Navigation

Data processing agreementものづくり

v1.0 - Last Updated 2026.07.24

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of and is incorporated by reference into the API Terms of Service published at https://takara.ai/api-terms (the "API Terms") between Takara.AI Ltd, a UK limited company with company number 15404713 and principal office at 128 City Road, London, United Kingdom, EC1V 2NX ("Takara" or the "Processor"), and the Customer identified in the API Terms (the "Customer" or the "Controller").

By accepting the API Terms, the Customer accepts and enters into this DPA. No signature is required. Capitalised terms used but not defined in this DPA have the meanings given in the API Terms. In the event of any conflict between this DPA and the API Terms, this DPA shall prevail in respect of data protection matters.

  • the Data Processing Agreement published at https://takara.ai/legal/data-processing-agreement (the “DPA”); and

  • Takara’s Data Privacy Policy published at https://takara.ai/legal/privacy-policy (the “Privacy Policy”), which governs Takara’s processing of personal data for which Takara is the Data Controller, including Customer’s account, billing, usage, and support data.

1. Definitions

“Customer Data” — has the meaning given in the API Terms — any data, including text, submitted by or on behalf of the Customer to the API Service for processing. For the purposes of this DPA, references to Customer Data include the Output generated from it.

“Data Protection Laws” — the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018 ("UK GDPR"), the Data Protection Act 2018, the General Data Protection Regulation (EU) 2016/679 where applicable, and any implementing or successor legislation, as amended or replaced from time to time.

“Data Subject” — an identified or identifiable natural person to whom Personal Data relates.

“API Call” — a single request submitted to the API Service and the corresponding response.

“Personal Data” — has the meaning given in the UK GDPR — any information relating to an identified or identifiable natural person. In this DPA, references to Personal Data mean Personal Data contained in Customer Data.

“Processing” — has the meaning given in the UK GDPR and includes any operation performed on Personal Data, including transient or temporary operations carried out in volatile memory.

“Security Incident” — any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA.

“Sub-processor” — any third party engaged by the Processor to process Personal Data on the Processor’s behalf in connection with the API Service.

“Supervisory Authority” — the Information Commissioner’s Office (ICO) in the United Kingdom, or any successor or equivalent authority.

2. Roles of the Parties

“Customer Data” — has the meaning given in the API Terms — any data, including text, submitted by or on behalf of the Customer to the API Service for processing. For the purposes of this DPA, references to Customer Data include the Output generated from it.

“Data Protection Laws” — the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018 ("UK GDPR"), the Data Protection Act 2018, the General Data Protection Regulation (EU) 2016/679 where applicable, and any implementing or successor legislation, as amended or replaced from time to time.

“Data Subject” — an identified or identifiable natural person to whom Personal Data relates.

“API Call” — a single request submitted to the API Service and the corresponding response.

“Personal Data” — has the meaning given in the UK GDPR — any information relating to an identified or identifiable natural person. In this DPA, references to Personal Data mean Personal Data contained in Customer Data.

“Processing” — has the meaning given in the UK GDPR and includes any operation performed on Personal Data, including transient or temporary operations carried out in volatile memory.

“Security Incident” — any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA.

“Sub-processor” — any third party engaged by the Processor to process Personal Data on the Processor’s behalf in connection with the API Service.

“Supervisory Authority” — the Information Commissioner’s Office (ICO) in the United Kingdom, or any successor or equivalent authority.

3. Scope and Nature of Processing

The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are set out in Annex B.

Processing under this DPA is stateless and transient by design. Customer Data exists in volatile memory only for the duration of each API Call. Upon completion of the API Call, memory is released and the data is irreversibly discarded. Takara does not store, retain, log, or cache Customer Data or Output. No human operators have access to Customer Data in transit. This architecture implements the principles of data protection by design and by default under Article 25 of the UK GDPR.

Takara shall not use any Personal Data processed under this DPA for the training, fine-tuning, or improvement of any artificial intelligence or machine learning model.

Takara collects only aggregated, anonymised usage metadata (request volumes, latency, and error rates) in connection with API Calls. Usage metadata never includes the content of Customer Data or Output.

4. Controller Obligations

The Customer warrants, represents, and undertakes that:

  1. it has and shall maintain a lawful basis under the Data Protection Laws for all Personal Data submitted to the API Service;

  2. it has provided appropriate notices to, and where required obtained the necessary consents from, Data Subjects in relation to the processing of their Personal Data via the API Service;

  3. it shall apply data minimisation principles and shall not submit Personal Data that is not necessary for its purposes, and shall not submit special category data (Article 9 UK GDPR) or criminal offence data (Article 10 UK GDPR) except where it has satisfied itself that an appropriate condition for processing applies;

  4. it is responsible for responding to requests from Data Subjects exercising their rights under the Data Protection Laws, as described in Section 8; and

  5. it shall comply at all times with the Data Protection Laws in connection with its use of the API Service.

