Ulam Alloy

Ulam Alloy — Data Processing Agreement

Version: 1.0

Last updated: 26 June 2026

Product: Ulam Alloy — AI chat interface and API for AI/model routing

Processor / Service Provider: Yotta Content LTD, a private limited company registered in the United Kingdom under company number 12683376

Registered office: 71–75 Shelton Street, London, Greater London, United Kingdom, WC2H 9JQ

Product status: Experimental product — use at your own risk

Privacy / data protection contact: privacy@ulam.ai

Subprocessor, partner and external model provider list: https://chat.ulam.ai/subprocessors


1. Introduction

This Data Processing Agreement, including its schedules, forms part of the agreement between Yotta Content LTD and the customer using Ulam Alloy for business, developer, API, workspace, or other organisational purposes.

This DPA applies where Yotta Content LTD processes Customer Personal Data on behalf of the customer through Ulam Alloy.

Ulam Alloy is an experimental AI interface and API. API gateway diagnostic payload logs, where kept by Yotta, are intended to be retained for up to one month / 30 days. Web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records may be retained for longer. Ulam Alloy may also share prompts, API requests, files, responses, outputs, metadata, and related data with partners, infrastructure providers, routing providers, and external AI/model providers.

This DPA is intended to address requirements under the UK GDPR, EU GDPR where applicable, and other applicable data protection laws. It should be reviewed against the parties' actual technical, commercial, and regulatory circumstances before signature.


2. Parties

2.1 Customer

The customer is the legal entity or person that has entered into a service agreement, order form, online subscription, API account, or other contract with Yotta Content LTD for use of Ulam Alloy.

The customer is referred to in this DPA as Customer, Controller, or you.

2.2 Processor

Yotta Content LTD is the service provider operating and processing Ulam Alloy.

Yotta Content LTD is referred to in this DPA as Yotta, Processor, we, us, or our.


3. Definitions

In this DPA:

Applicable Data Protection Laws means the UK GDPR, the Data Protection Act 2018, the EU GDPR where applicable, the Privacy and Electronic Communications Regulations where applicable, and any other data protection or privacy laws that apply to the processing of Customer Personal Data.

Customer Personal Data means personal data submitted to Ulam Alloy by or on behalf of Customer, including through the Ulam Alloy API, workspace, developer tools, or business account, where Yotta processes that personal data on Customer's behalf.

External Model Provider means a third-party AI, machine learning, inference, model hosting, embedding, classification, moderation, routing, or related provider to which Ulam Alloy may transmit Customer Personal Data or Customer Content to provide or operate the service.

Partner means a third party that supports, operates, integrates with, evaluates, improves, secures, or provides part of Ulam Alloy, including infrastructure, routing, analytics, monitoring, support, billing, security, and model providers.

Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data processed under this DPA.

Processing, Controller, Processor, Subprocessor, Personal Data, Data Subject, and Special Category Data have the meanings given to them under Applicable Data Protection Laws.

Service Data means operational data processed by Yotta in connection with Ulam Alloy, including account data, billing data, security logs, analytics, abuse-prevention data, support records, and product telemetry.

Ulam Alloy means the experimental AI chat interface, API, developer platform, routing layer, model-access interface, and related services made available by Yotta Content LTD.


4. Scope and order of precedence

This DPA applies only to the processing of Customer Personal Data by Yotta as Processor on behalf of Customer.

If there is a conflict between this DPA and the main service agreement, the following order applies for data protection matters:

1. mandatory requirements of Applicable Data Protection Laws;

2. applicable international transfer clauses or transfer addenda;

3. this DPA;

4. the main service agreement, order form, or online terms;

5. product documentation.

This DPA does not apply to data for which Yotta acts as an independent Controller, including account administration, billing, fraud prevention, platform security, legal compliance, general business records, and other independent-controller activities described in the Privacy Policy or service terms.


5. Roles of the parties

5.1 Customer as Controller

For Customer Personal Data submitted to Ulam Alloy by Customer or Customer's end users, Customer generally acts as Controller. Customer determines the purposes and means of processing, including what data is submitted, which end users may use the service, whether personal data is included in prompts or API requests, and whether Ulam Alloy is suitable for Customer's use case.

5.2 Yotta as Processor

Yotta acts as Processor for Customer Personal Data processed through Ulam Alloy to provide the service on Customer's behalf, subject to this DPA and the applicable service agreement.

Yotta will process Customer Personal Data only on Customer's documented instructions, including this DPA, the service agreement, order forms, product settings, API calls, routing configuration, support requests, and other written instructions accepted by Yotta.

