Data Processing Agreement (AVV)
Our standard data processing agreement under Art. 28 GDPR. It names every sub-processor and the region it processes in, commits that client data is never used to train any model, and records the input, model version and output behind every automated decision so you can reconstruct how a record reached its current state. Read it here, do not ask for it.
DATA PROCESSING AGREEMENT (Auftragsverarbeitungsvertrag under Art. 28 GDPR)
between
[Client legal name and address — completed at signature] — the "Client", acting as controller —
and
SOCIALY LTD, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, registered in England and Wales under number 17184561, business address Batthyany utca 67, 1015 Budapest, Hungary, trading as logicllab — the "Processor" —
1 SUBJECT MATTER AND DURATION
1.1 This Agreement governs the processing of personal data carried out by the Processor on behalf of the Client in the course of the services agreed between the parties (the "Services Agreement").
1.2 The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
1.3 This Agreement takes effect on the effective date of the Services Agreement and ends when the Services Agreement ends, subject to Section 11.
1.4 In matters of data protection, this Agreement prevails over the Services Agreement and over any general terms of either party.
1.5 "GDPR" means Regulation (EU) 2016/679. Where the Processor's own processing is additionally subject to the United Kingdom General Data Protection Regulation and the Data Protection Act 2018, the Processor complies with both, and references in this Agreement to obligations of a processor are to be read accordingly.
2 INSTRUCTIONS
2.1 The Processor processes personal data only on the documented instructions of the Client. The Services Agreement and this Agreement, including their annexes, constitute the Client's initial documented instructions. Further instructions must be given in text form to privacy@logicllab.com and are documented by both parties.
2.2 The Processor does not process personal data for its own purposes and does not determine the purposes or means of the processing. If the Processor were to determine the purposes and means of any processing, it would be considered a controller in respect of that processing under Art. 28 (10) GDPR.
2.3 Where the Processor is required by Union, Member State or United Kingdom law to process personal data beyond the Client's instructions, it informs the Client of that requirement before processing, unless the law prohibits it.
2.4 The Processor informs the Client without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law. The Processor may suspend execution of that instruction until the Client confirms or amends it.
2.5 The Processor does not transfer personal data to any country outside the scope permitted by Section 12 without the Client's prior instruction.
3 OBLIGATIONS AND RIGHTS OF THE CLIENT
3.1 The Client is the controller within the meaning of Art. 4 (7) GDPR and is responsible for the lawfulness of the processing carried out under this Agreement and for the lawfulness of its instructions.
3.2 The Client is responsible for establishing a legal basis for the processing, for informing data subjects under Art. 13 and 14 GDPR, for handling data subject requests, and for assessing whether a data protection impact assessment under Art. 35 GDPR is required.
3.3 Where the processing involves personal data of the Client's employees or contractors, the Client is responsible for compliance with applicable employment data protection law, including §26 BDSG, and for concluding any works agreement required under §87 (1) no. 6 BetrVG before the relevant processing begins.
3.4 The Client names in text form the persons authorised to issue instructions on its behalf, and keeps that information current.
3.5 The Client has the right to issue instructions on the processing at any time within the scope of the Services Agreement, and the right to verify the Processor's compliance under Section 10.
3.6 The Client informs the Processor without undue delay if it discovers an error or irregularity in the Processor's performance of this Agreement.
4 CONFIDENTIALITY
4.1 The Processor grants access to personal data only to persons who need it to perform the Services and who are bound by a written confidentiality undertaking that survives the end of their engagement.
4.2 Every such person receives instruction on the requirements of this Agreement and on the applicable data protection rules before being granted access, and at least annually thereafter.
4.3 The Processor maintains a current record of persons with access and revokes access within 24 hours of a person ceasing to require it.
5 SECURITY OF PROCESSING
5.1 The Processor implements the technical and organisational measures set out in Annex II, which are appropriate to the risk within the meaning of Art. 32 GDPR.
5.2 The Processor may change individual measures provided the level of protection is not reduced. Material changes are documented and made available to the Client on request.
5.3 The Processor reviews the measures in Annex II at least once every twelve months and after any personal data breach.
6 SUB-PROCESSORS
6.1 The Client gives the Processor general written authorisation to engage sub-processors. The sub-processors engaged at the date of this Agreement are listed in Annex III.
6.2 The Processor informs the Client in text form of any intended addition or replacement of a sub-processor at least 30 days in advance. The Client may object on reasonable data protection grounds within 14 days of being informed.
6.3 If the Client objects and the parties cannot agree on a solution within a further 30 days, the Client may terminate the affected part of the Services Agreement without penalty, with effect from the date the change would take place.
6.4 The Processor imposes on every sub-processor, by written contract, data protection obligations no less protective than those in this Agreement, and remains fully liable to the Client for the sub-processor's performance.
6.5 Providers of pure telecommunications services, postal and transport services, and maintenance of equipment on which no access to personal data takes place are not sub-processors within the meaning of this Section.
7 MODELS AND AI SERVICES
7.1 Where the Services involve automated processing using machine learning models operated by third parties, those providers are sub-processors and are named in Annex III, together with the region in which inference takes place and the retention period applicable to submitted data.
7.2 The Processor contracts with each such provider on terms under which Client data submitted through the provider's programming interface is not used to train, fine-tune or otherwise improve that provider's models.
7.3 Retention of submitted data by each provider is stated in Annex III. Where a provider offers a zero-retention or reduced-retention option for the models and interfaces actually used, the Processor enables it. Where the provider does not offer it, or excludes it for a particular model, the provider's standard retention applies and is stated in Annex III.
7.4 Retention periods stated in Annex III are those the providers undertake to apply. Where a provider is compelled by a court or authority to retain data beyond that period, the Processor informs the Client without undue delay once it becomes aware.
7.5 The Processor does not enter Client personal data into consumer-facing chat interfaces, browser extensions, developer consoles, or any tool not listed in Annex III.
7.6 Inputs and outputs of automated processing that contain personal data are stored under the measures in Annex II and deleted on the schedule in Section 11.
7.7 For each automated decision on a record, the Processor retains a log of the input, the rule or model version applied, and the output, so that the Client can reconstruct how the record reached its current state.
8 ASSISTANCE TO THE CLIENT
8.1 Taking into account the nature of the processing, the Processor assists the Client by appropriate technical and organisational measures in fulfilling the Client's obligation to respond to requests from data subjects under Chapter III GDPR.
8.2 If a data subject contacts the Processor directly, the Processor does not respond on the merits and forwards the request to the Client without undue delay.
8.3 The Processor assists the Client in complying with Art. 32 to 36 GDPR, including data protection impact assessments and prior consultation, taking into account the information available to it.
8.4 Assistance under this Section is included in the fees under the Services Agreement to the extent it is proportionate to the nature of the processing. Assistance requiring substantial engineering effort beyond that is charged at the Processor's standard rates, agreed in advance.
9 PERSONAL DATA BREACH
9.1 The Processor notifies the Client of any personal data breach affecting Client personal data without undue delay, and in any event within 48 hours of becoming aware of it.
9.2 The notification states, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information not available at the time is supplied as it becomes available.
9.3 The Processor takes immediate steps to contain the breach and to secure the data, documents all facts relating to it, and provides the Client with the documentation needed for the Client's own notifications under Art. 33 and 34 GDPR.
9.4 The Processor does not notify a supervisory authority or data subjects on its own initiative unless required by law to do so.
10 AUDITS AND EVIDENCE
10.1 The Processor makes available to the Client all information necessary to demonstrate compliance with Art. 28 GDPR, including the current Annex II, its record of processing activities for the Client's processing, and its sub-processor contracts in redacted form.
10.2 The Client, or an auditor mandated by the Client, may carry out audits and inspections of the processing under this Agreement. The Processor allows for and contributes to them.
