Try the new DeepSeek V4 Pro 0813 today. Frontier intelligence at a fraction of the cost. Here

Data Processing Agreement

Baseten Data Processing Addendum

Last Updated: August 27, 2026

This Data Processing Addendum (this "DPA") is incorporated into and forms part of the Baseten Terms and Conditions available at https://www.baseten.co/terms, or other written agreement between Baseten Labs, Inc., a Delaware corporation, with offices at 560 Davis St., Suite 250, San Francisco, CA 94111 ("Baseten") and Customer (each a "Party" and together the "Parties") governing Customer's use of the Services (in either case, the "Agreement"), and applies to the extent Baseten Processes Customer Personal Data on behalf of Customer in connection with the Services. This DPA governs Baseten's Processing of Customer Personal Data under the Agreement. Capitalized terms not defined in this DPA have the meanings set forth in the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA controls. If Baseten and Customer have entered into a separately executed data processing agreement or addendum, that executed agreement governs Baseten's Processing of Customer Personal Data instead of this online DPA.

  1. Definitions

"Applicable Data Protection Laws" means all privacy, data protection, and data security laws applicable to the Processing of Customer Personal Data, including the GDPR, UK GDPR, and U.S. Privacy Laws (each as and where applicable).

"CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and any binding regulations promulgated thereunder.

"Controller" means the entity that determines the purposes and means of the Processing of Personal Data, including any "business" as defined by the CCPA.

"Customer Personal Data" means any Personal Data comprised within Customer Content and Processed by Baseten or its Sub-Processors on behalf of Customer to perform the Services under the Agreement.

"Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates.

"GDPR" means as applicable: (i) the General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); and/or (ii) the EU GDPR as incorporated into UK law ("UK GDPR"), including applicable national implementing legislation.

"Personal Data" means "personal data," "personal information," "personally identifiable information," or any similar term defined in Applicable Data Protection Laws.

"Personal Data Breach" means a breach of Baseten's security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in Baseten's possession. Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data (such as unsuccessful log-in attempts, pings, port scans, or denial-of-service attacks).

"Process" means (and its inflections) any operation performed on Personal Data, whether or not by automated means.

"Processor" means the entity that Processes Personal Data on behalf of the Controller, including any "service provider" as defined by the CCPA.

"Restricted Transfer" means any transfer of Customer Personal Data to a jurisdiction that does not benefit from an adequacy decision, which would be prohibited without a legal basis under Chapter V of the GDPR.

"SCCs" means the standard contractual clauses approved by the European Commission pursuant to Implementing Decision (EU) 2021/914.

"Sub-Processor" means any third party appointed by or on behalf of Baseten to Process Customer Personal Data.

"U.S. Privacy Laws" means the CCPA and all other applicable comprehensive U.S. state privacy laws.

  1. Scope

This DPA applies to Baseten's Processing of Customer Personal Data under the Agreement to the extent subject to Applicable Data Protection Laws. Schedule 1 (European Annex) applies if and to the extent Processing is subject to the GDPR. Schedule 2 (U.S. Privacy Annex) applies if and to the extent Processing is subject to U.S. Privacy Laws.

  1. Roles of the Parties

  2. Roles. The Parties acknowledge and agree that with regard to the Processing of Customer Personal Data: (a) Baseten acts as a Processor; (b) Customer acts as a Controller, or as a Processor on behalf of its own controllers; and (c) Baseten will engage Sub-Processors pursuant to Section 7.

  3. Customer's Role. Customer shall, in its use of the Services and provision of instructions, Process Customer Personal Data in accordance with Applicable Data Protection Laws. Customer has sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired it. Where Customer is acting as a Processor on behalf of its own controllers, Customer represents and warrants that it has all necessary authority to instruct Baseten to Process such Customer Personal Data on the same terms set forth in this DPA, including the right to engage Baseten and Sub-Processors as authorized hereunder.

  4. Baseten's Role. Baseten shall Process Customer Personal Data only on Customer's Documented Instructions (defined in Section 4.1) or as required by applicable law.

