Last updated: 18 September 2025 | Version: 2025.09.18
This Data Protection Addendum ("DPA") forms part of the Terms of Service between SpicyAPI ("Processor") and Customer ("Controller") to reflect the parties' agreement with regard to the processing of personal data in accordance with GDPR, UK GDPR, and other applicable data protection laws.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion.
"Controller" means the Customer who determines the purposes and means of Processing Personal Data.
"Processor" means SpicyAPI, which Processes Personal Data on behalf of the Controller.
"Data Subject" means the individual to whom Personal Data relates.
"Sub-processor" means any third party engaged by Processor to Process Personal Data.
2.1 Customer as Controller: Customer acts as the Controller for all Personal Data submitted through the Services, including prompts, generated content, and end-user data. Customer is responsible for:
2.2 SpicyAPI as Processor: SpicyAPI acts solely as a Processor, Processing Personal Data only on documented instructions from Customer and in accordance with this DPA.
3.1 Scope: Processor shall Process Personal Data only to provide the Services as described in the Terms of Service and as necessary for the following purposes:
3.2 Instructions: Customer instructs Processor to Process Personal Data in accordance with this DPA and the Terms of Service. Additional instructions require written agreement.
Technical and Organizational Measures:
5.1 Authorization: Customer authorizes Processor to engage Sub-processors to Process Personal Data, provided Processor:
5.2 Current Sub-processors:
Updated list available at: spicyapi.com/sub-processors
6.1 Transfer Mechanisms: Where Personal Data is transferred outside the UK/EEA, appropriate safeguards include:
6.2 Data Localization: Customer may request data residency in specific regions (additional fees may apply).
7.1 Cooperation: Processor shall assist Customer in responding to Data Subject requests regarding:
7.2 Response Time: Processor will respond to Customer requests within 5 business days.
8.1 Retention Periods:
8.2 Deletion: Upon termination, Personal Data will be deleted within 30 days unless retention is required by law.
9.1 Audit Rights: Customer may audit Processor's compliance annually with 30 days notice, or immediately following a breach.
9.2 Certifications: Processor will maintain and provide upon request:
9.3 Regulatory Cooperation: Processor will cooperate with supervisory authorities and provide information as required.
10.1 Notification: Processor will notify Customer without undue delay and within 72 hours of becoming aware of a Personal Data breach.
10.2 Information Provided:
10.3 Documentation: Processor maintains records of all breaches and remediation efforts.
11.1 Processor Liability: Processor's liability for data protection violations shall be subject to the limitations in the Terms of Service, except for willful misconduct or gross negligence.
11.2 Customer Indemnification: Customer indemnifies Processor against claims arising from Customer's violation of data protection laws or instructions that infringe applicable law.
This DPA remains in effect for the duration of the Terms of Service. Upon termination, data deletion obligations in Section 8 apply. Sections relating to confidentiality and liability survive termination.
This DPA is governed by the laws of England and Wales. Disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.
CONTACT FOR DATA PROTECTION MATTERS:
Data Protection Officer: contact@spicyapi.com
Postal Address: SpicyAPI Ltd, London, United Kingdom
Response Time: Within 5 business days