Data Processing Agreement (DPA)
Last updated: July 2026
This page summarises, in plain language, the Data Processing Agreement (DPA) that governs how PrivateAI24 processes personal data on your behalf under Art. 28 of the GDPR (Regulation (EU) 2016/679). The integral DPA is signed with every plan and is also available on request.
1. Roles, subject matter and duration
You (the customer) act as the data controller; PrivateAI24, a service operated by [LEGAL ENTITY NAME], acts as the data processor. We process personal data solely to provide the contracted service and only on your documented instructions. The processing lasts for the duration of the service contract and any agreed wind-down period for the return or deletion of data.
2. Nature and purpose of the processing
The nature of the processing is the hosting and operation of a private AI environment (storage, computation, transmission and related support). Its purpose is limited to delivering that service. We do not use your data to train models and we do not process it for our own purposes.
3. Categories of data and data subjects
The specific categories are determined by the content you choose to process and are set out in full in the DPA. Typically:
- Data subjects: your employees, clients, contacts and any individuals referenced in the material you submit.
- Categories of data: identification and contact data, professional and business data, and any content contained in the documents, prompts and files you process. Special categories are processed only where your use case requires it and under your instructions.
4. Our obligations as processor
- Confidentiality: persons authorised to process the data are bound by an obligation of confidentiality.
- Security (Art. 32): appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, access controls, isolation of environments and logging.
- Assistance to the controller: we help you respond to data-subject requests (access, rectification, erasure, portability) and to meet your obligations under Art. 32–36 GDPR.
- Breach notification: we notify you without undue delay after becoming aware of a personal-data breach, with the information you need to fulfil your own reporting duties.
5. Sub-processors
You grant a general authorisation to engage sub-processors, listed by category on our Sub-processors page. We impose the same data-protection obligations on each sub-processor and remain responsible for their performance. We give advance notice of any intended addition or replacement so that you may object.
6. Data location and international transfers
By default, your data is processed and stored within the EU. If you choose the optional Confidential configuration, processing may take place outside the EU on confidential-computing infrastructure; in that case transfers are covered by the European Commission’s Standard Contractual Clauses (SCC) together with appropriate supplementary measures. You choose the option that fits your compliance requirements.
7. Audit
We make available the information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, under reasonable notice and confidentiality terms.
8. Return and deletion of data
On termination of the service, and at your choice, we return or delete all personal data and existing copies, unless retention is required by law. In the on-premise configuration, data remains on your own infrastructure.
The integral DPA is signed with every plan and available on request. To receive the text for signature, write to us at info@privateai24.com.