Data Processing Agreement
Last Updated: August 28, 2026
Between the Business Customer, hereinafter referred to as the Controller, and Solid Technologies AG, acting as Mono, hereinafter referred to as the Processor.
1. Subject of the Agreement The Processor provides artificial intelligence services to the Controller via the Mono platform. The Processor processes personal data on behalf of and upon the instructions of the Controller.
2. Categories of Data Subjects and Types of Data The processing includes text data, documents, and inputs that the Controller transfers into the Mono platform. It may also include account, configuration, service-usage, predefined product-event, and eligible session-replay data necessary to provide, test, and secure the Service after public analytics consent or while an authorized user is logged in. This may include limited account or profile data such as a user ID, name, email address, language, and subscription plan. This affects employees, customers, and business partners of the Controller. Except for the limited case described below, special categories of personal data are explicitly excluded from processing. In particular, health or medical data concerning third parties must not be entered into Mono unless they have first been irreversibly anonymized. A user's own health data remains sensitive or special-category personal data and requires special treatment. It may be entered only if the Controller has established a valid legal basis and satisfied all additional requirements applicable to such data, including obtaining explicit consent where required.
3. Use for Training Purposes Inputs and generated outputs of the Controller are not used for training, improving, or fine tuning the deployed AI models, except where an authorized user explicitly agrees to possible training use as described in Section 4. Where training use can be excluded, the Processor ensures this through contractual API agreements or provider settings.
4. Location of Data Processing Core customer data is stored and hosted on servers in Frankfurt, Germany. For the generation of responses, data is transmitted temporarily to external AI interfaces. Some model providers may retain request and response data and related metadata in security and abuse-monitoring logs for up to 30 days before deletion. If a selected provider may use submitted data for training, including where training use cannot be excluded contractually, the Mono interface clearly identifies this before transmission. The authorized user must explicitly agree to continue; without this agreement, the data is not sent to that provider.
During the current service test, PostHog data is processed in PostHog Cloud EU, hosted in Frankfurt, Germany, only after a logged-out visitor grants analytics consent or while an authorized user is logged in. Certain logged-in users may be excluded from session replay under Mono's recording rules. When active, session replay records page structure, rendered visible text, element attributes, and interaction sequences while masking form and input values. Mono disables console-log, network-payload, canvas, autocapture, automatic page-view, automatic exception, and performance capture. Because rendered visible text is not masked, readable page content displayed in the Service—including submitted prompts, model outputs, account details, and other text—may be processed by PostHog. Uploaded file contents are not intentionally captured unless rendered visibly on the page. Predefined product events and limited account or profile data may also be processed in PostHog Cloud EU while PostHog tracking is active.
5. Subprocessors The Controller grants general authorization for the Processor to use subprocessors to provide and operate the Service. The current relevant subprocessors and purposes include:
- Google: Hosting, infrastructure, and model services.
- OpenAI: Model services.
- Anthropic: Model services.
- OpenRouter: Model routing and model services.
- PostHog Inc. and its applicable affiliates: Product analytics and eligible session replay after public analytics consent or while an authorized user is logged in, using PostHog Cloud EU.
The Processor shall inform the Controller in a timely manner of any intended changes concerning the addition or replacement of subprocessors and provide a reasonable opportunity to object on legitimate data-protection grounds. The Processor remains responsible for imposing data-protection obligations on subprocessors as required by applicable law.
6. International Data Transfers If personal data is transferred outside Switzerland or the EEA, the Processor uses an applicable lawful transfer mechanism. Depending on the recipient, this may include an adequacy decision, the Swiss-U.S. or EU-U.S. Data Privacy Framework for certified recipients, or the European Commission's Standard Contractual Clauses with any required Swiss adaptations and supplementary measures. This also applies to restricted support or subprocessor access to data otherwise hosted in Frankfurt.
7. Technical and Organizational Measures The Processor implements technical and organizational measures appropriate to the risk, including encryption in transit and at rest, restrictive access controls, authentication, logging, backup controls, and procedures for handling security incidents. Access to production data is limited to authorized personnel and subprocessors who require it to provide, secure, support, or maintain the Service and who are subject to confidentiality and data-protection obligations.
8. Deletion of Data Deleted chat histories or account data are removed from the active systems once their purpose has been fulfilled or on a valid instruction from the Controller, subject to legal retention requirements. Mono-controlled backup copies are overwritten or permanently deleted within a maximum of 30 days. Copies held by subprocessors are deleted in accordance with the applicable subprocessor agreement and documented retention schedule. Where a valid deletion instruction covers analytics data, the Processor also initiates deletion of the corresponding PostHog person and event data.