This English translation is provided for convenience only. The Spanish version is the legally binding text.
This document is for information purposes only. It does not constitute legal advice. For its interpretation as applied to your specific situation, consult a professional.
| Version | v1.0 |
|---|---|
| Date | 19 May 2026 |
| Legal basis | Art. 28 of Regulation (EU) 2016/679 (GDPR) |
| Document | Contractual · binds the Parties from its acceptance |
| Acceptance | Click-through during onboarding to the Service or electronic signature |
© 2026 Alethexis · AI Governance & Compliance Framework for SMEs™ · Contractual document. Based on Regulation (EU) 2016/679 (GDPR). It does not constitute legal advice to the Customer on its obligations as controller; the Customer must assess the suitability of this DPA in relation to its own processing.
Controller (hereinafter, the "Customer"):
The natural or legal person contracting the Alethexis Service, whose full identification details are recorded in the sign-up form and reflected in the Service account. For the purposes of this Agreement, the Customer acts as controller within the meaning of Art. 4(7) GDPR.
Processor (hereinafter, "Alethexis" or the "Processor"):
ALETHEXIS, S.L. (Tax ID (CIF) B88758057 · registered office at C/ Tirso de Molina 36, 08940 Cornellà de Llobregat, Barcelona · CNAE 6201), represented by its sole director Rafael Luque, operator of the Service marketed under the brand Alethexis — AI Governance & Compliance Framework for SMEs™. Privacy contact point: [email protected]. For the purposes of this Agreement, Alethexis acts as processor within the meaning of Art. 4(8) GDPR.
I. The Customer has contracted the Alethexis Service, a SaaS application for artificial intelligence governance and GDPR compliance aimed at European SMEs (hereinafter, the "Service"), in accordance with the published terms of service and the subscribed plan.
II. The operation of the Service entails Alethexis processing personal data on behalf of the Customer, which constitutes a processing-on-behalf relationship subject to Art. 28 GDPR.
III. The Parties wish to document that engagement by means of this Data Processing Agreement (hereinafter, "DPA" or "Agreement"), which is incorporated into and forms an indivisible part of the terms of service.
IV. In the event of any conflict between this DPA and the terms of service in matters of personal data protection, the provisions of this DPA shall prevail.
For the purposes of this DPA, capitalised terms shall have the meaning set out below. Terms not defined here shall be interpreted in accordance with the GDPR.
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person, in accordance with Art. 4(1) GDPR, that the Customer processes through the Service. |
| Processing | Any operation or set of operations performed on Personal Data, in accordance with Art. 4(2) GDPR. |
| Data Subject | The natural person to whom the Personal Data relate (Art. 4(1) GDPR). In this DPA, the Data Subjects are the natural persons whose data are processed by the Customer through the Service. |
| Controller | The Customer, in accordance with Art. 4(7) GDPR. |
| Processor | Alethexis, in accordance with Art. 4(8) GDPR. |
| Sub-processor | The third party engaged by Alethexis that processes Personal Data on behalf of Alethexis in the context of the provision of the Service (Art. 28(4) GDPR). The up-to-date list is set out in Annex II. |
| Personal Data Breach | Any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed (Art. 4(12) GDPR). |
| Service | The Alethexis SaaS application and its components, including the modules M1 (Visibility), M2 (Governance), M3 (High-Risk Ready) and any additional modules or add-ons contracted by the Customer. |
| User | Any natural person authorised by the Customer to access the Service, assigned to one of the five canonical roles: Owner, AI Officer, DPO, Contributor or Auditor. |
| Account Data | Identification data of the Customer and its Users necessary for the provision of the Service (name, email, job title, organisation). In respect of these, Alethexis acts as an independent controller, not as a processor, as detailed in the public privacy policy. |
| Substantive Data | Data that the Customer enters, imports or generates within the Service in the context of its processing as controller (inventories of AI systems, FRIAs, DPIAs, evidence, etc.). In respect of these data Alethexis acts as processor, and they are the subject matter of this DPA. |
This DPA governs the processing of the Substantive Data carried out by Alethexis, on behalf and in the interest of the Customer, exclusively in the context of the provision of the Alethexis Service.
The following fall outside the scope of this DPA:
The processing carried out by Alethexis under this DPA is subordinate to the documented instructions of the Customer, as set out in this Agreement, in the terms of service and in the functional configuration of the Service.
