Legal
Data Processing
Last updated 16 August 2026
How we handle client data during an engagement. This is the summary for evaluation. The binding terms are in the Data Processing Addendum attached to the signed agreement, which we send on request before you commit to anything.
Roles
For data you entrust to us, you are the controller and we are the processor. We act on your documented instructions and tell you if an instruction looks like it breaches applicable law.
Training
We do not train models on client data, and we select providers whose API terms commit to the same in writing.
Where a workload cannot tolerate third-party processing, we deploy inside your own cloud account or on-premise.
Subprocessors
Hosting, model inference and monitoring, each under written terms no less protective than ours. We keep a current list, give advance notice of changes, and you may object.
Security
Encryption in transit and at rest. Least-privilege access, reviewed. Audit logging of what was sent to a model and when. Separation between client environments. Documented incident response with notification without undue delay.
Retention
We keep client data only as long as the engagement needs it. At the end we delete or return it at your choice within 30 days, except where law requires a copy.
Audit and assistance
We give you what you reasonably need to demonstrate compliance, and assist with data subject requests, impact assessments and breach notification for the processing we do for you.
Melchior AI
Registered in Brazil. Working worldwide.