Loading...
Please wait while we prepare your content
Please wait while we prepare your content
GDPR Article 28 Compliant Data Processing Agreement
Version 1.0 | Effective Date: November 23, 2025
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Adaptrix ("Processor", "we", "us") and the Customer ("Controller", "you") and governs the processing of personal data by Adaptrix on behalf of the Customer.
You are the Controller; Adaptrix is the Processor
Fully compliant with GDPR Article 28 requirements
Prompt notification of any data breaches
Primary data processing in Frankfurt, Germany
The Processor shall Process Personal Data on behalf of the Controller for the purpose of providing the Adaptrix AI-powered business intelligence platform and related services as described in the Terms of Service.
Processing shall continue for the duration of the subscription term plus any retention period required by law or as specified in Annex A.
The Personal Data may relate to:
The Controller warrants and undertakes that:
The Processor shall:
Process Personal Data only on documented instructions from the Controller, unless required by EU or Member State law.
Ensure that persons authorized to Process Personal Data have committed to confidentiality or are under appropriate statutory obligation.
Implement appropriate technical and organizational measures as described in Annex B to ensure a level of security appropriate to the risk.
Not engage another Processor without prior written authorization. See Section 5 and Annex C for current sub-processors.
Assist the Controller in responding to Data Subject requests and compliance with GDPR Articles 32-36.
At Controller's choice, delete or return all Personal Data within 30 days of contract termination.
Make available information necessary to demonstrate compliance and allow for audits with 30 days' notice.
The Controller grants general authorization for the Processor to engage sub-processors listed in Annex C and at /sub-processors.
The Processor shall provide 30 days' notice before adding or replacing sub-processors. The Controller may object to changes by providing reasonable grounds within the notice period.
The Processor shall ensure sub-processors are bound by data protection obligations no less protective than those in this DPA.
The Processor implements comprehensive technical and organizational measures including:
TLS 1.3 in transit, AES-256 at rest
RBAC, MFA, least privilege principle
Immutable logs with hash chaining
EU hosting (Frankfurt, Germany)
Full details of technical and organizational measures are provided in Annex B.
The Processor shall assist the Controller in responding to Data Subject requests including:
The Processor shall notify the Controller without undue delay and within 72 hours of becoming aware of a Personal Data breach affecting Controller data.
Notification shall include:
The Processor shall not transfer Personal Data outside the EEA unless:
Current sub-processors requiring international transfers are listed in Annex C with applicable transfer mechanisms.
Detailed description of:
Security controls including:
Current list of authorized sub-processors available at /sub-processors
EU Commission approved SCCs (Decision 2021/914) for international transfers
Enterprise customers requiring a signed Data Processing Agreement can contact our legal team. We typically process DPA requests within 5 business days.
Request DPAFor questions regarding this Data Processing Agreement, please contact:
[email protected]Adaptrix
Palma, Illes Balears, Spain