The purpose of the processing is to enable the Customer to operate the Alethexis Service in order to exercise its AI governance and GDPR diligence: registration of AI systems, P0–P6 classification, FRIA and DPIA assessments, policy publication, generation of evidence and the other contracted functionalities. The operational details of the processing are set out in Annex I.
This DPA shall remain in force for as long as the subscription agreement for the Service between the Parties remains in force and, in any event, until the return or deletion procedure provided for in clause 10 has been completed.
Alethexis undertakes not to process the Substantive Data for any purpose other than the provision of the Service. In particular, Alethexis expressly declares that it does not sell the Substantive Data, does not disclose them to third parties for their own purposes, does not use them to train its own or third-party artificial intelligence models and does not carry out profiling on them.
The details of the types of Personal Data processed and the categories of Data Subjects concerned are set out in Annex I.
By way of guidance and without being exhaustive, Data Subjects may include employees, candidates, patients, end customers and other natural persons whose data the Customer decides to incorporate into the Service in its inventories, FRIAs or DPIAs. The Personal Data may include, if the Customer so decides, special categories under Art. 9 GDPR (for example, health data in sectors such as dentistry). The Customer is solely responsible for the lawfulness, legal basis and proportionality of the data it enters into the Service.
Alethexis, in its capacity as Processor, assumes the obligations provided for in Art. 28(3) GDPR, as developed below.
Alethexis shall process the Personal Data only on documented instructions from the Customer, including with regard to international transfers, unless required to do so by Union or Member State law, in which case it shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on grounds of public interest.
The following constitute documented instructions:
If Alethexis considers that an instruction infringes the GDPR or other applicable data protection legislation, it shall inform the Customer without delay.
Alethexis shall ensure that persons authorised to process Personal Data:
This obligation extends to the operator of the Service itself and to any future team member, and is formalised by means of an NDA and a documented undertaking.
Alethexis shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR. The details of these measures are set out in Annex III, which forms an integral part of this DPA and may be updated to reflect technical improvements, provided that such updates do not reduce the level of protection.
The Customer grants Alethexis a prior general authorisation to engage Sub-processors, in accordance with Art. 28(2) GDPR. The up-to-date list of authorised Sub-processors is set out in Annex II.
Alethexis undertakes to:
Alethexis shall assist the Customer, by appropriate technical and organisational measures and insofar as this is possible, in responding to requests for exercising the Data Subjects' rights (access, rectification, erasure, restriction, portability, objection and automated individual decision-making — Arts. 15 to 22 GDPR).
To that end, the Service incorporates self-service functionalities that allow the Customer to:
Where assistance requires direct technical intervention by Alethexis (for example, complex exports or bulk deletions exceeding the self-service functionality), the Customer may request it at [email protected]. The obligation to handle Data Subjects' requests in the first instance lies with the Customer as controller; Alethexis does not reply directly to the Data Subject except on documented instructions from the Customer.
Alethexis shall assist the Customer in ensuring compliance with the obligations incumbent on the controller pursuant to Arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to it. In particular, it shall:
alethexis.com/trust), up-to-date information on its security posture.This assistance is proportionate to the role of Processorand does not replace the Customer's own obligations as controller, in particular those relating to the determination of the legal basis, the information to Data Subjects and the substantive response to their rights.
At the end of the provision of the Service, Alethexis shall return the Personal Data to the Customer or delete them, as detailed in clause 10 and in accordance with the five-level staged deletion policy described there.
Alethexis shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and shall allow for and contribute to audits, including inspections, in accordance with clause 9. If Alethexis considers that an instruction from the Customer in this area infringes the GDPR or other legislation, it shall immediately inform the Customer.
The full list of authorised Sub-processors, their functions, locations and safeguard mechanisms is set out in Annex II.
Certain third parties used by Alethexis (in particular GitHub for the code repository and Anthropic for development assistance with Claude Code) do not access the Customer's Substantive Data. This separation is structural, not contractual, and for that reason they are not included as Sub-processors within the scope of this DPA.
Alethexis has internal procedures for the detection, containment of and response to Personal Data Breaches, documented in its internal SECURITY_RUNBOOK.md and applied on an ongoing basis.
Alethexis shall notify the Customer without undue delay and, in any event, within 24 hours of becoming actually aware of a Personal Data Breach affecting the Customer's Substantive Data. The notification shall be sent by email to the contact address registered in the Customer's account and, where appropriate, by a notice in the Service.
