← All pages

1. What the document is: Despite being filed under "Data Processor Agreement," the captured page is actually a bare subprocessor/subcontractor list ("Meta Horizon Managed Solutions List of Sub-Processors and Subcontractors," effective 13 November 2023) — no GDPR Article 28 contractual obligations, no SCC references, and no substantive legal text are present in this capture. The document title ("Meta Horizon") suggests this list may be shared/reused across multiple Meta product DPAs rather than being Llama-API-specific.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

Llama API – Data Processor Agreement

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/Llama API/Data Processor Agreement/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2025-11-12 (only capture in this dataset)

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags on this page are LLM-assigned. Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: Despite being filed under “Data Processor Agreement,” the captured page is actually a bare subprocessor/subcontractor list (“Meta Horizon Managed Solutions List of Sub-Processors and Subcontractors,” effective 13 November 2023) — no GDPR Article 28 contractual obligations, no SCC references, and no substantive legal text are present in this capture. The document title (“Meta Horizon”) suggests this list may be shared/reused across multiple Meta product DPAs rather than being Llama-API-specific.

2. Input rights / 3. Output restrictions: Not addressed — this is purely an entity/location list.

4. Non-explicit predatory clauses: None directly, but notable: the data-centre-infrastructure subprocessor list is dominated by unusually-named single-purpose LLCs (Andale, Cassin Networks, Greater Kudu, Goldframe, Morning Hornet, Offprints, Omanyte, Paile, Raven Northbrook, Scout Development, Siculus, Sidecat, Stadion, Starbelt, Vitesse, Winner LLC d/b/a Ernst LLC, Woolhawk) — consistent with Meta’s publicly-documented practice of using anonymous shell entities to acquire data-center real estate, not itself predatory but worth flagging for transparency purposes since a user cannot tell from this list alone that these are Meta-controlled entities.

5. Regulatory references: None found in this capture — no GDPR or EU AI Act citation, unlike every other provider’s DPA in this dataset.

6. Regional variation: The subprocessor list spans US, Canada, France, Germany, Italy, Netherlands, Poland, Singapore, Spain, UK, Ireland, Denmark, Sweden, and the Philippines — broader geographic spread than most other providers’ DPA subprocessor lists in this dataset.

7. Key risk to users: Low directly, but the complete absence of GDPR/Article 28 contractual language (compared to OpenAI’s, Anthropic’s, and Mistral’s much more detailed DPAs) makes this the thinnest data-processing disclosure in the dataset — a transparency gap rather than an aggressive clause.

No AI-training, data-licensing, or feedback-rights clauses found — this document is a bare entity list.

Regulatory & Research Context

Llama API was not among the providers directly studied by Davidson et al. (2026) or Pandit et al. (2026) in this batch, but Edwards et al.’s (2025) “platformisation paradigm” framework — which describes providers positioning themselves as neutral intermediaries — applies by analogy to the transparency gap noted in Overview point 4: a subprocessor list dominated by unusually-named single-purpose LLCs (Andale, Greater Kudu, Goldframe, etc.) that a user cannot, from this document alone, identify as Meta-controlled entities. The complete absence of GDPR Article 28 contractual language, flagged in Overview point 5, leaves this as the thinnest data-processing disclosure among the DPA documents tracked in this dataset.


Changes Summary

DateWhat changed
2025-11-12Baseline and only version captured in this dataset (“Effective date: 13 November 2023”).

Version History

2025-11-12

No flaggable clauses — a bare subprocessor/subcontractor entity list with no contractual GDPR/data-protection terms attached in this capture.