Data Processing Addendum
GDPR Article 28 terms for customers who are controllers of personal data processed through Multigrid.
Last updated August 24, 2026 · Multigrid, Netherlands · KvK 42115387 · VAT NL005505617B30
1. Roles
For personal data contained in the requests you send through the gateway, you are the controller and Jelte Ludeke, trading as Multigrid, is the processor. Inference providers act as sub-processors under your instruction, expressed through your routing policy.
For your own account data (your name, email, organisation and billing details) we are the controller, not your processor, because we decide why and how it is processed. That data is governed by our Privacy Policy rather than by this addendum, and this document does not purport to change it.
2. Subject matter, duration and scope
Subject matter and purpose: routing your API requests to the inference provider you select, metering them, and providing the dashboard, analytics and guardrail features you have enabled.
Duration: for as long as your account is open, plus the retention periods set out in the Privacy Policy.
Types of personal data: whatever your requests happen to contain, which is under your control and not ours, together with the request metadata we record. Bodies are stored in two places, both under your control: a batch keeps each submitted line and each result until you delete the batch, and the response cache keeps a reply for the lifetime a request asks for, up to 24 hours. A synchronous request that does not ask for caching leaves no body with us at all. The Privacy Policy sets out both in full.
Categories of data subject: your end users, your staff, and any individual whose personal data you choose to include in a request.
3. Instructions and confidentiality
We process personal data only on your documented instructions, which include your platform configuration: routing preferences, retention settings and guardrail rules.
Everyone with access to personal data processed under this addendum is bound to confidentiality. Multigrid is operated by one person, so in practice that is a commitment by that person rather than a personnel policy, and we would rather say so than imply an organisation that does not exist.
4. Security
Technical and organisational measures are described in the Trust Center and include encryption in transit and at rest, least-privilege access and encryption of stored provider credentials. The Trust Center also sets out what is not in place, including the absence of any certification or independent penetration test; that list is part of these terms and is not a marketing summary of them.
5. Sub-processors
The current list is maintained in the Trust Center. Notice of a new infrastructure sub-processor is emailed to the address on your account, and you may object within 30 days of it, in which case you may terminate the affected service without penalty. Inference providers are added to the list as the configuration changes rather than on notice; the control over those is the routing constraint that excludes one, described in the Privacy Policy.
Each sub-processor is engaged under terms that impose data protection obligations equivalent in substance to those in this addendum. Where a sub-processor is outside the EEA, that engagement relies on the Standard Contractual Clauses or an adequacy decision, as described in the Privacy Policy. We remain responsible to you for a sub-processor's performance.
6. Audit and information
We make available the information you reasonably need to demonstrate compliance with Article 28, through the Trust Center and on request through the support form.
We cannot host an on-site audit or complete an unlimited number of bespoke questionnaires: Multigrid is one person, and pretending otherwise is how the rest of this document went wrong before. We will answer a proportionate written assessment once a year, and more often if there has been a breach affecting you.
7. Assistance
We assist with data-subject requests, DPIAs and breach notification, taking into account the nature of the processing and the information available to us.
Personal-data breaches are reported to you without undue delay after we confirm one, and in any event within 72 hours. The same deadline your own Article 33 notification runs to, so that the time is yours rather than spent waiting on us.
8. Deletion
On termination we delete or return personal data processed on your behalf. That happens when the account closes, in the same operation rather than within a notice period, except where retention is legally required. The nightly backups described in the Privacy Policy hold a copy until they age out at thirty days, and that is the only qualification. We can confirm in writing that the deletion has been carried out; we cannot supply a third-party-certified attestation, because there is no auditor to certify it.