Data Processing Agreement (DPA)

Processing of data on behalf of the Customer · Art. 28 GDPR

Last reviewed: 17 July 2026Version: 1.0

This English translation is provided for convenience only. The Spanish version is the legally binding text.

Read the Spanish version (legally binding)

This document is for information purposes only. It does not constitute legal advice. For its interpretation as applied to your specific situation, consult a professional.

Versionv1.0
Date19 May 2026
Legal basisArt. 28 of Regulation (EU) 2016/679 (GDPR)
DocumentContractual · binds the Parties from its acceptance
AcceptanceClick-through during onboarding to the Service or electronic signature

© 2026 Alethexis · AI Governance & Compliance Framework for SMEs™ · Contractual document. Based on Regulation (EU) 2016/679 (GDPR). It does not constitute legal advice to the Customer on its obligations as controller; the Customer must assess the suitability of this DPA in relation to its own processing.

1. Parties and recitals

1.1 The Parties

Controller (hereinafter, the "Customer"):

The natural or legal person contracting the Alethexis Service, whose full identification details are recorded in the sign-up form and reflected in the Service account. For the purposes of this Agreement, the Customer acts as controller within the meaning of Art. 4(7) GDPR.

Processor (hereinafter, "Alethexis" or the "Processor"):

ALETHEXIS, S.L. (Tax ID (CIF) B88758057 · registered office at C/ Tirso de Molina 36, 08940 Cornellà de Llobregat, Barcelona · CNAE 6201), represented by its sole director Rafael Luque, operator of the Service marketed under the brand Alethexis — AI Governance & Compliance Framework for SMEs™. Privacy contact point: [email protected]. For the purposes of this Agreement, Alethexis acts as processor within the meaning of Art. 4(8) GDPR.

1.2 Recitals

I. The Customer has contracted the Alethexis Service, a SaaS application for artificial intelligence governance and GDPR compliance aimed at European SMEs (hereinafter, the "Service"), in accordance with the published terms of service and the subscribed plan.

II. The operation of the Service entails Alethexis processing personal data on behalf of the Customer, which constitutes a processing-on-behalf relationship subject to Art. 28 GDPR.

III. The Parties wish to document that engagement by means of this Data Processing Agreement (hereinafter, "DPA" or "Agreement"), which is incorporated into and forms an indivisible part of the terms of service.

IV. In the event of any conflict between this DPA and the terms of service in matters of personal data protection, the provisions of this DPA shall prevail.

2. Definitions

For the purposes of this DPA, capitalised terms shall have the meaning set out below. Terms not defined here shall be interpreted in accordance with the GDPR.

TermDefinition
Personal DataAny information relating to an identified or identifiable natural person, in accordance with Art. 4(1) GDPR, that the Customer processes through the Service.
ProcessingAny operation or set of operations performed on Personal Data, in accordance with Art. 4(2) GDPR.
Data SubjectThe natural person to whom the Personal Data relate (Art. 4(1) GDPR). In this DPA, the Data Subjects are the natural persons whose data are processed by the Customer through the Service.
ControllerThe Customer, in accordance with Art. 4(7) GDPR.
ProcessorAlethexis, in accordance with Art. 4(8) GDPR.
Sub-processorThe third party engaged by Alethexis that processes Personal Data on behalf of Alethexis in the context of the provision of the Service (Art. 28(4) GDPR). The up-to-date list is set out in Annex II.
Personal Data BreachAny breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed (Art. 4(12) GDPR).
ServiceThe Alethexis SaaS application and its components, including the modules M1 (Visibility), M2 (Governance), M3 (High-Risk Ready) and any additional modules or add-ons contracted by the Customer.
UserAny natural person authorised by the Customer to access the Service, assigned to one of the five canonical roles: Owner, AI Officer, DPO, Contributor or Auditor.
Account DataIdentification data of the Customer and its Users necessary for the provision of the Service (name, email, job title, organisation). In respect of these, Alethexis acts as an independent controller, not as a processor, as detailed in the public privacy policy.
Substantive DataData that the Customer enters, imports or generates within the Service in the context of its processing as controller (inventories of AI systems, FRIAs, DPIAs, evidence, etc.). In respect of these data Alethexis acts as processor, and they are the subject matter of this DPA.

