Skip to content

GDPR

Data Processing Addendum

This Data Processing Addendum, also known as an Auftragsverarbeitungsvertrag, describes how customer personal data is processed for the exdata service.

1. Parties And Order Of Precedence

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer using the exdata product (“Customer”) and Outer Platforms Limited, with its address at Centris Business Gateway, Level 4/W, Triq Is-Salib Tal-Imriehel, Zone 3, Central Business District, Birkirkara, CBD 3020, Malta (“Provider”). The exdata product and related services are referred to in this DPA as the “Service.”

If this DPA conflicts with the main agreement, this DPA controls for the processing of Customer Personal Data. If an order form contains stricter data protection commitments, the stricter commitment applies for that order.

2. Roles

For Customer Personal Data contained in uploaded documents, extracted text, normalized fields, previews, webhook payloads, and customer-configured processing metadata, Customer is the controller and the Provider is the processor.

For account administration, billing, fraud prevention, Service security, support records, legal compliance, and product operations, the Provider may act as an independent controller as described in the Privacy Policy.

3. Processing Details

4. Customer Instructions

Customer instructs the Provider to process Customer Personal Data to provide the Service, comply with the agreement, follow account settings, perform support and security work, satisfy documented customer requests, and make transfers needed to provide the Service. The Provider will not process Customer Personal Data for unrelated purposes unless required by law.

If the Provider believes an instruction infringes applicable data protection law, the Provider will inform Customer unless prohibited by law.

5. Confidentiality And Personnel

The Provider restricts access to Customer Personal Data to personnel and service providers who need access for the Service, support, security, billing, or legal purposes. Personnel with access are bound by confidentiality obligations or equivalent professional duties.

6. Security Measures

The Provider implements technical and organizational measures designed to protect Customer Personal Data against unauthorized access, accidental loss, alteration, disclosure, or destruction. The current measures are listed in the Technical and Organizational Measures.

Customer is responsible for configuring account roles, API tokens, webhook endpoints, retention settings, and downstream systems in a secure manner.

7. Subprocessors

Customer gives the Provider general authorization to use subprocessors for the Service. Current subprocessors are listed on the Subprocessor List. The Provider will require subprocessors to protect Customer Personal Data with data protection obligations that are materially consistent with this DPA.

The Provider remains responsible to Customer for subprocessor obligations where required by applicable data protection law. When the Provider adds or replaces a subprocessor for production processing, the Provider will update the Subprocessor List or provide another reasonable notice channel. Customer may object on reasonable data protection grounds. If the parties cannot resolve the objection, Customer may stop using the affected Service feature or terminate the affected order where required by applicable law.

8. Assistance

Taking into account the nature of processing and the information available to the Provider, the Provider will reasonably assist Customer with data subject requests, security obligations, personal data breach notifications, data protection impact assessments, and regulator consultations where required by applicable data protection law.

9. Personal Data Breach

The Provider will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available to the Provider, such as affected systems, likely categories of data, known impact, mitigation steps, and recommended customer actions.

10. International Transfers

Where Customer Personal Data is transferred to a country that requires a transfer mechanism, the Provider will use appropriate safeguards such as adequacy decisions, the EU Standard Contractual Clauses or equivalent transfer terms, subprocessor transfer commitments, and supplementary measures where applicable.

11. Return And Deletion

During the account term, Customer may export API responses and delete documents through available Service controls. After termination or upon written request, the Provider will delete or return Customer Personal Data unless retention is required for legal, billing, audit, security, backup, or dispute purposes.

12. Audit Information

The Provider will make available information reasonably necessary to demonstrate compliance with this DPA, which may include these TOMs, the Subprocessor List, security documentation, policy summaries, incident summaries, and other relevant compliance information. Audits must be reasonable, scheduled in advance, limited to relevant systems and records, protect other customers and confidential information, and avoid disrupting the Service.