  5. Processing of Customer Personal Data

  6. Documented Instructions. The Parties agree that this DPA, the Agreement (including any Order Form), and Customer's configuration and use of the Services through the interfaces and APIs made available by Baseten constitute Customer's documented instructions to Baseten regarding the Processing of Customer Personal Data ("Documented Instructions"). Baseten will Process Customer Personal Data only in accordance with Documented Instructions (which, if Customer is acting as a Processor, may be based on the instructions of Customer's own controllers) or as required by applicable law. Additional instructions outside the scope of the Documented Instructions require prior written agreement between the Parties, including agreement on any additional fees payable for carrying out such instructions. If Baseten declines to follow instructions requested by Customer that are outside the scope of, or changed from, those given in or agreed to under this DPA, Customer may terminate this DPA and the Agreement in accordance with the termination provisions of the Agreement.

  7. Instructions Conflicting with Law. If Baseten forms the opinion that an instruction from Customer infringes Applicable Data Protection Laws, Baseten will promptly inform Customer, in which case Customer is entitled to withdraw or modify its instruction. Customer acknowledges that, taking into account the nature of the Processing, it is unlikely Baseten will be able to form an opinion on whether a Documented Instruction infringes Applicable Data Protection Laws.

  8. Details of Processing. The details of Processing are described in Annex A (Data Processing Details).

  9. No Training. Consistent with the Agreement, Baseten will not use Customer Personal Data to train, fine-tune, or otherwise develop machine learning or artificial intelligence models.

  10. Data Retention. Where the Services are provided under a Zero Data Retention posture (as described in the Security Practices https://www.baseten.co/security-practices), Baseten shall not log, record, or save Customer Personal Data contained in model inputs or outputs to persistent storage after real-time processing, subject to the product-specific practices and limited exceptions described in the Security Practices. Baseten may retain Usage Information (as defined in the Agreement) and metadata necessary for billing and technical operations, provided such information does not contain Customer Personal Data.

  11. Baseten Personnel

Baseten shall take commercially reasonable steps to ensure the reliability of personnel who Process Customer Personal Data, ensure such personnel are subject to written confidentiality obligations, and conduct background screening for personnel with logical access to Customer Personal Data.

  1. Security

Baseten shall implement and maintain technical and organizational measures as described in the Security Practices and Annex B (Security Measures), designed to protect Customer Personal Data against a Personal Data Breach. Baseten may update the Security Measures from time to time, provided the updated measures do not materially decrease the overall protection of Customer Personal Data.

  1. Sub-Processing

  2. Subprocessors. Customer generally authorizes Baseten to appoint Sub-Processors, including those listed at https://trust.baseten.co/ (the "Sub-Processor List"). Baseten will ensure each Sub-Processor is bound by a written agreement with data protection obligations substantially similar to this DPA. Baseten will be liable for any breach caused by a Sub-Processor to the extent Baseten would have been liable had the breach been caused by Baseten. Baseten shall notify Customer at least fifteen (15) days prior to engaging a new Sub-Processor by updating the Sub-Processor List or sending notification.

  3. Objection Right for New Subprocessors. Customer may object in writing to a new Sub-Processor based on reasonable data protection concerns by emailing privacy@baseten.co within ten (10) calendar days of notice. The Parties will discuss in good faith and if unable to resolve, Baseten will either (a) use reasonable efforts to make a commercially reasonable change to avoid use of that Sub-Processor; or (b) where such change is not feasible within thirty (30) days, either Party may terminate the affected portion of the Agreement, and Baseten will refund prepaid fees allocable to the period after termination. Infrastructure Providers (as defined in the Agreement) are not Sub-Processors under this DPA unless they have logical access to Customer Personal Data.

  4. Data Subject Rights

Baseten shall provide Customer with reasonable assistance to fulfill obligations to respond to data subject requests, to the extent required by Applicable Data Protection Laws. If Baseten receives a data subject request, Customer will be responsible for responding. Baseten shall promptly notify Customer and shall not respond except on Customer's instructions or as required by law.

