tidbit

Data Processing Addendum

Last updated July 16, 2026

This Data Processing Addendum supplements the Tidbit Terms of Service and governs how Tidbit processes personal data contained in Customer Content and Account Data on a customer's behalf. It is offered to business customers who route personal data through the Service.

1. Introduction and scope

This Data Processing Addendum (the "DPA") supplements the Tidbit Terms of Service (the "Agreement") between you (the "Customer") and Tidbit, a product of Neueway Creations LLC, a Delaware limited liability company ("Tidbit", "we", "us", or "our"). It applies where, and to the extent that, Tidbit processes Personal Data contained in Customer Content or Account Data on the Customer’s behalf in connection with the Service. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.

This DPA applies to processing that is subject to applicable data protection laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA/CPRA") and, where applicable, the EU General Data Protection Regulation and the UK GDPR (together, "European Data Protection Law"). It takes effect when the Customer accepts it or when the Customer begins routing Personal Data through the Service, whichever is earlier.

2. Definitions

"Personal Data" (also "personal information" under the CCPA/CPRA) means any information relating to an identified or identifiable natural person that is contained in Customer Content or Account Data and processed by Tidbit on the Customer’s behalf under the Agreement.

"Processing" means any operation performed on Personal Data, including collection, storage, use, transmission, disclosure, and deletion.

"Controller" means the entity that determines the purposes and means of Processing; it corresponds to a "business" under the CCPA/CPRA. "Processor" means the entity that Processes Personal Data on behalf of the Controller; it corresponds to a "service provider" under the CCPA/CPRA. "Sub-processor" means a third party engaged by the Processor to Process Personal Data on the Customer’s behalf ("contractor" under the CCPA/CPRA).

"Data Subject" means the identified or identifiable natural person to whom Personal Data relates ("consumer" under the CCPA/CPRA). "Customer Content" and "Account Data" have the meanings given in the Agreement. Terms such as "sell", "share", "business purpose", and "commercial purpose" have the meanings given to them in the CCPA/CPRA; "controller", "processor", "data subject", and "personal data" also carry the meanings given in European Data Protection Law where it applies.

3. Roles of the parties

As between the parties, the Customer is the Controller (business) and Tidbit is the Processor (service provider) with respect to Personal Data that Tidbit Processes on the Customer’s behalf under the Agreement. The Customer is responsible for the lawfulness of the Personal Data it routes through the Service and for having the necessary rights, notices, and, where required, consents to do so.

Where Tidbit acts as a Processor/service provider, it Processes Personal Data only on the Customer’s documented instructions and only for the business purposes described in this DPA and the Agreement. Tidbit acts as an independent controller (business) only for the limited Account Data it processes to operate, secure, meter, bill for, and improve the Service as its own controller, as described in the Privacy Policy; that processing is governed by the Privacy Policy rather than by this DPA.

4. Subject matter, nature, purpose, and duration of processing

Subject matter and nature. Tidbit operates a gateway that routes the Customer’s requests to the upstream large language model provider the Customer targets and applies optimizations intended to reduce token usage and cost while preserving output quality. The Processing consists of receiving, transforming, transmitting, and (where applicable) transiently storing the Customer’s requests and responses, together with associated operational metadata.

Purpose. Tidbit Processes Personal Data for the purpose of providing, securing, metering, and supporting the Service for the Customer, and, only where the Customer’s authorized administrator has separately opted in to the Traffic Sampling program, for improving optimization quality in aggregate as described in the Traffic Sampling Addendum.

Categories of Data Subjects. The Customer’s authorized users and administrators, and any individuals whose Personal Data the Customer chooses to include in the requests it routes through the Service.

Categories of Personal Data. Account and contact identifiers (name, work email, phone, company); authentication data; usage and gateway metadata; and any Personal Data the Customer includes within Customer Content routed through the gateway, the categories of which are determined and controlled by the Customer.

Duration. Processing continues for the term of the Agreement and until Personal Data is returned or deleted in accordance with the "Return and deletion of data" section below.

5. Customer instructions

Tidbit Processes Personal Data only on the Customer’s documented instructions, including with regard to transfers, unless required to do otherwise by applicable law (in which case Tidbit will, where legally permitted, inform the Customer of that legal requirement before Processing). The Agreement, this DPA, the Customer’s configuration and use of the Service (including which requests it routes and any features it enables), and any written instructions the Customer gives through the Service together constitute the Customer’s complete and final documented instructions for Processing.

Tidbit will inform the Customer if, in its opinion, an instruction infringes applicable data protection law, without obligation to actively monitor the Customer’s compliance. If Tidbit cannot Process Personal Data in accordance with an instruction without violating applicable law, it may suspend the affected Processing or the Service to the extent necessary and will notify the Customer.

6. Confidentiality

Tidbit treats Personal Data as the Customer’s confidential information and will not disclose it except as permitted by this DPA or as required by law. Tidbit ensures that personnel authorized to Process Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory) and are informed of the confidential nature of the Personal Data. Tidbit limits access to Personal Data to personnel who need it to provide the Service.

7. Security measures

Tidbit maintains technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, appropriate to the risk. These measures include, and are grounded in what the Service actually does:

Encryption in transit for connections to and from the Service; application-layer encryption of account personal information at rest under a per-tenant data-encryption key, with lookups performed through blind indexes rather than plaintext; hard tenant isolation so that one customer cannot access another customer’s data; role-based access controls and audit logging of privileged operations; API secrets shown once at creation and stored only in hashed form; and passwords stored only in hashed form.

For the optional Traffic Sampling program (opt-in only, off by default), additional controls apply: samples are redacted before storage on a fail-closed basis so that a sample that cannot be reliably redacted is discarded rather than stored; redacted samples are stored in a dedicated, segregated store separate from account, billing, and credential systems; and the sampling store structurally refuses credential material. A zero-data-retention mode, where enabled for a tenant, disables retention of request content at rest on a fail-closed basis.

The specific measures may evolve as the Service develops, provided Tidbit does not materially reduce the overall level of protection during the term. Further detail on Tidbit’s controls is available on request, and the description of measures set out in this "Security measures" section serves as the summary of technical and organizational measures for the purposes of this DPA.

8. Sub-processors

The Customer generally authorizes Tidbit to engage Sub-processors to Process Personal Data in connection with the Service. Tidbit’s current Sub-processors are published on the Subprocessors page, which identifies each Sub-processor, the function it performs, the categories of data it Processes, and its processing region.

Tidbit imposes on each Sub-processor, by written contract, data-protection obligations that are substantially the same as and no less protective than those in this DPA, to the extent applicable to the nature of the Sub-processor’s services. Tidbit remains responsible for the performance of each Sub-processor’s obligations to the same extent it would be responsible if performing the services directly.

Notice and objection. Tidbit will give affected customers advance notice before adding or replacing a Sub-processor that Processes Personal Data, of at least 30 days, by updating the Subprocessors page and, where the Customer has provided an administrative contact or subscribed to notifications, by email. During the notice period the Customer may object to the new Sub-processor on reasonable, documented data-protection grounds. The parties will work together in good faith to resolve the objection; if they cannot, the Customer may, as its sole and exclusive remedy, terminate the affected portion of the Service by written notice to Tidbit before the new Sub-processor begins processing the Customer’s Personal Data.

9. Assistance with data-subject rights

Taking into account the nature of the Processing, Tidbit will provide reasonable assistance to the Customer, by appropriate technical and organizational measures and insofar as possible, to enable the Customer to respond to requests from Data Subjects to exercise their rights under applicable data protection law (including rights of access, correction, deletion, restriction, portability, and objection).

If Tidbit receives a request from a Data Subject relating to Personal Data Processed on the Customer’s behalf, Tidbit will not respond directly except to confirm the request should be directed to the Customer, and will, to the extent legally permitted, promptly inform the Customer so the Customer can respond. Where the Service provides self-service functionality that allows the Customer to access, correct, or delete Personal Data, the Customer’s use of that functionality constitutes the assistance for those requests.

10. Personal data breach notification

Tidbit will notify the Customer without undue delay, and where feasible within 72 hours after becoming aware of a Personal Data breach affecting the Customer’s Personal Data. The notification will describe, to the extent known and as information becomes available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects.

Tidbit will take reasonable steps to contain and remediate the breach and will provide the Customer with reasonable cooperation and information the Customer needs to meet its own breach-notification obligations under applicable law. Tidbit’s notification of, or response to, a breach is not an acknowledgment of fault or liability.

11. Return and deletion of data

Upon termination or expiry of the Agreement, and at the Customer’s choice, Tidbit will return or delete the Personal Data it Processes on the Customer’s behalf, and delete existing copies, unless applicable law requires continued storage. Given the pass-through nature of the Service, request and response content is not retained in the request path except for the limited, time-boxed retention described in the Privacy Policy; those items expire automatically under their stated retention limits.

Personal Data held in the Customer’s account (Account Data) is deleted or de-identified in accordance with the retention schedule in the Privacy Policy following account closure, subject to records Tidbit is required or permitted to retain by law (for example, for security, dispute resolution, financial, audit, or legal-compliance purposes). Where deletion is not immediately feasible, Tidbit will isolate the Personal Data from further Processing until deletion is possible. The Customer may request confirmation of deletion.

12. Audits

Tidbit will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and, where required by applicable data protection law, will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable and appropriate confidentiality, security, scope, timing, and frequency controls.

Where available, Tidbit may satisfy an audit request by providing a then-current third-party audit report or certification (for example, a SOC 2 report, once one exists) in lieu of an on-site inspection. Tidbit may satisfy an audit request by making available its security documentation, a then-current third-party audit report, or a completed security questionnaire on the Customer’s written request, to demonstrate compliance with this DPA. On-site audits or inspections take place only where required by applicable data protection law, no more than once in any twelve-month period (except where a supervisory authority or applicable law requires otherwise, or following a Personal Data breach), on reasonable prior written notice of at least thirty days, at the Customer’s expense, under an obligation of confidentiality, and conducted during business hours in a manner that does not disrupt Tidbit’s operations or compromise the security or confidentiality of other customers’ data.

13. International transfers

Tidbit and its Sub-processors may Process Personal Data in, and transfer it to, countries other than the one in which the Customer or its Data Subjects are located, including the United States. Where such transfers are subject to European Data Protection Law, the parties rely on an appropriate transfer mechanism as required by that law, as set out below.

For Personal Data protected by European Data Protection Law, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA by reference and form part of it, and, for transfers subject to the UK GDPR, so is the UK International Data Transfer Addendum to those Clauses (and, for Switzerland, the Clauses apply with the adaptations required by Swiss law). The Clauses are completed as follows: the Customer is the data exporter and Tidbit is the data importer; the relevant module is Module Two (controller-to-processor); the docking clause (Clause 7) applies; the option for the parties’ general written authorization of Sub-processors under Clause 9 applies, consistent with the "Sub-processors" section above; and in Clause 17 (governing law) and Clause 18 (forum and jurisdiction) the parties select an EU Member State as required by the Clauses. The descriptions in this DPA and the Subprocessors page populate Annexes I and II; the specific supervisory authority, the Clause 17/18 Member State selection, and the final Annex I–III particulars are marked as placeholders to be completed at counsel review before general availability. Nothing in this DPA reduces the protections the Standard Contractual Clauses provide; in the event of any conflict between the Clauses and the other terms of this DPA, the Clauses prevail with respect to the transfer of Personal Data protected by European Data Protection Law.

14. CCPA/CPRA service provider terms

With respect to Personal Data that Tidbit Processes on the Customer’s behalf, Tidbit acts as a "service provider" (and where it engages contractors, imposes contractor terms) under the CCPA/CPRA, and certifies that it understands and will comply with the following restrictions. Tidbit will not: (a) sell or share the Personal Data (as "sell" and "share" are defined in the CCPA/CPRA); (b) retain, use, or disclose the Personal Data for any purpose other than the specific business purpose of performing the Service under the Agreement, or as otherwise permitted by the CCPA/CPRA; (c) retain, use, or disclose the Personal Data outside the direct business relationship between Tidbit and the Customer; or (d) combine the Personal Data with personal information Tidbit receives from, or on behalf of, another person, or collects from its own interaction with the Data Subject, except as permitted by the CCPA/CPRA (for example, to perform a business purpose permitted by its regulations).

Tidbit will comply with applicable obligations under the CCPA/CPRA and will provide the same level of privacy protection as the CCPA/CPRA requires of businesses. The Customer may take reasonable and appropriate steps to help ensure that Tidbit uses the Personal Data in a manner consistent with the Customer’s obligations under the CCPA/CPRA, and to stop and remediate unauthorized use. Tidbit will notify the Customer if it determines it can no longer meet its obligations under the CCPA/CPRA. The parties acknowledge that the transfer of Personal Data from the Customer to Tidbit under the Agreement is not a sale and does not constitute "sharing", and that no monetary or other valuable consideration is exchanged for the Personal Data.

15. Liability

Each party’s liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party’s liability means the aggregate liability of that party under the Agreement and this DPA together. This DPA does not create any additional liability caps beyond those in the Agreement.

16. General

This DPA is governed by the same law and subject to the same dispute-resolution and venue provisions as the Agreement, except to the extent applicable data protection law (or an incorporated transfer mechanism such as the Standard Contractual Clauses) requires otherwise. If any provision of this DPA is held unenforceable, the remainder remains in effect. Except as amended by this DPA, the Agreement remains in full force and effect; in case of conflict regarding the Processing of Personal Data, this DPA prevails.

17. Related documents

This DPA supplements our Terms of Service and is read together with our Privacy Policy, the published Subprocessors list, and, where the Customer enables it, the Traffic Sampling Addendum. Questions, or a request for a countersigned copy, can be sent to nibble@usetidbit.ai.