3. Subject matter of the Agreement

3.1 Material scope

This DPA governs the processing of the Substantive Data carried out by Alethexis, on behalf and in the interest of the Customer, exclusively in the context of the provision of the Alethexis Service.

3.2 Exclusions

The following fall outside the scope of this DPA:

  • The Account Data of the Customer itself and of its Users, in respect of which Alethexis acts as an independent controller as documented in its public privacy policy.
  • Personal data processed by the Customer outside the Service.
  • Personal data that the Customer decides not to enter into the Service.

3.3 Subordination

The processing carried out by Alethexis under this DPA is subordinate to the documented instructions of the Customer, as set out in this Agreement, in the terms of service and in the functional configuration of the Service.

4. Nature, purpose and duration of the processing

4.1 Nature and purpose

The purpose of the processing is to enable the Customer to operate the Alethexis Service in order to exercise its AI governance and GDPR diligence: registration of AI systems, P0–P6 classification, FRIA and DPIA assessments, policy publication, generation of evidence and the other contracted functionalities. The operational details of the processing are set out in Annex I.

4.2 Duration

This DPA shall remain in force for as long as the subscription agreement for the Service between the Parties remains in force and, in any event, until the return or deletion procedure provided for in clause 10 has been completed.

4.3 Unauthorised purposes

Alethexis undertakes not to process the Substantive Data for any purpose other than the provision of the Service. In particular, Alethexis expressly declares that it does not sell the Substantive Data, does not disclose them to third parties for their own purposes, does not use them to train its own or third-party artificial intelligence models and does not carry out profiling on them.

5. Types of Personal Data and categories of Data Subjects

The details of the types of Personal Data processed and the categories of Data Subjects concerned are set out in Annex I.

By way of guidance and without being exhaustive, Data Subjects may include employees, candidates, patients, end customers and other natural persons whose data the Customer decides to incorporate into the Service in its inventories, FRIAs or DPIAs. The Personal Data may include, if the Customer so decides, special categories under Art. 9 GDPR (for example, health data in sectors such as dentistry). The Customer is solely responsible for the lawfulness, legal basis and proportionality of the data it enters into the Service.

6. Obligations of the Processor (Art. 28(3) GDPR)

Alethexis, in its capacity as Processor, assumes the obligations provided for in Art. 28(3) GDPR, as developed below.

6.1 Processing only on documented instructions (Art. 28(3)(a))

Alethexis shall process the Personal Data only on documented instructions from the Customer, including with regard to international transfers, unless required to do so by Union or Member State law, in which case it shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on grounds of public interest.

The following constitute documented instructions:

  • This DPA and its Annexes.
  • The terms of service accepted by the Customer.
  • The configurations applied by the Customer or its authorised Users within the Service.
  • Any additional written instructions that the Customer may send to [email protected].

If Alethexis considers that an instruction infringes the GDPR or other applicable data protection legislation, it shall inform the Customer without delay.

6.2 Confidentiality of personnel (Art. 28(3)(b))

Alethexis shall ensure that persons authorised to process Personal Data:

  • Have committed themselves to confidentiality or are under an equivalent statutory obligation of confidentiality.
  • Receive appropriate training in data protection and information security.
  • Access the Personal Data only where necessary for the provision of the Service (principle of least privilege).

This obligation extends to the operator of the Service itself and to any future team member, and is formalised by means of an NDA and a documented undertaking.

6.3 Security measures (Art. 28(3)(c) and Art. 32)

Alethexis shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR. The details of these measures are set out in Annex III, which forms an integral part of this DPA and may be updated to reflect technical improvements, provided that such updates do not reduce the level of protection.

6.4 Sub-processors (Art. 28(3)(d), Art. 28(2) and Art. 28(4))

The Customer grants Alethexis a prior general authorisation to engage Sub-processors, in accordance with Art. 28(2) GDPR. The up-to-date list of authorised Sub-processors is set out in Annex II.

Alethexis undertakes to:

  • Impose on each Sub-processor, by way of a contract or other binding legal act, the same data protection obligations as those set out in this DPA, in particular those relating to security measures and purpose limitation.
  • Keep the list of Sub-processors up to date and publicly accessible at alethexis.com/legal/subprocessors.
  • Notify the Customer at least 30 days in advanceof any addition, removal or replacement of a Sub-processor, by email to the Customer's contact address and by a visible notice in the Service.
  • Recognise the Customer's right to object on reasoned grounds to the addition of a new Sub-processor within 30 days following the notification. In the event of a reasonable objection, the Parties shall negotiate in good faith an alternative solution. If this is not possible, the Customer may terminate the subscription agreement for the Service without penalty in respect of the unused portion.
  • Remain liable to the Customer for the performance of the data protection obligations by its Sub-processors.

