Skip to content
Trust

Data processing addendum

Standard structure, written for the gateway, which is the only path this deployment serves and therefore the only one where Finest processes customer content on your behalf.

Last updated 2026-08-01

1. Parties, and how this fits together

This addendum is between you and PM Frontier LLC, a Wyoming limited liability company and forms part of the terms of service. It applies where Finest processes personal data on your behalf. Where this addendum and the terms conflict on data protection, this addendum wins; where it conflicts with the Standard Contractual Clauses, the Clauses win.

“Data Protection Law” means the UK GDPR and Data Protection Act 2018, the EU General Data Protection Regulation, the Swiss Federal Act on Data Protection, and the US state privacy statutes, each as applicable to the processing.

2. Roles and definitions

Controller: You. You decide what is sent to a model and why.

Processor: Finest, on Door 1 only, and solely to serve the request and produce its receipt. For your account, our website and our own operations, PM Frontier LLC is a controller in its own right, and the privacy policy covers that.

Customer content: Prompts, completions, tool and schema definitions, and any evaluation data you supply.

Operational metadata: Route identifiers, the exact configuration tuple, token counts, latency, cost, validator outcomes and receipt references. It contains no customer content.

3. Scope and instructions

Finest processes customer content only to perform the service: serving a Door 1 request, computing its cost evidence, and running a verification you have approved against evidence you have supplied. Your configuration is the documented instruction. We do not process customer content for any other purpose, and specifically do not use it to train, fine-tune, distil, benchmark or evaluate models, whether for our own benefit or anyone else’s. Section 8 of the terms states that as a limit on the licence you grant, so it is not merely a promise in this document.

We will tell you if we believe an instruction of yours breaches Data Protection Law, and may pause the processing concerned until it is resolved.

4. Details of the processing

Subject matter and nature. Transmission of a request to the model provider you addressed, in-memory validation of the response, computation of a receipt, and storage of operational metadata. Prompt and completion content is processed in memory and is not stored: no table in the system has a column for it.

Purpose. Providing the service described in the terms, and nothing else.

Duration. For the term of the agreement, plus the retention described in clause 10.

Categories of data subject. Your personnel and authorised users, and any individual whose personal data you choose to include in a prompt.

Types of personal data. For account data: business email address, name where you supply it, workspace role, authentication records, billing contact. For gateway traffic: whatever you send, which is under your control. Special-category data, health data, payment card data, government identifiers and children’s data must not be sent; see the acceptable use policy. We have not implemented the controls those categories require and will not pretend a schema with no content column is a substitute for them.

Frequency. Continuous, for as long as your application sends requests.

5. Security measures

Tenant isolation is enforced in the database by row-level security, forced on the tenant tables, and the application connects as a role with data-manipulation rights only: it cannot alter schema or policy. A query that fails to claim a workspace returns zero rows rather than another tenant’s. Migration, runtime, worker, queue, catalogue-admission and erasure privileges are separate database principals, and the services refuse to start against a database login that is over-privileged.

Policy signing keys are held in AWS KMS and are not extractable by the application. Provider credentials are referenced by opaque handle bound to one workspace and provider; there is no code path that accepts raw key material, and key material never appears in the database, in API responses, in audit payloads or in logs. Identifiers that would tie a stored record to an individual are pseudonymized with a per-workspace derived key before storage.

Data is encrypted in transit with TLS and at rest by the managed storage layer. Access to production is limited to personnel who need it, through federated single sign-on. Errors sent to our error tracker are rebuilt from an allowlist so request bodies, local variables and credentials are absent by construction. Evidence and receipt journals are append-only by database constraint, and deletion requires a separately privileged role plus an explicit per-transaction flag that no request-path code sets.

Backups are automated with a 14-day point-in-time-recovery window. A restore procedure is documented; a full production restore drill has not yet been recorded, and we say so here rather than let a reader assume it. The current, dated picture, including what is not built, is on the security page.

6. Personnel and confidentiality

Personnel with access to personal data are bound by confidentiality obligations that survive their engagement, receive access on the principle of least privilege, and lose it when they no longer need it. Finest is a very small organisation, and where a control depends on separation of duties that a team of this size cannot provide, the security page says so rather than implying an org chart we do not have.

7. Sub-processors

You authorise the sub-processors published at /sub-processors. That page is updated before a new sub-processor is switched on, and the change is recorded in the changelog. To be notified in advance by email, subscribe using the mechanism on that page, and we will give at least 30 days’ notice of an addition that would process customer content.

