Effective date: 2026-07-09
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Letzgro, Inc. ("VitruAI", "Processor") and the customer ("Customer", "Controller") and applies where VitruAI processes personal data contained in Customer Data on the Customer's behalf.
1. Roles
The Customer is the controller (or processor for its own customers) and VitruAI is the processor. VitruAI processes personal data only on the Customer's documented instructions, including as set out in the Terms and this DPA.
2. Scope of processing
- Subject matter: provision of the VitruAI AI platform for AEC (its agents and workflows).
- Duration: the term of the Customer's account plus the retention period below.
- Nature/purpose: hosting, transmitting, and AI-processing model and project data through the agents the Customer uses to produce Output (analyses, reviews, documents, reports, and automation).
- Data types: account identifiers and any personal data the Customer includes in model data, files, or prompts (the Customer controls what it submits).
- Data subjects: the Customer's personnel and any individuals referenced in submitted data.
3. Processor obligations
VitruAI will: (a) process personal data only per the Customer's instructions and applicable law; (b) ensure personnel are bound by confidentiality; (c) implement the technical and organizational security measures in Annex B; (d) assist the Customer, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations; and (e) make available information reasonably necessary to demonstrate compliance.
4. Sub-processors
The Customer authorizes VitruAI to engage the sub-processors in Annex A. Because VitruAI routes each agent's requests to the LLM provider configured for that agent, the specific LLM sub-processor(s) that process Customer Data depend on the agents and providers the Customer uses. VitruAI will impose data-protection obligations on each sub-processor substantially similar to those in this DPA and remains responsible for their performance. VitruAI will give notice of intended additions/changes and a reasonable opportunity to object.
5. Data location
Personal data is processed in the United States. The Service is offered to US customers and is not directed to data subjects in the EEA or UK, and the parties do not currently rely on EU/UK cross-border transfer mechanisms. Before VitruAI begins offering the Service to EEA/UK customers, this section will be updated with the applicable transfer safeguards (e.g., Standard Contractual Clauses).
6. Data-subject requests, export, and deletion
VitruAI will assist the Customer in responding to data-subject requests. Data export and deletion are handled manually on the Customer's written request and completed within 30 days (self-serve export/delete is not yet available). On termination, Customer Data is available for export for 30 days, then deleted, subject to backup rotation (approximately 30 days) and legal retention.
Note (product coupling): this reflects the current manual capability. Do not amend to promise self-serve or shorter timelines until the export/delete and firm-suspension features ship.
7. Breach notification
VitruAI will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data and provide information reasonably available to assist the Customer's obligations.
8. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service.
Annex A — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic PBC | LLM inference (agents configured to use Anthropic) | US |
| OpenAI | LLM inference (agents configured to use OpenAI) + embeddings/file-search (RAG) | US |
| Other LLM providers as configured per agent | LLM inference for agents set to those providers | varies |
| Stripe, Inc. | Payments & billing | US |
| Resend | Transactional email | US |
| Hetzner Online GmbH | Cloud hosting & storage | US (Ashburn, VA) |
| Cloudflare, Inc. | DNS, CDN, TLS, WAF | Global edge |
Annex B — Security measures
Tenant isolation with per-tenant scoping of all data access; encryption in transit (TLS); credentialed, access-controlled databases; role-based access control; least-privilege operator access; encrypted off-site backups with tested restore; audit logging; and LLM-provider agreements that prohibit training foundation models on Customer Data.