Data Processing Agreement
This Agreement is incorporated by reference into the Customer's subscription with Attera. The Customer's act of subscribing constitutes acceptance of the terms below. A counter-signed PDF version is provided on request: email contact@attera.io with subject "DPA".
Published in full. No NDA. Read before you sign anything.
Contents
- RecitalsBackground
- 01Definitions
- 02Scope and roles
- 03Documented instructions
- 04Processor obligations
- 05Controller obligations
- 06Sub-processors
- 07Location and international transfers
- 08Security measures
- 09Personal data breaches
- 10Assistance to the Controller
- 11Audit rights
- 12Deletion and return
- 13Term and termination
- 14Liability and conflict
- 15Miscellaneous
- Sched. 1Details of the processing
Recitals
(A) The Customer (the "Controller") has subscribed to the document-extraction and compliance-reporting service operated by Attera, based in Belgium (the "Processor", together the "Parties").
(B) Provision of the service requires the Processor to process personal data on behalf of the Controller within the meaning of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
(C) This Agreement sets out the Parties' obligations under Article 28 GDPR and equivalent provisions of Applicable Data Law. It applies in addition to, and forms part of, the Terms of Service published at attera.io/terms (the "Terms").
1.Definitions
The following terms have the meanings set out below. Other capitalised terms used in this Agreement have the meanings given in the Terms or, where used in the GDPR, the meaning given in the GDPR.
- Applicable Data Law: the GDPR and any other data protection law applicable to the processing of Customer Data, including national implementations and any successor framework.
- Customer Data: any data, including Personal Data, that the Controller or its Authorised Users submit to the Processor's service, store within the service, or that the service generates on the Controller's instructions.
- Personal Data: Customer Data that constitutes personal data within the meaning of Article 4(1) GDPR.
- Personal Data Breach: a breach of security as defined in Article 4(12) GDPR, affecting Personal Data.
- Sub-Processor: any third party engaged by the Processor that processes Customer Data on the Processor's behalf in connection with the service.
- Schedule 1: the schedule at the end of this Agreement setting out the details of the processing.
2.Scope and roles
For all Personal Data within Customer Data, the Controller is the controller and Attera is the processor within the meaning of Articles 4(7) and 4(8) GDPR. The Processor processes Customer Data only on the Controller's documented instructions as defined in Article 3 below.
The subject-matter, duration, nature, purpose, categories of data subjects, and categories of Personal Data of the processing are set out in Schedule 1.
The Processor will not sell Customer Data, share Customer Data for advertising, or use Customer Data to train artificial-intelligence models. This obligation survives termination of the Agreement.
3.Documented instructions
The Controller's documented instructions for the processing of Customer Data are:
- The Controller's use of the service in accordance with the Terms and the product documentation.
- The configuration choices the Controller and its Authorised Users make inside the service (including but not limited to workspace settings, role assignments, retention preferences).
- Any specific written instruction the Controller sends to contact@attera.io and that the Processor confirms in writing.
The Processor will immediately inform the Controller if, in its opinion, an instruction infringes Applicable Data Law. The Processor may pause processing under that instruction pending clarification.
4.Processor obligations
The Processor will:
- Process Customer Data only on the Controller's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to process by Union or Member State law to which the Processor is subject (in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest).
- Ensure that persons authorised to process Customer Data are bound by written confidentiality obligations.
- Implement and maintain the technical and organisational measures set out in Article 8 below.
- Engage Sub-Processors only in accordance with Article 6.
- Assist the Controller in accordance with Article 10.
- Notify the Controller of Personal Data Breaches in accordance with Article 9.
- Delete or return Customer Data on termination in accordance with Article 12.
- Make available to the Controller, on request, all information necessary to demonstrate compliance with this Agreement, in accordance with Article 11.
5.Controller obligations
The Controller is responsible for:
- Establishing a lawful basis under Article 6 GDPR (and, where applicable, Article 9 GDPR) for the processing of Personal Data the Controller submits to the service.
- Ensuring that the categories of data subjects and Personal Data described in Schedule 1 accurately reflect the Controller's actual processing inside the service. The Processor relies on the Controller's selection of what to upload.
- Providing data subjects with the information required under Articles 13 and 14 GDPR concerning the processing.
- Configuring the service in accordance with the Controller's own data protection obligations, including reviewer permissions, retention settings, and access controls.
6.Sub-processors one only
The Processor engages one Sub-Processor:
| Provider | Entity and location | Purpose |
|---|---|---|
| Tailscale | Tailscale Inc., Delaware, USA | Private network coordination (the "control plane") between the machines the Processor operates in Belgium. Customer Data does not transit Tailscale's infrastructure. Tailscale handles only network coordination metadata: machine identifiers, public keys, IP addresses, connection timestamps. |
That is the entire list. No content delivery network. No analytics provider. No marketing platform. No third-party large-language-model API on any path that touches a document.
The Processor will give the Controller at least 30 days' written notice by email before engaging any new Sub-Processor that handles Customer Data. The Controller may object in writing within that period for legitimate data protection reasons. If the Parties cannot resolve the objection within a further 30 days, the Controller may terminate the affected portion of the service for cause and receive a pro-rata refund for the unused portion of the prepaid term.
The Processor remains liable for the acts and omissions of any Sub-Processor as if they were its own under this Agreement, save to the extent the Sub-Processor's act or omission results from the Controller's instruction.
7.Location and international transfers
Customer Data is processed and stored exclusively on hardware the Processor operates in Belgium. The local large-language model that processes documents runs on the same Belgian infrastructure. There is no replication outside the European Economic Area. There is no US edge cache. There is no third-party large-language-model API in the inference path.
Tailscale Inc. is the only Sub-Processor and is established in the United States. No Customer Data transits Tailscale's infrastructure. The control-plane metadata that Tailscale handles (machine identifiers, public keys, IP addresses, connection timestamps) may include data that qualifies as personal data under the GDPR concerning the Processor's own machines and personnel. To the extent any such metadata of the Controller's Authorised Users is incidentally processed, transfer to Tailscale Inc. takes place under the EU-U.S. Data Privacy Framework adopted by Commission Implementing Decision (EU) 2023/1795, in accordance with Article 45 GDPR, for so long as Tailscale Inc. maintains its self-certification under that framework. The Processor verifies Tailscale Inc.'s certification status on the U.S. Department of Commerce's Data Privacy Framework List periodically and will notify the Controller without undue delay if the certification lapses, at which point Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"), Module 3 (Processor-to-Processor), will apply between the Processor and Tailscale Inc.
The Processor will not engage any further Sub-Processor located outside the EEA without giving the Controller the notice and objection right set out in Article 6.
8.Security measures
The Processor implements and maintains the following technical and organisational measures, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32 GDPR:
- Encryption in transit: TLS 1.3 on all network connections; HSTS enforced; no fallback to earlier protocol versions.
- Encryption at rest: AES-256 on object storage and database volumes.
- Access control: least-privilege internal access; multi-factor authentication on administrative interfaces; audit logging on every administrative action.
- Network isolation: private peer-to-peer network between the machines the Processor operates; no public administrative endpoints; no third-party administrative SaaS.
- Backups: encrypted snapshots, stored in the European Union only. Cadence and retention are documented in the subscription order.
- Personnel: written confidentiality obligations for everyone with access; access removed on offboarding.
- Audit trail: per-workspace, append-only, hash-chained log of every reviewer action and every figure committed to a draft.
- Incident response: named contact (security@attera.io); best-effort acknowledgement within 24 hours of a confirmed report from the Controller; this is separate from and additional to the Article 9 breach notification obligation.
Schedule 1, section 7 sets out the same measures in the SCC-aligned format for incorporation by reference into a transfer instrument if the Controller subsequently engages a third party requiring such referencing.
9.Personal data breaches
The Processor will notify the Controller of any Personal Data Breach affecting Customer Data without undue delay and in any case within 48 hours of becoming aware of it. The notification will include, to the extent then known:
- A description of the nature of the breach, including where possible the categories and approximate number of data subjects and Personal Data records concerned.
- The name and contact details of the data-protection contact (security@attera.io).
- The likely consequences of the breach.