You may object to a new sub-processor on reasonable data protection grounds within that notice period. We will work with you to find an alternative, and if there is none, you may terminate the affected part of the service and we will refund the unused purchased Credits attributable to it. We impose data protection obligations on each sub-processor no less protective than these, and we remain responsible for their performance.

Model providers are addressed separately on that page, because which providers see your traffic is a routing decision you make and can audit from your receipts.

8. International transfers

The service runs in AWS US East (N. Virginia), us-east-1, so personal data you send is processed in the United States. There is no per-workspace region selection today.

Where personal data is transferred out of the UK, the EEA or Switzerland, the transfer relies on the European Commission’s Standard Contractual Clauses of 4 June 2021, Module Two (controller to processor), which are incorporated into this addendum by reference. For those Clauses: clause 7 (docking) applies; clause 9 option 2 (general written authorisation) applies with the notice period in clause 7 above; clause 11’s optional independent dispute resolution does not apply; clause 17 selects the law of Ireland; clause 18(b) selects the courts of Ireland. Annexes I and II are populated by clauses 4 and 5 of this addendum, and Annex III by the sub-processor page.

For UK transfers, the Clauses are modified by the UK International Data Transfer Addendum (version B1.0), with Tables 1 to 3 populated by this addendum, and neither party may terminate under Table 4 except as Data Protection Law requires. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the Federal Data Protection and Information Commissioner is the competent authority.

On Door 1, sending content to a provider outside the United States is a routing decision you make and control. Each provider’s stated region is listed on the sub-processor page, and whether a transfer to it is lawful for your data is your assessment to make.

9. Data subject requests, and helping you comply

If a data subject contacts us about content you sent through Door 1, we will not respond on the substance and will refer them to you, unless the law requires otherwise. We will help you respond to access, correction, deletion, portability and objection requests, taking into account the nature of the processing, using the console’s own export and deletion paths where they can do the work.

We will also give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority, to the extent it concerns our processing and is not available to you already from this site.

10. Personal data breach, and deletion

We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your personal data, with what is known at the time rather than waiting for a complete picture, and will follow up as the picture completes. We will describe the nature of the breach, the categories and approximate volume affected, the likely consequences, and the measures taken. Notice is not an admission of fault.

On termination, or on your request at any time, we will delete personal data we process on your behalf within 30 days, except where we are required by law to keep it or need it to substantiate an amount billed or in dispute. Encrypted backups continue to contain deleted records until they age out of the 14-day recovery window. Before deletion you can export your routes, policies, evidence records and receipts and verify the export stands independently of Finest. On written request we will confirm deletion.

11. Audit

On request, no more than once a year and under confidentiality, we will provide the documentation we hold about our security and processing, and answer a reasonable security questionnaire. No SOC 2 or ISO 27001 report exists today; when one does, it will be named here with its period rather than referred to in the abstract.

Where Data Protection Law or a supervisory authority requires an inspection that documentation cannot satisfy, we will accommodate a remote audit, scoped in advance, at your cost, conducted by an independent auditor who is not a competitor and is bound by confidentiality, and arranged so it does not disrupt the service or expose another customer’s data.

12. United States state privacy law

For personal information subject to the California Consumer Privacy Act as amended, and to the comparable statutes of other US states, Finest is a service provider and processor, not a third party. We process personal information only to perform the service and for the business purposes in the terms.

We do not sell personal information and do not share it for cross-context behavioural advertising. We do not retain, use or disclose it outside the direct business relationship, do not combine it with personal information from another source except as permitted for a service provider, and will notify you if we determine we can no longer meet these obligations. You may take reasonable steps to confirm we are using personal information consistently with your obligations, through clause 11. Sub-processors are engaged under the same restrictions.

13. Liability, and executing this

Each party’s liability under this addendum is subject to the limitations and exclusions in section 16 of the terms of service, except where Data Protection Law does not permit that.

This page is the current text and applies automatically where the law requires a processor agreement. If you need a countersigned instrument, or an order form that varies these clauses, contact us and we will send one for signature.

This addendum is operated by PM Frontier LLC, a Wyoming limited liability company. Legal notices take effect when delivered in writing to:

PM Frontier LLC30 N Gould StSheridan, WY 82801United States

Email to [email protected] reaches us faster and is sufficient for everything except a formal notice under the terms. Other routes are on the contact page.

Data processing addendum · Finest