Blaxel is joining Baseten. Read more

DORA Addendum

DORA Addendum

About This Document; When This Addendum Applies.

This is Baseten's standard DORA Addendum, for customers that are financial entities regulated under the EU Digital Operational Resilience Act. It does not apply by default: it applies only where Baseten and the customer have executed it or incorporated it by reference in an Order Form or other written agreement between them. If the version you executed or incorporated differs from this page, that version governs.

To put this DORA Addendum in place, contact support@baseten.co.

This Digital Operational Resilience Act Addendum ("DORA Addendum") is entered into between Baseten Labs, Inc., a Delaware corporation with offices at 560 Davis St., Suite 250, San Francisco, CA 94111 ("Baseten"), and the Customer identified in the relevant Order Form ("Customer") (each a "Party" and together the "Parties"). This DORA Addendum is supplemental to, and forms part of, the Baseten Terms and Conditions available at https://www.baseten.co/terms-and-conditions, the Master Services Agreement, and/or any other written agreement between Baseten and Customer, including the Data Processing Addendum (in all cases, the "Agreement"). Capitalized terms not defined in Section 1 have the meanings ascribed to them elsewhere in the Agreement (including the DPA) or in applicable law, unless otherwise specified.

Baseten provides cloud-based inference infrastructure for machine learning models. Customer acknowledges that Baseten is not, and shall not be considered, the developer, provider, or deployer of any machine learning or artificial intelligence model processed through the Services. Baseten's role under this DORA Addendum is that of an ICT third-party service provider supplying infrastructure, orchestration, and optimization for Customer Content and Customer Models chosen, configured, and controlled by Customer.

  1. Definitions

"Customer Content" has the meaning set forth in the Agreement and, solely for purposes of this DORA Addendum, includes Customer Personal Data as defined in the DPA.

"DORA" means the Digital Operational Resilience Act, Regulation (EU) 2022/2554, including applicable implementing and delegated acts.

"DPA" means Baseten's Data Processing Addendum, available at https://www.baseten.co/dpa, or other data processing addendum between Customer and Baseten governing the processing of Customer Personal Data by Baseten on behalf of Customer.

"ICT-Related Incident" means a single event or a series of linked events unplanned by Customer that compromises the security of the network and information systems, and that has an adverse impact on the availability, authenticity, integrity, or confidentiality of data, or on the services provided by Customer.

"Regulator" means any European financial-services regulator or national competent authority with monitoring or supervisory rights under Article 26 of DORA over Customer and/or over Baseten as an ICT third-party service provider to Customer.

"Security Practices" means the Baseten Security Practices, available at https://www.baseten.co/security-practices and incorporated by reference into the Agreement, as updated from time to time.

"Services" means the Services as defined in the Agreement.

  1. Scope

  2. Regulated Entities. To the extent Customer is not a "financial entity" as defined in DORA or is otherwise not regulated under DORA, this DORA Addendum shall not apply.

  3. DORA Critical or Important Functions. Customer acknowledges and agrees that Baseten is not, and during the Term of the Agreement is not expected to, provide the Services to Customer in support of a critical or important function of Customer. Should Customer intend to rely on the Services to support a critical or important function, Customer shall notify Baseten in advance so that the Parties may discuss any additional terms required to reflect such use.

  4. Description of the Services and Protection of Customer Content

  5. Description of the Services. A description of Baseten's Services is set forth in the Agreement and the Documentation. Baseten uses Infrastructure Providers and Subprocessors to perform parts of the Services, as further described in the DPA. A list of Infrastructure Providers and Subprocessors is maintained at https://trust.baseten.co/ (the "Sub-Processor List"). Customer may subscribe to changes to the Sub-Processor List as set forth in the DPA.

  6. Location of the Services. Processing locations for Customer Content are set forth in the Sub-Processor List and, where applicable, in the relevant Order Form. Customer controls model deployment locations through region-locking and deployment options described in the Security Practices. Customer Content processing locations may be added or changed in connection with the Services as set forth in the DPA.

