Data Processing Agreement
1. Subject matter, duration, nature and purpose
This data processing agreement (the “DPA”) sets out the terms on which MDigital Sp. z o.o. (the “Operator” or “Processor”) processes personal data for which the Client is the controller (the “Controller”), and implements the requirements of Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR). Capitalised terms not defined here have the meaning given to them in the Terms of Service.
The DPA forms an integral part of the agreement for the use of the Service and is concluded together with it, that is upon creation of the Account. It requires no separate signature; at the Client’s request the Operator provides its content on a durable medium or signs a separate counterpart of identical content.
The Operator acts in two distinct capacities towards the Client. In respect of Account data and data about the use of the Service, the Operator is an independent controller — that processing is described in the Privacy Policy. In respect of personal data contained in material fetched on the Client’s instruction, the Operator is a processor, and it is that capacity which this DPA governs.
The subject matter of the processing is personal data contained in Source Material fetched from Sources configured by the Controller within its Goals, in the metadata of that material, and in the Clusters and Content produced from it.
The nature and purpose of the processing cover the following operations performed within the Service:
- fetching publicly available material from Sources designated by the Controller and storing it together with its metadata,
- computing vector representations of that material and grouping it into Clusters by semantic similarity,
- filtering Clusters against criteria defined by the Controller, including by means of language models,
- producing Content from Clusters using language models supplied by third parties,
- making the material, Clusters and Content available to the Controller in the Service panel and through the application programming interface (API),
- delivering Content or Cluster data to channels designated by the Controller, in particular by webhook, API or the WordPress plugin.
The types of personal data comprise data contained in publicly published press and information material, in particular: names, roles and affiliations, statements and quotations, descriptions of professional activity, contact details given in the body of the publication, and data identifying the authors of the publication. The scope of the data is determined by the content of the Sources configured by the Controller and is not limited in advance by the Operator.
The categories of data subjects comprise: authors of publications, persons named in publications — including holders of public office, representatives of businesses and institutions, and experts speaking publicly — and other persons whose data has been included in a publication by its publisher.
The Controller represents that it has a legal basis for the processing it instructs the Operator to carry out and that the instructions it issues comply with the law. The Controller is responsible in particular for the information obligation towards persons whose personal data has not been obtained from them directly (Article 14 GDPR), for assessing the admissibility of the Sources it configures and the scope of the data obtained from them, and for handling those persons’ requests. The Operator carries out instructions in reliance on that representation and does not itself examine the legal basis for the processing instructed by the Controller.
The Controller holds against the Operator the rights set out in this DPA, in particular the right to change its instructions, the right to choose between the return and the deletion of the data once processing ends, the right to object to a change of sub-processor, and the right to audit.
The processing lasts for the term of the agreement for the use of the Service. After it ends, the Operator deals with the data in accordance with the section “Return and deletion of data”.
Rights to use Source Material — including the rights of its authors and publishers — do not constitute processing of personal data and fall outside the scope of this DPA. They are governed by the section “Rights to content” of the Terms of Service.
2. Controller’s instructions
The Operator processes the entrusted personal data solely on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation.
The documented instructions of the Controller consist jointly of:
- the Terms of Service and this DPA,
- the configuration made by the Controller in the Service panel — in particular the Goals created, the Sources configured, the filtering criteria, the instructions given to the models, the output contract and the delivery channels designated,
- requests made through the Service’s application programming interface (API) using tokens issued to the Controller,
- statements and requests sent to the Operator’s contact address.
Configuration made in the panel is recorded in the system together with the Account from which it was made and, to that extent, constitutes the documentation of instructions. A change to the configuration is a change of instruction and takes effect prospectively.
Where the Operator is required to process data otherwise by Union law or the law of a Member State to which it is subject, the Operator shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Operator shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions. Pending clarification, the Operator may suspend the execution of that instruction.
The Operator does not use the entrusted data for its own purposes and does not train machine learning models on it. The Controller’s private work product — its Goals, Source configuration, Clusters, the Content produced and the processing records — is not made available to other Clients. Source Material fetched from publicly available Sources, by contrast, forms a shared body of material described in the section “Security measures” and in the reservation in the section “Return and deletion of data”.
3. Confidentiality
The Operator ensures that persons authorised to process the entrusted personal data have committed themselves to confidentiality — under a separate undertaking or a statutory obligation of confidentiality — and that this commitment survives the end of their cooperation with the Operator.
Access to the entrusted data is limited to persons for whom it is necessary to perform this DPA, to the extent corresponding to the tasks assigned to them. Authorisations to process are granted to named individuals and withdrawn immediately once the reason for granting them ceases.
The confidentiality obligation does not extend to information whose disclosure is required by mandatory law or by a court judgment or an authority’s decision; in such a case the Operator informs the Controller of the disclosure request before complying with it, unless the law prohibits doing so.