5. Processor Obligations

Processing on instructions. Takara shall process Personal Data only as described in Section 2 and for no other purpose.

Confidentiality. Takara shall ensure that all persons authorised to operate the systems that process Customer Data are subject to appropriate obligations of confidentiality, whether by contract or statute. For the avoidance of doubt, no Takara personnel have access to the content of Customer Data.

No retention. Takara shall not retain Personal Data beyond the duration of each API Call. The obligations under Article 28(3)(g) of the UK GDPR to delete or return Personal Data at the end of the provision of services are satisfied continuously and by design: there is no Personal Data to delete or return upon termination.

Security. Takara shall implement and maintain appropriate technical and organisational measures to protect Personal Data during transient processing, as set out in Annex A.

Assistance. Taking into account the nature of the processing, Takara shall assist the Customer in meeting its obligations under Articles 32 to 36 of the UK GDPR, to the extent such assistance is possible given that no Personal Data is retained. The information in this DPA, Annex A, and Takara’s Documentation constitutes Takara’s assistance with the Customer’s data protection impact assessments and prior consultations, and Takara shall provide such further information as the Customer reasonably requests.

6. Security Measures

Takara shall implement and maintain the technical and organisational measures set out in Annex A, and shall regularly review, test, and where appropriate update those measures to ensure they remain appropriate to the risk presented by the processing.

7. Sub-processors

The Customer grants general written authorisation to Takara to engage Sub-processors for the provision of the API Service, provided that:

  1. Takara imposes data protection obligations on each Sub-processor that are no less protective than those set out in this DPA;

  2. Takara remains fully liable to the Customer for the performance of each Sub-processor’s obligations under this DPA; and

  3. Takara provides not less than 30 days’ prior notice of any intended addition or replacement of a Sub-processor, by updating the Sub-processor list at https://takara.ai/legal/sub-processors and notifying the Customer by email or account notification.

The Customer may object to a change on reasonable data protection grounds within 14 days of notice. If Takara cannot accommodate the objection, the Customer may terminate its account in accordance with the API Terms as its sole remedy.

As at the Last Updated date, Takara’s sole Sub-processor in connection with Customer Data is Amazon Web Services (cloud infrastructure on which the API Service runs). Because Customer Data is processed transiently in volatile memory and is never stored, logged, or cached, no Sub-processor retains Customer Data. Takara’s other service providers (payment, support, and analytics tools) process only Account Information and are addressed in the Privacy Policy, not this DPA.

8. Data Subject Rights

Taking into account the nature of the processing, Takara shall assist the Customer in fulfilling its obligation to respond to Data Subject requests under the Data Protection Laws. The parties acknowledge that, because Takara retains no Personal Data, Takara holds no data capable of being accessed, corrected, erased, ported, or restricted, and the Customer — who holds the source data and the Output — is solely able to fulfil Data Subject requests. Takara’s assistance obligation under Article 28(3)(e) of the UK GDPR is discharged accordingly, save that Takara shall confirm its no-retention architecture in writing upon the Customer’s reasonable request.

If Takara receives a request directly from a Data Subject relating to processing under this DPA, Takara shall promptly refer the request to the Customer where identifiable and shall not respond directly except as required by law.

9. Security Incident Notification

Takara shall notify the Customer without undue delay, and where feasible within 72 hours, upon becoming aware of a Security Incident. The notification shall, to the extent reasonably practicable, describe the nature of the incident, the likely consequences, the measures taken or proposed, and a contact point (security-incident@takara.ai) for further information. The parties acknowledge that, given the stateless architecture, a Security Incident affecting Personal Data could arise only from a compromise of data in transit or in volatile memory during processing.

Takara shall take reasonable steps to contain and mitigate any Security Incident and shall cooperate with the Customer in any subsequent investigation or notification to a Supervisory Authority or Data Subjects. Notification of or response to a Security Incident shall not be construed as an admission of fault or liability.

10. International Data Transfers

The API Service processes Customer Data transiently in the AWS regions identified in the Documentation [list regions]. Where processing of Personal Data takes place in, or Personal Data is routed through, a country outside the United Kingdom or the European Economic Area that is not covered by an adequacy decision, Takara shall ensure that an appropriate safeguard under the Data Protection Laws is in place, which may include the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism recognised under the Data Protection Act 2018. Takara shall, upon request, provide the Customer with details of the applicable transfer mechanisms.

