AltaMind Technologies

Data Processing Addendum

Version 1.0 · Effective 28 September 2026 · Forms part of the Terms of Service

The short version

  • You decide what to send and why; we only process it to return the model's answer. You are the organisation responsible for the personal information; we are your service provider.
  • Prompts and outputs are processed in British Columbia and are never stored. What we keep is listed below, and none of it is the text.
  • We don't train on your data, don't share it, and use five named subprocessors for payments, email, network and backup.
  • If something goes wrong we tell you without undue delay, and within 72 hours of learning of it.

1. Purpose and parties

This addendum ("DPA") sets out how AltaMind Technologies ("AltaMind", "we") processes personal information on behalf of the customer ("you") when you use the AltaMind Private AI API (the "Service"). It applies whenever the content you send includes personal information, meaning information about an identifiable individual, as that term is used in Canadian privacy law.

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act, Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25) and similar laws, you are the organisation responsible for the personal information and we are a service provider (or "processor") acting on your instructions. This DPA is meant to give you what those laws ask you to obtain from a service provider. If your organisation needs a signed copy, or a version with additional terms your regulator requires, email info@altamind.ca.

2. What is processed

CategoryWhat it isWhat we do with it
ContentThe prompts you send and the outputs the model returns, which may contain any personal information you choose to include (for example, names in a contract, details in a case note).Processed in memory on our hardware to generate the response. Not written to disk, not logged, not retained after the response is sent.
Usage recordsPer request: timestamp, the API key used, prompt and output token counts, response time, status code.Stored, to enforce your allowance, bill you, and keep the Service healthy.
Account dataCompany name, contact email, plan, Stripe customer and subscription identifiers.Stored, to run your subscription and contact you about it.

The people whose information may be in Content are whoever you choose to write about: your clients, patients, employees, suppliers or members of the public. You control that; we don't know who they are and don't look.

3. Our commitments

We will:

  1. process Content only to provide the Service to you, and only as these terms and your API requests instruct. We won't use it for any other purpose, including training, fine-tuning, evaluating or improving models, analytics or marketing;
  2. not sell, rent, share or disclose Content to anyone, except to the subprocessors in section 6 for the purpose named there, or where a Canadian law or court order requires it, in which case we tell you first unless the law forbids it;
  3. keep Content confidential. The only person with access to the systems that process it is the operator named in the Terms, who is bound by these obligations;
  4. tell you promptly if we believe an instruction from you would break privacy law;
  5. help you respond to requests from individuals (access, correction, deletion) and to your regulator, to the extent we hold anything relevant. Because Content isn't retained, in practice we can help with usage and account records only;
  6. help you with a privacy impact assessment (for example under Quebec's Law 25) by answering technical questions about the Service in writing;
  7. delete or return account data at the end of the subscription, as set out in section 7.

4. Where processing happens

  1. Model processing, and storage of usage and account records, happen on hardware we own and operate in British Columbia, Canada.
  2. API requests and responses travel over the public internet, encrypted with TLS, through Cloudflare's network before reaching our hardware. Cloudflare routes traffic through the point of presence nearest the client; for a client in Canada that is normally in Canada, but it can be elsewhere. Cloudflare forwards the encrypted request and does not retain Content.
  3. Payment data goes directly to Stripe and never reaches us. Your contact email is shared with Stripe (billing) and Resend (the confirmation email), both of which operate internationally.
  4. We do not otherwise transfer Content or personal information outside Canada, and we won't change that without 30 days' notice to you.

5. Security measures

  1. In transit: all API traffic is encrypted with TLS 1.2 or later, terminated at Cloudflare and again on our hardware. Our machine accepts connections only through an authenticated Cloudflare tunnel; it has no ports open to the internet.
  2. Content: processed in memory only. No request bodies or responses are written to disk or to logs, in normal operation or in error handling.
  3. API keys: generated with a cryptographic random source, shown once, and stored only as a one-way hash. Keys can be revoked instantly and are scoped to one client.
  4. Isolation: each client has its own rate limits and concurrency limits, so one customer's load can't be used to affect another's.
  5. Stored records: the usage and account database (which contains no Content) is held on the same hardware and copied nightly to a local backup and to an encrypted-in-transit copy in Apple iCloud Drive under our account. Backups contain no Content either.
  6. Access: administrative access requires physical access to the machine or an authenticated session on it, and is limited to the operator. There are no shared accounts.
  7. Physical: the hardware is in a locked private premises in Burnaby, BC, and restarts automatically after a power interruption.
  8. Software: the operating system, model server and gateway are kept up to date; changes are tested before deployment.

We keep these measures under review and will not reduce the overall level of protection during the term.

6. Subprocessors

We use these third parties. Each processes only the data named, for the purpose named.

SubprocessorPurposeDataLocation
Cloudflare, Inc.DNS, network routing and the tunnel to our hardwareEncrypted API traffic in transit; connection metadata (IP address, timing)Global network; US company
Stripe, Inc.Subscription billing and paymentsCompany name, contact email, card details (which we never see), invoicesUS and Ireland
Resend, Inc.Sends the subscription confirmation emailContact email, company name, planUS
Zoho CorporationHosts our info@altamind.ca mailboxEmail you send to us and our repliesData centre region chosen at account setup
Apple Inc. (iCloud Drive)Off-site copy of the nightly database backupUsage records and account data; never ContentUS company; Apple-operated storage

We'll give you at least 30 days' notice by email before adding or replacing a subprocessor that would handle personal information. If you object on reasonable privacy grounds and we can't resolve it, you may cancel and section 5 of the Terms applies, with a refund of the unused part of the current month.

7. Retention and deletion

  1. Content: not retained. It exists in memory only for the duration of the request.
  2. Usage records and account data: kept while you're a subscriber, and afterwards for as long as tax and record-keeping law requires, since token counts are the basis of what you were billed. In Canada that's generally up to seven years for billing records.
  3. On request after termination, we delete account data that we're not required to keep within 30 days, and confirm by email. Local backups rotate within 30 days; the off-site backup copies are kept for up to 400 days and are not edited individually.

8. Incidents

If we become aware of unauthorised access to, or loss or disclosure of, personal information we process for you (a "breach"), we will tell you without undue delay and in any case within 72 hours of becoming aware, by email to your account address. The notice will say what happened, what data and how many people are likely affected as far as we know, what we've done about it, and a contact. We'll keep you updated as we learn more and will help you with any notification you have to make to individuals or regulators.

9. Verification

Once a year, or after a breach, you may ask us in writing to confirm that we're complying with this DPA. We'll answer a reasonable questionnaire and provide relevant documentation within 30 days. An on-site review can be arranged by agreement, at your cost, with reasonable notice and confidentiality undertakings.

10. Your obligations

  1. You are responsible for having the lawful authority (consent or another legal basis) to send the personal information you send, and for telling the individuals concerned what you're doing, where the law requires it.
  2. You are responsible for reviewing outputs before acting on them, and for any decisions made using them.
  3. If your organisation is subject to rules that require specific contract terms (for example a health-sector agreement or a Quebec Law 25 assessment), tell us; we'll work with you on them.

11. General

  1. This DPA is part of the Terms of Service and lasts as long as your subscription, plus the retention periods in section 7. Where it conflicts with the Terms on the handling of personal information, this DPA prevails.
  2. The limitation of liability in the Terms applies to this DPA, except where the law doesn't allow it.
  3. It is governed by the laws of British Columbia and the federal laws of Canada applicable there.
  4. Contact for anything under this DPA: Zhouwu Huang, info@altamind.ca, AltaMind Technologies, Burnaby, British Columbia.