Last updated: 7 August 2026

Data Processing Agreement (DPA)

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer organization (the “Controller”) and Alusia s.r.o. (the “Processor”) and governs the processing of personal data contained in Customer Content under Article 28 GDPR and Act No. 18/2018 Coll. on personal data protection.

The Slovak version of this document is the governing text. This English translation is provided for information only. View the Slovak version

1. Parties and roles

The Controller is the customer organization that uploads documents to the Service. The Processor is Alusia s.r.o., registered office [TO BE COMPLETED], Company ID (IČO) [TO BE COMPLETED], registered in the Commercial Register [TO BE COMPLETED]. For personal data contained in Customer Content the customer decides purposes and means; Alusia processes only on the customer’s behalf.

2. Subject-matter and duration

The subject-matter is the processing of personal data contained in documents the Controller uploads to the Service and in the questions asked over them. Processing lasts for the duration of the service agreement and ends with the deletion or return of Customer Content under Section 12.

3. Nature and purpose of processing

Processing consists of hosting, text extraction, indexing (keyword and vector), retrieval, AI-assisted answer generation with citations, display to authorized members, backup, and deletion - solely to provide the document-intelligence service. Customer Content is never used to train machine-learning models.

4. Types of personal data and categories of data subjects

The Controller determines what its documents contain. Typically: identification and contact data, professional data, and contractual data of the Controller’s employees, clients, suppliers, and other parties named in business documents. The Service is not intended for special categories of data under Article 9 GDPR; if the Controller uploads such data it must ensure a lawful basis. Data subjects are the persons referred to in the uploaded documents and the Controller’s workspace users.

5. Documented instructions

The Processor processes personal data only on the Controller’s documented instructions - given through the Service’s controls (upload, organize, query, share, export, delete) and the agreement - including with regard to transfers to third countries, unless required to process by EU or Member State law; in that case the Processor informs the Controller before processing, unless the law prohibits it. The Processor informs the Controller immediately if, in its opinion, an instruction infringes data-protection law.

6. Confidentiality

The Processor ensures that every person authorized to process personal data is bound by contractual or statutory confidentiality. Access to Customer Content by the Processor’s personnel is restricted to what operating, securing, or supporting the Service requires, and administrative access is logged.

7. Security of processing (Article 32)

Taking into account the state of the art and the risks, the Processor implements and maintains: encryption in transit and at rest; per-organization isolation enforced by database row-level security and re-checked at retrieval time before any AI processing; role-based access control and collection-level permissions; server-side-only handling of credentials and API keys; audit logging of administrative actions; rate limiting; environment separation; and documented backup and recovery procedures.

8. Subprocessors (further processors)

The Controller grants a general authorization to engage the subprocessors on the Subprocessor List page, which states each subprocessor’s purpose and processing location. The Processor imposes data-protection obligations no less protective than this DPA on every subprocessor and remains fully liable for their performance. The Processor gives prior notice of intended additions or replacements; the Controller may object on reasonable data-protection grounds within 30 days, and if no resolution is found may terminate the affected service.

9. International transfers

Customer Content is stored at rest in the European Union (Frankfurt, Germany). AI inference and embedding generation on standard plans are performed by OpenAI and may involve processing outside the EU/EEA; such transfers are protected by the European Commission’s Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, and OpenAI’s API terms prohibit using the data to train models. EU-region-only AI processing is available as an Enterprise configuration. No other routine transfer of Customer Content outside the EU takes place.

10. Assistance to the Controller

Taking the nature of processing into account, the Processor assists the Controller with appropriate technical and organizational measures in fulfilling data-subject requests (access, rectification, erasure, restriction, portability, objection) - primarily through the Service’s built-in search, export, and deletion functions - and, considering the information available to it, in ensuring compliance with Articles 32 to 36 GDPR. The Processor notifies the Controller of a personal-data breach affecting Customer Content without undue delay after becoming aware of it, with the information Article 33(3) requires as it becomes available.

11. Audit and information

The Processor makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates - subject to reasonable notice, at most once per year unless a breach has occurred, during business hours, without access to other customers’ data, and under confidentiality. Current security documentation and the Security page satisfy routine information requests.

12. Deletion, return, and final provisions

Upon termination of the service agreement the Controller may export Customer Content; after the agreed retention window (30 days unless otherwise agreed) the Processor deletes Customer Content from documents, indexes, embeddings, conversations, citations, and storage, unless EU or Member State law requires further storage. This DPA is governed by Slovak law. The supervisory authority is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR), Galvaniho 16130/7B, 821 04 Bratislava, statny.dozor@pdp.gov.sk. Data-protection contact: privacy@alusia.net.

Questions about these documents can be sent through the contact page while the dedicated legal address is being set up. alusia.net/en/contact