Data Processing Agreement
Last updated: 21 April 2026.
This Data Processing Agreement ("DPA") forms part of the Order entered into between AIGIUS B.V. ("Processor") and Customer ("Controller"). It implements the requirements of Article 28 GDPR and applies whenever the Processor processes personal data on the Controller's behalf.
1. Subject matter and duration
The subject matter is the processing of Customer Data to provide the document-processing Services described in the Order. Processing continues for the duration of the Order and any agreed data-return period after termination.
2. Nature and purpose of processing
Ingestion, classification, extraction, validation, and transmission of business documents and their metadata into the Customer's ERP or designated downstream system, and any automated acknowledgement replies configured by the Controller.
3. Categories of data subjects and personal data
- Categories of data subjects: Controller's customers, suppliers, and the authorised personnel of both, as reflected in the documents processed.
- Categories of personal data: Contact data (name, email, phone), commercial data (order numbers, amounts, VAT numbers, bank references), and any free-text content the Controller routes to AIGIUS.
- Special categories: Not intended. The Controller must not route special-category or criminal-conviction data to the Services without a separate written agreement.
4. Location of processing
Core Services run on dedicated hardware in certified datacenters in Germany and the Netherlands. Personal data processed in documents does not leave the EU in the course of the Services. Sub-processors outside the EU, where used for support functions, operate under the European Commission's Standard Contractual Clauses.
5. Instructions
The Processor processes personal data only on documented instructions from the Controller, including those contained in the Order and configurations set by the Controller's authorised users. The Processor immediately informs the Controller if, in its opinion, an instruction infringes GDPR or other EU or Member State data-protection law.
6. Confidentiality
Personnel with access to personal data are bound by written confidentiality obligations and trained on data-protection duties.
7. Security measures (art. 32 GDPR)
- Encryption: TLS 1.2+ in transit, AES-256 at rest.
- Access control: role-based, least-privilege, tenant-isolated databases, MFA for administrative access.
- Network isolation: no outbound requests to hyperscaler AI APIs. Local AI models only.
- Audit trail: immutable log of every extraction, validation, correction, and ERP write, retrievable by the Controller.
- Resilience: regular backups, restore testing, documented incident-response procedure.
- Secure SDLC: peer review, dependency scanning, signed model updates.
8. Sub-processors
A current list of sub-processors is available on request. The Controller is notified at least 30 days before any intended addition or replacement, with a right to object on reasonable data-protection grounds.
9. Assistance to the Controller
The Processor assists the Controller, taking into account the nature of processing and the information available, in fulfilling its obligations to respond to requests by data subjects and to comply with articles 32 to 36 GDPR.
10. Personal data breach
The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data, providing the information required under art. 33(3) GDPR to the extent available.
11. Return and deletion
On termination of the Order and at the Controller's choice, the Processor returns all personal data to the Controller and deletes existing copies, unless EU or Member State law requires retention. Residual backups are purged on their ordinary rotation, typically within 35 days.
12. Audit
The Processor makes available to the Controller all information necessary to demonstrate compliance with art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it, on reasonable notice and under confidentiality.