Data Processing Agreement
The Article 28 agreement covering personal data we process on your behalf. We sign it on request, or work from your own template.
1 · What this is
This Data Processing Agreement forms part of the Terms of Service between Sociaro Baltic OÜ ("processor") and you ("controller"), and applies whenever we process personal data on your behalf in providing the gateway. Where it conflicts with the Terms on a data protection matter, this agreement prevails.
We sign this on request. Write to dpo@sociaro.com and we will send a copy for signature; a countersigned copy comes back to you.
2 · Roles
You are the controller for personal data contained in requests you send through the gateway and for the data of your own end users. We are the processor for that data, and process it only on your documented instructions — your use of the service being the primary instruction.
For your own account and billing data we are the controller, and the Privacy Policy governs it.
3 · Subject matter and scope
- Subject matter
- Provision of API access to AI models through the Sociaro gateway
- Duration
- For as long as your account is active, plus the retention periods in the Privacy Policy
- Nature
- Transmission to the model provider you address, metering, billing, storage of generated assets
- Purpose
- Delivering the output you requested and billing you for it
- Data subjects
- Your personnel, and any individuals whose data you include in a request
- Categories
- Account identifiers; request metadata; whatever personal data you choose to place in a request or in uploaded media
Request content is not stored by us. It is transmitted to the provider and the response is returned to you. What we retain is metadata, described in the Privacy Policy. This limits, but does not eliminate, processing of whatever personal data you choose to send — the transmission itself is processing.
3a · Your obligations and rights as controller
- You determine the purposes and means of the processing, and you are responsible for having a lawful basis for the personal data you send through the gateway.
- You are responsible for the content of your requests, including for not sending special-category data under Article 9 unless you have established a lawful basis for doing so and have assessed the transfer implications.
- You give and withdraw instructions, may audit us as set out below, and may require deletion or return of the data at the end of the service.
- You are responsible for informing your own end users as their controller, including about the sub-processors listed here.
4 · Our obligations
- We process personal data only on your instructions, unless EU or member state law requires otherwise — in which case we tell you first, unless that law forbids it.
- Everyone we authorise to process your data is bound by confidentiality.
- We implement the technical and organisational measures required by Article 32, described on the security page.
- We assist you, so far as we reasonably can, with data subject requests, impact assessments and prior consultations.
- On termination we delete or return personal data at your choice, except where law requires retention.
- We make available the information needed to demonstrate compliance with Article 28 and allow audits as set out below.
5 · Sub-processors
You give general authorisation for us to engage the sub-processors listed on the sub-processors page, which identifies each one, what it does and what data it receives.
We give at least 30 days' notice before adding or replacing a sub-processor. You may object within that period on reasonable data-protection grounds; we will then work with you on an alternative, and failing that you may terminate the affected part of the service without penalty.
Each sub-processor is bound by obligations no less protective than these, and we remain liable to you for their performance.
6 · International transfers
The gateway, its database and all accounting run in the EU. Whether request content leaves the EEA depends on the inference mode you choose: in EU-only mode it does not, and in global mode it may, because the provider you address may operate outside the EEA.
Where a transfer outside the EEA occurs, it takes place under an adequacy decision, the Standard Contractual Clauses, or another Chapter V mechanism as applicable to the provider concerned. Set your account to EU-only if you need transfers excluded entirely.
7 · Security and breach
Our measures are described on the security page and form Annex II to this agreement. We will notify you of a personal data breach affecting your data without undue delay after becoming aware of it, and in any event within 48 hours, with the information available at that point and updates as the picture develops.
8 · Audit
We will answer your reasonable questions and complete security questionnaires. Where that is not sufficient for your obligations, you may audit us — on reasonable notice, no more than once a year unless a regulator or an incident requires otherwise, during business hours, and without disrupting other customers. You bear your own audit costs.
9 · Liability
The liability provisions of the Terms of Service apply to this agreement, except where the GDPR provides otherwise for claims by data subjects or regulators.
10 · Changes
Where the law changes or supervisory guidance requires it, we may update this agreement on 30 days' notice. If a change materially reduces your protections you may terminate before it takes effect.
Need it signed? Write to dpo@sociaro.com with your entity details. We can sign this document as it stands, or work from your own DPA template.
Sociaro Baltic OÜ · Registry code 16252815 · Karu tn 14-8, Kesklinna linnaosa, 10120 Tallinn, Estonia