  1. Personal Data Breach; Return and Deletion

  2. Breach Notification. Baseten shall notify Customer without undue delay, and in any event within forty-eight (48) hours, upon discovering a Personal Data Breach affecting Customer Personal Data. Baseten shall provide information to assist Customer in meeting obligations under Applicable Data Protection Laws.

  3. Cooperation. Baseten shall reasonably cooperate with Customer and take commercially reasonable steps to assist in investigation and mitigation of any Personal Data Breach. Customer is solely responsible for complying with notification laws and fulfilling third-party notification obligations. If Customer's notification identifies Baseten, Customer agrees to notify Baseten in advance and consider reasonable clarifications.

  4. Return and Deletion. Upon cessation of Services involving Processing of Customer Personal Data, Baseten shall cease Processing except for storage or as permitted under this DPA. For thirty (30) days following cessation (the "Post-Term Period"), Customer may retrieve Customer Personal Data via the Services. On written request during the Post-Term Period, Baseten shall within thirty (30) days either (a) return a complete copy by secure transfer, or (b) delete all Customer Personal Data. If Customer does not instruct Baseten during the Post-Term Period, Baseten shall promptly delete all Customer Personal Data following expiry of the Post-Term Period. Baseten may retain Customer Personal Data where required by applicable law, subject to confidentiality and purpose limitation.

  5. Audit Rights

Baseten shall make available to Customer, on request, information reasonably appropriate to demonstrate compliance with this DPA, including its most recent SOC 2 Type II report under NDA. If Customer provides documentary evidence that the information above in this Section 10 is insufficient, Baseten shall allow audits by Customer or its mandated auditor, subject to: (a) at least fourteen (14) days' advance notice; (b) a mutually agreed audit plan; (c) reasonable time, place, and manner conditions; (d) confidentiality obligations; and (e) no more than once annually unless required by a regulator. Where controls are addressed in a SOC 2 Type II or similar audit report within twelve (12) months, Customer agrees to accept such report in lieu of auditing those controls. Customer shall reimburse Baseten's reasonable costs for cooperation under this Section 10 at Baseten's then-current professional services rates.

  1. Liability

The total aggregate liability of either Party under this DPA shall be subject to the limitations and exclusions of liability in the Agreement. Nothing in this Section affects any person's liability to Data Subjects under the SCCs.

  1. Cross-Border Transfers

To the extent Processing involves a Restricted Transfer from Customer to Baseten, the Parties shall comply with the SCCs incorporated by reference as set forth in Schedule 1. Baseten may replace the SCCs with any new or replacement transfer mechanism enabling lawful transfer under Chapter V of the GDPR upon notice to Customer.

  1. Precedence

This DPA is incorporated into the Agreement. In the event of conflict: (a) this DPA prevails over the Agreement with respect to the Processing of Customer Personal Data; and (b) the SCCs prevail over this DPA and the Agreement with respect to the applicable Restricted Transfer.


Annex and Schedule List

Annex A: Data Processing Details

Annex B: Security Measures

Schedule 1: European Annex

Schedule 2: U.S. Privacy Annex

Annex A: Data Processing Details

Baseten (Data Importer / Processor): Baseten Labs, Inc., 560 Davis St., Suite 250, San Francisco, CA 94111. Contact: privacy@baseten.co. Role: Processor.

Customer (Data Exporter / Controller): As identified in the Agreement. Role: Controller (or Processor on behalf of its own controllers, where applicable).

Categories of Data Subjects: End Users and other users of Customer's products and services; Customer's employees, contractors, and agents; any other Data Subjects whose Personal Data Customer submits to the Services.

Categories of Personal Data: Personal details that Customer causes Baseten to process, which may include name, contact information, and other identifiers submitted by Customer.

Sensitive Data: None by default. Customer must not submit PHI or other special categories of Personal Data to the Services unless a BAA or other supplemental agreement covering such data is in effect.

