Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into under Article 28 of Regulation (EU) 2016/679 (the "GDPR") between the customer identified in the order form or account (the "Customer", acting as controller) and DIGITAK SAS, a société par actions simplifiée, registered with the RCS of Paris under SIREN 827 679 093, with registered office at 47 boulevard de Courcelles, 75008 Paris, France (the "Processor", acting as processor). It forms part of the terms of service and applies whenever the Processor processes personal data on behalf of the Customer through the Euravo inference API (the "Service"). Terms not defined here have the meaning given in the GDPR.
1. Subject matter and duration
The subject matter of this DPA is the processing of personal data contained in the content the Customer sends to the Service (prompts, files, and generated outputs, together "API content"). The DPA takes effect when the Customer first uses the Service and remains in force for as long as the Processor processes personal data on the Customer's behalf, including after termination of the terms of service until the deletion described in section 9.
2. Nature and purpose of the processing
- Purpose: running inference, that is, producing a model output in response to each API request. The Processor processes API content for no other purpose.
- Nature: API content is received over TLS, processed in memory, passed to the inference provider, and returned to the Customer.
- Zero retention: API content is never written to disk, logs, databases, or backups, and is not kept after the response is delivered. It is never used to train, fine-tune, or evaluate models.
3. Types of personal data and categories of data subjects
- Types of personal data: any personal data the Customer chooses to include in API content. The Processor does not control or inspect what that content contains. The Customer should avoid sending special categories of data (GDPR Art. 9) unless it has a lawful basis and has assessed the processing.
- Data subjects: any individuals whose personal data the Customer includes in API content, such as the Customer's staff, its own customers and end users, or other people named in that content.
Data the Processor processes as a controller (account, billing, and operational metadata) is described in the privacy policy and is outside the scope of this DPA.
4. Obligations of the Processor
The Processor shall:
- process personal data only on the Customer's documented instructions, which consist of these terms and the Customer's API requests, unless EU or Member State law requires otherwise, in which case it will inform the Customer before processing unless that law prohibits it;
- inform the Customer immediately if, in its opinion, an instruction infringes the GDPR or other EU or Member State data-protection law;
- ensure that every person authorised to process personal data is bound by confidentiality;
- implement the security measures described in section 6;
- engage sub-processors only as described in section 5;
- assist the Customer as described in sections 7 and 8;
- make available the information needed to demonstrate compliance with Article 28 GDPR, as described in section 10.
5. Sub-processors
- The Customer gives general authorisation for the Processor to engage the sub-processors listed on the sub-processors page.
- The Processor will notify the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds during that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service without penalty before the change takes effect.
- The Processor imposes on each sub-processor, by written contract, data-protection obligations equivalent to those in this DPA, and remains fully liable to the Customer for each sub-processor's performance.
- API content is processed only in EU datacenters and is never sent to any sub-processor outside the EU/EEA.
6. Security measures
Taking into account the state of the art and the risks of the processing (GDPR Art. 32), the Processor maintains at least the following measures:
- EU-only processing: API content is processed only in datacenters located in the EU.
- No logging of content: prompts, completions, and upstream error bodies are never written to logs, metrics, or the usage ledger.
- Metadata-only records: for each request the Processor records only operational metadata (request ID, model, streaming flag, HTTP status, error category, token counts, and latency), never content.
- Hashed API keys: API keys are stored as one-way SHA-256 hashes, never in plaintext.
- Encryption in transit: all traffic to the Service is encrypted with TLS.
- Access control: access to production systems is restricted to authorised staff and logged.
7. Assistance with data-subject rights
Because API content is not retained, the Processor holds no API content to which access, rectification, or erasure could apply after a request completes. The Processor will promptly forward to the Customer any request it receives from a data subject relating to the Customer's processing, will not respond to it directly except on the Customer's instruction, and will otherwise provide reasonable assistance so that the Customer can meet its obligations under Chapter III of the GDPR. It will also assist the Customer, taking into account the information available to it, with data-protection impact assessments and prior consultations (GDPR Art. 35 and 36).
8. Personal data breaches
The Processor will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer's personal data. The notification will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. The Processor will provide further information as it becomes available and assist the Customer with its notifications to the supervisory authority and to data subjects (GDPR Art. 33 and 34).
9. Deletion or return at the end of the contract
API content is deleted from memory as soon as each response is delivered, so none remains at the end of the contract. For any other personal data processed on the Customer's behalf, the Processor will, at the Customer's choice, delete or return it at the end of the provision of the Service and delete existing copies, unless EU or Member State law requires their storage.
10. Audits
The Processor will make available to the Customer all information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates. Audits must be requested in writing at least 30 days in advance, take place during business hours, be limited to once per year unless a breach or a supervisory authority requires otherwise, and be bound by confidentiality. Each party bears its own audit costs.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the terms of service, except where the GDPR does not allow them. If this DPA conflicts with the terms of service on the processing of personal data, this DPA prevails.
12. Governing law and jurisdiction
This DPA is governed by French law. Any dispute that cannot be settled amicably shall be submitted to the exclusive jurisdiction of the courts of Paris.
Contact
Questions about this DPA, sub-processor notifications, and breach reports: privacy@euravo.co. To receive a countersigned copy, email the same address.