Continuer → Aperçu

Data Processing Agreement

This agreement applies whenever you send personal data to the NameGender API or upload a file for batch processing. It forms part of the Terms of Service and takes effect automatically when you create an account. No signature is required; a countersigned copy is available on request.

Effective date: 28 août 2026

Ce document est conservé uniquement dans les langues ci-dessous, afin qu'une erreur de traduction ne puisse pas en modifier le sens. La version anglaise prévaut en cas de litige. Disponible en : English Türkçe

1. Roles

You are the controller of the personal data you submit. NameGender is the processor and acts only on your documented instructions, which are the API requests and batch jobs you send.

For your own billing data — the account you register and the orders you place — NameGender is a controller in its own right, and the Privacy Policy governs that processing rather than this agreement.

2. Subject matter, nature and purpose

The processing consists of receiving a value, matching it against a name dataset, and returning a gender estimate together with the evidence behind it. Nothing else is done with the data.

Processing lasts for as long as your account is active. It ends when the account is closed or when you delete the data sooner.

3. Categories of data

The categories are determined by what you choose to send. In normal use they are:

  • Data subjects: the individuals whose names, email addresses or usernames you submit — typically your customers, contacts, users or survey respondents.
  • Personal data: first names and full names; email addresses; usernames or social handles; and any additional columns present in a file you upload for batch processing.
  • No special category data is required by the service, and the service must not be used to infer it. A gender estimate produced by this service is a statistical inference, not a statement about any individual.

4. Instructions and confidentiality

NameGender processes personal data only on your instructions, including on transfers, unless required to do otherwise by law that applies to it. Where such a legal requirement arises, you will be informed before processing unless that law forbids it.

Personnel authorised to process personal data are bound by confidentiality.

5. Security measures

The following measures are in place. They are described concretely rather than as a list of adjectives, so you can assess them:

  • Transport encryption for all API and dashboard traffic.
  • API keys are stored as cryptographic hashes. The full key is shown once at creation and cannot be recovered afterwards; keys can be restricted and revoked from the dashboard.
  • Uploaded source files are deleted as soon as processing finishes, in every path including failure.
  • Result files are retained for at most the retention period shown in your dashboard, and can be deleted immediately by you at any time.
  • Raw request logs are pruned on a schedule; aggregate usage counters, which contain no submitted values, are retained for billing and support.
  • Database backups are encrypted at rest, retained on a fixed rotation, and monitored — a backup that has not run is treated as a fault.
  • Availability and integrity of the service are monitored continuously, including by an external heartbeat that fires an alarm when the service stops reporting at all.

6. Sub-processors

You give general authorisation for the sub-processors below. You will be notified before a new sub-processor is added, and you may object; if an objection cannot be resolved you may terminate the affected service and receive a refund of unused credits.

  • Hosting and storage provider: operates the servers, database and file storage. Location is stated on request.
  • Anthropic PBC: used only when you explicitly enable the AI fallback for your account. Only the name itself is sent — never the surrounding row, the email address or any other column. Retention at the provider is limited, and the exact provider, model and retention are stated in your dashboard and in the API response.
  • The AI fallback is off by default and cannot be switched on by an API parameter alone; it requires a recorded account-level consent, and that consent is invalidated when the provider or the nature of the processing changes.

7. Payments

Card payments are handled by Paddle acting as merchant of record. Paddle is a separate controller for the payment data it collects; NameGender does not receive or store card details. Crypto payments involve no third-party processor and no personal data beyond the order record.

8. Assistance with data subject rights

Taking into account the nature of the processing, NameGender assists you in responding to requests to exercise data subject rights. Because submitted values are not retained beyond the periods described above, most requests can be satisfied by deletion, which you can perform yourself from the dashboard without contacting support.

NameGender also assists you with security, breach notification and data protection impact assessments, taking into account the information available to it.

9. Personal data breach

NameGender notifies you without undue delay after becoming aware of a personal data breach affecting your data, with the information needed for you to meet your own notification obligations.

10. Return and deletion

Uploaded source files are deleted automatically after processing. Result files are deleted at the end of the retention period, or immediately when you choose to delete them.

On termination, remaining data is deleted. Records required for accounting, fraud prevention or a legal obligation — order records, credit ledger entries and aggregate usage counters — are retained for as long as that obligation lasts. These contain no submitted names.

11. Audits

NameGender makes available the information necessary to demonstrate compliance with this agreement and allows for audits, including inspections, by you or an auditor you mandate. Audits are conducted on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, and must not compromise the confidentiality of other customers.

12. International transfers

Where personal data is transferred outside the EEA or the UK, the transfer is covered by an adequacy decision or by Standard Contractual Clauses with the relevant sub-processor. Copies are available on request.

13. Contact

Questions about this agreement, requests for a countersigned copy, sub-processor locations or transfer documentation:

info@namegender.com

Service operator

Operator
NameGender
Contact email
info@namegender.com