6.5 Assistance in the exercise of Data Subjects' rights (Art. 28(3)(e))

Alethexis shall assist the Customer, by appropriate technical and organisational measures and insofar as this is possible, in responding to requests for exercising the Data Subjects' rights (access, rectification, erasure, restriction, portability, objection and automated individual decision-making — Arts. 15 to 22 GDPR).

To that end, the Service incorporates self-service functionalities that allow the Customer to:

  • Access and edit the Substantive Data directly.
  • Export the data in structured formats (JSON, CSV) and, where applicable, the PDFs generated by the Service.
  • Delete data by itself through the interface, without the need for Alethexis to intervene.

Where assistance requires direct technical intervention by Alethexis (for example, complex exports or bulk deletions exceeding the self-service functionality), the Customer may request it at [email protected]. The obligation to handle Data Subjects' requests in the first instance lies with the Customer as controller; Alethexis does not reply directly to the Data Subject except on documented instructions from the Customer.

6.6 Assistance with security, breaches, DPIA and prior consultation (Art. 28(3)(f), Arts. 32-36)

Alethexis shall assist the Customer in ensuring compliance with the obligations incumbent on the controller pursuant to Arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to it. In particular, it shall:

  • Make available to the Customer the information in Annex III (security measures) and, through the public Trust Center (alethexis.com/trust), up-to-date information on its security posture.
  • Notify the Customer of Personal Data Breaches in accordance with clause 8.
  • Where the Customer carries out a DPIA (Art. 35 GDPR) or a prior consultation (Art. 36 GDPR) relating to processing that includes the use of the Service, reasonably provide the technical and organisational information necessary on the processing that Alethexis carries out in its capacity as Processor.

This assistance is proportionate to the role of Processorand does not replace the Customer's own obligations as controller, in particular those relating to the determination of the legal basis, the information to Data Subjects and the substantive response to their rights.

6.7 Return or deletion at the end of the provision of services (Art. 28(3)(g))

At the end of the provision of the Service, Alethexis shall return the Personal Data to the Customer or delete them, as detailed in clause 10 and in accordance with the five-level staged deletion policy described there.

6.8 Information to demonstrate compliance and audits (Art. 28(3)(h))

Alethexis shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and shall allow for and contribute to audits, including inspections, in accordance with clause 9. If Alethexis considers that an instruction from the Customer in this area infringes the GDPR or other legislation, it shall immediately inform the Customer.

7. Authorised Sub-processors

The full list of authorised Sub-processors, their functions, locations and safeguard mechanisms is set out in Annex II.

7.1 Procedure for notifying changes

  • Any addition, removal or replacement of a Sub-processor shall be notified to the Customer at least 30 calendar days in advance, by email to the contact address registered in the Customer's account and by a visible notice in the Service.
  • The public list of Sub-processors shall be updated simultaneously at alethexis.com/legal/subprocessors.

7.2 Controller's right to object

  • The Customer may object on reasoned grounds to the addition of a new Sub-processor within 30 days following the notification, by written communication to [email protected].
  • In the event of a reasonable objection, the Parties shall negotiate in good faith, for a period of up to 30 days, an alternative solution (for example, a configuration of the Service that avoids the objected Sub-processor, or replacement by another provider).
  • If no agreement is reached, the Customer may terminate the subscription agreement for the Service early by written notice, with the right to a pro-rata refund of the unused portion of the subscribed plan.

7.3 Sub-processors not applicable to Substantive Data

Certain third parties used by Alethexis (in particular GitHub for the code repository and Anthropic for development assistance with Claude Code) do not access the Customer's Substantive Data. This separation is structural, not contractual, and for that reason they are not included as Sub-processors within the scope of this DPA.

8. Personal data breaches

8.1 Detection and containment

Alethexis has internal procedures for the detection, containment of and response to Personal Data Breaches, documented in its internal SECURITY_RUNBOOK.md and applied on an ongoing basis.

