Data Processing Agreement (DPA)

Effective: October 6, 2026 | Last updated: October 6, 2026


Agreement

This Data Processing Agreement (“DPA“) forms part of the Terms of Service (the “Principal Agreement“) between SIA AJELIX, reg. no. 40203482950, Peldu iela 7, Jelgava, LV-3002, Latvia (“Processor“, “Ajelix”) and the customer of the Ajelix platform (“Controller“, “you”), and reflects the parties’ agreement on the processing of personal data under Art. 28 GDPR. It applies automatically when Ajelix processes personal data on behalf of Controller in the provision of the Service, including via the Google Workspace add-on (AI Agent for Work).

Where Controller is itself a processor (e.g. Controller processes data for its own customers), this DPA applies with Controller acting as (sub)processor and its customer as the controller; Controller is responsible for obtaining any necessary authorizations from its own customers under Art. 28(2).


1. Roles, scope, duration

  • Subject matter: provision of the Service (agentic AI processing of files and prompts, hosting, add-on integrations) as detailed in Annex I.
  • Duration: the term of the Principal Agreement.
    Nature and purpose: see Annex I; categories of data subjects and data: Annex I.
  • Processing location: EU/EEA only. All platform data — including AI inference on Ajelix-owned servers and application hosting (Hetzner DE, OVHcloud DE) — is processed within the European Economic Area.
  • Service continuity fallback. In exceptional situations, such as a disruption or failure of Processor’s own infrastructure, Processor may engage a vetted external AI provider for as long as needed to maintain the Service. In that event: the provider is subject to data protection obligations no less protective than this DPA, is prohibited from using Controller data for AI training, any transfer outside the EEA is covered by the Standard Contractual Clauses or an adequacy mechanism, and the provider is notified as a subprocessor change per §4 before processing begins. Processor will communicate such use to Controller.

2. Confidentiality and personnel

Ajelix ensures personnel authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b)); that commitment survives termination. Employees receive security and data-protection training; pre-employment checks cover publicly available information.


3. Security (Art. 32)

Ajelix implements the technical and organizational measures in Annex II (which references the Security page) and may update them (no degradation of protection).


4. Subprocessors (Art. 28(2))

  • Controller grants general written authorization for the subprocessors listed at (“Subprocessor Page“).
  • Ajelix will notify Controller of changes (add/replacement) by updating the Subprocessor Page at least 7 days in advance, giving Controller the opportunity to object in writing on reasonable data-protection grounds. Unresolved objections give Controller the right to terminate the affected Service with a pro-rata refund of prepaid, unused fees.
  • Ajelix imposes data protection obligations on subprocessors by written contract (Art. 28(4)); remains fully liable for subprocessor performance; makes the subprocessor terms available to Controller on request where required.

5. Data subject rights

Ajelix notifies Controller without undue delay if it receives a request from a data subject to exercise rights (access, rectification, erasure, restriction, portability, objection). Taking into account the nature of the processing, Ajelix assists Controller by appropriate technical and organizational measures, insofar as possible, to fulfill the obligation to respond. Self-service controls available in the Service, including account deletion with full data deletion and billing management, constitute such measures. Assistance beyond reasonable support, such as bespoke engineering, may be charged at standard rates.


6. Controller assistance (Art. 32–36)

Ajelix assists Controller in ensuring compliance with obligations on security (Art. 32), breach notification (Art. 33), data protection impact assessments (Art. 35), and prior consultation (Art. 36), taking into account the nature of processing and information available to Ajelix.


7. Personal data breach

Ajelix notifies Controller without undue delay and, where feasible, within 48 hours of becoming aware of a personal data breach affecting Controller’s data, providing: the nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, and measures taken (Annex I section D). Notification may be staged as information becomes clear. Notification channels: status.ajelix.com and direct email to Controller’s administrative contact. Controller is responsible for notifying its own authorities/users.


8. Return and deletion (Art. 28(3)(g))

Ajelix deletes Controller data upon Controller’s instruction: account deletion results in the immediate, permanent, and irreversible deletion of prompts, outputs, files, and usage data, with no recovery possible; Controllers should export any data they wish to retain before deleting the account. On termination of the Service (other than by account deletion), Controller may request deletion or an export of Customer Data within a 14-day window; thereafter Ajelix deletes or anonymizes the data, including from backups on the backup cycle, unless EU/member-state law requires storage (billing records: 5 years under Latvian accounting law). On request, Ajelix certifies deletion in writing.


9. Audits (Art. 28(3)(h))

Ajelix makes available all information reasonably necessary to demonstrate compliance and allows for and contributes to audits, including inspections, by Controller or its mandatee.

  • Audit rights are satisfied by: (a) Ajelix’s published Security page and available documentation, including the ISO 27001 certification effort in progress; (b) security questionnaires; (c) an on-site audit only where (a) and (b) are insufficient, at Controller’s cost, on 30 days’ notice, no more than once per 12 months, during business hours, and without disrupting production; emergency inspections per SCC Annex clause where required.

10. Transfers of personal data

Primary processing takes place exclusively in the EU/EEA (Latvia, Germany). Where a listed subprocessor involves a transfer outside the EEA (currently: Google — OAuth/Workspace platform; Stripe — payment processing; Mailtrap — email delivery, hosted on US servers), the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) apply, incorporated by reference, completed as follows:

  • Module Two (controller→processor) for Controller’s data, and Module Three (processor→processor) where Controller acts as a processor for its customers;
  • Clause 7 (docking): included;
  • Clause 9(a) notification period: 7 days; Annex I B points to the Subprocessor Page;
  • Clause 11(a) independent dispute resolution: not used;
  • Clause 17 governing law: Latvia;
  • Clause 18 forum: courts of Latvia;
  • Annex I (parties, description of transfer), Annex II (technical measures), Annex III (subprocessor list — the Subprocessor Page).
  • Google and Stripe are certified under the EU–US Data Privacy Framework; the DPF applies as an alternative safeguard for their covered processing. Mailtrap relies on the Standard Contractual Clauses.
  • UK: for transfers subject to UK GDPR, the UK International Data Transfer Addendum to the SCCs applies, incorporated by reference (version in force at the time of transfer; tables completed with the same Annex I/II content). Switzerland: the FADP-equivalent of the SCCs applies.

11. International transfer impact and government access

Where any transfer outside the EEA occurs (currently limited to Google, Stripe, and Mailtrap functions), Ajelix will notify Controller (where lawfully permitted) of any binding request for disclosure of Controller data by a public authority, challenge it where reasonable, and minimize disclosure, mirroring SCC Clause 15. No other third-country transfers occur: AI inference and all core processing run on Ajelix-owned infrastructure in the EU.


12. Liability

Liability under this DPA follows the Principal Agreement’s limitation (Terms §13: a cap of 12 months’ platform fees, with AI usage fees and expert hourly fees excluded from the basis of the cap), applied to the parties’ aggregate liability under the DPA and SCCs combined.


13. Order of precedence

If there is any conflict: (1) the SCCs (for transfers they cover), (2) a signed enterprise agreement, (3) this DPA, (4) the Principal Agreement’s other privacy clauses.
Signed by the parties when Controller accepts the Terms of Service (electronically) or signs an Order Form referencing these Terms.


Annex I — Description of processing and transfer

A. List of parties

  • Data exporter (Controller): the Ajelix Customer (name, address, contact per Order Form; where the exporter is a processor, its controller is identified to Ajelix).
  • Data importer (Processor): SIA AJELIX, reg. no. 40203482950, Peldu iela 7, Jelgava, LV-3002, Latvia; contact: support@ajelix.com.

B. Description of processing

  • Categories of data subjects: Controller’s employees, contractors, and end users authorized by Controller; individuals contained in files Controller processes through the Service.
  • Categories of personal data: account identifiers (name, email, user ID), authentication metadata, content and files processed by Controller (may contain any personal data Controller inputs), usage/execution logs, billing contact data.
  • Sensitive data: not intentionally processed; Controller must not upload special-category data unless lawfully justified for its processing. Frequency: continuous, on Controller’s instructions.
  • Nature, purpose: hosting, agentic AI inference and task execution, storage, backup, support.
  • Duration: term of the Principal Agreement; immediate, permanent deletion upon account deletion; 14 days post-termination for termination without account deletion; backups within a 1-year purge cycle; billing records 5 years by law.

C. Subprocessors — see Subprocessor List. Note: AI inference runs on Ajelix-owned hardware — no external AI model providers.
D. Breach info — see DPA §7 (48-hour notification target).


Annex II — Technical and organizational measures

Reference: Security page (kept current; snapshots on request). Baseline includes:

  1. Encryption in transit (TLS on all sites and APIs);
  2. Encryption at rest with industry-standard encryption; passwords and secrets stored only as one-way hashes; additional encryption layers for sensitive fields;
  3. Access control: encrypted VPN with two-factor authentication for production access; network firewalls; least-privilege access; access reviews at least twice a year;
  4. Tenant isolation: database- and storage-level segregation with strict per-tenant access-scope checks on every request; per-customer databases available for enterprise customers;
  5. Logging and monitoring on self-hosted infrastructure;
  6. Backup and restore procedures (30–60 day cycle), encrypted;
  7. Incident response incl. 48-hour breach notification workflow;
  8. Personnel security: confidentiality agreements, security training;
  9. Data minimization; no AI training on customer data; inference on Ajelix-owned EU infrastructure;
  10. Secure development: mandatory unit testing, static and dynamic application security testing, multi-layer AI-assisted security review, and stress testing before release.