Company: Netraedge
DATA PROCESSING AGREEMENT (DPA)
This Data Processing Agreement forms part of any service agreement between:
Controller (Customer)
and
Processor: Netraedge
- Definitions
- Personal Data – as defined by GDPR
- Processing – as defined by GDPR
- Services – AI-powered data processing services
- Sub-processor – third-party processing data on behalf of Netraedge
- Roles
|
Party |
Role |
|
Customer |
Data Controller |
|
Netraedge |
Data Processor |
- Scope of Processing
Netraedge processes personal data solely for:
- AI inference
- Data analysis
- Service delivery
- System security
- Abuse prevention
No secondary usage.
- Categories of Data
May include:
- Names
- Business emails
- Technical metadata
- Documents
- Free-text fields
- Structured datasets
- Processing Instructions
Netraedge shall:
- Process only on documented instructions
- Not sell or monetize data
- Not train AI models using customer data without written consent
- Confidentiality
All personnel:
- Are contractually bound by confidentiality
- Receive security training
- Are subject to access controls
- Security Measures (SOC-2 & ISO-27001 Controls)
Netraedge maintains:
Technical Controls
- TLS 1.2+ encryption in transit
- AES-256 encryption at rest
- Network firewalls
- DDoS protection
- Intrusion detection
- Audit logging
Organizational Controls
- Role-based access control (RBAC)
- Least-privilege principle
- Background checks (where permitted)
- Security awareness training
- Incident response plan
- Vendor risk assessments
- Change management procedures
Physical Controls
- Cloud provider certified data centers (SOC-2 / ISO-27001)
- Sub-processors
Authorized categories:
- Cloud infrastructure provider (e.g., AWS, Azure, GCP)
- CDN & security provider
- Payment processor
- International Transfers
Protected by:
- EU Standard Contractual Clauses (SCCs)
- GDPR Article 46 safeguards
- Data Breach Notification
Netraedge shall notify:
- Within 72 hours of confirmation
- With nature, impact, mitigation steps
- Data Subject Rights
Netraedge assists with:
- Access
- Erasure
- Rectification
- Portability
- Restriction
- Objection
- Data Retention & Deletion
|
Data Type |
Retention |
|
AI input/output |
≤ 30 days or per contract |
|
Logs |
90 days |
|
Business contacts |
Contract + 24 months |
Secure deletion methods applied.
- Audits
Customer may:
- Request SOC-2 / ISO reports
- Perform audit with 30 days notice (max once/year)
- Liability
Limited as per main agreement.
- Governing Law
The Netherlands.
2) API-Specific Privacy Annex (for Netraedge)
API PRIVACY ANNEX
This annex supplements the Privacy Policy of Netraedge for API usage.
- Data Received via API
May include:
- Request payloads
- Headers
- IP addresses
- Authentication tokens
- Structured and unstructured datasets
- Purpose
Processed solely for:
- Generating AI outputs
- Monitoring system performance
- Preventing abuse
- Debugging failures
- No Model Training
API data is never used for AI training, fine-tuning, or third-party sharing.
- Data Isolation
- Logical tenant separation
- No cross-client access
- Encrypted storage
- Retention
|
Data Type |
Retention |
|
API payloads |
≤ 30 days |
|
Logs |
90 days |
|
Errors |
30 days |
- Security
- API key / token protection
- Rate limiting
- IP filtering (optional)
- Abuse detection
- Logging & alerting
- Customer Responsibilities
Customers must:
- Avoid sending unnecessary personal data
- Secure API keys
- Notify of compromise
Netraedge uses essential cookies to ensure the secure and proper functioning of this website. These cookies are required for security, load balancing, and system stability. We do not use advertising or tracking cookies.
You may accept essential cookies or view our Privacy Policy for more information.
Netraedge operates a privacy-first AI platform. We do not maintain user accounts, do not sell personal data, and do not train AI models using customer data by default. Our infrastructure follows SOC-2 and ISO-27001 aligned controls. GDPR-compliant DPA and SCCs are available upon request.
Netraedge – Security Whitepaper
Version: 1.0
Last Updated: [20 01 2026]
- Executive Summary
Netraedge provides enterprise-grade AI services with a strong focus on data protection, confidentiality, integrity, and availability. Our security program is designed to meet the expectations of regulated enterprises and aligns with industry standards including SOC 2 Trust Services Criteria and ISO/IEC 27001.
We do not operate user accounts, do not sell personal data, and do not use customer data for AI model training by default.
- Contact
Netraedge Security Team
Please use online contact form for this purpose.