Data Processing Addendum
Last updated: August 12, 2026
Eridian is a product of RENEDOR LLC. These documents are the current published policies for Eridian, operated by RENEDOR LLC. Viewing this page does not create an order form, DPA, or other contract. Send legal and data-subject requests to the addresses listed in each document.
1. Incorporation and Parties
This Data Processing Addendum (the "DPA") forms part of the Terms of Service or other master agreement (the "Agreement") between the customer identified in the Agreement ("Customer") and RENEDOR LLC, with its registered office at Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates ("Processor"). Eridian is a product of RENEDOR LLC. Eridian is operated by Processor. If there is a conflict on the subject of personal data processing, this DPA prevails over the Agreement.
This DPA applies when Processor processes Customer Personal Data on Customer's instructions in connection with the Service. It does not apply to Processor's independent processing of account, billing, or website data as a controller, which is described in the Privacy Policy.
2. Roles
Customer is the Controller (and, where Customer is itself a processor for a third-party controller, Customer warrants it is authorized to appoint Processor as a subprocessor). RENEDOR LLC is the Processor with respect to Customer Personal Data processed through the Service.
"Customer Personal Data" means personal data contained in Customer Data. "Applicable Data Protection Law" means the UAE PDPL, GDPR, UK GDPR, and any other data-protection law that applies to the processing under this DPA.
3. Processing Details
Subject matter: provision of the Service. Duration: the term of the Agreement plus any post-termination retention stated in the Agreement. Nature: hosting, transmission, inference orchestration, logging, security, and support.
Purpose: to provide inference orchestration, workspace features, observability, governance, and related support. Types of data: identifiers, professional data, and any personal data Customer elects to include in prompts, documents, or context, which may include names, contact details, and, if Customer submits them, special-category or financial data. Data subjects: Customer's personnel, counterparties, and other individuals whose data Customer submits. Processor does not determine those categories.
4. Instructions and Confidentiality
Processor shall process Customer Personal Data only on documented instructions from Customer, including the Agreement, this DPA, configuration in the Service (such as region, model, retention, and redaction settings), and written instructions from Customer's authorized administrators, unless required to process otherwise by applicable law, in which case Processor shall notify Customer before processing unless the law prohibits notice.
Processor shall ensure that persons authorized to process Customer Personal Data are bound by confidentiality and receive data-protection training appropriate to their role.
5. Security Measures
Processor shall implement appropriate technical and organizational measures, taking into account the state of the art, cost of implementation, and the nature, scope, context, and purposes of processing. Current measures include:
- AES-256 encryption at rest and TLS 1.3 in transit.
- SSO/SAML, SCIM where offered, role-based access control, and multi-factor authentication.
- Network segmentation, least-privilege production access, and logging of administrative actions.
- Optional PII redaction at inference time, configurable per project.
- Configurable data residency for Customer Data at rest (United Arab Emirates, European Union, United States, Asia-Pacific, as offered).
- Zero-Data-Retention with selected model providers on Enterprise where the provider supports it.
- Vulnerability management, vendor review, and incident response procedures.
6. Subprocessors and Thirty-Day Notice
Customer authorizes Processor to engage subprocessors to deliver the Service. The current list is published at /legal/subprocessors. Processor shall impose written data-protection obligations on each subprocessor that are no less protective of Customer Personal Data than this DPA, including the flow-down of Applicable Data Protection Law duties that apply to processors.
Processor shall provide Customer at least thirty (30) days' prior notice of the addition or replacement of a subprocessor, by updating the Subprocessors page and notifying workspace administrators by email. Customer may object on reasonable data-protection grounds within fifteen (15) days of notice. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Service without penalty and receive a refund of prepaid unused fees for that portion.
Processor remains responsible for each subprocessor's performance of Processor's obligations under this DPA.
7. International Transfers
Where Processor transfers Customer Personal Data out of the UAE, the EEA, or the UK, Processor shall ensure a valid transfer mechanism under Applicable Data Protection Law.
For GDPR-restricted transfers, the parties are deemed to enter into the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller to processor), with Customer as data exporter and Processor as data importer, including the UK Addendum and Swiss addendum where those laws apply. Annex details are as set out in this DPA and the Subprocessors list. For UAE PDPL-restricted transfers, Processor shall use a mechanism recognized by the UAE Data Office.
8. Assistance, Data Subject Rights, and DPIAs
Taking into account the nature of processing, Processor shall assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligations to respond to data subject requests under Applicable Data Protection Law. Processor shall not respond to a data subject as if it were the controller, except to redirect the request to Customer or as required by law.
Processor shall assist Customer with data protection impact assessments and consultations with the UAE Data Office or other supervisory authorities, to the extent the required information is available to Processor. Reasonable time-and-materials charges may apply to assistance that goes beyond the standard functionality of the Service, unless the assistance is required because of Processor's breach.
9. Personal Data Breach
Processor shall notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a personal data breach affecting Customer Personal Data, using the security or admin contact on the account. The notice shall describe, to the extent then known: the nature of the breach, categories and approximate number of data subjects and records, likely consequences, and measures taken or proposed.
Processor shall cooperate with Customer on investigation and mitigation. Notification under this Section is not an admission of fault. Customer is responsible for notifications to data subjects and to the UAE Data Office or other authorities except where Processor is independently required to notify.
10. Audits
Upon written request, Processor shall make available information reasonably necessary to demonstrate compliance with this DPA, including relevant SOC 2 Type II and ISO 27001 reports under NDA. Customer may conduct an audit once per twelve (12) month period, on thirty (30) days' notice, remotely or on-site at Processor's facilities during business hours, in a manner that does not unreasonably disrupt operations. On-site audits are at Customer's expense unless they reveal a material breach of this DPA.
If Customer is itself regulated, additional audit rights required by that regulator will be honored to the extent legally required and operationally feasible.
11. Return and Deletion
Upon termination or expiry of the Agreement, Processor shall, at Customer's choice, return Customer Personal Data in a reasonable export format or delete it from production systems within thirty (30) days, and delete remaining backups on their ordinary rotation, except where UAE or other law requires retention. Certification of deletion will be provided on written request.
12. No Training Without Consent
Processor shall not use Customer Personal Data to train, fine-tune, or improve foundation models except with Customer's prior written consent. Processor shall flow this restriction down to model-provider subprocessors for Customer Personal Data except where Customer has separately consented.
13. Customer Obligations
Customer shall: (a) have a lawful basis for the personal data it submits; (b) not instruct Processor to process data in violation of Applicable Data Protection Law; (c) configure residency, retention, and redaction settings appropriate to its risk; and (d) impose equivalent data-protection obligations on any third party to whom Customer discloses personal data processed through the Service.
14. Liability and Term
Liability under this DPA is subject to the limitations in the Agreement, except that nothing in this DPA limits a party's liability to a data subject where Applicable Data Protection Law makes that liability non-excludable. This DPA remains in effect for the duration of the Agreement and until Processor has deleted or returned Customer Personal Data.
15. Governing Law
This DPA is governed by the same law and courts as the Agreement, except that the Standard Contractual Clauses are governed as those Clauses require.
Notices under this DPA: contact@geteridian.com and contact@geteridian.com. RENEDOR LLC, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates.