Data Processing Agreement
Art. 28 GDPR · Version 2026-06-16 · Deutsche Fassung
This Data Processing Agreement ("DPA") governs the processing of personal data carried out by Gus IT LLC ("Gus IT", the Processor), registered in Florida, USA, on behalf of the customer (the Controller) in the course of providing the Luca Express / AIOS AI-Workforce service. It is presented and accepted at checkout; each acceptance is recorded with its version and timestamp.
1. Subject-matter and scope
Persona orchestration, day-to-day operations, deployment, and support around the customer's own Claude subscription.
2. Roles — the Anthropic commercial-terms split
The AI-Workforce service is bring-your-own-key (BYO key):
- Claude inference runs on the customer's own Anthropic account / API key, under Anthropic's commercial terms and data-processing relationship — directly between the customer and Anthropic PBC. Under Anthropic's commercial terms, commercial API data is not used to train Anthropic's models. That is the customer's relationship with Anthropic, not something Gus IT controls on Anthropic's behalf.
- Gus IT's processing under this DPA covers only the personal data Gus IT itself processes to operate the service (account/identity, billing metadata, operational telemetry, support content).
This is why "your data never trains our models" is accurate: we do not train models on customer data, and the Claude no-training position is the customer's own Anthropic relationship.
3. Duration
For the term of the customer's subscription, plus the return/deletion obligations in §9.
4. Nature and purpose of processing
Hosting, integration, orchestration, deployment, billing, support and security of the service.
5. Types of personal data
Account holder identity (name, business email), authentication identifiers, billing/VAT metadata, support correspondence, operational logs, and any personal data the customer chooses to route through the service.
6. Categories of data subjects
The customer's authorised users and the customer's own contacts to the extent routed through the service.
7. Obligations of the Processor
Gus IT shall process personal data only on documented customer instructions; ensure confidentiality of authorised persons; implement appropriate technical and organisational measures (Art. 32); respect the sub-processor conditions in §8; assist with data-subject requests and Arts. 32–36; delete or return personal data at end of provision; and make available the information necessary to demonstrate compliance and allow audits.
8. Sub-processors
The customer provides general authorisation for the sub-processors in our sub-processor list. Gus IT gives at least 30 days' notice before adding or replacing a sub-processor; the customer may object on reasonable data-protection grounds.
9. Return and deletion
On termination, Gus IT deletes or returns all personal data and deletes existing copies unless storage is required by law. Per-tenant residency pinning and crypto-shred deletion are available.
10. International transfers
Gus IT LLC is a US entity. Transfers rely on the EU Standard Contractual Clauses and supplementary measures; per-tenant EU residency pinning is available for the hosted tier. The customer's EU representative under Art. 27 GDPR (OBSECOM) is named in the privacy policy.
11. Technical and organisational measures (Art. 32)
Encryption in transit and at rest, schema-per-tenant isolation, gVisor runtime isolation, least-privilege RBAC, and tamper-evident audit logging.