Data Processing Agreement (DPA)

1. Parties and definitions

This Data Processing Agreement (the «DPA» or «Agreement») governs the relationship between the client engaging The AI Web Factory to develop, host, maintain or operate a digital product (the «Controller») and The AI Web Factory (the «Processor») where personal data of third parties is processed in the course of that engagement: the Controller’s end users, customers, employees or contacts.

This DPA is signed electronically upon acceptance of the service terms and forms an integral part of them. It applies automatically and is deemed accepted when the Controller first transmits a third party’s personal data to the Processor.

On the one hand, the Data Controller is the client, whether a natural or legal person, who engages the service and transmits or makes available personal data of third parties over which it holds ownership or a legitimate interest in the processing.

On the other hand, the Data Processor is Tarraco App Lab, S.L.U. (in incorporation), owner of The AI Web Factory (a registered trade mark owned by it), with registered office at C/ Pau Claris, 2 - 43005 Tarragona, Spain, and contact address privacidad@tarracoapplab.com.

The definitions in Article 4 of Regulation (EU) 2016/679 (GDPR) and in Spanish Organic Law 3/2018 (LOPDGDD) apply.

2. Subject matter, duration and nature of the processing

Subject matter. Processing by the Processor, on behalf of the Controller, of the personal data it accesses or that is transmitted to it in the course of designing, developing, migrating, hosting, maintaining or supporting the site or application commissioned.

Duration. The duration of the processing coincides with the duration of the contractual service relationship, subject to any subsequent mandatory legal retention.

Nature. Automated processing on cloud infrastructure, with encryption in transit and at rest, in accordance with the technical and organisational measures described in clause 6.

Purpose. Solely the provision of the services engaged: building and deploying the product, migrating content and data, resolving incidents, evolutionary maintenance and the technical support requested by the Controller.

3. Categories of data and of data subjects

The categories of personal data processed and the data subjects affected vary according to the product commissioned. The most common are as follows.

Sites and applications with forms. Data subjects: the Controller’s end users, prospective customers and contacts. Identification and contact data: first name, surname, email address, telephone, company and message content.

Private areas and user accounts. Data subjects: users registered on the Controller’s product. Data: name, email address, session identifiers and credentials, always stored using a secure derivation function and never in plain text, plus any profile data the Controller defines in its data model.

Migrations and maintenance. Data subjects: all data subjects present in the Controller’s source databases or systems. Data: that contained in those systems, which the Processor accesses on a limited and temporary basis to carry out the migration or resolve the incident.

The Controller undertakes not to transmit special categories of data (racial origin, health, ideology, sex life or orientation, genetic or biometric data) except where strictly necessary and with an appropriate legal basis, and to give prior notice so that the corresponding enhanced measures can be activated.

4. Obligations of the Processor

The Processor undertakes to:

5. Authorised sub-processors

The Controller grants the Processor general authorisation to use the following sub-processors, all bound by a GDPR-compatible contract:

The Processor will give the Controller at least 30 calendar days’ notice of any addition or replacement of a sub-processor. The Controller may object on reasoned grounds within that period and, if the objection is reasonable, the Processor must offer an alternative or the Controller may terminate the contract without penalty.

6. Technical and organisational measures

Encryption. TLS 1.2/1.3 mandatory on all communications, with HSTS enabled. AES-256 at rest for the database and file storage. Passwords hashed with bcrypt or equivalent.

Access control. Row-Level Security in the database, so each user can only access their own data. Rotatable and revocable API keys, session tokens with expiry, administrative access with mandatory multi-factor authentication and least-privilege principle. Credentials and secrets kept out of the codebase, in the provider’s encrypted environment variables.

Resilience and availability. Automatic backups with 7 to 30 days’ retention depending on plan, infrastructure with the cloud provider’s availability SLA, and a basic continuity plan with RTO and RPO under 24 hours.

Staff confidentiality. Perpetual confidentiality undertaking signed by anyone with access to systems, periodic data protection training and revocation of access upon termination of the employment or collaboration relationship.

Verification and auditing. Periodic review of logs and dependencies, penetration testing whenever a new critical component is introduced, and an internal incident register with analysis and corrective measures.

7. International transfers

Where a sub-processor is located outside the European Economic Area, the Processor will apply the safeguards provided for in Chapter V GDPR: in particular, the standard contractual clauses approved by the European Commission in Decision 2021/914, supplemented by the additional measures derived from the impact assessment required by the Schrems II judgment.

The Processor will make available to the Controller a copy of the safeguards applied to any international transfer, upon reasonable request.

8. Security breach

In the event of a breach affecting the Controller’s personal data, the procedure is as follows:

9. Audit

The Controller may audit compliance with this DPA once a year, with at least 4 weeks’ prior written notice, during business hours and without interrupting service provision.

To minimise the impact, the Processor may offer a current external audit report (ISO 27001, SOC 2 or equivalent). The audit may not extend to other clients’ data.

The costs of the audit are borne by the Controller, unless material breaches by the Processor are found, in which case the Processor bears them.

10. Liability, duration and changes

Each party is liable for damage arising from a breach of its obligations, in accordance with Article 82 GDPR. The limitation of liability regime is governed by the general terms of service, and the Processor will maintain professional civil liability insurance appropriate to the volume of the service.

This DPA remains in force for as long as the contractual relationship for the processing of third-party personal data continues. Termination of the main contract entails termination of the DPA, without prejudice to obligations that by their nature survive.

The Processor may modify this DPA where required by a change in legislation or a substantial improvement in security measures. Changes will be published on this page with the revision date and notified with reasonable notice. The Controller may object on reasoned grounds and, if the objection is not resolved by agreement, terminate the contract without penalty.

11. Applicable law and jurisdiction

This DPA is governed by Spanish law (GDPR, LOPDGDD and other applicable legislation).

The parties submit, expressly waiving any other jurisdiction, to the competent Courts and Tribunals of Spain in accordance with the applicable procedural rules.