Data Processing Agreement

Last updated: 1 October 2026 · Version 1.0

This Data Processing Agreement ("DPA") is entered into under Article 28 of Regulation (EU) 2016/679 (the "GDPR") between the customer identified in the order form or account (the "Customer", acting as controller) and DIGITAK SAS, a société par actions simplifiée, registered with the RCS of Paris under SIREN 827 679 093, with registered office at 47 boulevard de Courcelles, 75008 Paris, France (the "Processor", acting as processor). It forms part of the terms of service and applies whenever the Processor processes personal data on behalf of the Customer through the Euravo inference API (the "Service"). Terms not defined here have the meaning given in the GDPR.

1. Subject matter and duration

The subject matter of this DPA is the processing of personal data contained in the content the Customer sends to the Service (prompts, files, and generated outputs, together "API content"). The DPA takes effect when the Customer first uses the Service and remains in force for as long as the Processor processes personal data on the Customer's behalf, including after termination of the terms of service until the deletion described in section 9.

2. Nature and purpose of the processing

3. Types of personal data and categories of data subjects

Data the Processor processes as a controller (account, billing, and operational metadata) is described in the privacy policy and is outside the scope of this DPA.

4. Obligations of the Processor

The Processor shall:

5. Sub-processors

6. Security measures

Taking into account the state of the art and the risks of the processing (GDPR Art. 32), the Processor maintains at least the following measures:

7. Assistance with data-subject rights

Because API content is not retained, the Processor holds no API content to which access, rectification, or erasure could apply after a request completes. The Processor will promptly forward to the Customer any request it receives from a data subject relating to the Customer's processing, will not respond to it directly except on the Customer's instruction, and will otherwise provide reasonable assistance so that the Customer can meet its obligations under Chapter III of the GDPR. It will also assist the Customer, taking into account the information available to it, with data-protection impact assessments and prior consultations (GDPR Art. 35 and 36).

8. Personal data breaches

The Processor will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer's personal data. The notification will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. The Processor will provide further information as it becomes available and assist the Customer with its notifications to the supervisory authority and to data subjects (GDPR Art. 33 and 34).

9. Deletion or return at the end of the contract

API content is deleted from memory as soon as each response is delivered, so none remains at the end of the contract. For any other personal data processed on the Customer's behalf, the Processor will, at the Customer's choice, delete or return it at the end of the provision of the Service and delete existing copies, unless EU or Member State law requires their storage.

10. Audits

The Processor will make available to the Customer all information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates. Audits must be requested in writing at least 30 days in advance, take place during business hours, be limited to once per year unless a breach or a supervisory authority requires otherwise, and be bound by confidentiality. Each party bears its own audit costs.

11. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the terms of service, except where the GDPR does not allow them. If this DPA conflicts with the terms of service on the processing of personal data, this DPA prevails.

12. Governing law and jurisdiction

This DPA is governed by French law. Any dispute that cannot be settled amicably shall be submitted to the exclusive jurisdiction of the courts of Paris.

Contact

Questions about this DPA, sub-processor notifications, and breach reports: privacy@euravo.co. To receive a countersigned copy, email the same address.