Skip to main content

Data Processing Agreement Overview

Version and effective date: 2026-08-19.

This page describes the managed-instance contracting framework. It is not an executed agreement and is not legal advice. Request the applicable executed documents from contact@metrum.ai before a managed-instance deal closes.

For customer workloads, the customer normally determines the purposes and means of processing and acts as controller; Metrum acts as processor when it operates a managed router instance. The final executed agreement controls and may define roles differently for a specific engagement.

The router ordinarily processes scalar usage telemetry such as request IDs, caller labels, route selection, status, timing, token counts, and calculated costs. Raw prompts, images, tool outputs, credentials, and unsanitized provider responses are excluded from ordinary usage diagnostics. Optional governed content capture is a separate, disabled-by-default feature that requires explicit configuration, encryption, restricted access, and retention policy.

Applicable subprocessors and processing locations are described in the Subprocessor List and Transfer Schedule. Customer-selected BYOK model providers are customer choices and are not Metrum subprocessors unless Metrum operates or contracts them for the managed service.

Contact Metrum to request the current executed DPA, SCCs, security exhibits, subprocessor terms, or data-subject request support procedure.