11. Audits and Compliance

Takara shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR. Given the self-service, multi-tenant nature of the API Service, Takara satisfies audit requests by providing: (a) this DPA and Annex A; (b) relevant third-party certifications, security audit reports, or penetration test summaries, subject to appropriate confidentiality undertakings; and (c) written responses to reasonable security questionnaires. On-site audits are permitted only where required by a Supervisory Authority or mandatory law, on not less than 30 days’ written notice, at the Customer’s cost, no more than once per calendar year, and subject to Takara’s reasonable security and confidentiality requirements.

12. Term and Termination

This DPA takes effect on the Effective Date of the API Terms and continues for so long as Takara processes Personal Data on the Customer’s behalf in connection with the API Service. It terminates automatically upon termination of the API Terms. No return or deletion of Personal Data is required on termination, as none is retained (see Section 5, No retention). Accrued rights and liabilities survive termination.

13. Liability

Each party’s liability under this DPA is subject to and governed by the limitations and exclusions of liability set out in the API Terms. Each party is individually liable for any breach of its own obligations under the Data Protection Laws. The Customer’s indemnity in respect of Customer Data, including Personal Data unlawfully collected or processed by the Customer, is as set out in the API Terms.

14. General Provisions

This DPA is governed by the laws of England, and the parties submit to the exclusive jurisdiction of the courts of England. Takara may update this DPA to reflect changes in the Data Protection Laws or the API Service on not less than 30 days’ notice in accordance with the change mechanism in the API Terms; changes shall not materially reduce the protections for Personal Data. If any provision is held invalid, the remainder continues in full force. This DPA is made for the benefit of the parties only; the Contracts (Rights of Third Parties) Act 1999 is excluded.

Annex A — Technical and Organisational Measures

A.1 Architecture

The API Service is stateless: Customer Data and Output are never written to persistent storage, logs, or caches. Data exists in volatile memory only for the duration of each API Call and is irreversibly discarded on completion.

Application logging is configured to exclude request and response payloads. Only aggregated, anonymised usage metadata (request volumes, latency, error rates) is recorded.

A.2 Encryption and Transmission Security

All API communications are encrypted in transit using Transport Layer Security (TLS) version 1.2 or higher. Connections using deprecated protocols (SSL, TLS 1.0, TLS 1.1) are rejected.

Authentication to the API Service is by unique API Keys, transmitted only over encrypted connections.

A.3 Infrastructure Security

The API Service is deployed on Amazon Web Services in accordance with the AWS Well-Architected Framework, using Virtual Private Clouds, security groups, and network access controls.

Access to production infrastructure is restricted to authorised personnel using role-based access control, the principle of least privilege, and multi-factor authentication for all administrative access. No personnel have access to the content of Customer Data.

Infrastructure activity is monitored and logged using AWS CloudWatch and AWS CloudTrail (infrastructure events only — never Customer Data payloads), with automated security patching of all components.

A.4 Personnel and Organisational Measures

All personnel with access to production systems are subject to confidentiality obligations and receive data protection awareness training.

Takara maintains an incident response procedure for Security Incidents and conducts regular security assessments and reviews of these measures.

Annex B — Processing Description

Subject matter

Provision of the API Service: a stateless embedding API that accepts text input and returns numerical vector representations (embeddings), as described in the API Terms and the Documentation.

Nature of processing

Transient, automated processing in volatile memory for the duration of each API Call: receipt of text input over an encrypted connection, mathematical transformation into embedding vectors, and return of the Output. No storage, retention, logging, or caching of Customer Data or Output. No human access to content.

Purpose

Solely to generate and return Output in response to each API Call submitted by the Customer.

Duration

The duration of each individual API Call (typically fractions of a second). The DPA remains in force for the term of the API Terms, but no Personal Data persists between API Calls.

Types of Personal Data

Any Personal Data contained in text submitted by the Customer to the API Service. The Customer determines the content of Customer Data; Takara has no visibility into or control over it. The API Service is not intended for special category or criminal offence data (see Section 4(c)).

Categories of Data Subjects

Any individuals whose Personal Data appears in text submitted by the Customer, as determined by the Customer.

Retention

None. Customer Data and Output are irreversibly discarded upon completion of each API Call.

Sub-processors

Amazon Web Services (cloud infrastructure; transient processing only — no retention of Customer Data). Current list maintained at https://takara.ai/legal/sub-processors.

Ray graphicRay graphicRay graphic
Ray graphicRay graphicRay graphicRay graphic

Stay in the loop

Subscribe for the latest news & updates.