Data Processing Agreement
Revision date: June 29th, 2026
This Data Processing Agreement (“DPA”) is entered into between:
- the customer identified in the Agreement (the “Customer”, acting as “Controller”), and
- Eqolux (acting as “Processor”),
each a “Party” and together the “Parties”, in connection with the Customer’s use of the Eqolux platform (the “Platform”).
This DPA is incorporated by reference into the Subscription Services Agreement (together with the Contract signed by Eqolux and the Customer, the “Agreement”). If there is any conflict between the Agreement and this DPA, this DPA will govern with respect to data protection.
1. Definitions
Defined terms in this DPA have the meanings set forth in the GDPR. Additional terms:
- Personal Data: any information relating to identified or identifiable natural persons that the Customer provides or makes available to Eqolux in connection with the Platform.
- Sub-processor: a third party engaged by Eqolux to process Personal Data on behalf of the Customer.
- Processing: any operation on Personal Data carried out by Eqolux for the Customer’s purposes.
2. Roles of the Parties
- The Customer is the Data Controller: it determines the purposes and means of the processing of Personal Data.
- Eqolux is the Data Processor: it processes Personal Data on behalf of the Customer, strictly in accordance with the Customer’s documented instructions and this DPA. The Agreement, this DPA and the Customer’s use of the features of the Platform constitute the Customer’s complete documented instructions.
3. Subject Matter, Duration, Nature and Purpose of Processing
Annex 1 contains:
- The services provided by Eqolux.
- Categories of Data Subjects.
- Types of Personal Data processed.
- Processing operations and their duration (aligned with the term of the Agreement).
4. Customer Obligations
The Customer shall:
- Ensure lawfulness of processing (legal basis, transparency, data subject rights).
- Provide only necessary and appropriate Personal Data for the use of the Platform.
- Maintain records of processing activities as required by GDPR.
- Ensure that its instructions to Eqolux comply with applicable data protection law.
5. Eqolux Obligations
Eqolux shall:
- Process Personal Data only per the Customer’s documented instructions, including with regard to international transfers, unless required to do so by law — in which case Eqolux will inform the Customer of that legal requirement before processing, unless the law prohibits it.
- Ensure personnel handling Personal Data are under confidentiality obligations.
- Implement appropriate technical & organisational measures to ensure security of Personal Data, in line with GDPR Article 32 (see Annex 2).
- Assist the Customer in meeting its obligations under GDPR Articles 32–36 and Chapter III (security, breach notifications, impact assessments, data subject rights — see Annex 4).
- Notify the Customer without undue delay on detection of any personal data breach (see Annex 4).
- At the Customer’s choice, delete or return all Personal Data on termination of the Agreement, unless otherwise required by law, and certify deletion. Active data is deleted within 30 days of the end of the Agreement; backups containing deleted data expire automatically at the end of their 30-day retention cycle, so complete erasure (active data and backups) is effective no later than 60 days after the end of the Agreement.
- Make available to the Customer all information necessary to demonstrate compliance with this DPA (see Section 8).
6. Sub‑processors
- The Customer gives Eqolux general authorization to engage the Sub‑processors listed in Annex 3 for the processing operations described there.
- Eqolux shall inform the Customer of any intended additions or replacements to its Sub‑processors with at least 30 calendar days’ prior notice; the Customer may object on reasonable data-protection grounds within that period (absence of objection = deemed consent).
- Eqolux imposes on each Sub‑processor, by written contract, data protection obligations materially equivalent to those of this DPA, and remains liable to the Customer for Sub‑processor compliance.
7. International Transfers
If processing involves transfers of Personal Data outside the EEA, Eqolux shall ensure appropriate safeguards are in place before transfer, in accordance with Chapter V of the GDPR: Standard Contractual Clauses of the European Commission concluded with the Sub‑processors concerned, supplemented where applicable by the provider’s certification under the EU‑U.S. Data Privacy Framework. The hosting region of the Customer’s dedicated instance can be customised on request (European regions are available).
8. Audits and Inspections
- The Customer or an appointed auditor may review Eqolux’s compliance with this DPA, upon reasonable notice.