4. Security measures (Article 32 GDPR)
The Operator implements technical and organisational measures ensuring a level of security appropriate to the risk, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing. As at the effective date of this DPA, the following measures are in place:
- Encryption in transit — all communication with the Service, both in the panel and through the API, uses the TLS protocol.
- Tenant isolation — the data of individual Clients is separated at the database level by row level security. The application connects to the database under a non-privileged role for which the isolation rules are enforced by the database engine, and not by application code alone. That isolation covers the Controller’s private work product: its Goals, Clusters, the Content produced and the processing records. It does not cover Source Material fetched from publicly available Sources — that material forms a shared body from which several Clients build Clusters in parallel and is accessible to every Client that has configured the same Source; see the reservation in the section “Return and deletion of data”.
- Authentication — passwords are stored solely as cryptographic hashes (bcrypt) and API access tokens as SHA-256 hashes. Plaintext values are neither stored nor recoverable.
- Two-factor authentication — the Service offers an optional second authentication factor based on one-time codes (TOTP) generated in an authenticator application, together with backup codes. Irreversible operations, including deletion of the Account, require the password to be re-entered together with the second factor where it is enabled.
- Encryption of model keys at rest — API keys to model providers brought by the Controller (BYOK) are encrypted with the Fernet scheme under a key derived by PBKDF2-HMAC-SHA256 with domain separation, so that the encryption key material is cryptographically independent of the other uses of the server secret. Once saved, a key is never returned in plaintext, either in the panel or through the API.
- Backups — the database is backed up once a day using restic, retaining the five most recent snapshots. The backup repository is encrypted and its password is kept outside the production server, so that compromise of the backup storage alone does not give access to its contents.
- Access control and accountability — access to the production environment is limited to persons authorised by the Operator and takes place over key-authenticated channels. The Service records the sessions of Account users and allows the Controller to revoke a single session, all sessions, and any API token issued.
- Monitoring and restoration capability — application errors are recorded in a system operated on the Operator’s own infrastructure in Poland with personal data collection disabled. The ability to restore availability of the data promptly is provided by the daily backup cycle together with a weekly integrity check.
The Operator reviews the measures in place whenever the Service changes materially and after every established personal data breach, and may change them provided that the level of security is not reduced. The Operator carries out no periodic penetration tests and no external security audits; what is verified regularly, on a weekly cycle, is the integrity of the backups. The Operator gives notice of any material change to the security measures in the manner applicable to amendments of the Terms of Service.
5. Sub-processors
The Controller gives the Operator general written authorisation to engage further processors (sub-processors) within the meaning of the second sentence of Article 28(2) GDPR. The current list of sub-processors, together with their role, the location of processing and the basis for transferring data outside the European Economic Area, forms an annex to this DPA and is published at List of sub-processors.
The annex is incorporated by reference: a change to the list of sub-processors does not require an amendment to this DPA but follows the procedure set out below.
The Operator gives the Controller at least 30 days’ notice before adding a sub-processor or replacing an existing one — by a message sent to the email address associated with the Account and by updating the list — stating the name of the entity, the scope of the processing entrusted to it, the location of processing and the basis for any transfer outside the European Economic Area.
Within 30 days of the notice the Controller may raise a reasoned objection to the change. The Operator shall then seek to accommodate the objection, in particular by proposing an alternative technical arrangement. Where the objection cannot be accommodated without disproportionate cost or without materially limiting the functionality of the Service, the Controller may terminate the agreement for the use of the Service with effect from the day preceding the engagement of the sub-processor, free of any charge and retaining the right to export its data on the terms set out in the section “Data export and switching providers” of the Terms of Service.
The Operator imposes on every sub-processor, by contract or another legal act, data protection obligations equivalent to those set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data protection obligations, the Operator remains fully liable to the Controller for the performance of that sub-processor’s obligations.
Processing entrusted to entities established outside the European Economic Area takes place on the basis of the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 or of an adequacy decision — the basis applicable to each entity is stated in the annex.
6. Assistance to the Controller
Taking into account the nature of the processing, the Operator assists the Controller by appropriate technical and organisational measures in fulfilling the Controller’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III GDPR.
Where a data subject’s request reaches the Operator directly, the Operator does not answer it on the merits and takes no action on the entrusted data on its basis, but forwards it to the Controller without undue delay and no later than 3 working days from receipt.
At the Controller’s request the Operator provides information about the entrusted data relating to a designated person and rectifies, erases or restricts the processing of that data — without undue delay and no later than 7 days from receipt of the request — so that the Controller can meet the time limits under Article 12(3) GDPR. Such requests are to be sent to the Operator’s contact address.
Independently of the above, the Controller may itself, in the Service panel, remove an individual item of Source Material from a Cluster, stop further fetching from a designated Source, take a Goal out of further processing, and delete the entire Account. The effects of deleting the Account are described in the section “Return and deletion of data”.
