Data Processing Agreement (DPA)
Effective date: September 6, 2026
Scope. This Data Processing Agreement ("DPA") applies to business and individual-business Members who use the developer API (Terms Section 11c) or the Coding Agent CLI (Terms Section 11d) to process the personal data of their own end users or other third parties in their applications, services, or work (each, a "Customer"). It does not apply to Members using the Service as consumers — the Privacy Policy governs that use. By agreeing to the Terms and using the developer API or the Coding Agent CLI, this DPA is automatically incorporated into the Terms between the Customer and Road Financial ("Company") without a separate signature. A Customer who needs a countersigned copy may request one via the contact in Section 15.
This document is a translation of our Korean-language DPA, drafted primarily under South Korea's Personal Information Protection Act (PIPA). Where PIPA and GDPR terminology differ, we use GDPR-style terms (controller/processor/sub-processor) in parentheses for clarity. Where there is any inconsistency between this translation and the Korean version, the Korean version controls.
1. Purpose and relationship
- This DPA governs the Company's obligations, as a processor engaged by a controller under the PIPA (corresponding to a "processor" under GDPR and similar laws), when the Customer uses the developer API or the Coding Agent CLI (together, the "API") to process the personal data of its own end users or other data subjects ("Customer Personal Data").
- In this relationship, the Customer is the controller and the Company is the processor. The Customer is solely responsible for establishing and maintaining a lawful basis (consent, contractual necessity, etc.) for processing its end users' personal data. The Company is not a party to the relationship between the Customer and its end users.
- If this DPA conflicts with the Terms of Service or the Privacy Policy with respect to the processing of Customer Personal Data, this DPA controls. All other matters are governed by the Terms and the Privacy Policy.
2. Definitions
- "Customer Personal Data" means information that identifies the Customer's end users or other third parties, contained in prompts, uploaded files, or other input the Customer transmits when calling the API.
- "Processing" means any operation on personal data — collection, transmission, storage, use, destruction, etc.
- "Sub-processor" means any party the Company further engages to process Customer Personal Data in providing the API, as listed in Section 5.
- Terms not defined here have the meanings given in the Terms of Service and Privacy Policy.
3. Nature and scope of processing
- Subject matter and data subjects: all personal data of the Customer's end users or other third parties that the Customer transmits via the API in the course of its own application or business. The Company does not pre-screen or classify the content Customers submit to the API, so the specific categories and sensitivity of personal data depend entirely on how the Customer uses the Service.
- Purpose: providing the Service under the API agreement between the Customer and the Company (generating AI model responses, returning web-search results, storing/retrieving files, etc.) and the incidental purposes of billing, abuse prevention, and content moderation. No other purpose.
- Duration: for as long as the API agreement remains in effect; following termination, withdrawal, or API key revocation, data is destroyed under Section 7 of the Privacy Policy and Section 12 of this DPA.
- Method: real-time transmission and processing over the network. The developer API is designed to be stateless in principle — it does not persistently store conversation history on our servers, and each request must include the context it needs. We do, however, store usage metadata for each request (model used, token counts, credits, response time, request identifier — excluding message content) for billing and rate-limiting purposes.
4. Customer obligations
- The Customer is solely responsible for establishing and maintaining a lawful basis to process its end users' personal data. The Company is not involved in that relationship.
- Before submitting sensitive categories of personal data (health, political opinions, sex life, etc.) or children's personal data to the API, the Customer must independently assess whether such processing is lawful for it and whether the cross-border transfers described in Section 6 are acceptable. Because the Company does not pre-screen API input content, the decision to submit such data, and the associated risk, rests with the Customer.
- The Customer must comply with Section 10 (prohibited conduct) and Sections 11c/11d of the Terms, and must inform its own end users of the limitations of AI-generated output (Terms Section 11a).
- A Customer using the Coding Agent CLI must independently ensure it has lawful authority before letting the CLI read personal data or trade secrets of third parties contained in its local repository and transmit them to an AI model. Details are governed by Terms Section 11d.
5. Company obligations and sub-processors
- The Company processes Customer Personal Data only within the purposes stated in Section 3 and does not use it for any other purpose, including training its own AI models.
- The Company uses the following sub-processors to provide the API. This is the same list as the outsourcing/cross-border-transfer tables in Sections 5–6 of the Privacy Policy, which always reflects the current list.
| Sub-processor | Processing activity | Location |
|---|---|---|
| Convex, Inc. | Storage of API usage metadata and uploaded files (developer API file-upload endpoint) | United States |
| OpenRouter, Inc. and the underlying AI model provider selected on each call (e.g., infrastructure serving OpenAI, Anthropic, Google, xAI, DeepSeek, or Meta models) | Processing prompts/input data to generate AI model responses | United States, etc. (varies by underlying provider — see Section 6) |
| OpenAI, L.L.C. | Content moderation (classification of illegal/harmful content) | United States |
| Exa Labs, Inc. (when the web search feature is used) | Processing search queries and returning search results | United States |
| fal.ai (Features and Labels, Inc.) (when image generation is used) | Processing image-generation prompts | United States |
| NHN Cloud Corp. | Service server operation | Republic of Korea |
| NHN KCP Corp. | Card registration and billing for API usage fees (the Customer's own payment information — not Customer Personal Data) | Republic of Korea |
- When the Company adds or changes a sub-processor, it will announce this through updates to Sections 5–6 of the Privacy Policy and an in-Service notice. A Customer that objects to a particular sub-processor may contact us using Section 15, and may terminate the API agreement if no reasonable alternative is available.
