Data Processing Addendum

Last updated: 2026-07-17

In plain English: if you're building on Ringside, you're the controller and we're the processor. You decide what personal data reaches the API. We only process it to run the service, and we delete or return it within 30 days of you leaving. We use sub-processors, they're listed publicly, and we tell you 30 days before we add one. No signature needed, this takes effect when you send your first request.

This DPA supplements the Ringside Terms of Service for customers who are "controllers" of personal data processed by Fight Club as a "processor" under the UK GDPR, EU GDPR, or equivalent laws. It takes effect automatically when you create a Ringside API account or send your first request to the API; no signature is required, though one is available on request (privacy@fightclub.pro).

1. Definitions

"Controller", "Processor", "Personal Data", "Processing", "Data Subject" follow the UK/EU GDPR meanings. "Customer Data" means personal data you provide to us or instruct us to process through the Ringside API (including your end-users' prompts, conversation history, usage events).

2. Subject matter & scope

We process Customer Data solely to provide the Ringside API described in our documentation, per your instructions issued through the API, dashboard, and these terms. You determine the purposes and means of processing; we are a processor.

3. Duration

Processing continues for as long as your account is active. On termination, we delete or return Customer Data within 30 days unless you instruct otherwise or retention is required by law.

4. Nature of processing

5. Data subject categories

Your (the controller's) customers and end-users whose data you send to the Ringside API.

6. Data categories

Identifiers (user/customer IDs you assign), prompt content, LLM outputs, metadata (tags, properties, session IDs), usage timestamps. You control what additional personal data you submit.

7. Our obligations

8. Sub-processors

You authorise us to use the sub-processors listed at /sub-processors. We notify you at least 30 days before adding a new sub-processor; you may object (leading to termination of the affected service) within that window. All sub-processors are contractually bound to protections no less protective than this DPA.

9. Technical & organisational measures

The measures we have in place today:

10. International transfers

Primary storage is in the EU (Germany), and encrypted off-site backups go to OVH in France (EU). Inference routing is separate from storage: by default, prompts are processed in the US via sub-processors including OpenRouter, OpenAI, Anthropic, Google (Gemini and Vertex), AWS Bedrock, Groq and others listed at /sub-processors. EU-region inference is available on providers that offer it (for example AWS Bedrock and Google Vertex) via region suffixes; DeepSeek processing occurs in China. Where Customer Data is transferred to a non-adequate country, we rely on the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.

11. Audit

Once per 12 months, you may request a written summary of our technical and organisational measures and our sub-processor list. On 30 days' notice and subject to a mutually agreed confidentiality agreement, you may audit the parts of our environment that process your Customer Data.

12. Contact

Privacy/DPA questions: privacy@fightclub.pro.