10.3 An audit may be conducted remotely, by written questionnaire or video session at a time agreed between the parties, or on site.
10.4 On-site inspections take place during normal business hours, on at least 30 days' written notice, no more than once in any twelve-month period, subject to a confidentiality undertaking by the Client and any auditor, and without access to other clients' data or systems.
10.5 The limits in Section 10.4 do not apply where there are concrete indications of a personal data breach or of a material failure to comply with this Agreement, or where a supervisory authority requires an inspection.
10.6 Each party bears its own costs of an audit.
11 RETURN AND DELETION
11.1 On termination of the Services Agreement, the Processor, at the Client's choice, returns all Client personal data in a commonly used machine-readable format or deletes it, together with all existing copies.
11.2 The Client makes that choice within 30 days of termination. If the Client does not, the Processor deletes the data.
11.3 Deletion from live systems is completed within 30 days of the Client's instruction. Data held in encrypted backups is deleted as those backups expire under the rotation cycle, and in any event within 90 days.
11.4 The Processor confirms deletion in text form on request.
11.5 Sections 11.1 to 11.3 do not apply to data the Processor is required by Union, Member State or United Kingdom law to retain. Such data remains subject to this Agreement until it is deleted.
12 INTERNATIONAL TRANSFERS
12.1 The Processor carries out the processing under this Agreement from its business address in Budapest, Hungary. Personal data processed under this Agreement remains within the European Economic Area except as stated in Annex III.
12.2 The Processor is incorporated in the United Kingdom. On 19 December 2025 the European Commission renewed its adequacy decisions for the United Kingdom for six years, until 27 December 2031, subject to a review after four years. Transfers of personal data from the European Economic Area to the Processor are covered by those decisions.
12.3 Should the adequacy decisions be suspended, repealed or annulled, the parties will without undue delay conclude the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914, Module Two or Module Three as applicable), which then form part of this Agreement without further action. The Processor will carry out and share a transfer impact assessment on request.
12.4 Onward transfers by the Processor to sub-processors outside the European Economic Area and the United Kingdom take place only on the legal basis stated for that sub-processor in Annex III. Where such a transfer is made from the United Kingdom, it is made under the Information Commissioner's International Data Transfer Agreement, or under the standard contractual clauses together with the UK International Data Transfer Addendum.
13 LIABILITY
13.1 Art. 82 GDPR applies to liability towards data subjects.
13.2 As between the parties, liability is governed by the Services Agreement. Any limitation of liability in the Services Agreement does not limit either party's liability towards data subjects or towards a supervisory authority.
14 FINAL PROVISIONS
14.1 This Agreement is governed by the law of the Federal Republic of Germany, excluding its conflict-of-law rules. No exclusive place of jurisdiction is agreed; the statutory rules apply.
14.2 Amendments must be in text form. This also applies to any waiver of the text-form requirement.
14.3 If any provision is or becomes invalid, the validity of the remainder is unaffected. The parties will replace the invalid provision with one that comes closest to its economic purpose.
[Place, date][Place, date]
______________________________________________
For the ClientFor the Processor
ANNEX I — Description of the processing
1 SUBJECT MATTER
Migration, cleansing, normalisation, enrichment and matching of the Client's master and transactional records; design, operation and monitoring of automated and agent-based processing of those records; handling of records the automated processing cannot decide; and support, diagnosis and correction of faults in the systems built for the Client.
2 NATURE AND PURPOSE OF THE PROCESSING
Collection, structuring, storage, alteration, retrieval, comparison, automated evaluation, transmission to systems designated by the Client, restriction and erasure — carried out solely to deliver the Services and for no other purpose.
3 CATEGORIES OF DATA SUBJECTS
(a) Employees and contractors of the Client whose details appear in the systems in scope, as users of those systems or as named contacts on records.
(b) Contact persons at the Client's suppliers, vendors, distributors and subcontractors — buyers, sales representatives, technical and quality contacts — appearing in purchase orders, quotations, order confirmations, part specifications, supplier master data and related correspondence.