- Transparency note — limits of the sub-processor chain. The Company contracts with major infrastructure providers such as OpenRouter under each provider's standard terms of service. Individual AI model providers routed through OpenRouter (OpenAI, Anthropic, Google, xAI, DeepSeek, Meta, etc.) are not the Company's direct contractual counterparties but sub-processors of OpenRouter; how they actually handle data is governed by the agreement between OpenRouter and each provider. Based on our review, OpenRouter and most of these providers do not offer a signable, GDPR-style DPA to standard self-serve customers — that is generally available only under an enterprise-tier agreement. Accordingly, the Company cannot re-warrant, to the Customer, protections equivalent to an individually signed DPA with respect to these sub-processors; each provider's published policy (Section 6) is the operative standard. A Customer that needs stricter contractual assurances for this chain should contact us in advance via Section 15.
6. Cross-border transfer and provider-specific notes
- Customer Personal Data is transferred overseas through the sub-processors in Section 5; the destination countries are as described in Section 6 of the Privacy Policy. The Customer is responsible for disclosing this cross-border transfer to its own end users.
- 🔴 Notice regarding DeepSeek models. If the Customer pins a DeepSeek model in a request to the API or the Coding Agent CLI, that request's data is routed through OpenRouter and processed in the People's Republic of China, under the policies of the DeepSeek operator (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.). Based on our review of DeepSeek's published policies, unlike most other providers, DeepSeek may by default use data submitted via its API to train its own models, and we found no clear opt-out mechanism for API-only accounts, nor a separate DPA. Customers who wish to process data that may contain personal or sensitive information using DeepSeek models should weigh these facts when choosing a model. The Company does not currently offer a way to exclude a specific model provider at the API-key level — a Customer that wants to categorically block a particular model should control model selection at its own application layer, or contact us via Section 15.
- Notice regarding web search. The search provider currently active in production (Exa Labs, Inc.) states in its published policy that it may use search-query data to improve and train its own models, and we found no documented opt-out for standard customers. It is the Customer's responsibility to avoid including personal data in search queries.
- Other model providers (OpenAI, Anthropic, Google, xAI, Meta-hosted infrastructure, etc.) publicly state that they do not, by default, use API-submitted data for training. This is each provider's own published policy; it may change without notice to us, and the Company cannot directly warrant its enforcement. Please consult each provider's own current published materials for the latest position.
7. Cooperation with data-subject rights requests
- Where the Customer's end user asks the Customer to access, correct, or delete their personal data, the Company will reasonably cooperate with the Customer's request with respect to information the Company holds (usage metadata under Section 5, files uploaded through the developer API, etc.).
- Because the Coding Agent CLI's conversation sessions, memory, and MCP configuration are stored only on the Customer's (the user's) local device, which the Company cannot access, requests to view or delete that data must be handled by the Customer directly on its own local environment, not by the Company.
- The Company's ability to cooperate may be limited with respect to the AI model's response-generation process itself, once that processing is complete and cannot be reproduced.
8. Security measures
The Company applies the same administrative, technical, and physical measures described in Section 9 of the Privacy Policy to secure Customer Personal Data. In particular, developer API keys are stored only as one-way hashes, with the original shown once at issuance, and files uploaded via the API are access-scoped to their owning Customer.
9. Data breach notification
- Where the Company becomes aware of a breach affecting Customer Personal Data (unauthorized access, leakage, etc.), it will notify the Customer without undue delay, as required by applicable law.
- The notification will include the facts as understood, the scope of personal data believed to be affected, and the measures the Company has taken or plans to take.
10. Restrictions on further sub-processing
Where the Company further sub-processes Customer Personal Data, it discloses this as a sub-processor under Section 5 and endeavors to impose data-protection obligations on that sub-processor consistent with this DPA. As noted in Section 5(4), where a sub-processor offers only standard terms of service and does not permit individual negotiation, there are limits to the obligations the Company can impose.
11. Audit
With reasonable advance notice, the Customer may submit written questions or request relevant documentation (such as the security-measures description in the Privacy Policy) as needed to verify compliance with this DPA. On-site audits may be conducted only by mutual agreement, given the Company's scale.
12. Return and destruction on termination
Upon termination of the API agreement or withdrawal by the Customer, Customer Personal Data held by the Company is destroyed under Section 7 of the Privacy Policy. Payment and transaction records subject to a statutory retention obligation are retained in anonymized form as described there. Data stored locally by the Coding Agent CLI is never held by the Company in the first place and so is not subject to destruction by us — the Customer manages it directly in its own local environment.
13. Limitation of liability
The Company's liability under this DPA is governed by Section 13 (Damages and disclaimers) of the Terms of Service. The Company remains liable, as required by applicable law, for a personal-data breach caused by its willful misconduct or gross negligence.
14. Governing law
This DPA is governed by the laws of the Republic of Korea; disputes are governed by Section 14 of the Terms of Service.
15. Contact
- Company name: Road Financial (로드 파이낸셜)
- Representative: Inung Kang (강인웅)
- Email: support@roadfinancial.co.kr
Contact the email above for a countersigned DPA document, further information about our sub-processors, or any question about this DPA.
Effective date
This DPA is effective as of September 6, 2026.