The Operator assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR — security of processing, notification of breaches, data protection impact assessment and prior consultation — taking into account the nature of the processing and the information available to it. That assistance includes in particular providing information about the security measures in place, the locations of processing and the sub-processors engaged.
7. Personal data breaches
The Operator notifies the Controller of a breach of the security of the entrusted personal data without undue delay and no later than 24 hours after becoming aware of it, by a message sent to the email address associated with the Account. That period is set so as to allow the Controller to meet its own 72-hour deadline under Article 33(1) GDPR.
The notification contains at least, to the extent known to the Operator:
- a description of the nature of the breach, including the categories and approximate number of data subjects concerned and the categories and approximate number of data records concerned,
- the name and contact details of a person from whom more information can be obtained,
- a description of the likely consequences of the breach,
- a description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
Where it is not possible to provide the full information within that period, the Operator provides it in phases as it is established, without undue delay.
Notification of a breach to the supervisory authority and communication to the data subjects are made by the Controller. The Operator does not make them on the Controller’s behalf unless the parties agree otherwise in writing. The Operator documents breaches affecting the entrusted data and makes that documentation available to the Controller on request.
8. Return and deletion of data
After the provision of the Service ends, the Operator — at the Controller’s choice — deletes or returns the entrusted personal data and deletes existing copies of it, unless Union law or the law of a Member State requires further storage. Absent a different decision by the Controller, the Operator deletes the data.
Return of the data takes place through the export procedure described in the section “Data export and switching providers” of the Terms of Service, in a commonly used, structured and machine-readable format.
After the agreement is terminated, Account data remains available for download for 30 days unless the Controller requests its earlier deletion. Deleting the Account in the Service panel is carried out immediately and irreversibly — it covers Goals, Source configuration, Clusters, the Content produced, processing records, sessions and API access tokens — so any export should be performed beforehand.
Source Material is subject to automatic expiry: after the lifespan set for the Goal has elapsed, and once the limit on the number of items stored for a given Source is exceeded. Expiry removes the vector representations of the material and excludes it from further processing.
Data deleted from the production environment remains in backups until its retention cycle expires, that cycle covering the five most recent daily snapshots, that is approximately five days. During that time it is protected by the measures described in the section “Security measures” and is not used for any operation other than restoring the system after a failure.
Separately from the backups, the content of model requests and responses remains in the observability logs described in the section “Security measures”. Until a retention period for those logs is determined they are not deleted automatically after a fixed period; the Operator deletes them at the Controller’s request sent to its contact address, within the period stated in the section “Assistance to the Controller”.
At the Controller’s request the Operator confirms deletion of the data by a written or electronic statement.
9. Audits and demonstrating compliance
The Operator makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it.
That obligation is discharged in the first instance by providing information: answering a security questionnaire and supplying a description of the technical and organisational measures in place, the current list of sub-processors and information about the locations of processing. The Operator responds without undue delay and no later than 30 days from receipt of the request.
Where the information provided in that manner is not sufficient, the Controller may conduct an audit on site or remotely, no more than once in any 12-month period, on at least 30 days’ prior notice, on the Operator’s working days and hours, and in a manner that does not unduly disrupt the ongoing provision of the Service. The frequency limit does not apply where a breach of the security of the entrusted data has occurred or where a supervisory authority so requires.
The auditor is bound by confidentiality and may not be a competitor of the Operator. An audit may not extend to the data of other Clients of the Operator or to information constituting a third party’s trade secret. The Controller bears the auditor’s costs; the Operator may claim reimbursement of its reasonable own costs where the audit goes beyond the activities described in the second paragraph, unless the audit reveals a breach of this DPA on the Operator’s part.
The Operator promptly informs the Controller of any inspection or request by a supervisory authority concerning the entrusted data, unless prohibited by law from doing so.
10. The Controller’s own model key (BYOK)
The Service allows the Controller to connect its own API key to a model provider of its choice instead of using the Operator’s default configuration.
Where the Controller uses its own key, requests containing the entrusted data are routed to the provider designated by the Controller and billed to the Controller’s account. The relationship with that provider is the Controller’s relationship, not the Operator’s: it is the Controller that is party to the contract with the provider, that is responsible for concluding any required data processing agreement with it and for providing a basis for transfers outside the European Economic Area, and that holds the rights arising from that relationship. Such a provider is not a sub-processor of the Operator and is not listed in the annex referred to in the section “Sub-processors”.
In that configuration the Operator’s role is confined to transmitting the request and receiving the response using the Controller’s key, in accordance with the instruction expressed through the Goal configuration. The Operator is not responsible for how the provider designated by the Controller processes the data, nor for the terms on which that provider supplies its services.
A key brought by the Controller is protected by the measures described in the section “Security measures” and may be removed by the Controller at any time in the Service panel. Removing the key reverts processing to the Operator’s default configuration, in which the model providers are sub-processors of the Operator listed in the annex.