HorusEngine
API guidePricingSupportSign inGet started

Data Processing Agreement

Effective date August 15, 2026 · Last updated August 15, 2026

This Data Processing Agreement ("DPA") supplements the Terms of Service ("Agreement") entered into between ZOEARK LLC (doing business as ZOEARK, ZOEARK Studio, ZOEARK Labs) (“the Company”, “we”, “us”, or “our”) and the entity agreeing to these terms ("Customer", "Developer", "Integrator", or "you"). This DPA governs the processing of any personal data submitted by Customer through HorusEngine (the "Service", or “API”).

1 DEFINITIONS

1.1 "Data Protection Laws" means all applicable privacy and data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1.2 "Customer Personal Data" means any personal data or image payloads processed by HorusEngine on behalf of the Customer via the API.
1.3 "Controller" and "Processor" have the meanings given under applicable Data Protection Laws.

2 ROLES AND PROCESSING INSTRUCTIONS

2.1 Roles: The parties acknowledge and agree that Customer acts as a Data Controller, and ZOEARK LLC acts strictly as a Data Processor regarding Customer Personal Data.
2.2 Instructions: ZOEARK LLC shall process Customer Personal Data solely to provide, maintain, and secure the API Service as documented in the Agreement, or as otherwise instructed by Customer.
2.3 Compliance: Customer represents and warrants that it has obtained all necessary consents, rights, and provided required privacy disclosures to its end-users to lawfully transmit data through the API.

3 STATELESS NATURE AND DATA RETENTION

3.1 Volatile Processing: Customer acknowledges that the HorusEngine API is designed to be stateless. Image and text payloads are processed entirely in volatile memory and are instantly discarded from HorusEngine’s application layer upon delivery of the API response.
3.2 Logs: We do not store, archive, or inspect payload contents. We retain only operational technical metadata (e.g., status codes, latency, token counts) for a period of ninety (90) days to manage billing and prevent system abuse.

4 SUBPROCESSORS

4.1 Authorized Subprocessors: Customer grants generic written authorization for ZOEARK LLC to engage third-party infrastructure providers ("Subprocessors") to fulfill the Service. A current list of our approved Subprocessors, including their locations and processing activities, is maintained at horusengine.com/subprocessors.

4.2 Notice of Changes: We will update our online Subprocessor list at least thirty (30) days before authorizing any new Subprocessor. Customer's continued use of the API constitutes acceptance of the updated list.

5 SECURITY AND BREACH NOTIFICATION

5.1 Technical Measures: We implement industry-standard technical and organizational security measures to safeguard our API infrastructure and developer access keys.
5.2 Incident Response: In the event of a confirmed security incident impacting our infrastructure that compromises Customer account data, we will notify Customer via email without undue delay. Because payload data is stateless and not stored by us, security incidents do not expose historical text or image uploads.

6 DATA TRANSFERS AND LIABILITY

6.1 International Transfers: To the extent Customer Personal Data originates from the European Economic Area (EEA), UK, or Switzerland and is transferred to servers in the United States, the parties agree that such processing relies on standard contractual safeguards implemented by our underlying hosting and processing partners.
6.2 Limitation of Liability: Each party’s total aggregate liability arising out of or related to this DPA shall be strictly limited by the liability caps set forth in the core Agreement.

← Back to home · Privacy Policy · Subprocessors

© 2026 ZOEARK LLC

API guidePricingSupportTermsPrivacyDPASubprocessorsSign in