The notification shall include, to the extent available at the time of the notice, the elements provided for in Art. 33(3) GDPR:
If not all the information is available at the time of the initial notification, Alethexis shall provide successive updates as the investigation progresses.
Notification to the competent supervisory authority (in Spain, the AEPD, the Spanish Data Protection Authority) in accordance with Art. 33 GDPR and, where applicable, communication to the Data Subjects in accordance with Art. 34 GDPR, are the responsibility of the Customer as controller. Alethexis shall assist the Customer by providing the available information and by responding reasonably to additional requests from the Customer and, where applicable, from the authority.
Alethexis shall retain, for a minimum of 5 years, the evidence relating to Breaches detected and notified, as well as the post-mortem analyses and the corrective measures applied, for defensive and continuous-improvement purposes.
The Customer, as controller, has the right to verify Alethexis's compliance with the obligations of Art. 28 GDPR and of this DPA, by means of:
alethexis.com/trust), which includes up-to-date informationon sub-processors, security measures and applicable certifications or adherences, where relevant.Unless there is a reasonable cause justifying otherwise (for example, a significant Personal Data Breach or a request from an authority), the right of audit shall be exercised:
The Customer may carry out the audit itself or through a qualified independent auditor, who may in no case be a direct competitor of Alethexis. The auditor shall first sign a confidentiality agreement (NDA) with Alethexis.
The audit shall be limited to verifying compliance with the obligations arising from this DPA and from Art. 28 GDPR. The following are excluded: proprietary source code, the data of other customers, trade secrets unrelated to the processing and any information whose disclosure could compromise the security of the Service.
The costs of the audit shall be borne by the Customer, unless the audit reveals material breaches attributable to Alethexis, in which case Alethexis shall bear the reasonable costs directly related to the audit.
The foregoing is without prejudice to the powers of inspection and audit vested in the AEPD, the AESIA (Spanish Agency for the Supervision of Artificial Intelligence) or other competent authorities. Alethexis shall cooperate in good faith with such authorities and shall keep the Customer informed, insofar as legally possible.
At the end of the provision of the Service, whether by termination of the agreement, deletion requested by the Customer or any other cause, Alethexis shall apply the following staged deletion policy, aligned with Art. 17 GDPR and with the applicable commercial and documentary-defence obligations:
| Level | Data | Treatment at the end of the provision of services |
|---|---|---|
| 1 | Identifying personal data of Users (name, email, telephone) | Deleted or pseudonymised by irreversible hash within a maximum of 30 days from the verified request. |
| 2 | Customer's compliance evidence (FRIA, DPIA, policy, RACI, signed PDFs, incident records, decisions) | A full exportis offered to the Customer's Owner before deletion. Once the export is confirmed, they are deleted from the active system. Post-export custody passes to the Customer. |
| 3 | Invoices and legally required records (Holded) | Retained for ≥ 6 years in accordance with Art. 30 of the Spanish Commercial Code (Código de Comercio) and applicable tax legislation. Legal basis: Art. 17(3)(b) GDPR (legal obligation). Not deleted even if the Customer makes an Art. 17 request. |
| 4 | Audit logs (audit.access_log) | Pseudonymised (irreversible hash of user_id, retention of account_id and event) with a retention period of 5 years for defence in the event of an inspection (AEPD, AESIA or others). |
| 5 | Backups | Rolling 30 days. Deleted data naturally disappear from the backup within ≤ 30 days after deletion. No selective restores are performed that could reintroduce already deleted data. |
At the close of the process, the Customer's Owner shall receive a confirmation email including:
After cancellation of the agreement and before starting the deletion procedure, Alethexis shall apply a 30-day grace period during which the Customer may:
Once that period has elapsed without reactivation, the deletion cascade described in 10.1 shall begin.
Where Union or Member State law requires the retention of Personal Data beyond the above periods (for example, court orders, tax obligations), Alethexis shall inform the Customer and shall retain the strictly necessary data for the legally required period.
In the current version of the Service (Wave 1), Alethexis has configured its infrastructure so that the Substantive Data are stored within the European Economic Area (Supabase, eu-central-1 · Frankfurt). However, the provision of the Service entails the Substantive Data transiting through the delivery and edge network of infrastructure providers with a presence outside the EEA (United States), in particular Cloudflare (proxy/CDN/WAF) and Vercel (hosting and edge network). Such transfers are covered by safeguards in accordance with Chapter V of the GDPR: Standard Contractual Clauses (Art. 46(2)(c)) and, where applicable, the EU-US Data Privacy Framework, with such supplementary measures as may be necessary (Schrems II). The location and safeguard mechanism of each Sub-processor are set out in Annex II and in the up-to-date public list at alethexis.com/subprocessors.
If in the future an additional Sub-processor or a processing operation entailing a new transfer of Substantive Data outside the EEA other than those declared in 11.1 were to be incorporated, Alethexis shall:
Each Party shall be liable for the damage caused as a result of a breach of the obligations that the GDPR and this DPA assign to it in its respective capacity as controller or processor, on the terms of Art. 82 GDPR.
Alethexis's liability towards the Customer arising from this DPA is limited to damage directly attributable to its breach of the obligations incumbent on it as Processor. In particular, Alethexis shall not be liable for:
Except in cases of wilful misconduct or gross negligence, or where the applicable law does not permit it, the aggregate liability of each Party towards the other under this DPA shall be limited as provided in the terms of service. This limitation does not apply to fines imposed by a supervisory authority directly on one of the Parties, nor to compensation to Data Subjects resulting from such fines, which shall be governed by Art. 82 GDPR.
If a Data Subject, authority or third party brings a claim in relation to the processing covered by this DPA, both Parties shall cooperate in good faith to coordinate the defence and the response, sharing the information reasonably necessary.
This DPA shall enter into force on the date of its acceptance by the Customer (click-through during onboarding to the Service or electronic signature) and shall remain in force for as long as the subscription agreement for the Service between the Parties remains in force, unless the return and deletion clauses (clause 10) or the audit clauses (clause 9) require their subsequent application.
Alethexis may amend this DPA in the following cases:
Amendments shall be notified to the Customer with reasonable notice, a minimum of 30 calendar days where materially possible, by email and by a notice in the Service. If the amendment substantially reduces the level of protection or introduces changes that the Customer cannot reasonably accept, the Customer shall be entitled to terminate the subscription agreement without penalty.
If any provision of this DPA is declared null and void or unenforceable, the remainder of the Agreement shall remain valid. The Parties shall negotiate in good faith a replacement clause that reflects, insofar as possible, the original intention.
This DPA is governed by Spanish law and by the applicable law of the European Union, in particular Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
The Parties submit, expressly waiving any other forum to which they may be entitled, to the Courts and Tribunals of the city of Barcelona (Spain) for the resolution of any dispute arising from this DPA, without prejudice to the powers conferred by law on the AEPD or on other supervisory authorities.
Processing of Personal Data by Alethexis, on behalf of the Customer, in the context of the provision of the Alethexis Service (modules M1 Visibility, M2 Governance, M3 High-Risk Ready and, where applicable, Agentic Add-on).
For as long as the subscription agreement for the Service remains in force, plus the return and retention periods provided for in clause 10 of the DPA.
| Aspect | Detail |
|---|---|
| Nature | Automated processing on a multi-tenant SaaS platform with isolation by Row Level Security (RLS) per account_id. |
| Main purpose | To enable the Customer to operate the functional sections of the Service: inventory of AI systems, P0–P6 classification, FRIA and DPIA assessments, usage policy, governance (committee, RACI, risks, decisions, changes, operations), evidence and references. |
| Authorised secondary purposes | Generation of evidentiary PDFs (Policy, Committee, RACI, FRIA, DPIA), immutable audit log, Service notifications, technical support subject to the Customer's prior authorisation. |
The following types are included by way of guidance. The actual determination lies with the Customer.
| Category | Examples | Source |
|---|---|---|
| Identifying data of Users | First name, surname, professional email, job title, assigned role | User registration by the Customer |
| Identifying data of third-party Data Subjects | Name, internal identifiers, contact details | Entered by the Customer in FRIA, DPIA, evidence |
| Professional data | Department, position, organisation | FRIA, DPIA, operational records |
| Sensitive data · Art. 9 GDPR (where applicable) | Health data (e.g. dental sector), other Art. 9 data that the Customer decides to process | Customer's decision |
| Data relating to AI systems | Provider identifiers, configuration, technical assessments (not necessarily personal in themselves, but they may be associated with Data Subjects) | Customer's configuration |
| Audit log | account_id, user_id, action performed, timestamp, event metadata | Generated automatically by the Service |
The Customer undertakes not to enter into the Service Personal Data that are unnecessary for the declared purpose, in accordance with the data minimisation principle of Art. 5(1)(c) GDPR.