  7. Protection of the Services and Customer Content. Baseten will implement technical and organizational controls to protect the availability, authenticity, integrity, and confidentiality of Customer Content, including Customer Personal Data, in accordance with the DPA and the Security Practices. Baseten does not use Customer Content to train, fine-tune, or otherwise develop any machine-learning or artificial-intelligence models.

  8. Access and Return of Customer Content. Baseten provides for the availability, recovery, and return of Customer Content in accordance with the DPA and the Security Practices.

  9. 4. Service Level Descriptions

Baseten's service-level commitments are described in the Agreement and the Documentation. Historical uptime of the Services is available on Baseten's status page at https://status.baseten.co.

  1. ICT Incidents

  2. Support for ICT Incidents. Baseten will provide commercially reasonable assistance to Customer in connection with an ICT-Related Incident that relates to the Services. Where an ICT-Related Incident is not attributable to Baseten or the Services, Customer acknowledges and agrees that Baseten reserves the right to charge commercially reasonable fees, including for personnel costs, for supporting such an ICT-Related Incident.

  3. Notification and Assistance. In the event of an ICT-Related Incident that could have a negative impact on the continuity or security of the Services, Baseten will: (a) without undue delay, and in any event consistent with the 48-hour notification commitment in the Security Practices where applicable, notify Customer of the ICT-Related Incident; and (b) provide Customer with reasonably requested information needed for Customer to mitigate risks associated with the ICT-Related Incident and to meet Customer's regulatory reporting obligations under DORA.

  4. 6. Cooperation with Regulators

To the extent required by applicable law and at Customer's expense, Baseten will reasonably cooperate with a Regulator, including persons appointed by the Regulator or by Customer, to provide information relating to the Services, provided that Customer does not otherwise have access to the relevant information. Baseten's cooperation is subject to the confidentiality and audit-scope limitations set forth in the Agreement, the DPA, and the Security Practices.

  1. 7. Termination Rights

  2. Termination Rights. In addition to the termination rights specified in the Agreement and subject to Section 7.2, Customer may terminate the Agreement: (a) if necessary to comply with Article 28(7) of DORA; (b) if formally required to do so by a Regulator; or (c) if Baseten is unable to demonstrate its compliance with the applicable requirements of DORA.

  3. Right to Cure and Minimum Notice Period. Customer may terminate the Agreement as set forth in Section 7.1, provided that (a) the termination right is limited to the Services subject to this DORA Addendum and (b) Customer gives Baseten written notice describing the nature of the breach, and Baseten has failed to cure the breach within thirty (30) days following receipt of Customer's notice.

  4. Effect of Termination. In the event that Customer terminates the Agreement in accordance with Sections 7.1 and 7.2, the refund or payment-upon-termination-for-cause provisions of the Agreement shall apply.

  5. 8. Security Training

Baseten provides security-awareness training to its personnel, including periodic updates on relevant policies, as described in the Security Practices. Subject to a separate written agreement and where required by applicable law, Baseten personnel may, at Customer's expense, participate in Customer's DORA training, provided that such training is reasonable and relevant to the Services.

  1. 9. Miscellaneous

  2. Term and Termination. This DORA Addendum shall terminate automatically upon the expiration or termination of the Agreement.

  3. Conflict. In the event of a conflict between the Agreement and this DORA Addendum as it relates to Customer's obligations under DORA, the terms of this DORA Addendum shall control. All other terms of the Agreement, including the Limitation of Liability provisions, remain in full force and effect.

  4. Remedy. Customer's sole and exclusive remedy for any breach by Baseten in relation to this DORA Addendum is to terminate this DORA Addendum and the Order Form for the affected Services. For the purposes of this DORA Addendum, the rights and obligations of the Parties are in addition to, and not in replacement of, the rights and obligations of the Parties under the Agreement, except that this Section 9 will prevail over any conflicting term in the Agreement. Except as amended by this DORA Addendum, the Agreement remains in full force and effect. Except to the extent otherwise mandated by applicable law, this DORA Addendum will be governed by and construed in accordance with the governing-law and jurisdiction provisions in the Agreement.

To put this DORA Addendum in place or ask questions, contact support@baseten.co.