This Data Processing Agreement ("DPA") forms part of the agreement between RENVAR INC ("Elai", "Processor") and a business or enterprise customer ("Customer", "Controller") using Elai Marketplace to manage AI Agents, Digital Employees, or physical-robot fleets on behalf of its own end users or employees. It applies where Customer acts as a data controller and Elai processes personal data on Customer's behalf and instructions.
1. Roles
For personal data that Customer submits to or through the Platform on behalf of its own users (e.g. task inputs sent to an installed Agent, or records of its employees' installations), Customer is the Controller and Elai is the Processor. For Elai's own account/billing relationship with Customer, Elai acts as an independent controller — see our Privacy Policy.
2. Subject matter and duration
Processing covers personal data submitted through the Platform for the duration of Customer's active subscription, plus any post-termination retention period described in Section 7.
3. Nature and purpose of processing
- Operating Agent installations, spend caps, and Agent Passports on Customer's behalf;
- Routing task inputs to the configured AI model provider via the Platform's AI Gateway to generate Agent outputs;
- Maintaining the audit log of actions taken under Customer's account;
- Billing and usage metering.
4. Sub-processors
Elai currently uses the following named sub-processors:
- Stripe (United States) — payment card processing and saved-card storage.
- YooKassa (Russia) — payment processing for transactions in Russian rubles.
- SendGrid (United States) — transactional email delivery (account, order, and dispute notifications).
- Twilio (United States) — SMS delivery, only for users who have opted into SMS notifications.
- Sentry (United States) — application error and crash monitoring, which may incidentally capture an account identifier or email address in a crash report.
- An AI model provider (e.g. OpenAI), reached through Elai's self-hosted AI Gateway — receives the task text a Customer's installed Agent is invoked with, in order to generate the Agent's output. Elai does not send account credentials or payment details to the model provider.
This list reflects the integrations enabled in a given deployment; a deployment operator who has not configured a given provider's credentials is not using that sub-processor. We will update this list if we add a new sub-processor category.
5. Security measures
Elai maintains the following technical and organizational measures:
- Passwords are hashed with a salted scrypt derivation; Elai never stores a plaintext password.
- Optional two-factor authentication (TOTP) with one-time backup codes.
- Role-based access control (buyer/developer/admin roles) enforced on every authenticated API route, plus scoped API credentials (Agent Passports) with configurable spend caps for AI Agent installs.
- An append-only audit log recording the actor, action, and outcome of account and admin actions.
- Rate limiting on authentication and API endpoints, backed by Redis where available.
- TLS encryption in transit for all traffic to the Platform (automatically provisioned via Let's Encrypt).
- Automated content-scanning of listings for known prompt-injection and malicious-command patterns.
- Self-service data export and account deletion tools (see our Privacy Policy).
Elai does not currently encrypt data at rest at the application level, and has not obtained a third-party security certification (e.g. SOC 2, ISO 27001). If either matters for your use case, contact us using the details in Section 10 before relying on the Platform for it.
6. International transfers
The Platform runs on a self-hosted server whose hosting region is chosen by the deployment operator and is not fixed to a specific country or cloud region as a matter of this Agreement. Elai does not currently rely on a formal cross-border transfer mechanism (such as Standard Contractual Clauses) because no fixed transfer corridor is committed to here. If your use of the Platform requires data to stay within, or be transferred under a specific safeguard for, a particular jurisdiction, contact us using the details in Section 10 before relying on the Platform for that requirement.
7. Data deletion and return
On termination of Customer's subscription, Elai will, at Customer's request, delete or return personal data processed on Customer's behalf, subject to any retention required by law.
8. Assistance with data subject requests
Elai will provide reasonable assistance to Customer in responding to data subject requests (access, correction, deletion, portability) concerning personal data processed under this DPA.
9. Audit rights
On reasonable written request, no more than once per 12-month period, Elai will provide Customer with the security and processing information reasonably necessary to confirm Elai's compliance with this DPA (e.g. a written description of the measures in Section 5). Elai does not currently hold a third-party security certification to offer in lieu of a direct audit, and does not offer on-site audits at this time.
10. Contact
Data processing / DPA questions: renvar.inc@gmail.com.