Legal pages
Parties and roles.
This agreement is between you, the client (the “controller”), and {{ENTITY_NAME}}, with registered address at {{ENTITY_ADDRESS}} and tax identification number {{ENTITY_TAX_ID}} (the “processor”). It applies whenever we process personal data on your behalf as part of a project or service you have engaged us for.
REVIEW: confirm the registered entity, address and tax ID, and have counsel review this agreement against local data protection law before it is signed.
Subject matter and duration.
We process personal data only for the duration of the underlying project or service agreement, and only to deliver what that agreement describes. When the agreement ends, this data processing agreement ends with it, subject to the retention rules in “Deletion or return of data” below.
Nature and purpose of the processing.
The processing consists of the operations needed to build, run and support the system we deliver: storing, structuring, analyzing and, where the project requires it, training or evaluating models on the data you provide. We do not process your data for any purpose beyond what your project requires.
Categories of data and data subjects.
The categories of data and data subjects depend on your project and are described in the project agreement or its technical appendix, not in this general document. We process only the data you give us access to, and nothing we collect independently.
Our obligations as processor.
We process personal data only on your documented instructions, keep it confidential, and apply the security measures described below. We tell you if an instruction you give us would, in our view, break data protection law, before we carry it out.
Sub-processors.
We use a small number of sub-processors to host and run the systems we build for you, such as cloud infrastructure and model providers. We choose sub-processors that commit to data protection terms at least as strict as this agreement, and we tell you before we add a new one so you can object.
Security measures.
We apply technical and organizational measures appropriate to the risk: encryption in transit, access limited to the people who need it, and monitoring of the systems that hold your data. {{ENTITY_NAME}} reviews these measures as the project and the data they protect change.
Data subject requests.
If someone asks you to access, correct or delete their data and it lives in a system we operate for you, we help you answer that request within the time the law allows. We do not respond to a data subject directly unless you ask us to.
Breach notification.
If we become aware of a personal data breach affecting data we process for you, we tell you without undue delay, with what we know at that point: what happened, what data is affected, and what we are doing about it. We keep you updated as we learn more.
Audits.
You can ask us for information that shows we meet the obligations in this agreement, and, where reasonably needed, request an audit of the relevant systems. We agree on scope, timing and confidentiality with you before an audit takes place.
Deletion or return of data.
When the project agreement ends, we delete or return the personal data we hold for you, at your choice, unless the law requires us to keep it longer. We confirm in writing once deletion is complete.
Governing law.
This agreement is governed by the law that governs the underlying project agreement, unless local data protection law requires otherwise.
