Data Processing Agreement

Version 1.0 · Effective 22 July 2026

This Data Processing Agreement ("DPA") is entered into between Neural Compute Ltd, a company registered in England and Wales with company number 17195150, whose registered office is at 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF, trading as Sference ("Sference"), and the customer or partner agreeing to these terms ("Customer").

This DPA forms part of the agreement between Sference and Customer governing Customer's use of Sference's managed inference services (the "Agreement"), including our Terms of Service where no separately negotiated agreement applies. If there is a conflict between this DPA and the Agreement, this DPA prevails in respect of data protection matters.

1. Definitions

1.1 "Applicable Data Protection Law" means, as applicable to the Processing of Personal Data under the Agreement: (a) Regulation (EU) 2016/679 (the "EU GDPR"); (b) the UK General Data Protection Regulation and the Data Protection Act 2018 (together, the "UK GDPR"); (c) the EU e-Privacy Directive 2002/58/EC as implemented; and (d) any other data protection or privacy laws applicable to a Party in its capacity under this DPA, in each case as amended or replaced from time to time.

1.2 "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" (and "Process"), "Sub-processor", and "Supervisory Authority" have the meanings given in Applicable Data Protection Law.

1.3 "Customer Personal Data" means Personal Data contained in Customer Content that Sference Processes on behalf of Customer under the Agreement.

1.4 "Customer Content" means inputs submitted to the Services by or on behalf of Customer (including prompts, documents, files, embeddings inputs, and fine-tuning or customer-provided model data) and the outputs generated by the Services in response.

1.5 "EEA" means the European Economic Area.

1.6 "Restricted Transfer" means a transfer of Personal Data from the EEA or the UK to a third country that is not subject to an adequacy decision or adequacy regulations under Applicable Data Protection Law.

1.7 "SCCs" means (a) the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (the "EU SCCs"); and (b) the UK International Data Transfer Agreement ("UK IDTA") or the UK International Data Transfer Addendum to the EU SCCs (the "UK Addendum") issued by the UK Information Commissioner's Office, as applicable to a given Restricted Transfer.

1.8 "Services" means Sference's managed inference platform and related services provided under the Agreement, including serverless and dedicated inference endpoints, batch and asynchronous processing, model hosting (including customer-provided fine-tunes and distillations), and associated APIs, logging, and dashboards.

1.9 Capitalised terms not defined in this DPA have the meanings given in the Agreement.

2. Scope, Roles, and Instructions

2.1 Roles. Customer acts as either (a) a Controller of Customer Personal Data, or (b) a Processor acting on behalf of one or more third-party Controllers (for example, where Customer provides an AI platform, gateway, or application to its own customers). Sference Processes Customer Personal Data as Customer's Processor or, where Customer is itself a Processor, as Customer's Sub-processor.

2.2 Customer as Processor. Where Customer acts as a Processor on behalf of third-party Controllers, Customer warrants that: (a) its instructions to Sference are consistent with the instructions and authorisations it has received from the relevant Controller(s); (b) it has been authorised by the relevant Controller(s) to appoint Sference as a Sub-processor; and (c) it will serve as the sole point of contact for Sference in respect of the relevant Controller(s), and Sference may fulfil any obligation owed to such Controller(s) by fulfilling it to Customer.

2.3 Details of Processing. The subject matter, duration, nature, and purpose of the Processing, and the categories of Personal Data and Data Subjects, are set out in Annex 1.

2.4 Instructions. Sference shall Process Customer Personal Data only on documented instructions from Customer, including as set out in the Agreement, this DPA, Customer's use and configuration of the Services, and any further written instructions agreed between the Parties. If Sference is required by law to which it is subject to Process Customer Personal Data otherwise, it shall inform Customer of that legal requirement before Processing, unless that law prohibits such notification on important grounds of public interest. Sference shall immediately inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

2.5 Compliance. Each Party shall comply with its obligations under Applicable Data Protection Law. Customer is responsible for the lawfulness of the Customer Personal Data it provides and of its instructions, including establishing a lawful basis and providing any required notices to Data Subjects.

