestation, because there is no auditor to certify it.