5.3 Yotta as independent Controller

Yotta may act as an independent Controller for certain processing activities, including:

5.4 External provider roles may vary

Customer acknowledges that Ulam Alloy may send Customer Personal Data and Customer Content to External Model Providers and Partners. Depending on the provider, contract, and processing activity, those providers may act as Subprocessors, independent Controllers, or separate service providers under their own terms.

Yotta does not guarantee that every External Model Provider operates as a zero-retention processor or that every External Model Provider prohibits all uses of submitted data for monitoring, evaluation, safety, abuse prevention, product improvement, model improvement, or training. Customer is responsible for reviewing provider suitability for its use case.


6. Customer instructions

Customer instructs Yotta to process Customer Personal Data as necessary to:

Customer acknowledges that routing to External Model Providers and Partners is a core feature of Ulam Alloy and authorises Yotta to transmit relevant Customer Personal Data, Customer Content, prompts, API requests, files, responses, outputs, and metadata to those providers for the purposes described in this DPA.


7. Customer responsibilities

Customer is responsible for:

Customer must not submit data to Ulam Alloy if the onward sharing, retention, experimental processing, or external model processing described in this DPA is not acceptable for that data.


8. Processing details

The details of processing are set out in Schedule 1.

In summary:


9. Confidentiality

Yotta will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations, whether contractual, statutory, or professional.

Yotta will limit access to Customer Personal Data to personnel, contractors, systems, Partners, and External Model Providers that need access for the purposes described in this DPA, the service agreement, or applicable instructions.


10. Security measures

Yotta will implement and maintain commercially reasonable technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.

The current security measures are described in Schedule 2.

Customer acknowledges that Ulam Alloy is experimental. Unless expressly agreed in writing, Yotta does not represent that Ulam Alloy is certified to SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or any regulated-industry standard.

Customer is responsible for assessing whether Yotta's security measures are appropriate for Customer's data and use case.


11. Subprocessors, partners, and external model providers

11.1 General authorisation

Customer gives Yotta general written authorisation to engage Subprocessors, Partners, infrastructure vendors, routing providers, support vendors, security vendors, analytics vendors, and External Model Providers as necessary to provide, operate, secure, monitor, support, test, evaluate, and improve Ulam Alloy.

11.2 External model provider sharing

Customer expressly authorises Yotta to share Customer Personal Data and Customer Content with External Model Providers and Partners for:

11.3 Subprocessor list

Yotta will maintain a list of material Subprocessors, Partner categories, and External Model Provider categories at: https://chat.ulam.ai/subprocessors.

The list should identify, where practical, provider name or category, purpose of processing, processing location or region, and transfer mechanism.

11.4 Changes to subprocessors

Yotta may update the Subprocessor, Partner, and External Model Provider list from time to time. Where required by Applicable Data Protection Laws or the service agreement, Yotta will provide notice of material changes and an opportunity to object.

If Customer objects to a new provider on reasonable data protection grounds, the parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may stop using the affected functionality or terminate the affected service in accordance with the service agreement.

11.5 Subprocessor obligations

Where a third party acts as Yotta's Subprocessor for Customer Personal Data, Yotta will impose data protection obligations on that Subprocessor that are substantially similar to those in this DPA, to the extent required by Applicable Data Protection Laws.

Where a third-party provider acts as an independent Controller or processes data under its own terms, Customer acknowledges that the provider's own terms, privacy policy, retention practices, and legal obligations may apply.


12. International transfers

Customer acknowledges that Yotta is established in the United Kingdom and that Ulam Alloy may involve transfers of Customer Personal Data to Partners, External Model Providers, infrastructure providers, and other vendors located outside the United Kingdom, European Economic Area, or Customer's jurisdiction.

Where Yotta transfers Customer Personal Data in a way that constitutes a restricted transfer under Applicable Data Protection Laws, Yotta will use an appropriate transfer mechanism where required, such as:

Customer authorises Yotta to make such transfers for the purposes described in this DPA. Customer is responsible for determining whether its use of Ulam Alloy, including onward sharing with External Model Providers, is lawful for the personal data, jurisdictions, and use case involved.


13. Data retention and deletion

13.1 Payload, chat, and account retention

API gateway diagnostic payload logs, where kept by Yotta, are intended to be retained for up to one month / 30 days. Web chat history, uploaded files, account records, usage records, billing records, security logs, support records, legal records, backups, and external-provider records may be retained for longer.

This retention may be used for service operation, debugging, reliability, monitoring, safety, abuse prevention, support, product experimentation, evaluation, improvement, billing verification, and investigation of errors or policy violations.