8.2 Notification to the Customer

Alethexis shall notify the Customer without undue delay and, in any event, within 24 hours of becoming actually aware of a Personal Data Breach affecting the Customer's Substantive Data. The notification shall be sent by email to the contact address registered in the Customer's account and, where appropriate, by a notice in the Service.

8.3 Content of the notification

The notification shall include, to the extent available at the time of the notice, the elements provided for in Art. 33(3) GDPR:

  • The nature of the Breach and, where possible, the categories and approximate number of Data Subjects and records concerned.
  • Details of the contact point at Alethexis where more information can be obtained.
  • The likely consequences of the Breach.
  • The measures taken or proposed to address the Breach and, where appropriate, to mitigate its possible adverse effects.

If not all the information is available at the time of the initial notification, Alethexis shall provide successive updates as the investigation progresses.

8.4 Notification to authorities and Data Subjects

Notification to the competent supervisory authority (in Spain, the AEPD, the Spanish Data Protection Authority) in accordance with Art. 33 GDPR and, where applicable, communication to the Data Subjects in accordance with Art. 34 GDPR, are the responsibility of the Customer as controller. Alethexis shall assist the Customer by providing the available information and by responding reasonably to additional requests from the Customer and, where applicable, from the authority.

8.5 Retention of evidence

Alethexis shall retain, for a minimum of 5 years, the evidence relating to Breaches detected and notified, as well as the post-mortem analyses and the corrective measures applied, for defensive and continuous-improvement purposes.

9. Audits

9.1 Customer's right of audit

The Customer, as controller, has the right to verify Alethexis's compliance with the obligations of Art. 28 GDPR and of this DPA, by means of:

  • Requests for information addressed to [email protected], which Alethexis shall answer within a reasonable period.
  • Consultation of the public Trust Center (alethexis.com/trust), which includes up-to-date informationon sub-processors, security measures and applicable certifications or adherences, where relevant.
  • Where appropriate, an on-site or remote audit on the terms of clauses 9.2 to 9.5.

9.2 Frequency and notice

Unless there is a reasonable cause justifying otherwise (for example, a significant Personal Data Breach or a request from an authority), the right of audit shall be exercised:

  • With a maximum of one audit per calendar year.
  • With at least 30 calendar days' prior written notice.
  • During normal business hours and in a manner that does not unreasonably interfere with the operation of the Service.

9.3 Auditor

The Customer may carry out the audit itself or through a qualified independent auditor, who may in no case be a direct competitor of Alethexis. The auditor shall first sign a confidentiality agreement (NDA) with Alethexis.

9.4 Scope

The audit shall be limited to verifying compliance with the obligations arising from this DPA and from Art. 28 GDPR. The following are excluded: proprietary source code, the data of other customers, trade secrets unrelated to the processing and any information whose disclosure could compromise the security of the Service.

9.5 Cost

The costs of the audit shall be borne by the Customer, unless the audit reveals material breaches attributable to Alethexis, in which case Alethexis shall bear the reasonable costs directly related to the audit.

9.6 Audits by authorities

The foregoing is without prejudice to the powers of inspection and audit vested in the AEPD, the AESIA (Spanish Agency for the Supervision of Artificial Intelligence) or other competent authorities. Alethexis shall cooperate in good faith with such authorities and shall keep the Customer informed, insofar as legally possible.

10. Return or deletion at the end of the provision of services

10.1 Five-level staged deletion policy

At the end of the provision of the Service, whether by termination of the agreement, deletion requested by the Customer or any other cause, Alethexis shall apply the following staged deletion policy, aligned with Art. 17 GDPR and with the applicable commercial and documentary-defence obligations:

LevelDataTreatment at the end of the provision of services
1Identifying personal data of Users (name, email, telephone)Deleted or pseudonymised by irreversible hash within a maximum of 30 days from the verified request.
2Customer's compliance evidence (FRIA, DPIA, policy, RACI, signed PDFs, incident records, decisions)A full exportis offered to the Customer's Owner before deletion. Once the export is confirmed, they are deleted from the active system. Post-export custody passes to the Customer.
3Invoices and legally required records (Holded)Retained for ≥ 6 years in accordance with Art. 30 of the Spanish Commercial Code (Código de Comercio) and applicable tax legislation. Legal basis: Art. 17(3)(b) GDPR (legal obligation). Not deleted even if the Customer makes an Art. 17 request.
4Audit logs (audit.access_log)Pseudonymised (irreversible hash of user_id, retention of account_id and event) with a retention period of 5 years for defence in the event of an inspection (AEPD, AESIA or others).
5BackupsRolling 30 days. Deleted data naturally disappear from the backup within ≤ 30 days after deletion. No selective restores are performed that could reintroduce already deleted data.