Frequency of Transfer: Ongoing, as initiated by Customer through its use of the Services.

Nature of Processing: Processing operations required to provide the Services in accordance with the Agreement, including inference, deployment, orchestration, optimization, and monitoring of Customer Models.

Purpose of Processing: To provide the Services as initiated by Customer, and to comply with Customer's Documented Instructions.

Duration / Retention: For the period determined in accordance with the Agreement, this DPA, and the Security Practices, including any applicable Zero Data Retention posture and the thirty (30) day Post-Term Period.

Annex B: Security Measures

The technical and organizational measures Baseten maintains to protect Customer Personal Data are the administrative, physical, and technical safeguards set forth in the Baseten Security Practices, available at https://www.baseten.co/security-practices, which are incorporated into this DPA by reference. The Security Practices include, among other things, Baseten's platform controls, access management, encryption in transit and at rest, product-specific data retention practices (including Zero Data Retention postures), incident management, business continuity, and personnel practices.

Schedule 1: European Annex

  1. Processing Instructions. Where Baseten receives an instruction from Customer that infringes the GDPR, Baseten shall inform Customer.

  2. Data Protection Impact Assessments. Baseten shall provide reasonable assistance, at Customer's cost, with data protection impact assessments and prior consultations with Supervisory Authorities required under Articles 35 or 36 of the GDPR.

  3. Restricted Transfers (EU). To the extent Processing involves an EU Restricted Transfer, the SCCs are deemed entered into and incorporated by reference, applied as follows:

  4. When Customer is acting as a Controller, the Controller-to-Processor Clauses (Module Two) apply.

  5. When Customer is acting as a Processor on behalf of its own controllers, the Processor-to-Processor Clauses (Module Three) apply. Customer acknowledges that Baseten typically has no direct relationship with Customer's controllers and therefore Customer shall fulfil Baseten's obligations to Customer's controllers under Module Three (including the obligation to keep controllers informed and to obtain their authorizations as required).

In each case, the SCCs are populated as follows: Clause 7 (Docking) is omitted; Clause 9 Option 2 (General Written Authorization) applies; Clause 11 optional language is omitted; Clause 17 Option 1 applies (governing law: Ireland); Clause 18 (jurisdiction: Ireland). Annexes to the SCCs are populated with the information in Annex A and Annex B to this DPA.

  1. Restricted Transfers (UK). To the extent Processing involves a UK Restricted Transfer, the SCCs as varied by the UK Transfer Addendum (ICO template Addendum B.1.0) are deemed entered into and incorporated by reference.

  2. Operational Clarifications. Customer shall protect Baseten's trade secrets and confidential information when complying with transparency obligations under the SCCs. Audits under the SCCs are subject to Section 10 of this DPA.

Schedule 2: U.S. Privacy Annex

  1. CCPA. With respect to Customer Personal Data subject to the CCPA:

  2. Baseten acts as a "service provider." Baseten acknowledges that Customer Personal Data is disclosed only for the limited purposes described in the Agreement.

  3. Baseten shall comply with applicable CCPA obligations and provide the same level of privacy protection as required by the CCPA.

  4. Baseten shall not: (i) sell or share any Customer Personal Data; (ii) retain, use, or disclose Customer Personal Data for any purpose other than performing under the Agreement; (iii) retain, use, or disclose Customer Personal Data outside of the direct business relationship; or (iv) combine Customer Personal Data with personal information from other sources, except as permitted by the CCPA.

  5. Customer has the right to take reasonable steps under Section 10 of this DPA to verify Baseten's CCPA compliance.

  6. Other U.S. State Privacy Laws. To the extent other U.S. state privacy laws apply, Baseten shall Process Customer Personal Data in accordance with Customer's Documented Instructions and shall not use Customer Personal Data for purposes other than performing under the Agreement.

Questions about this DPA? Contact privacy@baseten.co.

Data Processing Agreement