2.6 No training. Sference shall not use Customer Content (including Customer Personal Data) to train, retrain, or improve any machine learning model of Sference or of any third party, except: (a) where and to the extent expressly instructed or agreed by Customer in writing (for example, a fine-tuning job submitted by Customer for Customer's own model, or a training arrangement specifically agreed in respect of paid Services); or (b) in respect of Services expressly designated by Sference as free of charge, where and to the extent the applicable service terms disclose such use and Customer elects to use those Services. Where sub-paragraph (b) applies, Customer shall not submit Customer Personal Data to the designated free Services unless the Parties have agreed the roles and safeguards for that use in writing.

3. Confidentiality and Personnel

3.1 Sference shall ensure that all persons authorised to Process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory obligation of confidentiality, and Process Customer Personal Data only as needed to provide the Services.

3.2 Sference shall provide its personnel with appropriate data protection and information security training.

4. Security

4.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects, Sference shall implement and maintain the technical and organisational measures set out in Annex 2 ("TOMs") to ensure a level of security appropriate to the risk, including protection against unauthorised or unlawful Processing and against accidental loss, destruction, or damage.

4.2 Sference may update the TOMs from time to time, provided the updates do not materially reduce the overall level of security of the Services.

5. Sub-processors

5.1 General authorisation. Customer provides general written authorisation for Sference to engage the Sub-processors listed in Annex 3 (maintained at sference.com/legal/subprocessors) to Process Customer Personal Data in connection with the Services.

5.2 Changes. Sference gives notice of intended additions to or replacements of Sub-processors by updating its sub-processor page and notifying Customer (by email to subscribed contacts or through the Services) at least fourteen (14) days before the new Sub-processor Processes Customer Personal Data, except where an urgent replacement is required for security or continuity reasons, in which case notice will be given as soon as practicable. Customer may object on reasonable data protection grounds within the notice period. If Customer reasonably objects and the Parties cannot agree a resolution within thirty (30) days, Customer may terminate the affected part of the Services (or, where not severable, the Agreement) without penalty.

5.3 Flow-down. Sference shall impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.

5.4 Liability. Sference remains fully liable to Customer for the performance of each Sub-processor's obligations.

6. International Transfers

6.1 Data residency. Sference Processes Customer Content on inference and storage infrastructure located within the EEA, as described in Annex 2. Ancillary Processing (such as platform analytics and content delivery) is described in Annex 3.

6.2 EEA to UK. Where Customer Personal Data is transferred from the EEA to Sference in the United Kingdom, the transfer is made pursuant to the European Commission's adequacy decision in respect of the United Kingdom. If that adequacy decision is suspended, invalidated, or withdrawn, the EU SCCs (Module Two or Module Three, as applicable) shall automatically apply to such transfers in accordance with Clause 6.3.

6.3 Restricted Transfers. Neither Party shall make a Restricted Transfer of Customer Personal Data except in compliance with Applicable Data Protection Law. Where a Restricted Transfer takes place in connection with the Services, the applicable SCCs are incorporated into this DPA by reference, completed as set out in Annex 4, with the data exporter being Customer (or the relevant Controller) and the data importer being Sference or the relevant Sub-processor.

6.4 Precedence. If there is a conflict between this DPA and any incorporated SCCs, the SCCs prevail in respect of the transfer they govern.

7. Assistance

7.1 Data Subject rights. Taking into account the nature of the Processing, Sference shall assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests for exercising Data Subject rights (access, rectification, erasure, restriction, portability, objection). If Sference receives a request directly from a Data Subject relating to Customer Personal Data, it shall (unless prohibited by law) promptly forward the request to Customer and shall not respond substantively without Customer's authorisation.

7.2 Compliance assistance. Taking into account the nature of Processing and the information available to it, Sference shall assist Customer in ensuring compliance with Customer's obligations under Articles 32 to 36 of the EU GDPR / UK GDPR (security of Processing, breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities).

7.3 Government and third-party requests. If Sference receives a legally binding request from a public authority or other third party for access to or disclosure of Customer Personal Data, Sference shall (unless legally prohibited) promptly notify Customer, challenge over-broad or unlawful requests where reasonable grounds exist, and disclose only the minimum data required.

7.4 Costs of assistance. Sference provides the assistance described in Clauses 7.1 and 7.2 free of charge to the extent it can do so using its standard tooling and reasonable efforts. Customer shall bear Sference's reasonable, documented costs of assistance that materially exceeds this, provided Sference notifies Customer of the anticipated costs in advance.

8. Personal Data Breach

8.1 Sference shall notify Customer without undue delay, and in any event within forty-eight (48) hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 The notification shall include, to the extent known and as information becomes available: (a) the nature of the breach, including the categories and approximate numbers of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the breach and mitigate its possible adverse effects; and (d) a point of contact for further information.

8.3 Sference shall reasonably cooperate with Customer in investigating, mitigating, and remediating the breach and in meeting Customer's notification obligations to Supervisory Authorities and Data Subjects. Sference's notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability.

9. Audit

9.1 Sference shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the EU GDPR / UK GDPR and this DPA.

9.2 Sference shall allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer (bound by confidentiality and not a competitor of Sference), on at least thirty (30) days' prior written notice, no more than once per calendar year, except where (a) required by a Supervisory Authority, or (b) following a confirmed Personal Data Breach affecting Customer Personal Data.

9.3 Sference may first satisfy an audit request by providing a recent third-party audit report or certification relevant to the Services (such as SOC 2, ISO/IEC 27001, or equivalent, where available), together with written responses to reasonable follow-up questions. An on-site inspection shall only proceed where such materials do not reasonably demonstrate compliance.

9.4 Audits shall be conducted during normal business hours, with minimal disruption to Sference's business, and subject to Sference's reasonable confidentiality and security requirements. Customer shall bear Sference's reasonable, documented costs of any on-site inspection under Clause 9.2, except where the inspection is required by a Supervisory Authority or reveals material non-compliance with this DPA, in which case Sference bears its own costs.

10. Retention, Deletion, and Return

10.1 During the Term. Sference retains Customer Content only as long as necessary to provide the Services (including queued asynchronous and batch workloads), to maintain security and abuse-prevention logs, and to comply with law. Inference inputs and outputs are not retained longer than operationally necessary as described in Annex 1.

10.2 On termination. On termination or expiry of the Agreement, Sference shall, at Customer's written choice, delete or return all Customer Personal Data and delete existing copies within thirty (30) days, unless and to the extent retention is required by applicable law. Absent an election by Customer within thirty (30) days of termination, Sference will delete.

10.3 Legal retention. Where Sference is required by law to retain Customer Personal Data, it shall (a) notify Customer (unless prohibited), (b) continue to protect the data in accordance with this DPA, and (c) limit Processing to the purposes mandated by that law. Deletion from backups occurs in the ordinary course of backup rotation.

11. Records; Liability; General

11.1 Records. Sference shall maintain records of Processing carried out on behalf of Customer as required by Article 30(2) of the EU GDPR / UK GDPR.

11.2 Liability. The exclusions and limitations of liability set out in the Agreement apply to the Parties' obligations under this DPA, except to the extent Applicable Data Protection Law does not permit liability to be limited. Where the Agreement contains no limitation of liability, each Party's total aggregate liability arising out of or in connection with this DPA is limited to the fees paid or payable by Customer under the Agreement in the twelve (12) months preceding the event giving rise to the liability, save for liability that cannot be limited by law. Nothing in this DPA limits either Party's liability to Data Subjects under Applicable Data Protection Law.

11.3 Term. This DPA takes effect on the effective date of the Agreement (or, if later, the date it is agreed) and remains in force for as long as Sference Processes Customer Personal Data.

11.4 Governing law. This DPA is governed by the laws of England and Wales and the Parties submit to the exclusive jurisdiction of the courts of England and Wales, except (a) where the SCCs mandate a different governing law or forum for the transfers they govern, and (b) that nothing prevents mandatory rights of Data Subjects or Supervisory Authorities under Applicable Data Protection Law.

11.5 Severability; updates. If any provision of this DPA is held invalid, the remainder stays in effect. Sference may update this DPA to reflect changes in Applicable Data Protection Law; material changes will be notified to Customer.

