Data Processing Agreement

Revision date: June 29th, 2026

This Data Processing Agreement (“DPA”) is entered into between:

each a “Party” and together the “Parties”, in connection with the Customer’s use of the Eqolux platform (the “Platform”).

This DPA is incorporated by reference into the Subscription Services Agreement (together with the Contract signed by Eqolux and the Customer, the “Agreement”). If there is any conflict between the Agreement and this DPA, this DPA will govern with respect to data protection.

1. Definitions

Defined terms in this DPA have the meanings set forth in the GDPR. Additional terms:

2. Roles of the Parties

3. Subject Matter, Duration, Nature and Purpose of Processing

Annex 1 contains:

4. Customer Obligations

The Customer shall:

  1. Ensure lawfulness of processing (legal basis, transparency, data subject rights).
  2. Provide only necessary and appropriate Personal Data for the use of the Platform.
  3. Maintain records of processing activities as required by GDPR.
  4. Ensure that its instructions to Eqolux comply with applicable data protection law.

5. Eqolux Obligations

Eqolux shall:

  1. Process Personal Data only per the Customer’s documented instructions, including with regard to international transfers, unless required to do so by law — in which case Eqolux will inform the Customer of that legal requirement before processing, unless the law prohibits it.
  2. Ensure personnel handling Personal Data are under confidentiality obligations.
  3. Implement appropriate technical & organisational measures to ensure security of Personal Data, in line with GDPR Article 32 (see Annex 2).
  4. Assist the Customer in meeting its obligations under GDPR Articles 32–36 and Chapter III (security, breach notifications, impact assessments, data subject rights — see Annex 4).
  5. Notify the Customer without undue delay on detection of any personal data breach (see Annex 4).
  6. At the Customer’s choice, delete or return all Personal Data on termination of the Agreement, unless otherwise required by law, and certify deletion. Active data is deleted within 30 days of the end of the Agreement; backups containing deleted data expire automatically at the end of their 30-day retention cycle, so complete erasure (active data and backups) is effective no later than 60 days after the end of the Agreement.
  7. Make available to the Customer all information necessary to demonstrate compliance with this DPA (see Section 8).

6. Sub‑processors

7. International Transfers

If processing involves transfers of Personal Data outside the EEA, Eqolux shall ensure appropriate safeguards are in place before transfer, in accordance with Chapter V of the GDPR: Standard Contractual Clauses of the European Commission concluded with the Sub‑processors concerned, supplemented where applicable by the provider’s certification under the EU‑U.S. Data Privacy Framework. The hosting region of the Customer’s dedicated instance can be customised on request (European regions are available).

8. Audits and Inspections

9. Liability

10. Termination

Term of this DPA matches term of the Agreement. Termination of the Agreement, for any reason, terminates this DPA. Provisions about confidentiality, deletion/return of Personal Data, breach notification, security measures and liability survive termination.

Annex 1: Details of the Processing

This Annex provides the required details of processing in accordance with Article 28(3) of the GDPR.

Subject matter and nature of the processing. Provision of the Eqolux Platform, a SaaS purchasing-management solution: hosting of Customer Data; centralisation of supplier relations; digitisation and analysis of delivery notes and invoices (automated import and OCR); tracking of prices and purchase volumes; analytics and reporting; and an AI-powered data assistant (“Julia”).

Purpose. Enabling the Customer to manage and analyse its purchasing data through the Platform.

Duration. The term of the Agreement. At the end of the Agreement, Personal Data is deleted or returned as described in Section 5.

Categories of Data Subjects.

Types of Personal Data.

The Platform does not process any banking data of users, health data, or special categories of data within the meaning of Article 9 of the GDPR.

Annex 2: Technical and Organisational Measures

Eqolux implements, and ensures that its Sub‑processors implement, the following (or materially equivalent) technical and organisational security measures, in line with Article 32 GDPR:

1. Physical Access Control

2. Logical Access Control

3. Data Access and Separation

4. Encryption

5. Backup & Disaster Recovery

6. Vulnerability Management

7. Personnel Security & Training

8. Incident Management

Annex 3: Approved Sub‑processors

The Customer authorizes the engagement of the following Sub‑processors. Any change to this list is subject to the 30‑day prior notice and objection mechanism described in Section 6.

Sub‑processorPurpose of ProcessingCategories of Data SubjectsTypes of Personal DataRetention PeriodLocation of ProcessingCertifications
Xano, Inc.Backend hosting, database, file storageCustomer’s Users, supplier contacts, individuals in purchasing documentsAll Personal Data processed by the Platform (see Annex 1)Duration of contractGoogle Cloud — USASOC 2, ISO 27001/27701, DPA, GDPR
Netlify, Inc.Frontend delivery (CDN) — no business dataCustomer’s UsersIP addresses, technical metadata, static site trafficDuration of contractGlobal CDN (USA)SOC 2, DPA, SCCs
WorkOS, Inc.Identity federation (SSO SAML/OIDC)Customer’s UsersNames, emails, identity provider identifiersDuration of contractUSASOC 2, DPA, SCCs
AnthropicAI assistant (Julia)Customer’s Users, individuals mentioned in queried dataText prompts, user identifiers, conversational logsAPI inputs/outputs retained up to ~30 days (abuse detection only), then deletedUSASOC 2, DPA, no training on API data
Amazon Web Services (Bedrock)Document OCR (Claude models via Bedrock)Individuals mentioned in purchasing documentsScanned documents, invoice data, image metadataNot retained beyond processing of the requestUSAISO 27001, SOC 2, DPA, no training on data
Google Cloud (Vertex AI)AI services (Claude models via Vertex AI)Customer’s Users, individuals mentioned in purchasing documentsText prompts, document contentsNot retained beyond processing of the requestUSAISO 27001, SOC 2, DPA, no training on data
OpenAISemantic search (embeddings)Product labels from the purchasing catalogue (no personal data)API inputs/outputs retained up to ~30 days (abuse detection only), then deletedUSASOC 2, DPA, no training on API data
Postmark (ActiveCampaign)Transactional emailsCustomer’s UsersNames, email addresses, message contentDuration of contractUSADPA, SCCs

Annex 4: Assistance with Data Subject Rights and Breach Notifications

Eqolux assists the Customer in fulfilling its obligations under GDPR Chapter III (Rights of the Data Subject) and Article 33 (Notification of a Personal Data Breach), including:

1. Data Subject Rights Assistance

2. Personal Data Breach Notification