Legal

DPA summary & sub-processors

Honest summary for self-hosted ReboundPad. A counsel-drafted DPA / MSA is still required for enterprise contracts. Last updated 2026-09-30.

Self-hosted (primary)

For a customer-operated deployment, ReboundPad is typically not a processor of customer prompts, credentials, or flow data, because that data never leaves the customer environment. There are no ReboundPad sub-processors for that data path.

Details: product pack compliance/SUBPROCESSORS.md and compliance/SHARED_RESPONSIBILITY.md.

What customers usually process themselves

  • Model providers (Azure OpenAI, Bedrock, Vertex, Ollama, gateways)
  • Cloud / on-prem infrastructure
  • Connector targets (Jira, Slack, databases, …)
  • Optional observability backends

Those relationships are between the customer and those vendors.

Self-hosted cloud ops vs hosted SaaS

Self-hosted cloud ops (tenants/regions/provisioning + Helm/TF on your infrastructure) is GA. ReboundPad-hosted multi-cloud SaaS with billing/SLA is not offered. If/when a hosted control plane processes customer data, a formal sub-processor list and DPA will be published before that offering is sold. Do not treat this page as authorization to process regulated data in a ReboundPad-hosted environment today.

Marketing site

Demo-request email content is handled as ordinary sales correspondence. See Privacy.

Next step for procurement

Request the security pack (compliance/) and a counsel-reviewed DPA/MSA via [email protected].