13.2 Deletion after retention period

After the intended one-month API gateway diagnostic payload retention period, Yotta will aim to delete or anonymise those diagnostic payload logs from active systems, unless longer retention is necessary for legal, security, fraud prevention, accounting, dispute resolution, backup, compliance, or other legitimate purposes described in this DPA or the Privacy Policy. Web chat history and uploaded files may remain available in the user account until deleted by the user, removed by Yotta, or the account is closed, subject to product capabilities and legal retention needs.

13.3 Metadata and records

Yotta may retain metadata, audit logs, security logs, account data, billing records, support records, and legal records for longer than one month where necessary for service operation, security, fraud prevention, accounting, tax, compliance, dispute resolution, or legal claims.

13.4 Backups

Customer Personal Data may remain in backups, snapshots, disaster recovery systems, or archive copies for a limited period after deletion from active systems. Where immediate deletion from backups is not practical, Yotta will protect the data from ordinary use and delete or overwrite it according to the normal backup lifecycle. Backups are protected using the security measures available for the relevant infrastructure; Yotta does not promise a specific backup encryption architecture unless expressly agreed in writing.

13.5 End of services

On termination of the service agreement or on Customer's written request, Yotta will delete or return Customer Personal Data in accordance with the service agreement, this DPA, product capabilities, and Applicable Data Protection Laws, unless retention is required or permitted by law.


14. Assistance with data protection obligations

Taking into account the nature of processing and information available to Yotta, Yotta will provide reasonable assistance to Customer with:

Yotta may charge reasonable fees for assistance that is not included in the standard service, unless prohibited by Applicable Data Protection Laws or the service agreement.


15. Data Subject requests

If Yotta receives a request from a Data Subject relating to Customer Personal Data for which Customer is Controller, Yotta may redirect the request to Customer unless legally required to respond directly.

Customer is responsible for responding to Data Subject requests where Customer acts as Controller.

Yotta will provide reasonable assistance where Customer cannot reasonably fulfil the request without Yotta's help, taking into account product capabilities, retention periods, security requirements, and legal limitations.


16. Personal Data Breach notification

Yotta will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data processed by Yotta as Processor.

The notification will include information reasonably available to Yotta at the time, such as:

Yotta may provide information in phases as it becomes available.

Notification of a security incident is not an admission of fault or liability.

Customer is responsible for determining whether the incident triggers notification obligations to supervisory authorities, Data Subjects, customers, end users, or other parties.


17. Audits and compliance information

Yotta will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, operational, and commercial restrictions.

Yotta may satisfy audit requests by providing appropriate documentation, written responses, security summaries, subprocessor information, retention summaries, or other compliance materials.

Any on-site or live-system audit requires prior written agreement, reasonable notice, scope limitations, confidentiality obligations, security restrictions, and measures to avoid disruption or risk to Yotta, its customers, Partners, and systems.

Customer may not access data, systems, or records relating to other customers, users, Partners, or confidential business operations.


18. Restricted and sensitive data

Unless Yotta expressly agrees in writing, Customer must not submit to Ulam Alloy:

If Customer submits such data despite this restriction, Customer remains responsible for ensuring a lawful basis, conditions for processing, notices, consents, authorisations, safeguards, transfer mechanisms, and risk assessments.


19. AI outputs and automated decisions

Yotta provides an experimental AI interface and API. Outputs may be inaccurate, incomplete, biased, outdated, offensive, unsafe, or unsuitable.

Customer must not use Ulam Alloy outputs as the sole basis for decisions that produce legal or similarly significant effects concerning individuals, including decisions involving employment, credit, housing, insurance, healthcare, education, immigration, criminal justice, law enforcement, eligibility, benefits, or access to essential services.

Customer is responsible for human review, validation, explainability, fairness assessment, recordkeeping, and compliance where outputs are used in consequential contexts.


20. Return or deletion on termination

Upon termination or expiry of the service agreement, Yotta will delete or return Customer Personal Data in accordance with this DPA, the service agreement, and product capabilities, unless retention is required or permitted by law.

The intended one-month API gateway diagnostic payload retention period may continue for data submitted before termination, subject to any legally required or agreed deletion request. Web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records may be retained for longer as described in this DPA and the Privacy Policy.

Metadata, billing records, security logs, support records, backups, and legal records may be retained as described in this DPA and the Privacy Policy.


21. Liability

Each party's liability under this DPA is subject to the liability limits, exclusions, and remedies in the applicable service agreement, except where Applicable Data Protection Laws require otherwise.