10.2 Closure communication

At the close of the process, the Customer's Owner shall receive a confirmation email including:

  • Hash of the export delivered (proof of delivery).
  • A summary of which data are retained, on which medium and on what legal basis.
  • An approximate schedule for the purge of the backup.

10.3 Grace period

After cancellation of the agreement and before starting the deletion procedure, Alethexis shall apply a 30-day grace period during which the Customer may:

  • Carry out the final export of its data itself from the Service.
  • Reactivate the subscription without loss of data.

Once that period has elapsed without reactivation, the deletion cascade described in 10.1 shall begin.

10.4 Legal exceptions

Where Union or Member State law requires the retention of Personal Data beyond the above periods (for example, court orders, tax obligations), Alethexis shall inform the Customer and shall retain the strictly necessary data for the legally required period.

11. International transfers

11.1 General regime

In the current version of the Service (Wave 1), Alethexis has configured its infrastructure so that the Substantive Data are stored within the European Economic Area (Supabase, eu-central-1 · Frankfurt). However, the provision of the Service entails the Substantive Data transiting through the delivery and edge network of infrastructure providers with a presence outside the EEA (United States), in particular Cloudflare (proxy/CDN/WAF) and Vercel (hosting and edge network). Such transfers are covered by safeguards in accordance with Chapter V of the GDPR: Standard Contractual Clauses (Art. 46(2)(c)) and, where applicable, the EU-US Data Privacy Framework, with such supplementary measures as may be necessary (Schrems II). The location and safeguard mechanism of each Sub-processor are set out in Annex II and in the up-to-date public list at alethexis.com/subprocessors.

  • Storage of Substantive Data: Supabase eu-central-1 (Frankfurt) — EEA.
  • Transit / edge: Cloudflare (USA) and Vercel (USA primary + global edge) — under Chapter V safeguards.
  • Error monitoring: Sentry, EU region (Frankfurt).
  • Payments, email to users and customer correspondence: they process Account Data (Alethexis as controller) — see the privacy policy, not this DPA.

11.2 Additional future transfers

If in the future an additional Sub-processor or a processing operation entailing a new transfer of Substantive Data outside the EEA other than those declared in 11.1 were to be incorporated, Alethexis shall:

  • Apply one of the safeguard mechanisms provided for in Chapter V of the GDPR (Arts. 44 to 49), preferably the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR) accompanied by such supplementary measures as may be necessary in accordance with the applicable case law (Schrems II, among others).
  • Notify the Customer in accordance with the procedure for changes of Sub-processors (clause 7.1).
  • Make available to the Customer the documentation evidencing the safeguard mechanism applied.

12. Liability and limitations

12.1 Allocation of liability

Each Party shall be liable for the damage caused as a result of a breach of the obligations that the GDPR and this DPA assign to it in its respective capacity as controller or processor, on the terms of Art. 82 GDPR.

12.2 Limitation proportionate to the role of Processor

Alethexis's liability towards the Customer arising from this DPA is limited to damage directly attributable to its breach of the obligations incumbent on it as Processor. In particular, Alethexis shall not be liable for:

  • The Customer's decisions as controller (legal basis of the processing, information to Data Subjects, substantive handling of their rights, compliance with Art. 5 GDPR).
  • The suitability or lawfulness of the data that the Customer decides to enter into the Service.
  • The consequences arising from instructions of the Customer with which Alethexis has complied in accordance with this DPA, unless such instructions were manifestly unlawful and Alethexis had not reported them in accordance with clause 6.1.

12.3 Amount

Except in cases of wilful misconduct or gross negligence, or where the applicable law does not permit it, the aggregate liability of each Party towards the other under this DPA shall be limited as provided in the terms of service. This limitation does not apply to fines imposed by a supervisory authority directly on one of the Parties, nor to compensation to Data Subjects resulting from such fines, which shall be governed by Art. 82 GDPR.