4 TYPES OF PERSONAL DATA
Name and job title
Business email address and business telephone number
Employer or organisation and, where recorded, department
System identifiers: user ID, role and permission assignment, audit-log entries
Sender and recipient details appearing within processed business documents
5 DATA NOT WITHIN SCOPE
The Processor does not process on the Client's behalf, and the Client will not make available:
special categories of personal data under Art. 9 GDPR
personal data relating to criminal convictions and offences under Art. 10 GDPR
personal data of children
personal data of the Client's consumer end-customers
payment card data, bank credentials or government identification numbers
If such data is found within material supplied by the Client, the Processor informs the Client without undue delay and does not process it further until the Client instructs otherwise.
6 NOTE ON THE PROPORTION OF PERSONAL DATA
The substantial majority of the material processed under the Services — part numbers, descriptions, technical specifications, catalogue structures, order and stock records, prices and terms — is not personal data. Personal data occurs within it incidentally, as the contact persons attached to those records. The measures in Annex II are applied to the material as a whole and therefore to the personal data within it.
7 DURATION
For the term of the Services Agreement, followed by the deletion procedure in Section 11.
ANNEX II — Technical and organisational measures (Art. 32 GDPR)
1 PSEUDONYMISATION AND ENCRYPTION
All data in transit is encrypted with TLS 1.2 or higher.
All data at rest is encrypted with AES-256 or an equivalent algorithm.
Credentials and keys are held in a managed secrets store, never in source code, configuration files, or ticketing systems.
Development and test environments use pseudonymised or synthetic data. Production data is not copied into them.
2 ACCESS CONTROL
Individual named accounts only. Shared accounts are not used.
Multi-factor authentication is mandatory on every system holding Client data.
Permissions follow least privilege and are granted per engagement, not per person.
Access rights are reviewed quarterly and revoked within 24 hours of a person leaving the engagement or the company.
3 SEPARATION OF CLIENTS
Each Client has a separate environment with separate credentials.
Client data is not combined, compared or stored together across clients.
Client data is never used to develop, test or improve work for another client.
4 ENDPOINT AND PHYSICAL SECURITY
Full-disk encryption on every device with access to Client data.
Client production data is not stored on local devices other than during active exception review, and is removed when that review ends.
Removable media are not used for Client data.
Screen lock enforced after 5 minutes of inactivity.
5 TRANSFER CONTROL
Client data is transmitted only over encrypted channels agreed with the Client.
Client data is not sent through consumer messaging services or personal email accounts.
Transfers to sub-processors take place only as described in Annex III.
6 INPUT AND TRACEABILITY CONTROL
An append-only audit log records who accessed or changed which records and when.
Every automated decision on a record retains its input, the rule or model version applied, and its output.
Logs are retained for 12 months and are available to the Client on request.
7 AVAILABILITY AND RESILIENCE
Encrypted daily backups, retained 30 days.
Restore procedure tested at least quarterly, with the test documented.
Documented recovery objectives: RTO 4 hours, RPO 24 hours. Full duplication is maintained; RPO follows from the daily backup cycle above.
8 ORGANISATIONAL MEASURES
Written confidentiality undertakings from every person with access, surviving the end of the engagement.
Data protection briefing at onboarding and at least annually thereafter.
Documented incident response procedure with named responsibilities.
Signed data processing agreements and current technical and organisational measures on file for every sub-processor.
Annual review of this Annex, and a review after any personal data breach.
ANNEX III — Sub-processors
Sub-processor Hetzner Online GmbH
Service Hosting, storage and compute
Location Falkenstein and Nuremberg, Germany
Transfer Processing within the EEA — no third-country transfer
Retention For the term of the Services Agreement
Sub-processor Amazon Web Services EMEA SARL
Service Model inference via Amazon Bedrock
Location eu-central-1, Frankfurt, Germany
Transfer Processing within the EEA — no third-country transfer
Retention Prompts and completions are not retained by the provider. Client data is not used to train any model.