Data Processing Agreement (DPA)
Draft · This agreement forms part of the Terms of Service of the Eva Service and is entered into between the customer (Controller) and [OPERATOR] (Processor).
1. Subject matter and duration of processing
The Processor processes personal data for the Controller solely for the purpose of providing the Eva Service (fetching e-mails, triaging them, preparing reply drafts, managing the knowledge base and the chat), for the duration of the Controller's account.
2. Nature and categories
- Data subjects:the Controller's customers and correspondents, and the Controller's users.
- Categories of data:identification and contact data (name, e-mail), the content of e-mail communication including attachments, and data contained in the Controller's knowledge base.
- Special categories of data (Art. 9) are not intentionally processed by the Service; they may occur in the content of e-mails — the Controller bears responsibility for the lawfulness of processing them.
3. The Controller's instructions
The Processor processes data only on the documented instructions of the Controller; use of the Service and its configuration are deemed to be such an instruction. Reply drafts are sent solely after the Controller's approval (human-in-the-loop).
4. Confidentiality and security (Art. 32)
- encryption in transit (TLS) and at rest,
- mailbox credentials encrypted at application level (AES-256-GCM),
- isolation of customer data at the database level (Row Level Security),
- data stored in the EU (Frankfurt), compute in the EU (Frankfurt),
- access to the data only by persons bound by an obligation of confidentiality.
5. Sub-processors
The Controller grants a general authorisation for engaging sub-processors. Current list: Supabase, Inc. (database/storage, EU), Vercel, Inc. (hosting, compute in the EU, SCCs), Anthropic, PBC (AI processing, USA — transfer based on SCCs; contractually does not train models on the data and retains it for max. 30 days), planned: Stripe (payments). The Processor will announce changes to the list at least 30 days in advance; the Controller may object and terminate the agreement.
6. Assistance and incidents
- The Processor assists the Controller in fulfilling the rights of data subjects (access, erasure, export) and with the obligations under Art. 32–36.
- The Processor will notify the Controller of a security breach without undue delay, at the latest within 48 hours of becoming aware of it, including the details known — so that the Controller can meet the 72-hour deadline under Art. 33.
7. Erasure and return
Upon termination of the account, the Processor deletes all personal data (erasure is immediate; at the sub-processor Anthropic, copies expire according to its retention within 30 days). Before termination, the Controller may download the data using the export function.
8. Audit
The Processor will provide the Controller with the information necessary to demonstrate compliance; an audit may be carried out at most once a year, with prior notice and at the Controller's cost.