12.4 Cooperation in defence

If a Data Subject, authority or third party brings a claim in relation to the processing covered by this DPA, both Parties shall cooperate in good faith to coordinate the defence and the response, sharing the information reasonably necessary.

13. Term, amendment, governing law and jurisdiction

13.1 Term

This DPA shall enter into force on the date of its acceptance by the Customer (click-through during onboarding to the Service or electronic signature) and shall remain in force for as long as the subscription agreement for the Service between the Parties remains in force, unless the return and deletion clauses (clause 10) or the audit clauses (clause 9) require their subsequent application.

13.2 Amendment

Alethexis may amend this DPA in the following cases:

  • Legislative or regulatory changes affecting the GDPR or related legislation.
  • Decisions of supervisory authorities requiring adjustments.
  • Improvements to the technical and organisational measures that increase the level of protection.
  • Changes to the list of Sub-processors, in accordance with the procedure in clause 7.

Amendments shall be notified to the Customer with reasonable notice, a minimum of 30 calendar days where materially possible, by email and by a notice in the Service. If the amendment substantially reduces the level of protection or introduces changes that the Customer cannot reasonably accept, the Customer shall be entitled to terminate the subscription agreement without penalty.

13.3 Severability

If any provision of this DPA is declared null and void or unenforceable, the remainder of the Agreement shall remain valid. The Parties shall negotiate in good faith a replacement clause that reflects, insofar as possible, the original intention.

13.4 Governing law

This DPA is governed by Spanish law and by the applicable law of the European Union, in particular Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

13.5 Jurisdiction

The Parties submit, expressly waiving any other forum to which they may be entitled, to the Courts and Tribunals of the city of Barcelona (Spain) for the resolution of any dispute arising from this DPA, without prejudice to the powers conferred by law on the AEPD or on other supervisory authorities.

Annex I · Details of the processing

A.I.1 Subject matter of the processing

Processing of Personal Data by Alethexis, on behalf of the Customer, in the context of the provision of the Alethexis Service (modules M1 Visibility, M2 Governance, M3 High-Risk Ready and, where applicable, Agentic Add-on).

A.I.2 Duration of the processing

For as long as the subscription agreement for the Service remains in force, plus the return and retention periods provided for in clause 10 of the DPA.

A.I.3 Nature and purpose

AspectDetail
NatureAutomated processing on a multi-tenant SaaS platform with isolation by Row Level Security (RLS) per account_id.
Main purposeTo enable the Customer to operate the functional sections of the Service: inventory of AI systems, P0–P6 classification, FRIA and DPIA assessments, usage policy, governance (committee, RACI, risks, decisions, changes, operations), evidence and references.
Authorised secondary purposesGeneration of evidentiary PDFs (Policy, Committee, RACI, FRIA, DPIA), immutable audit log, Service notifications, technical support subject to the Customer's prior authorisation.

A.I.4 Types of Personal Data

The following types are included by way of guidance. The actual determination lies with the Customer.

CategoryExamplesSource
Identifying data of UsersFirst name, surname, professional email, job title, assigned roleUser registration by the Customer
Identifying data of third-party Data SubjectsName, internal identifiers, contact detailsEntered by the Customer in FRIA, DPIA, evidence
Professional dataDepartment, position, organisationFRIA, DPIA, operational records
Sensitive data · Art. 9 GDPR (where applicable)Health data (e.g. dental sector), other Art. 9 data that the Customer decides to processCustomer's decision
Data relating to AI systemsProvider identifiers, configuration, technical assessments (not necessarily personal in themselves, but they may be associated with Data Subjects)Customer's configuration
Audit logaccount_id, user_id, action performed, timestamp, event metadataGenerated automatically by the Service

The Customer undertakes not to enter into the Service Personal Data that are unnecessary for the declared purpose, in accordance with the data minimisation principle of Art. 5(1)(c) GDPR.

A.I.5 Categories of Data Subjects

CategoryDescription
Customer's UsersNatural persons authorised by the Customer to access the Service, in the five canonical roles: Owner, AI Officer, DPO, Contributor, Auditor.
Customer's employeesNatural persons whose data may appear in the inventories, FRIA or DPIA assessments or evidence that the Customer records in the Service (for example, employees affected by an HR AI system).
CandidatesIn recruitment or onboarding AI systems registered by the Customer.
Patients and/or end customersWhere the Customer registers AI systems that process them (e.g. dental clinics with assisted diagnosis systems).
Suppliers and professional contactsWhere the Customer records data relating to GPAI providers or other third parties in VIS-4 (due diligence).
Other natural personsAny other Data Subjects whose data the Customer decides to record within the Service.

