This Data Processing Agreement ("DPA") forms part of the Terms of Service between Deus XAI sp. z o.o., registered office at Rybaki 22/14, 61-884 Poznań, Poland, KRS 0001204126 ("Processor", "we"), and the customer agreeing to the Terms of Service ("Controller", "you"), together the "Parties". It governs the processing of personal data that the Processor carries out on behalf of the Controller in connection with the CDM Creator service (the "Service").
Where there is a conflict between this DPA and the Terms of Service in relation to the processing of personal data, this DPA prevails.
1. Definitions
1.1. "Data Protection Law" means all applicable laws on the protection of personal data, including the EU GDPR, the UK GDPR, the Data Protection Act 2018 (UK), and the Polish Personal Data Protection Act.
1.2. Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
1.3. "Customer Personal Data" means personal data processed by the Processor on behalf of the Controller under the Service, as described in Annex 1.
2. Roles and scope
2.1. The Controller is the controller and the Processor is the processor in respect of Customer Personal Data.
2.2. The Controller determines the purposes and means of processing and is responsible for the lawfulness of the processing, including for having a valid legal basis and for providing required information and notices to data subjects.
2.3. The Processor processes Customer Personal Data only for the purpose of providing the Service and as set out in this DPA.
3. Processor obligations (Article 28(3) GDPR)
The Processor shall:
3.1. Documented instructions. Process Customer Personal Data only on the Controller's documented instructions (including the Terms of Service, this DPA and use of the Service), including regarding international transfers, unless required to process by law, in which case the Processor will inform the Controller (unless the law prohibits it). The Processor shall inform the Controller if, in its opinion, an instruction infringes Data Protection Law.
3.2. Confidentiality. Ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations.
3.3. Security. Implement appropriate technical and organisational measures under Article 32 GDPR, as described in Annex 3.
3.4. Sub-processing. Engage sub-processors only in accordance with clause 4.
3.5. Assistance — data subject rights. Taking into account the nature of the processing, assist the Controller by appropriate measures, insofar as possible, to respond to requests to exercise data subject rights.
3.6. Assistance — compliance. Assist the Controller in ensuring compliance with its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and information available to the Processor.
3.7. Breach notification. Notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide reasonable information to help the Controller meet its own breach-notification obligations.
3.8. Deletion or return. At the Controller's choice, delete or return all Customer Personal Data after the end of the provision of the Service, and delete existing copies unless storage is required by law.
3.9. Audits. Make available information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, frequency limits and the Processor's security policies. The Processor may satisfy audit obligations by providing relevant certifications or third-party audit reports where available.
4. Sub-processors
4.1. The Controller provides general authorisation for the Processor to engage sub-processors to provide the Service. Current sub-processors are listed in Annex 2.
4.2. The Processor shall impose on each sub-processor data protection obligations substantially equivalent to those in this DPA, and remains liable to the Controller for the performance of each sub-processor's obligations.
4.3. The Processor shall inform the Controller of intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data-protection grounds within a reasonable period. If the Parties cannot resolve a reasonable objection, the Controller may terminate the affected part of the Service.
5. International transfers
5.1. The Processor (established in the EEA/Poland) and its sub-processors may transfer Customer Personal Data outside the EEA and the UK where necessary to provide the Service.
5.2. Any such transfer shall be subject to appropriate safeguards under Data Protection Law, such as the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Agreement/Addendum, or an adequacy/data-bridge decision where available. Transfers from the UK to the EEA are permitted on the basis of the UK's adequacy findings for the EEA.
6. Liability
6.1. Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, to the extent permitted by Data Protection Law.
7. Duration
7.1. This DPA takes effect on acceptance of the Terms of Service and continues while the Processor processes Customer Personal Data, after which clause 3.8 applies.
8. Governing law, precedence of mandatory law and severability
8.1. This DPA is governed by the laws of the Republic of Poland and subject to the jurisdiction clause in the Terms of Service, without prejudice to mandatory rights of data subjects and the powers of supervisory authorities under Data Protection Law.
8.2. If any provision of this DPA conflicts with a mandatory provision of applicable Data Protection Law or other applicable law, the mandatory provision of law shall apply in place of the conflicting provision to the extent of the conflict, and all remaining provisions of this DPA shall continue in full force and effect.
8.3. If any provision is held invalid or unenforceable, the remaining provisions remain in force, and the invalid provision shall be applied with the minimum modification necessary to make it valid while giving effect to its original intent and to Data Protection Law.
Annex 1 — Details of processing
- Subject matter: provision of the CDM Creator document-generation and management service.
- Duration: for the term of the Service and as required to fulfil the Terms.
- Nature and purpose: hosting, storage, generation, editing, organisation and making available of Health & Safety and compliance documentation; management of contacts and projects; and (where available) collection of electronic confirmations/signatures.
- Categories of data subjects: the Controller's contacts, clients, site personnel and key personnel (e.g. site managers, first aiders, fire marshals), subcontractors, workers, and — where the feature is used — document signatories.
- Types of personal data: names, business/role information, email addresses, telephone numbers, project/site associations, and — where applicable — electronic signature/confirmation data and related metadata. The Controller must not enter special-category data unless strictly necessary and lawful, and must inform the Processor if it intends to do so.
- Frequency: continuous, for the duration of the Service.
Annex 2 — Approved sub-processors
The Controller provides general authorisation for the Processor to engage the sub-processors and categories of sub-processor listed below to provide the Service. A current, itemised list (including the identity, location and transfer safeguard of each specific sub-processor) is available on request by contacting info@cdmcreator.co.uk. The Processor will inform the Controller of intended changes concerning the addition or replacement of sub-processors in accordance with clause 4.3.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Anthropic | AI document generation | USA | UK IDTA / SCCs and supplementary measures |
| Stripe | Payment processing | EEA / USA | UK IDTA / SCCs / applicable UK data bridge |
| Cloud hosting provider | Hosting and infrastructure | Available on request | Within UK/EEA, or UK IDTA / SCCs where outside |
| Transactional email provider | Service and account emails | Available on request | Within UK/EEA, or UK IDTA / SCCs where outside |
| SDS / COSHH data provider | Safety-data-sheet content | Available on request | Within UK/EEA, or UK IDTA / SCCs where outside |
| Address lookup provider | Address autocomplete | Available on request | Within UK/EEA, or UK IDTA / SCCs where outside |
| Company-register verification | Business/company verification | UK | Within the UK |
| E-signature provider (when the feature is live) | Electronic signatures | Available on request | Within UK/EEA, or UK IDTA / SCCs where outside |
Annex 3 — Technical and organisational security measures
The Processor implements and maintains appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, including:
- Encryption of Customer Personal Data in transit (TLS) and, where appropriate, at rest.
- Access controls, role-based permissions and authentication, applying the principle of least privilege.
- Secure storage of credentials using industry-standard password hashing, and enforcement of a strong password policy.
- Network security, firewalls, and monitoring and logging of access to systems that process Customer Personal Data.
- Regular backups and tested procedures for restoring the availability of and access to Customer Personal Data in a timely manner after an incident.
- Vulnerability management, including the timely application of security patches and updates.
- Confidentiality undertakings and data-protection awareness for personnel authorised to process Customer Personal Data.
- A documented process for detecting, investigating, managing and reporting personal data breaches.
- Engagement of reputable sub-processors that provide appropriate security guarantees, including physical and environmental security at their hosting facilities.
- Measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
- Data minimisation and, where appropriate, pseudonymisation.
- Periodic review and, where necessary, updating of these measures.
This DPA is entered into by the Controller on accepting the Terms of Service, and by the Processor as operator of the Service.