Legal · DPA

Data Processing Agreement

Last updated · 30 September 2026 Entity · Sociaro Baltic OÜ Contact · dpo@sociaro.com

The Article 28 agreement covering personal data we process on your behalf. We sign it on request, or work from your own template.

1 · What this is

This Data Processing Agreement forms part of the Terms of Service between Sociaro Baltic OÜ ("processor") and you ("controller"), and applies whenever we process personal data on your behalf in providing the gateway. Where it conflicts with the Terms on a data protection matter, this agreement prevails.

We sign this on request. Write to dpo@sociaro.com and we will send a copy for signature; a countersigned copy comes back to you.

2 · Roles

You are the controller for personal data contained in requests you send through the gateway and for the data of your own end users. We are the processor for that data, and process it only on your documented instructions — your use of the service being the primary instruction.

For your own account and billing data we are the controller, and the Privacy Policy governs it.

3 · Subject matter and scope

Subject matter
Provision of API access to AI models through the Sociaro gateway
Duration
For as long as your account is active, plus the retention periods in the Privacy Policy
Nature
Transmission to the model provider you address, metering, billing, storage of generated assets
Purpose
Delivering the output you requested and billing you for it
Data subjects
Your personnel, and any individuals whose data you include in a request
Categories
Account identifiers; request metadata; whatever personal data you choose to place in a request or in uploaded media

Request content is not stored by us. It is transmitted to the provider and the response is returned to you. What we retain is metadata, described in the Privacy Policy. This limits, but does not eliminate, processing of whatever personal data you choose to send — the transmission itself is processing.

3a · Your obligations and rights as controller

4 · Our obligations

5 · Sub-processors

You give general authorisation for us to engage the sub-processors listed on the sub-processors page, which identifies each one, what it does and what data it receives.

We give at least 30 days' notice before adding or replacing a sub-processor. You may object within that period on reasonable data-protection grounds; we will then work with you on an alternative, and failing that you may terminate the affected part of the service without penalty.

Each sub-processor is bound by obligations no less protective than these, and we remain liable to you for their performance.

6 · International transfers

The gateway, its database and all accounting run in the EU. Whether request content leaves the EEA depends on the inference mode you choose: in EU-only mode it does not, and in global mode it may, because the provider you address may operate outside the EEA.

Where a transfer outside the EEA occurs, it takes place under an adequacy decision, the Standard Contractual Clauses, or another Chapter V mechanism as applicable to the provider concerned. Set your account to EU-only if you need transfers excluded entirely.

7 · Security and breach

Our measures are described on the security page and form Annex II to this agreement. We will notify you of a personal data breach affecting your data without undue delay after becoming aware of it, and in any event within 48 hours, with the information available at that point and updates as the picture develops.

8 · Audit

We will answer your reasonable questions and complete security questionnaires. Where that is not sufficient for your obligations, you may audit us — on reasonable notice, no more than once a year unless a regulator or an incident requires otherwise, during business hours, and without disrupting other customers. You bear your own audit costs.

9 · Liability

The liability provisions of the Terms of Service apply to this agreement, except where the GDPR provides otherwise for claims by data subjects or regulators.

10 · Changes

Where the law changes or supervisory guidance requires it, we may update this agreement on 30 days' notice. If a change materially reduces your protections you may terminate before it takes effect.

Need it signed? Write to dpo@sociaro.com with your entity details. We can sign this document as it stands, or work from your own DPA template.