A.I.6 Processing operations

Collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, internal disclosure between Sub-processors in accordance with Annex II, alignment, restriction, erasure, destruction and export.

A.I.7 Location of the processing

Storage in the European Economic Area (Frankfurt). Transit through edge infrastructure with a presence outside the EEA under Chapter V GDPR safeguards. Details per Sub-processor in Annex II.

Annex II · List of authorised Sub-processors

Version: 1.0 · Review date: 17 July 2026 · The live source of this list is the public page alethexis.com/subprocessors, which prevails in the event of a temporary divergence between updates.

#Sub-processorLegal nameMain locationPurpose / Service providedSafeguard mechanism
1SupabaseSupabase Inc. (EU operation via Supabase EU)Frankfurt (eu-central-1) · GermanyPostgreSQL database, authentication, file storage, Edge Functions, database monitoring. Processes all of the Customer's Substantive Data.Supabase DPA signed · operation in the EEA · Standard Contractual Clauses (US entity).
2VercelVercel Inc.USA (primary processing) + global edgeHosting of the Next.js frontend and edge network. Processes HTTP logs and request metadata; does not store Substantive Data, processes them in transit.Vercel DPA signed · EU-US Data Privacy Framework + Standard Contractual Clauses.
3CloudflareCloudflare, Inc.USA (proxy over all traffic)DNS proxy, CDN, WAF and Turnstile (captcha). Processes Substantive Data in transit(TLS termination) and visitors' IP addresses and browser signals.Cloudflare DPA · EU-US Data Privacy Framework + Standard Contractual Clauses.
4Stripe Payments EuropeStripe Payments Europe LimitedUSA (+ India)Payment and subscription processing. Processes Account Data(the Customer's payment and tax data), not Substantive Data — see privacy policy. Acts as an independent sub-processor with its own liability for payment data, in accordance with its own processing agreement. Ireland is the contracting entity, not the location of the data.Stripe Data Processing Agreement · Standard Contractual Clauses + EU-US Data Privacy Framework.
5HoldedHolded Technologies, S.L.SpainStatutory invoicing, official invoice sequence, accounting integration. Processes the Customer's tax data.Holded DPA signed · operation in Spain.
6ResendResend (Plus Five Five, Inc.)USATransactional email sending (Service notifications, password recovery, alerts). Processes the recipient email address and the email content — Account Data (email to users).Resend DPA signed · Standard Contractual Clauses + EU-US Data Privacy Framework.
7SentryFunctional Software, Inc. (EU operation)EU (Frankfurt)Error monitoring. Processes stack traces with automatic PII scrubbing, error metadata and, where applicable, pseudonymised User identifiers.Sentry DPA · EU configuration active.

Notes:

  • The list reflects the status as at 17 July 2026. The current version is published at alethexis.com/legal/subprocessors.
  • GitHub (code repository) and Anthropic (development assistance with Claude Code) do not access the Customer's Substantive Data and are therefore not included as Sub-processors in this Annex. The separation is structural: GitHub stores source code without production data and Anthropic only receives development prompts.
  • Any addition, removal or replacement shall be notified to the Customer in accordance with clause 7 of the DPA, with at least 30 calendar days' notice.

Annex III · Technical and organisational measures (TOM · Art. 32 GDPR)

The following measures are those applied at the time of signing the DPA. They may be updated to reflect improvements, provided that such updates do not reduce the level of protection.

A.III.1 Encryption

  • In transit: TLS 1.3 mandatory on all connections with the Service and between the Sub-processors (Vercel, Supabase, Resend, Stripe, Holded, Sentry).
  • At rest: AES-256 encryption applied by Supabase to the database and to file Storage.
  • Administrative connections to the database: restricted to authorised IP addresses and protected with MFA.

