Legal
Data Processing Agreement
Effective date: 30 September 2026 · Version 1.0. For business customers. This DPA forms part of the Software Agreement and applies automatically when a Business Customer accepts it. It does not apply to consumers.
This Data Processing Agreement (DPA) forms part of the Software Agreement between Autonomyware B.V., a private limited liability company (besloten vennootschap) incorporated under Dutch law, having its registered office in the municipality of Waadhoeke and its business address at Siaerdamasingel 57, 9035 GG Dronryp, the Netherlands, registered with the Dutch Chamber of Commerce under number 42037699, VAT number NL869420446B01 (Autonomyware or the Processor) and the Business Customer (the Customer or the Controller). It applies automatically when a Business Customer accepts the Software Agreement. It does not apply to consumers.
1. Definitions and Scope
1.1 Terms such as personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meaning given in the General Data Protection Regulation (EU) 2016/679 (GDPR). Other capitalised terms have the meaning given in the Software Agreement.
1.2 This DPA applies to personal data that Autonomyware processes on behalf of the Customer when providing the Software (Customer Personal Data). Annex 1 describes the processing.
1.3 This DPA does not apply to personal data that Autonomyware processes as a controller, such as Account, billing, support and usage data, which is covered by the Privacy Policy.
1.4 Where the Customer connects an Own Key, the supplier of that model processes data under its own agreement with the Customer. That supplier is not a sub-processor of Autonomyware, and this DPA does not govern its processing.
2. Instructions
2.1 Autonomyware processes Customer Personal Data only on the Customer's documented instructions, unless required to do so by Union or Member State law, in which case Autonomyware informs the Customer of that requirement before processing, unless the law prohibits this.
2.2 The Software Agreement, this DPA and the Customer's use and configuration of the Software, including its selection of Features and Included Models, are the Customer's complete instructions. Further instructions must be in writing and consistent with the Software Agreement.
2.3 Autonomyware informs the Customer without delay if it considers that an instruction infringes the GDPR or other data protection law.
2.4 The Customer is responsible for the lawfulness of the processing, including having a legal basis and informing data subjects. The Customer should not submit special categories of personal data or criminal data unless strictly necessary and lawful.
3. Confidentiality
3.1 Autonomyware ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. Security
4.1 Autonomyware implements the technical and organisational measures set out in Annex 2 to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Autonomyware may update these measures, provided that the overall level of security is not reduced.
5. Sub-processors
5.1 The Customer gives Autonomyware general authorisation to engage sub-processors. The sub-processors engaged at the effective date are listed in Annex 3. The current list is available at autonomyware.ai/terms.
5.2 Autonomyware notifies the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by email or in the Software. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the Software Agreement with effect from the date the change takes effect, with a pro rata refund of prepaid fees and of unused Credits.
5.3 Where the change concerns a Model Provider, the Customer may alternatively choose not to use the Included Models of that Model Provider.
5.4 Autonomyware imposes on each sub-processor data protection obligations that offer at least the same level of protection as this DPA, and remains liable to the Customer for the performance of the sub-processor's obligations.
6. International Transfers
6.1 Autonomyware transfers Customer Personal Data to a country outside the European Economic Area only where Chapter V GDPR is complied with, in particular on the basis of an adequacy decision (including the EU-U.S. Data Privacy Framework for certified recipients) or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, supplemented where necessary by additional measures.
6.2 Autonomyware hosts Customer Personal Data in the European Union, on servers of its hosting provider in Paris, France. Customer Personal Data is processed outside the European Economic Area only where this is necessary to run a Feature that uses an Included Model of a Model Provider located outside the European Economic Area, or where Annex 3 provides otherwise.
7. Assistance
7.1 Taking into account the nature of the processing, Autonomyware assists the Customer by appropriate technical and organisational measures in responding to requests from data subjects. Autonomyware forwards any request it receives directly to the Customer without undue delay and does not respond itself unless authorised by the Customer.
7.2 Autonomyware assists the Customer in complying with its obligations under Articles 32 to 36 GDPR, taking into account the information available to Autonomyware. Autonomyware may charge reasonable costs for assistance that goes beyond providing the information in this DPA and the standard documentation.