Annex 1: Details of Processing

A. Subject matterProvision of the Services (managed inference for open-weight and customer-provided models) by Sference to Customer under the Agreement.
B. DurationThe term of the Agreement plus any post-termination period under Clause 10.
C. Nature of ProcessingReceipt, transient storage, computation (model inference), queuing (for asynchronous and batch workloads), return, and deletion of Customer Content, with associated logging, monitoring, metering, and security Processing. Hosting of customer-provided model weights where applicable.
D. PurposeTo provide, secure, meter, and support the Services in accordance with the Agreement.
E. Categories of Personal DataDetermined by Customer. May include any Personal Data contained in prompts, documents, or other Customer Content (e.g. names, contact details, identifiers, free text relating to identified or identifiable individuals) and in generated outputs; account, usage, and API metadata of Customer's authorised users (names, business emails, API keys, logs).
F. Special categoriesNone intended. Customer must not submit special-category or criminal-conviction data unless the Parties have agreed additional safeguards in writing.
G. Categories of Data SubjectsDetermined by Customer. May include Customer's (or its Controllers') end users, customers, employees, contractors, and suppliers, and any individuals referred to in Customer Content; Customer's authorised platform users.
H. FrequencyContinuous, on demand, as Customer submits workloads during the term.
I. RetentionInference inputs/outputs: transient, only as long as operationally necessary to execute the workload and return results (including queue time for async/batch jobs). API and security logs: limited retention for security, abuse prevention, billing, and support. Customer-provided model weights and stored artifacts: for the term or until deleted by Customer. All subject to Clause 10.

Annex 2: Technical and Organisational Measures

Sference implements and maintains the following measures. Measures may be updated per Clause 4.2.

  1. Access control. Role-based access control, least privilege, multi-factor authentication for administrative access, unique accounts, access reviewed and revoked promptly on role change or departure.
  2. Encryption. Customer Content encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent). Key management restricted to authorised personnel.
  3. Network and API security. Segmented network architecture, firewalls, DDoS protection, per-customer scoped API keys, rate limiting.
  4. Data residency. Inference and storage of Customer Content on infrastructure located within the EEA.
  5. Data minimisation and no training. Only Personal Data necessary to execute Customer's instructions is Processed. Customer Content is not used to train Sference's or any third party's models except as permitted by Clause 2.6.
  6. Model isolation. Customer-provided weights and fine-tunes are logically isolated per customer and served only to that customer.
  7. Personnel. Written confidentiality obligations; data protection and security awareness appropriate to role.
  8. Logging and monitoring. Audit logging of administrative and data access events, centralised log retention, error and availability alerting.
  9. Incident response. Defined incident response and escalation process; breach notification aligned with Clause 8.
  10. Business continuity. Backups of platform state and recovery procedures. Customer Content in inference pipelines is transient and excluded from long-term backups.
  11. Sub-processor vetting. Security and data protection due diligence before engagement; written flow-down agreements (Clause 5.3).
  12. Physical security. Compute infrastructure operated in datacentres certified to recognised standards (ISO/IEC 27001, SOC 2, or equivalent), with physical access controls, environmental controls, and 24/7 monitoring.
  13. Secure development. Code review, dependency and vulnerability scanning, separation of production and development environments.

Annex 3: Authorised Sub-processors

The current list of authorised Sub-processors is maintained at sference.com/legal/subprocessors and is incorporated into this DPA by reference. Changes follow Clause 5.2.

Annex 4: International Transfer Provisions

Where a Restricted Transfer takes place in connection with the Services:

Transfers from the EEA are governed by the EU SCCs (Decision (EU) 2021/914), incorporated by reference with the following selections: Module Two (Controller to Processor) where Customer is a Controller; Module Three (Processor to Processor) where Customer is a Processor; Clause 7 (docking): applies; Clause 9(a): Option 2 (general authorisation) with the notice period in Clause 5.2 of this DPA; Clause 11(a) optional redress: does not apply; Clause 17 governing law: Ireland (or the law of the exporter's Member State where mandatory); Clause 18 forum: the courts of the country whose law governs; Annex I.A/I.B/I.C: completed by reference to the Agreement, Annex 1, and the competent Supervisory Authority of the exporter; Annex II: completed by reference to Annex 2; Annex III: completed by reference to Annex 3.

Transfers from the UK are governed by the UK Addendum to the EU SCCs (or, where agreed, the UK IDTA), with tables completed by reference to this DPA and its annexes, and with either Party able to end the Addendum as set out in Section 19 of the Addendum.

Adequacy first. No transfer mechanism is required where the transfer is to a country, sector, or framework covered by a valid adequacy decision or adequacy regulations (including EEA-UK transfers under the UK adequacy decision and transfers to EU-US Data Privacy Framework certified recipients, for as long as such decisions remain valid).

Sference is a trading name of Neural Compute Ltd (England & Wales, company no. 17195150). Data protection contact: [email protected]. To request a countersigned copy of this DPA, contact us at the same address.