Nothing in this DPA limits liability that cannot legally be limited.


22. Term and survival

This DPA remains in effect for as long as Yotta processes Customer Personal Data on behalf of Customer.

Sections relating to confidentiality, deletion, international transfers, liability, audit records, and legal compliance survive termination to the extent necessary.


Schedule 1 — Details of processing

A. Subject matter

Processing of Customer Personal Data through Ulam Alloy, an experimental AI chat interface and API for AI/model routing, inference, generation, embeddings, transformations, evaluation, monitoring, debugging, support, abuse prevention, and product improvement.

B. Duration

For the term of Customer's use of Ulam Alloy and thereafter as necessary for deletion, backup cycles, legal compliance, security, billing, dispute resolution, and other purposes described in the DPA.

API gateway diagnostic payload logs, where kept by Yotta, are intended to be retained for up to one month / 30 days unless deleted earlier or retained longer where required or permitted. Web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records may be retained for longer.

C. Nature and purpose of processing

D. Categories of Data Subjects

E. Categories of Personal Data

F. Special categories of data

Special Category Data, criminal offence data, children's data, payment card data, credentials, government identifiers, confidential legal material, trade secrets, and other restricted data are not permitted unless expressly agreed in writing.

G. Processing locations

The United Kingdom and other countries where Yotta, Partners, External Model Providers, infrastructure providers, support providers, or other vendors operate.

H. Retention

API gateway diagnostic payload logs, where kept by Yotta: intended up to one month / 30 days.

Web chat history and uploaded files: account life or until deleted, subject to product capabilities and legal/security needs.

Operational metadata, security logs, billing records, account data, support records, and legal records: may be retained longer where necessary.

Backups: deleted or overwritten on the normal backup lifecycle.


Schedule 2 — Technical and organisational measures

Yotta will maintain commercially reasonable technical and organisational measures appropriate to an experimental AI routing product. Measures may include, as applicable:

AreaMeasures
Transport securityHTTPS/TLS for web and API traffic
Access controlsAccount authentication, API keys, workspace or role controls where available
Least privilegeInternal access limited to personnel and systems with a business need
ConfidentialityPersonnel and contractors with access to personal data subject to confidentiality obligations
Logging and monitoringService logs, error logs, usage logs, abuse monitoring, and security monitoring
Retention controlsAPI gateway diagnostic payload logs, where kept by Yotta, intended to be retained for up to one month / 30 days, subject to stated exceptions; web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records may be retained longer
Vendor managementUse of cloud, infrastructure, model, routing, support, analytics, and security vendors necessary to operate the service
Abuse preventionRate limiting, misuse detection, content-safety review, blocking, account enforcement, and investigation where appropriate
Incident responseInvestigation, mitigation, and notification of relevant security incidents
BackupsBackup and disaster recovery processes where implemented
Data minimisationUsers and customers instructed not to submit unnecessary sensitive or confidential data

Unless expressly agreed in writing, this DPA does not claim that Ulam Alloy has SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or equivalent certification.


Schedule 3 — Subprocessors, partners, and external model providers

Yotta may use the following categories of providers:

CategoryPurpose
External AI/model providersInference, generation, embeddings, classification, transformation, moderation, evaluation
Routing providersRouting, fallback selection, provider availability, latency management
Cloud and hosting providersCompute, storage, networking, databases, infrastructure
Observability and logging providersReliability, debugging, error monitoring, security monitoring
Analytics providersProduct analytics, usage measurement, experimentation
Support providersCustomer support, ticketing, user communications
Payment and billing providersPayments, subscriptions, invoicing, tax, billing records
Security providersAbuse prevention, fraud detection, security monitoring, incident investigation
Professional advisersLegal, accounting, insurance, compliance, audit support

Current provider list: https://chat.ulam.ai/subprocessors

Customer acknowledges that External Model Providers and Partners may have their own retention, logging, training, improvement, monitoring, security, and geographic processing practices.


Schedule 4 — International transfer terms

Where restricted transfers occur, the parties will use appropriate transfer mechanisms where required by Applicable Data Protection Laws.

For transfers subject to EU GDPR, the parties may rely on the European Commission Standard Contractual Clauses, including Module 2 or Module 3 as applicable.

For transfers subject to UK GDPR, the parties may rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable.

Where Yotta transfers Customer Personal Data to External Model Providers or Partners outside the UK or EEA, Yotta will use appropriate transfer safeguards where required and available. Customer acknowledges that provider availability, routing, and processing locations may vary.


Schedule 5 — Customer-controlled compliance checklist

Before using Ulam Alloy in production, Customer should confirm: