This Data Processing Agreement (“DPA“) forms part of the Terms of Service (the “Principal Agreement“) between SIA AJELIX, reg. no. 40203482950, Peldu iela 7, Jelgava, LV-3002, Latvia (“Processor“, “Ajelix”) and the customer of the Ajelix platform (“Controller“, “you”), and reflects the parties’ agreement on the processing of personal data under Art. 28 GDPR. It applies automatically when Ajelix processes personal data on behalf of Controller in the provision of the Service, including via the Google Workspace add-on (AI Agent for Work).
Where Controller is itself a processor (e.g. Controller processes data for its own customers), this DPA applies with Controller acting as (sub)processor and its customer as the controller; Controller is responsible for obtaining any necessary authorizations from its own customers under Art. 28(2).
Ajelix ensures personnel authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b)); that commitment survives termination. Employees receive security and data-protection training; pre-employment checks cover publicly available information.
Ajelix implements the technical and organizational measures in Annex II (which references the Security page) and may update them (no degradation of protection).
Ajelix notifies Controller without undue delay if it receives a request from a data subject to exercise rights (access, rectification, erasure, restriction, portability, objection). Taking into account the nature of the processing, Ajelix assists Controller by appropriate technical and organizational measures, insofar as possible, to fulfill the obligation to respond. Self-service controls available in the Service, including account deletion with full data deletion and billing management, constitute such measures. Assistance beyond reasonable support, such as bespoke engineering, may be charged at standard rates.
Ajelix assists Controller in ensuring compliance with obligations on security (Art. 32), breach notification (Art. 33), data protection impact assessments (Art. 35), and prior consultation (Art. 36), taking into account the nature of processing and information available to Ajelix.
Ajelix notifies Controller without undue delay and, where feasible, within 48 hours of becoming aware of a personal data breach affecting Controller’s data, providing: the nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, and measures taken (Annex I section D). Notification may be staged as information becomes clear. Notification channels: status.ajelix.com and direct email to Controller’s administrative contact. Controller is responsible for notifying its own authorities/users.
Ajelix deletes Controller data upon Controller’s instruction: account deletion results in the immediate, permanent, and irreversible deletion of prompts, outputs, files, and usage data, with no recovery possible; Controllers should export any data they wish to retain before deleting the account. On termination of the Service (other than by account deletion), Controller may request deletion or an export of Customer Data within a 14-day window; thereafter Ajelix deletes or anonymizes the data, including from backups on the backup cycle, unless EU/member-state law requires storage (billing records: 5 years under Latvian accounting law). On request, Ajelix certifies deletion in writing.
Ajelix makes available all information reasonably necessary to demonstrate compliance and allows for and contributes to audits, including inspections, by Controller or its mandatee.
Primary processing takes place exclusively in the EU/EEA (Latvia, Germany). Where a listed subprocessor involves a transfer outside the EEA (currently: Google — OAuth/Workspace platform; Stripe — payment processing; Mailtrap — email delivery, hosted on US servers), the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) apply, incorporated by reference, completed as follows:
Where any transfer outside the EEA occurs (currently limited to Google, Stripe, and Mailtrap functions), Ajelix will notify Controller (where lawfully permitted) of any binding request for disclosure of Controller data by a public authority, challenge it where reasonable, and minimize disclosure, mirroring SCC Clause 15. No other third-country transfers occur: AI inference and all core processing run on Ajelix-owned infrastructure in the EU.
Liability under this DPA follows the Principal Agreement’s limitation (Terms §13: a cap of 12 months’ platform fees, with AI usage fees and expert hourly fees excluded from the basis of the cap), applied to the parties’ aggregate liability under the DPA and SCCs combined.
If there is any conflict: (1) the SCCs (for transfers they cover), (2) a signed enterprise agreement, (3) this DPA, (4) the Principal Agreement’s other privacy clauses.
Signed by the parties when Controller accepts the Terms of Service (electronically) or signs an Order Form referencing these Terms.
A. List of parties
B. Description of processing
C. Subprocessors — see Subprocessor List. Note: AI inference runs on Ajelix-owned hardware — no external AI model providers.
D. Breach info — see DPA §7 (48-hour notification target).
Reference: Security page (kept current; snapshots on request). Baseline includes: