Lumoswitch Legal
English translation for reference. Use the language switch to consult the original Chinese text. The operator's official name is 泉州丰泽哈基科技有限公司.
Lumoswitch Enterprise Data Processing Agreement (DPA)
This DPA is a template for separate execution by enterprise customers, setting out responsibilities and security requirements for entrusted processing of personal information.
Important notice
This is an enterprise data processing agreement template provided by 泉州丰泽哈基科技有限公司 ("Provider"). It takes effect only when the enterprise customer and Provider sign or affix their seals to it, or execute an order expressly incorporating it. Ordinary account registration does not itself activate enterprise services, audit rights, an SLA, or customized retention periods.
1. Roles and processing instructions
The enterprise customer determines the data categories, model providers, purposes, and methods of processing through Lumoswitch and acts as the relevant personal information handler. Provider processes customer data only on the customer's lawful, written, and executable instructions, as needed to provide inference runtime, control, metering, security, and operations services.
If Provider considers an instruction unlawful, it promptly informs the customer and suspends the affected processing unless the law prohibits notification.
2. Processing details
- Subject matter: Lumoswitch multi-model inference, fixed/failover routing, access-key limits, usage metering, logs, and technical support.
- Duration: the enterprise service order's term and the deletion window agreed by the parties.
- Data subjects: the customer's employees, users, developers, clients, or other people selected by the customer.
- Data types: account identifiers, device and log information, prompts, attachments, model responses, business configurations, and other data submitted by the customer.
- Sensitive information: processed only where the customer has a lawful basis, completes necessary assessments, and gives explicit instructions. Customers must not submit sensitive personal information unnecessarily.
3. Provider obligations
- Process only as instructed; do not use customer data for Provider's advertising or to train general-purpose models for other customers.
- Ensure that people authorized to access customer data are bound by confidentiality and follow least privilege.
- Adopt technical and organizational measures appropriate to the risks and regularly assess their effectiveness.
- Reasonably assist with personal information rights requests, impact assessments, and regulatory inquiries.
- Promptly contain and investigate personal information security incidents and provide available information to the customer.
4. Security measures
- Encryption in transit, sensitive-credential encryption, and key access controls.
- Identity verification, permission isolation, session revocation, and administrative-operation auditing.
- Risk alerts and temporary restrictions based on calls, billing, source profiles, and anomaly rules.
- Vulnerability remediation, dependency management, backup protection, and business-continuity measures.
- Minimized call logs, excluding complete prompts and model responses from ordinary logs by default.
- Content-safety checks retain only decision metadata such as rule matches, actions, and associated request identifiers by default. Stricter retention or human-review workflows chosen by a customer should be separately agreed in an order, security appendix, or internal notice.
- Employee and contractor confidentiality, security training, and access removal on departure.
5. Subprocessors and model providers
The customer generally authorizes Provider to use subprocessors for cloud infrastructure, SMS, email, security, and support. Provider requires equivalent or stronger data-protection obligations by contract and remains responsible for their entrusted activities.
Model providers configured or designated by the customer, or supplied with customer credentials, are generally third parties directly selected by the customer rather than subprocessors independently chosen by Provider. The customer evaluates their terms, regions, and compliance. A specific list and change-notification process may be agreed in the order.
6. Cross-border processing and data location
Both parties comply with applicable localization and cross-border-transfer requirements. Without customer instructions, Provider does not independently change the agreed processing region. When selecting an overseas model provider, the customer must ensure a lawful basis and complete necessary notices, separate consent, impact assessments, or other procedures.
7. Security incidents
After confirming an incident affecting customer data, Provider notifies the customer without undue delay, describing the known nature, likely impact, affected data, actions taken, and a contact. Notification is not an admission of liability. The parties cooperate on statutory reporting and individual-notification obligations. Specific deadlines may be agreed in an enterprise order.
8. Return, deletion, and termination
Upon enterprise service termination or a lawful customer instruction, Provider returns, deletes, or irreversibly anonymizes customer data within the agreed period and requires entrusted subprocessors to do the same. The minimum data subject to mandatory retention is isolated and deleted when the required period ends.
9. Audits and evidence
Provider supplies reasonable security explanations, questionnaire responses, or available third-party evidence appropriate to the maturity of its enterprise services. On-site audits require a reasonable basis, advance notice, confidentiality and security safeguards, and must not affect other customers or system security. Frequency, costs, and scope are separately agreed in the order.
10. Liability and document precedence
This DPA forms part of the enterprise service agreement. For conflicting data-protection provisions, this DPA prevails. Liability caps and dispute resolution remain governed by the main agreement unless mandatory law provides otherwise.
To execute a DPA or agree on subprocessors, data regions, or security appendices, contact soraincloud@hakihakii.com.