Aqentra AI
Home About FAQ Knowledge DE

Data Processing Agreement

Last updated: September 9, 2026

1. Scope and Relationship to the Terms

This Data Processing Agreement ("DPA") supplements the Terms of Use ("Terms") between you ("Customer", "controller") and Rasmus Rosenkranz, trading as "Aqentra AI" ("we", "us", "processor"), and reflects the parties' agreement regarding the processing of personal data contained in Customer Data, within the meaning of Art. 28 GDPR. It is incorporated into the Terms by reference and applies automatically for as long as you use the managed hosted Aqentra AI product; no separate signature is required, though a countersigned copy is available on request at [email protected].

This DPA applies only to our managed hosted service. If you use a self-hosted or local deployment, Customer Data stays within your own infrastructure, we do not process it, and we are not your processor — this DPA does not apply, except that Annex 3 (Sub-processors) still describes any third-party AI model provider your own configuration sends requests to when you enable AI-assisted features with an external, non-local model.

Terms not defined in this DPA have the meaning given to them in the Terms or, where used, in the GDPR (e.g. "processing," "personal data," "controller," "processor," "data subject," "personal data breach").

2. Subject Matter and Duration

We process personal data contained in Customer Data solely to provide the Aqentra AI product to you as described in the Terms and our Privacy Policy. Details of the processing (subject matter, duration, nature and purpose, types of personal data, and categories of data subjects) are set out in Annex 1. Processing under this DPA lasts for as long as you maintain an account for the managed hosted service, plus any retention or export period following termination described in Section 10 of the Terms and Section 9 below.

3. Instructions

We process Customer Data only on your documented instructions, including regarding transfers of personal data to a third country, unless required to do otherwise by EU or German law; in that case, we will inform you of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. Your use of the product's ordinary features and configuration options (uploading files, connecting data sources, enabling AI-assisted analysis, inviting users) constitutes an instruction to process Customer Data accordingly. If we consider that an instruction infringes the GDPR or other applicable data protection law, we will inform you without undue delay.

4. Confidentiality

We ensure that persons authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to Customer Data is limited to what is necessary for the purposes described in Annex 1.

5. Technical and Organizational Measures

We implement the technical and organizational measures described in Annex 2, appropriate to the risk, pursuant to Art. 32 GDPR. We may update these measures over time, provided the updated measures do not materially decrease the overall level of protection.

6. Sub-processors

You grant us general authorization to engage the sub-processors listed in Annex 3 for the processing described in Annex 1. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remain liable to you for a sub-processor's performance of those obligations. We will inform you of any intended addition or replacement of a sub-processor with reasonable advance notice (e.g. by email or in-product notice, at least 14 days where practicable), giving you the opportunity to object on reasonable data-protection grounds. If you object and the parties cannot resolve the objection, either party may terminate the affected part of the Services.

This general authorization is limited to the sub-processors listed in Annex 3 for the freely available Product, which uses Google Gemini as its AI model provider. It does not extend to OpenAI or Anthropic. As described in Section 6 of the Terms, we make those providers available only under a separate Provider-Specific Agreement — either a distinct written agreement between you and us covering that specific provider, or your own license or account with that provider connected under your own agreement with it. If and to the extent we act as your processor in connection with OpenAI or Anthropic under a Provider-Specific Agreement, the sub-processor authorization and data protection terms for that engagement are set out exclusively in that Provider-Specific Agreement, not in this DPA.

7. Assistance with Data Subject Requests

Taking into account the nature of the processing, we assist you, insofar as possible and using appropriate technical and organizational measures, in fulfilling your obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR. If a data subject contacts us directly regarding Customer Data, we will forward the request to you without undue delay and will not respond to it substantively ourselves unless required by law.

8. Assistance with Security, Breach Notification, and Impact Assessments

We assist you in ensuring compliance with your obligations under Art. 32 to 36 GDPR, taking into account the nature of processing and the information available to us, including by notifying you without undue delay after becoming aware of a personal data breach affecting Customer Data, and providing information reasonably necessary for you to meet your own notification obligations under Art. 33 and 34 GDPR.

9. Deletion or Return of Data

At your choice, we delete or return all Customer Data to you after the end of the provision of services relating to processing, and delete existing copies, in line with Section 10 of the Terms, unless EU or German law requires storage of the personal data.

