Data Processing Agreement (Gated)
8 source changes since auditThis page confirms that a Data Processing Agreement exists and explains how to request it. The agreement itself is contractual and gated; it is not authored in these public docs.
What it is
Citrate maintains a Data Processing Agreement, with the service-level and subprocessor terms that go alongside it, as part of its contracting package. Because Citrate runs on-premise on Citrate Ground, a customer's data and models stay on the customer's own hardware, and the data-handling boundary sits with the customer. The agreement is what states that boundary in writing, so each side knows what it is responsible for.
We do not reproduce any of the terms here. No service levels, no subprocessor identities, and no customer specifics appear on this page or anywhere in the public docs.
How to request access
Access is for named principals with a contractual reason to read the agreement, each under a non-disclosure agreement.
- Ask through your account channel or your commercial contact at Citrate.
- We confirm your role and put the non-disclosure agreement in place.
- We share the current document of record from its private home.
Access and canon
The agreement is confidential. It is served at request time from its private home, under a non-disclosure agreement, to named recipients only. It is never copied into this documentation tree, and the public build never includes it. Every access is logged. The sanitized public summary of our compliance posture, which anyone may read, is at Compliance posture.
Source and verification
Private source: the citrate-compliance corpus. Audited against citrate-compliance SHA 8757357. Status: Implemented (the agreement exists and is maintained as the document of record); no terms are shown here.