Data Processing Addendum
Last updated: 2026-07-17
In plain English: if you're building on Ringside, you're the controller and we're the processor. You decide what personal data reaches the API. We only process it to run the service, and we delete or return it within 30 days of you leaving. We use sub-processors, they're listed publicly, and we tell you 30 days before we add one. No signature needed, this takes effect when you send your first request.
This DPA supplements the Ringside Terms of Service for customers who are "controllers" of personal data processed by Fight Club as a "processor" under the UK GDPR, EU GDPR, or equivalent laws. It takes effect automatically when you create a Ringside API account or send your first request to the API; no signature is required, though one is available on request (privacy@fightclub.pro).
1. Definitions
"Controller", "Processor", "Personal Data", "Processing", "Data Subject" follow the UK/EU GDPR meanings. "Customer Data" means personal data you provide to us or instruct us to process through the Ringside API (including your end-users' prompts, conversation history, usage events).
2. Subject matter & scope
We process Customer Data solely to provide the Ringside API described in our documentation, per your instructions issued through the API, dashboard, and these terms. You determine the purposes and means of processing; we are a processor.
3. Duration
Processing continues for as long as your account is active. On termination, we delete or return Customer Data within 30 days unless you instruct otherwise or retention is required by law.
4. Nature of processing
- Storage, retrieval, transmission of prompts + completions.
- Routing prompts to upstream LLM providers (see sub-processors). Inference runs in the US by default; EU-region routing is available on providers that offer it via region suffixes.
- Billing, usage analytics, abuse detection, support.
- Where you configure them, transmitting Customer Data to your own endpoints (for example SIEM, ServiceNow or PAM webhooks). These are your systems, not our sub-processors, and you control what is sent.
5. Data subject categories
Your (the controller's) customers and end-users whose data you send to the Ringside API.
6. Data categories
Identifiers (user/customer IDs you assign), prompt content, LLM outputs, metadata (tags, properties, session IDs), usage timestamps. You control what additional personal data you submit.
7. Our obligations
- Process Customer Data only on your documented instructions.
- Ensure anyone authorised to process is under confidentiality obligations.
- Implement appropriate technical and organisational measures (see § 9).
- Assist you in responding to data subject requests (Art. 15-22).
- Assist you with DPIAs and prior consultations (Art. 35-36).
- Notify you of personal data breaches without undue delay and in any event within 72 hours of becoming aware.
- Delete or return Customer Data on termination.
8. Sub-processors
You authorise us to use the sub-processors listed at /sub-processors. We notify you at least 30 days before adding a new sub-processor; you may object (leading to termination of the affected service) within that window. All sub-processors are contractually bound to protections no less protective than this DPA.
9. Technical & organisational measures
The measures we have in place today:
- Encryption in transit, and field-level encryption at rest for sensitive values (vault keys, provider API keys, IP addresses) using AES-256-GCM.
- Per-user password hashing with scrypt; the vault password is never stored, only a verifier.
- Mutual TLS between internal services.
- Tenant isolation on the Ringside API: a cross-tenant request returns 404, not 403, so it cannot be used to confirm that another tenant's record exists.
- Role-based access control on admin surfaces, with audit logging of privileged Ringside admin actions.
- Database backups encrypted before they leave our servers, rotated on a 30-day window.
10. International transfers
Primary storage is in the EU (Germany), and encrypted off-site backups go to OVH in France (EU). Inference routing is separate from storage: by default, prompts are processed in the US via sub-processors including OpenRouter, OpenAI, Anthropic, Google (Gemini and Vertex), AWS Bedrock, Groq and others listed at /sub-processors. EU-region inference is available on providers that offer it (for example AWS Bedrock and Google Vertex) via region suffixes; DeepSeek processing occurs in China. Where Customer Data is transferred to a non-adequate country, we rely on the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
11. Audit
Once per 12 months, you may request a written summary of our technical and organisational measures and our sub-processor list. On 30 days' notice and subject to a mutually agreed confidentiality agreement, you may audit the parts of our environment that process your Customer Data.
12. Contact
Privacy/DPA questions: privacy@fightclub.pro.