8. Personal Data Breaches
8.1 Autonomyware notifies the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notification includes, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information that is not yet available is provided in phases.
8.3 The Customer decides whether to notify the supervisory authority and data subjects. Autonomyware does not notify them on the Customer's behalf unless required by law.
9. Return and Deletion
9.1 At the end of the Software Agreement, the Customer may export its data in accordance with clause 11.5 of the Software Agreement. Autonomyware then deletes Customer Personal Data within 60 days, unless Union or Member State law requires storage. Copies in backups are deleted in the ordinary backup cycle and are not restored in the meantime except for recovery purposes.
10. Information and Audits
10.1 Autonomyware makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, such as summaries of security measures and relevant certifications or audit reports of Autonomyware or its sub-processors.
10.2 If that information is not sufficient, the Customer may, at its own cost and no more than once a year (unless following a personal data breach or at the request of a supervisory authority), have an audit carried out by an independent auditor bound by confidentiality, on at least 30 days' notice, during business hours and without unreasonable disruption. Audits of sub-processors take place through the audit reports those sub-processors make available.
11. Liability and Term
11.1 The limitations of liability in the Software Agreement apply to this DPA, without prejudice to the rights of data subjects under Article 82 GDPR.
11.2 This DPA applies for as long as Autonomyware processes Customer Personal Data. Clauses that by their nature are intended to survive, survive termination.
11.3 This DPA is governed by Dutch law. Clause 20 of the Software Agreement applies to disputes.
Annex 1 — Description of the Processing
| Subject matter and purpose | Provision of the Software to the Customer: storing and processing Inputs and Outputs, running Features, including transmission to Model Providers of the Included Models the Customer selects, support and troubleshooting at the Customer's request. |
|---|---|
| Nature of processing | Hosting, storage, retrieval, transmission to AI models, analysis and generation of content, export and deletion. |
| Categories of data subjects | The Customer's user; persons whose data the Customer includes in Inputs, such as the Customer's employees, clients, suppliers and contact persons. |
| Categories of personal data | Names, contact details, job titles and similar identification data contained in Inputs, project files, specifications, documentation and code; any other personal data the Customer chooses to include in Inputs. |
| Special categories | None intended. The Customer should not include them (clause 2.4). |
| Duration | The term of the Software Agreement and the deletion period in clause 9. |
| Retention by Model Providers | xAI: zero data retention. OpenAI and Anthropic: retention under their standard policies for API customers, generally up to 30 days for abuse and misuse monitoring, and longer where the law requires this. Content flagged under a Model Provider's usage policies may be retained longer; for Anthropic, up to 2 years. |
Annex 2 — Technical and Organisational Measures
- Role-based access control based on least privilege; periodic access reviews.
- Separation of customer data.
- Logging and monitoring of administrative access and security events.
- Vulnerability management, patching and periodic security testing.
- Backups with tested restore procedures; hosting in the European Economic Area (Scaleway, Paris, France).
- Incident response procedure including breach notification in accordance with clause 8.
- Confidentiality undertakings and security awareness for staff and contractors.
- Configuration of Model Provider accounts so that inputs and outputs are not used for model training, and zero data retention where agreed with the Model Provider (currently xAI).
- Due diligence of sub-processors before engagement.
Annex 3 — Sub-processors
| Sub-processor | Service | Location | Transfer mechanism |
|---|---|---|---|
| OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, CA 94158, United States | Included Models (GPT) and image generation | USA | Data Privacy Framework (where certified) or Standard Contractual Clauses |
| Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, United States | Included Models (Claude) | USA | Data Privacy Framework (where certified) or Standard Contractual Clauses |
| X.AI LLC, 1450 Page Mill Road, Palo Alto, CA, United States | Included Models (Grok) | USA | Data Privacy Framework (where certified) or Standard Contractual Clauses |
| Scaleway SAS | Hosting and storage | France (Paris) | Not applicable |
| Cloudflare, Inc. | Content delivery network and security | Western Europe | Data Privacy Framework (where certified) or Standard Contractual Clauses |
| Microsoft (Microsoft 365) | Email and support communications | European Union / EFTA | Data Privacy Framework (where certified) or Standard Contractual Clauses |