- The measures taken or proposed to address the breach and to mitigate possible adverse effects.
Where it is not possible to provide all information at once, information will be provided in stages without undue further delay. The Processor will cooperate with the Controller in any subsequent investigation or notification to a competent supervisory authority or data subject.
10.Assistance to the Controller
The Processor will assist the Controller, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Controller's obligations to:
- Respond to requests by data subjects under Articles 15 to 22 GDPR (access, rectification, erasure, restriction, portability, objection, automated decision-making). Most requests can be completed by the Controller directly using the export and delete controls inside the service.
- Conduct data-protection impact assessments under Article 35 GDPR and consult the supervisory authority under Article 36 GDPR, including by providing on request information about the security measures and the categories of processing.
- Respond to inquiries or instructions from a competent supervisory authority concerning the processing of Customer Data under this Agreement.
Assistance under this Article that imposes more than a reasonable burden on the Processor will be provided at the Processor's then-current professional services rates, agreed in writing in advance.
11.Audit rights
The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this Agreement. In the first instance, the Processor satisfies this obligation by:
- Publishing the full sub-processor list in Article 6.
- Publishing the security measures in Article 8 and Schedule 1, section 7.
- Providing on request a completed security questionnaire and, where available, third-party certification or attestation reports.
- Walking through the inference machine on a video call on request, including the model file on disk and the document data flow.
Where the documentation above is insufficient to demonstrate compliance, the Controller may, at its own cost, conduct a documentation-based audit, or commission an independent auditor reasonably acceptable to the Processor to conduct one, on at least 30 days' written notice, no more than once per twelve-month period, during normal business hours, and in a manner that does not unreasonably interfere with the Processor's operations. The Processor's cooperation beyond a half-day per audit is provided at the Processor's then-current professional services rates.
12.Deletion and return
On termination of the subscription or at any time on the Controller's written request, the Processor will, at the Controller's choice:
- Return all Customer Data to the Controller in a commonly used machine-readable format, or
- Securely delete all Customer Data from the Processor's systems.
Deletion is completed within 30 days of the request. Encrypted backup snapshots are purged on the next backup-retention cycle, which is documented in the subscription order. The Processor will provide written confirmation of completion on request.
The Processor may retain Customer Data only to the extent and for the duration required by Union or Member State law. Where retention is so required, the Processor will (i) inform the Controller of the legal requirement before retention unless prohibited from doing so, (ii) protect the retained data with the same measures as live data, and (iii) delete it as soon as the legal requirement no longer applies.
13.Term and termination
This Agreement enters into force on the start date of the Controller's subscription and continues for as long as the Processor processes Customer Data on the Controller's behalf, plus the deletion window in Article 12. The Articles concerning confidentiality (4), location (7), security (8), assistance (10), audit (11), deletion (12), liability (14), and miscellaneous (15) survive termination to the extent necessary to give them effect.
Either Party may terminate this Agreement for material breach by the other on 30 days' written notice, with a cure period of 30 days from receipt of notice. Termination of this Agreement automatically terminates the Controller's subscription if a continuing processing relationship is no longer possible under Applicable Data Law.
14.Liability and conflict
The liability of each Party under and in connection with this Agreement is governed by the limitation-of-liability provisions of the Terms, save that nothing in this Agreement or the Terms limits or excludes liability that cannot be limited or excluded under Applicable Data Law (including, in respect of natural-person data subjects, the rights conferred by Article 82 GDPR).
In the event of any conflict between this Agreement and the Terms with respect to the processing of Personal Data, this Agreement prevails.
15.Miscellaneous
Notices. Notices under this Agreement are sent to the Processor at contact@attera.io, with a copy to security@attera.io for matters concerning security or a Personal Data Breach. Notices to the Controller are sent to the contact address designated in the Controller's subscription order.
Amendment. The Processor may update this Agreement from time to time. Material updates take effect 30 days after notice to the Controller. The version in force at any given time is the version published at attera.io/dpa, dated as shown above the recitals.
Severability. If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions remain in full force and effect.
Assignment. Neither Party may assign this Agreement without the other Party's prior written consent, save that the Processor may assign this Agreement to an affiliate or to a successor in connection with a merger, acquisition, or sale of substantially all of the assets of the relevant business, on the same terms.
Governing law and jurisdiction. This Agreement is governed by Belgian law. The courts of Leuven, Belgium have exclusive jurisdiction over any dispute arising under or in connection with it, without prejudice to mandatory rights of data subjects under Article 79 GDPR.
Electronic signature. The Parties accept electronic signature of this Agreement in accordance with Regulation (EU) 910/2014 (eIDAS).
Schedule 1 · Details of the processing
This Schedule sets out the information required by Article 28(3) GDPR.
1. Subject-matter and duration
Subject-matter: provision of the Processor's document-extraction and compliance-reporting service to the Controller under the Terms.
Duration: the term of the Controller's subscription, plus the deletion window in Article 12, plus any retention required by Applicable Law.
2. Nature and purpose of the processing
The Processor reads documents the Controller uploads to the service, extracts structured figures and references, generates draft compliance disclosures (including CSRD and equivalent reports) with figures cited back to the source document and page, and produces audit-defensible output files. Processing is necessary to provide the service.
3. Categories of data subjects
Personal Data processed by the Processor on the Controller's instructions may concern:
- The Controller's employees, contractors, and other personnel (named on HR exports, organisational charts, payroll documents).
- The Controller's Authorised Users of the service (account holders, reviewers, approvers).
- The Controller's suppliers and their personnel (named on invoices, contracts, communications).
- Customers, agents, brokers, and other counterparties of the Controller (named on commission statements, reconciliation documents, contracts).
- Signatories and other natural persons named in source documents the Controller uploads.
4. Categories of personal data
Personal Data processed may include:
- Identification and contact data: names, business email addresses, business addresses, business phone numbers, professional titles.
- Employment data: job titles, department, employment dates, work locations, role descriptions, headcount metrics where attributable to identifiable individuals.
- Compensation and remuneration data: salaries, bonuses, commissions, benefits, expense reimbursements, where appearing on documents the Controller uploads.
- Contractual data: party identifiers, contract references, dates, signatures, authorisations.
- Financial data attributable to identifiable individuals: invoiced amounts, paid amounts, outstanding balances, payment dates.
- Technical data: Authorised User account identifiers, IP addresses, timestamps of actions inside the service, audit-log entries.
- Any further Personal Data the Controller chooses to upload as part of source documents.
The Processor does not solicit and the service is not designed to receive special categories of Personal Data within the meaning of Article 9 GDPR. The Controller is responsible for not uploading such data unless the Controller has established an Article 9 lawful basis and notified the Processor in writing.
5. Processing locations
Customer Data is processed and stored on hardware the Processor operates in Belgium. The local large-language model used to process documents runs on the same Belgian infrastructure. There is no replication outside the European Economic Area. The sole Sub-Processor (Tailscale Inc.) is located in the United States; the international-transfer mechanism is set out in Article 7.
6. Retention and deletion
Live Customer Data is retained for the duration of the subscription or until the Controller deletes it through the service, whichever is earlier. On termination or at the Controller's request, Article 12 applies.
Encrypted backup snapshots follow the cadence and retention documented in the Controller's subscription order. Audit-trail entries required by Article 8 are retained for the duration of the subscription plus seven years for evidentiary purposes, unless the Controller requests earlier deletion in writing.
7. Technical and organisational measures
The measures listed in Article 8 form the agreed technical and organisational measures for the purposes of Articles 28 and 32 GDPR. They are reproduced here in a form suitable for incorporation by reference into any transfer instrument:
- Pseudonymisation and encryption: AES-256 at rest; TLS 1.3 in transit; encrypted backup snapshots.
- Confidentiality, integrity, availability and resilience: private peer-to-peer network; least-privilege access; audit logging; per-workspace hash-chained audit trail.
- Restoration of availability: encrypted backup snapshots stored in the EU only; documented cadence in the subscription order.
- Process for testing, assessing, and evaluating effectiveness: documented internal review on each release cycle; vulnerability monitoring on the production hardware; named security contact (security@attera.io).