| Category | Description |
|---|---|
| Customer's Users | Natural persons authorised by the Customer to access the Service, in the five canonical roles: Owner, AI Officer, DPO, Contributor, Auditor. |
| Customer's employees | Natural persons whose data may appear in the inventories, FRIA or DPIA assessments or evidence that the Customer records in the Service (for example, employees affected by an HR AI system). |
| Candidates | In recruitment or onboarding AI systems registered by the Customer. |
| Patients and/or end customers | Where the Customer registers AI systems that process them (e.g. dental clinics with assisted diagnosis systems). |
| Suppliers and professional contacts | Where the Customer records data relating to GPAI providers or other third parties in VIS-4 (due diligence). |
| Other natural persons | Any other Data Subjects whose data the Customer decides to record within the Service. |
Collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, internal disclosure between Sub-processors in accordance with Annex II, alignment, restriction, erasure, destruction and export.
Storage in the European Economic Area (Frankfurt). Transit through edge infrastructure with a presence outside the EEA under Chapter V GDPR safeguards. Details per Sub-processor in Annex II.
Version: 1.0 · Review date: 17 July 2026 · The live source of this list is the public page alethexis.com/subprocessors, which prevails in the event of a temporary divergence between updates.
| # | Sub-processor | Legal name | Main location | Purpose / Service provided | Safeguard mechanism |
|---|---|---|---|---|---|
| 1 | Supabase | Supabase Inc. (EU operation via Supabase EU) | Frankfurt (eu-central-1) · Germany | PostgreSQL database, authentication, file storage, Edge Functions, database monitoring. Processes all of the Customer's Substantive Data. | Supabase DPA signed · operation in the EEA · Standard Contractual Clauses (US entity). |
| 2 | Vercel | Vercel Inc. | USA (primary processing) + global edge | Hosting of the Next.js frontend and edge network. Processes HTTP logs and request metadata; does not store Substantive Data, processes them in transit. | Vercel DPA signed · EU-US Data Privacy Framework + Standard Contractual Clauses. |
| 3 | Cloudflare | Cloudflare, Inc. | USA (proxy over all traffic) | DNS proxy, CDN, WAF and Turnstile (captcha). Processes Substantive Data in transit(TLS termination) and visitors' IP addresses and browser signals. | Cloudflare DPA · EU-US Data Privacy Framework + Standard Contractual Clauses. |
| 4 | Stripe Payments Europe | Stripe Payments Europe Limited | USA (+ India) | Payment and subscription processing. Processes Account Data(the Customer's payment and tax data), not Substantive Data — see privacy policy. Acts as an independent sub-processor with its own liability for payment data, in accordance with its own processing agreement. Ireland is the contracting entity, not the location of the data. | Stripe Data Processing Agreement · Standard Contractual Clauses + EU-US Data Privacy Framework. |
| 5 | Holded | Holded Technologies, S.L. | Spain | Statutory invoicing, official invoice sequence, accounting integration. Processes the Customer's tax data. | Holded DPA signed · operation in Spain. |
| 6 | Resend | Resend (Plus Five Five, Inc.) | USA | Transactional email sending (Service notifications, password recovery, alerts). Processes the recipient email address and the email content — Account Data (email to users). | Resend DPA signed · Standard Contractual Clauses + EU-US Data Privacy Framework. |
| 7 | Sentry | Functional Software, Inc. (EU operation) | EU (Frankfurt) | Error monitoring. Processes stack traces with automatic PII scrubbing, error metadata and, where applicable, pseudonymised User identifiers. | Sentry DPA · EU configuration active. |
Notes:
The following measures are those applied at the time of signing the DPA. They may be updated to reflect improvements, provided that such updates do not reduce the level of protection.
account_id. Automated RLS tests in CI; no change is deployed if the tests fail.audit.access_log table with REVOKE UPDATE, DELETE at database level. Retention 5 years.pnpm audit and Dependabot.max-age=63072000; includeSubDomains; preload.unsafe-inline or unsafe-eval in script-src.SECURITY_RUNBOOK.md, with a notification period to the Customer of ≤ 24 hours (clause 8).© 2026 Alethexis · AI Governance & Compliance Framework for SMEs™ · Confidential contractual document · Based on Regulation (EU) 2024/1689 (EU AI Act) and Regulation (EU) 2016/679 (GDPR). It does not constitute legal advice to the Customer on its obligations as controller.