10. Audits

We make available to you all information reasonably necessary to demonstrate compliance with the obligations in Art. 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you. Given our size, we may satisfy this obligation by providing documentation (such as this DPA, our Privacy Policy, and a description of the measures in Annex 2) in lieu of an on-site audit, and will reasonably cooperate with a documentation-based or remote audit; an on-site audit may be requested with reasonable advance notice, at your cost, no more than once per year unless triggered by a personal data breach or a supervisory authority's request.

11. International Transfers

Where a sub-processor listed in Annex 3 processes personal data outside the EU/EEA, that transfer is safeguarded by the EU Standard Contractual Clauses (Art. 46 GDPR) between us and that sub-processor, or another valid transfer mechanism under Chapter V GDPR. Where you require it, we will make the relevant transfer safeguards available to you on request.

12. Liability

Liability under this DPA is governed by Section 13 (Liability) of the Terms, which applies to this DPA as if set out in full.

13. Precedence and Term

This DPA remains in effect for as long as the Terms remain in effect and we process Customer Data on your behalf. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails; for all other matters, the Terms prevail. This DPA is drafted in both English and German; where the two versions differ, the German version prevails, as German law governs this agreement.

Annex 1 — Details of Processing

Subject matter: Provision of the managed hosted Aqentra AI product, under which we store, clean, analyze, and generate outputs from Customer Data at your instruction.

Duration: For as long as you maintain an account for the managed hosted service, plus any retention period described in Section 10 of the Terms.

Nature and purpose of processing: Storage and hosting of uploaded files and connected data sources; automated data cleaning, statistical analysis, model building, and forecasting; generation of AI-assisted summaries and explanations; account administration.

Categories of data subjects: Determined by you and the Customer Data you choose to upload or connect — typically your own customers, employees, users, or other individuals whose data appears in the datasets you provide. We have no visibility into or control over which categories of data subjects your Customer Data contains.

Categories of personal data: Determined by you — typically identifiers and business records contained in the datasets you upload or connect (e.g. names, contact details, transaction or usage records). You are responsible for ensuring you have the legal basis to upload any personal data, including special categories of personal data under Art. 9 GDPR; we do not expect or request special-category data and process it only to the extent you choose to include it in Customer Data. The free / pilot version of the Product is not intended for special-category, classified, or otherwise highly sensitive data; Section 5 of the Terms describes your responsibility for that decision and the associated liability position.

Annex 2 — Technical and Organizational Measures

  • Encryption in transit via TLS for all connections to the managed hosted product.
  • Passwords stored as salted cryptographic hashes, never in plain text.
  • Connector credentials for external data sources encrypted at rest.
  • Access to Customer Data restricted to what is necessary to operate and support the product, enforced through role-based access controls.
  • Session security enforced through HttpOnly, Secure, SameSite session cookies.
  • Hosting and database infrastructure for the managed hosted service located within the EU/EEA (see Annex 3).
  • Rate limiting and abuse-prevention controls on authentication and other sensitive endpoints.

Annex 3 — Approved Sub-processors (General Authorization)

Sub-processor Purpose Location / Processing Region
Aiven OY Managed database hosting Customer Data Netherlands (EU/EEA)
Oracle Cloud Infrastructure (Oracle Corporation) Application hosting for the managed hosted product Frankfurt, Germany (region eu-frankfurt-1, EU/EEA)
Brevo (Sendinblue SA) Delivery of account-related transactional email (verification, password reset) France (EU/EEA)
Google Ireland Limited / Google LLC (Google Gemini) AI model provider for the freely available Product's AI-assisted analysis features, per Section 7 of the Privacy Policy Ireland / global, including the United States — safeguarded by EU Standard Contractual Clauses

We will update this list and notify you in line with Section 6 above before adding a new sub-processor or replacing one of the above.

OpenAI, L.L.C. and Anthropic are not covered by this general authorization and are not approved sub-processors under this DPA. We make them available only under a separate Provider-Specific Agreement, as described in Section 6 above and Section 6 of the Terms; where applicable, that agreement (not this DPA) sets out the sub-processor authorization, processing location, and data protection terms for that provider.

© 2026 Aqentra AI
About Impress Privacy Policy Terms of Use

We use necessary cookies, and with consent, Google Tag Manager. Privacy Policy

Share Feedback

How was your experience on this page?

Rating