Legal
Data Processing Addendum
Last updated: 21 June 2026
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", "Controller") and Terradium, created by Kugie and operated by PT. Semesta Solusi Digital ("Terradium", "Processor"), and governs Terradium's processing of personal data on the Customer's behalf when using the Service — including the visitor events collected by the Terradium Embed SDK.
1. Roles of the parties
With respect to personal data Terradium processes on the Customer's behalf — in particular the Embed SDK visitor events collected on the Customer's website — the Customer is the Controller and Terradium is the Processor. Terradium processes such data only on the Customer's documented instructions, which include this DPA, the configuration the Customer chooses in the dashboard, and the use of the Service in accordance with its documentation.
Terradium acts as an independent Controller for limited data relating to its own account administration, billing, and security; that processing is described in our Privacy Policy.
2. Subject matter and nature of processing
- Subject matter. Provision of the Service — generating and serving content, sampling AI engines for visibility metrics, and collecting visitor attribution events via the Embed SDK.
- Categories of data subjects. The Customer's authorized users and the visitors to the Customer's website on which the embed is installed.
- Categories of personal data. By default, non-PII traffic-source signals collected by the embed (referrer and AI- referral classification, UTM/
gclidparameters, entry path, and optional survey answers). Source IP addresses are anonymized server-side and not stored in raw form. The embed does not collect names, emails, advertising identifiers, or precise location by default.
3. Customer obligations
- Install the embed only on websites the Customer operates or is authorized to instrument.
- Provide an accurate privacy notice to visitors and obtain any consent required by applicable law before the embed collects attribution or survey data.
- Configure the embed's consent posture appropriately for its jurisdictions; when consent is required and not granted, the embed remains in a no-op / minimal mode.
- Issue lawful instructions and not require Terradium to process personal data in violation of applicable data protection law.
4. Sub-processors
The Customer authorizes Terradium to engage sub-processors to provide the Service. Terradium imposes data protection obligations on each sub-processor that are no less protective than those in this DPA. Current sub-processors include:
- Clerk — authentication (account users only).
- OpenRouter and underlying model providers — content generation and prompt sampling.
- Google — Search Console data for connected properties.
- Cloudflare R2 — object storage for generated images.
- Polar — billing and customer portal.
- Resend — transactional and notification email.
- Slack — optional notification delivery.
Terradium will give the Customer reasonable notice of any new or replacement sub-processor that processes personal data on the Customer's behalf, and the Customer may object on reasonable data protection grounds.
5. Security measures
- Encryption of secrets at rest using AES-256-GCM (API keys, webhook secrets, and connected-integration tokens).
- Encryption in transit via TLS for all API, dashboard, and embed traffic.
- Server-side anonymization of source IP addresses at the embed ingestion endpoint; raw IPs are not stored.
- Tenant isolation — every record is scoped to the owning account at the database level.
- Authentication on all API and embed requests, with rate limiting on the public embed endpoint.
- Access controls and audit logging for administrative operations.
6. Data location
The Service and its primary data stores are self-hosted on infrastructure managed via Coolify. Certain sub-processors named in section 4 may process limited data in other regions to deliver their part of the Service. Where personal data is transferred across borders, Terradium relies on appropriate safeguards.
7. Data subject requests
Taking into account the nature of the processing, Terradium will assist the Customer, by appropriate technical and organizational measures and insofar as possible, in responding to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability, or objection). Because the embed operates without PII by default, individual visitor records are generally not directly identifiable; Terradium will assist with deletion or aggregation of the relevant visitor_events where a request can be reasonably matched. If a data subject contacts Terradium directly about data collected via a Customer's embed, Terradium will refer them to the Customer as Controller.
8. Retention and deletion of visitor_events
Embed visitor events (stored as visitor_events) are retained only as long as needed to power attribution reporting and are then deleted or aggregated into non-identifying counts. On termination of the Customer's account, or on a valid deletion request, Terradium will delete or return the visitor_events processed on the Customer's behalf within a reasonable period, except where retention is required by law.
9. How to request deletion
The Customer can delete a project and its associated visitor_events from the dashboard, or request deletion by emailing legal@kugie.app from the account owner's address, identifying the project(s) concerned. We will confirm completion of the deletion request.
10. Personal data breach
Terradium will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will provide information reasonably available to it to help the Customer meet its own notification obligations.
11. Audits
On reasonable prior written request, and subject to confidentiality, Terradium will make available information necessary to demonstrate compliance with this DPA and will contribute to reasonable audits conducted by the Customer or an auditor it mandates.
12. Contact
For DPA questions, to request a signed copy, or to exercise rights under this DPA, contact us at legal@kugie.app.