A.III.2 Access control

  • Authentication: Supabase Auth with bcrypt password hashing. Magic link available. Microsoft SSO planned for Wave 1.1.
  • MFA: opt-in for all Users from launch; mandatory for Alethexis's own Owner role. Mandatory MFA for the Customer's Owner and DPO roles planned for Wave 2.
  • Multi-tenant isolation: Row Level Security (RLS) active on all tables with account_id. Automated RLS tests in CI; no change is deployed if the tests fail.
  • Least privilege: canonical Customer roles (Owner, AI Officer, DPO, Contributor, Auditor) with differentiated permissions; sensitive sections (e.g. DPIA) restricted by role through additional RLS policies.
  • Supabase service role keys: used exclusively in Edge Functions and backend Server Actions, never exposed to the client.

A.III.3 Auditability and immutability

  • Append-only audit log in the audit.access_log table with REVOKE UPDATE, DELETE at database level. Retention 5 years.
  • FRIA and DPIA PDFs signed with a SHA-256 hash embedded in the metadata and visible on the last page. Database triggers verify immutability after approval.
  • Snapshots of published policies are versioned; changes create a new version without overwriting earlier ones.

A.III.4 Secrets management

  • Environment variables stored in Vercel and, where appropriate, in Supabase Vault. Never in the code repository.
  • Scheduled quarterly rotation (January, April, July, October) of sensitive external provider keys (Stripe restricted keys, Resend, Sentry, Anthropic, GitHub PAT).
  • Documented emergency rotation procedure in the event of suspected exposure.
  • Detection of secrets in commits by means of gitleaks in pre-commit and CI.

A.III.5 Vulnerabilities and patches

  • Dependencies monitored with pnpm audit and Dependabot.
  • Critical patches applied within a target of < 72 hours from publication of the advisory.
  • Basic SAST scanning in CI; security review on every relevant Pull Request.

A.III.6 Backups and recovery

  • Point-in-Time Recovery (PITR) enabled in Supabase.
  • Backup retention: 30 days rolling.
  • Quarterly restore test to the staging environment to verify integrity and procedure.

A.III.7 HTTP headers and web hardening

  • HSTS with max-age=63072000; includeSubDomains; preload.
  • Content-Security-Policy with a dynamic nonce, without unsafe-inline or unsafe-eval in script-src.
  • X-Frame-Options: DENY · X-Content-Type-Options: nosniff · Referrer-Policy: strict-origin-when-cross-origin · restrictive Permissions-Policy.
  • Self-hosted fonts (Montserrat, Open Sans, JetBrains Mono); Google Fonts CDN is not used, minimising third-party dependencies in rendering.

A.III.8 Environment segregation

  • Separate development, staging and production environments.
  • Preview deployments with Vercel authentication (Standard Protection); never publicly accessible with real data.
  • Customer data only in production; staging uses synthetic data.

A.III.9 Sub-processors and providers

  • DPA signed with each Sub-processor in Annex II.
  • Up-to-date public list at alethexis.com/legal/subprocessors.
  • Procedure for notifying changes to the Customer with 30 days' notice.

A.III.10 Organisational measures

  • Restricted internal access: principle of least privilege; only the operator of the Service and, where applicable, future team members with an NDA and a documented confidentiality undertaking.
  • Ongoing and documented AI Literacy and GDPR training for staff with access to Personal Data.
  • Internal AI use policy (BYOAI): development with Claude Code does not include Customer Substantive Data; only code and development prompts.
  • Breach procedure documented in the internal SECURITY_RUNBOOK.md, with a notification period to the Customer of ≤ 24 hours (clause 8).
  • Annual review of the technical and organisational measures, with an update of this Annex where appropriate.

A.III.11 What Alethexis expressly declares it does NOT do

  • Does not sell Substantive Data to third parties under any circumstances.
  • Does not use Substantive Data to train its own or third-party AI models.
  • Does not carry out profiling on the Substantive Data.
  • Does not accessthe Customer's functional sections except for technical support with the Customer's explicit authorisation and a record of the action in the audit log.
  • Does not take automated decisions with legal effects on the Customer or on its Data Subjects (plans and access are contracted, not assigned algorithmically).
  • Does not incorporate generative AI within the Service in Wave 1 (canonical decision of Alethexis).

© 2026 Alethexis · AI Governance & Compliance Framework for SMEs™ · Confidential contractual document · Based on Regulation (EU) 2024/1689 (EU AI Act) and Regulation (EU) 2016/679 (GDPR). It does not constitute legal advice to the Customer on its obligations as controller.