Standard template · last updated July 25, 2026
This DPA is between the Customer ("Customer", the controller) and Astral AI Inc. ("Rampt", the processor), and forms part of the agreement under which Rampt provides its service. Where GDPR or similar law applies, "controller" and "processor" carry their statutory meanings.
Rampt shall: (a) process personal data only on the Customer's documented instructions, the configuration file being the primary standing instruction; (b) ensure persons processing the data are bound by confidentiality; (c) implement the technical and organizational measures of Annex B; (d) not use personal data to train AI models, and make no AI model calls against end-user personal data at service runtime; (e) assist the Customer, taking into account the nature of processing, in responding to data subject requests (access, deletion, portability), noting that the Customer can serve most such requests self-serve via the raw export and deletion controls; (f) notify the Customer without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting the Customer's workspace; (g) delete or return all personal data within 30 days of termination, deletion confirmed in writing on request; (h) make available information reasonably necessary to demonstrate compliance, and allow audits as set out in section 5.
Current subprocessors: Vercel Inc. (hosting), Neon Inc. (managed database). The Customer authorizes these and grants general authorization for replacements, subject to 30 days' advance notice and the right to object on reasonable data-protection grounds; equivalent obligations flow down to every subprocessor by contract.
Rampt's processing is inspectable by design: the complete event schema is public, every message shown to an end user is logged verbatim and exportable, denied actions are logged (including Rampt's own per-session enforcement probe), and the Customer can export its raw data at any time without Rampt's involvement. On written request, Rampt will additionally provide its then-current security documentation and reasonable written responses to audit questionnaires, no more than twice per year absent a breach or regulator requirement.
Where personal data is transferred from jurisdictions requiring a transfer mechanism, the parties incorporate the applicable Standard Contractual Clauses, and Rampt will maintain records of subprocessor hosting regions.
Liability under this DPA is subject to the limitations of the main agreement, except where data protection law does not permit such limits. Where this DPA conflicts with the main agreement on data protection matters, this DPA prevails.
In place now:
Planned, stated as roadmap and not as current fact: SOC 2 Type II examination; independent penetration test. Rampt will not represent either as complete until it is, and will provide reports to the Customer when they exist.
Vercel Inc., hosting, USA. Neon Inc., managed Postgres, region per workspace. (Stripe Inc. processes Customer billing as an independent controller and is listed here for completeness, not as a subprocessor of end-user data.)