Last Updated / May 13, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between RightNow AI, Inc. (“RunInfra,” “we,” “us”) and the customer (“Customer,” “you”) whenever the Service processes personal data on the Customer's behalf. It implements the GDPR Article 28 processor obligations and the equivalent obligations under the UK GDPR, the California Consumer Privacy Act (“CCPA”), and other applicable data protection law.
This DPA is offered as a standing agreement. By signing up for a paid plan, accepting an enterprise order form, or otherwise using the Service to process personal data belonging to data subjects, the Customer accepts this DPA in full. Enterprise customers requiring a signed counter-party copy can request one at legal@runinfra.ai.
Defined terms not specified in this DPA take the meaning given in the Terms of Service and the Privacy Policy.
This DPA applies whenever RunInfra processes personal data on the Customer's behalf in connection with the Service. RunInfra acts as a processor; the Customer acts as the controller and determines the purpose and means of the processing.
Where the Customer is itself a processor acting on behalf of a third-party controller, RunInfra acts as a sub-processor and the Customer represents that it has obtained the controller's prior authorization for RunInfra's engagement.
RunInfra processes personal data for its own purposes (account administration, billing, security, product improvement on aggregated and anonymized data) as a controller. Those activities are governed by the Privacy Policy and not by this DPA.
Subject matter. RunInfra processes Customer Personal Data to provide the Service: profiling models, optimizing inference pipelines, deploying managed endpoints, routing inference traffic, and the supporting operations described in the documentation.
Duration. Processing lasts for the term of the underlying agreement and any period thereafter required to return or delete Customer Personal Data per Section XII.
Nature and purpose. Storing, hosting, transmitting, transforming, and benchmarking Customer Personal Data only to the extent necessary to deliver the Service the Customer has configured.
Categories of personal data typically processed:
Categories of data subjects may include:
Special categories. The Customer is responsible for not submitting special categories of personal data (GDPR Article 9) through the Service unless the Customer has a lawful basis under Article 9 and has notified RunInfra in advance so we can confirm the Service's suitability.
RunInfra shall:
RunInfra will not sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising as those terms are defined under the CCPA.
The Customer authorizes RunInfra to engage the sub-processors listed in the Privacy Policy sub-processors table to provide the Service. RunInfra will:
RunInfra implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as required by Article 32 GDPR. A description of those measures is published on the Security page and includes encryption in transit and at rest, role-based access control, audit logging, vulnerability management, and the SOC 2 Type II controls covered by our most recent attestation.
The measures may be updated from time to time to reflect improvements; updates will not materially reduce the overall protection of Customer Personal Data.
Where a data subject submits a request directly to RunInfra concerning Customer Personal Data, RunInfra will promptly forward the request to the Customer and will not respond to the data subject directly except to acknowledge receipt and redirect the request, unless legally compelled to act.
RunInfra will, on the Customer's written request and at the Customer's expense, provide reasonable assistance to enable the Customer to respond to requests to exercise data subject rights, taking into account the nature of the processing.
RunInfra will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent known at the time:
Where the information cannot be provided at the same time, it may be provided in phases without further undue delay. RunInfra will document every Personal Data Breach and make the documentation available to the Customer and supervisory authorities on reasonable request.
Customer Personal Data is processed primarily in the United States. Where Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to or accessed from a country that has not received an adequacy decision, the transfer is governed by the Standard Contractual Clauses (Module Two, controller-to-processor) and, for transfers from the United Kingdom, the UK IDTA. The SCCs are incorporated into this DPA by reference, with the following selections:
RunInfra has performed and maintains transfer impact assessments for the destination countries and the supplementary measures required to protect Customer Personal Data. Copies are available to enterprise customers on request to privacy@runinfra.ai.
RunInfra will make available to the Customer, on reasonable request and no more than once per year except where required by a supervisory authority or following a Personal Data Breach, the most recent independent third-party audit reports relevant to the Service (currently a SOC 2 Type II report). The Customer agrees to treat the audit reports as confidential information.
Where the audit reports do not provide sufficient information for the Customer to demonstrate compliance, the Customer may request an on-site audit. The on-site audit will be conducted during normal business hours, with reasonable prior notice (at least 30 days unless a supervisory authority requires sooner), and subject to a mutually agreed scope and confidentiality terms. Customer bears its own audit costs.
This DPA remains in effect for as long as RunInfra processes Customer Personal Data. On termination or expiry of the underlying agreement, RunInfra will, at the Customer's choice and within 30 days, return all Customer Personal Data in a commonly used format or delete it. Backups containing Customer Personal Data are purged on the standard rolling schedule (no later than 90 days from termination).
Where RunInfra is required by EU or Member State law to retain certain Customer Personal Data beyond termination, RunInfra will continue to protect that data in accordance with this DPA until deletion is lawful.
All notices to RunInfra under this DPA, including questions about scope, requests for signed enterprise copies, sub-processor objections, and audit requests, can be sent to privacy@runinfra.ai with a copy to legal@runinfra.ai.
RightNow AI, Inc.
131 Continental Dr
Newark, DE 19713
United States
On this page
© 2026 RunInfra. All rights reserved.