- Eqolux shall cooperate and provide all relevant information, including its security documentation and the available audit reports or certifications of its Sub‑processors (e.g. SOC 2, ISO 27001).
9. Liability
- The limitations on liability set out in the Agreement apply, except that breaches of data protection obligations may give rise to the Customer’s rights under GDPR.
- Each Party is liable in accordance with Article 82 of the GDPR. Eqolux is not liable for processing carried out pursuant to instructions provided by the Customer or for the Customer’s failure to comply with data protection law.
10. Termination
Term of this DPA matches term of the Agreement. Termination of the Agreement, for any reason, terminates this DPA. Provisions about confidentiality, deletion/return of Personal Data, breach notification, security measures and liability survive termination.
Annex 1: Details of the Processing
This Annex provides the required details of processing in accordance with Article 28(3) of the GDPR.
Subject matter and nature of the processing. Provision of the Eqolux Platform, a SaaS purchasing-management solution: hosting of Customer Data; centralisation of supplier relations; digitisation and analysis of delivery notes and invoices (automated import and OCR); tracking of prices and purchase volumes; analytics and reporting; and an AI-powered data assistant (“Julia”).
Purpose. Enabling the Customer to manage and analyse its purchasing data through the Platform.
Duration. The term of the Agreement. At the end of the Agreement, Personal Data is deleted or returned as described in Section 5.
Categories of Data Subjects.
- The Customer’s Users (employees and other individuals authorized by the Customer to access the Platform);
- The Customer’s supplier contacts;
- Individuals incidentally mentioned in purchasing documents (e.g. a supplier contact named on an invoice).
Types of Personal Data.
- User data: professional identity (first and last name), professional email address, organisation, interface preferences;
- Supplier contact data: professional contact details entered by the Customer;
- Incidental personal data contained in purchasing documents (delivery notes, invoices).
The Platform does not process any banking data of users, health data, or special categories of data within the meaning of Article 9 of the GDPR.
Annex 2: Technical and Organisational Measures
Eqolux implements, and ensures that its Sub‑processors implement, the following (or materially equivalent) technical and organisational security measures, in line with Article 32 GDPR:
1. Physical Access Control
- Data centers managed by certified providers (e.g. AWS, Azure, GCP) with 24/7 surveillance, access logs, and badge-based entry.
- Restricted employee access based on job function.
2. Logical Access Control
- Multi-factor authentication (MFA) for all administrative access.
- Role-based access controls (RBAC) to enforce least privilege.
- Audit logs maintained for access to production systems.
3. Data Access and Separation
- Segregation of customer environments and datasets where applicable.
- Customer data logically isolated through application-level controls.
4. Encryption
- In Transit: TLS 1.2+ encryption for all data in motion.
- At Rest: AES-256 or stronger encryption at rest.
5. Backup & Disaster Recovery
- Daily backups of critical systems.
- Geographic redundancy and failover capabilities.
- Regular testing of disaster recovery procedures.
6. Vulnerability Management
- Regular internal security testing and external penetration tests.
- Patch management programs for OS and dependencies.
7. Personnel Security & Training
- Security training for all personnel.
- Access only granted to trained and authorized employees.
- NDA and confidentiality agreements in place.
8. Incident Management
- Breach detection and notification procedures.
- 24/7 monitoring of systems with defined escalation paths.
- The Customer is notified of any personal data breach without undue delay (per GDPR Article 33 — see Annex 4).
Annex 3: Approved Sub‑processors
The Customer authorizes the engagement of the following Sub‑processors. Any change to this list is subject to the 30‑day prior notice and objection mechanism described in Section 6.
| Sub‑processor | Purpose of Processing | Categories of Data Subjects | Types of Personal Data | Retention Period | Location of Processing | Certifications |
|---|---|---|---|---|---|---|
| Xano, Inc. | Backend hosting, database, file storage | Customer’s Users, supplier contacts, individuals in purchasing documents | All Personal Data processed by the Platform (see Annex 1) | Duration of contract | Google Cloud — USA | SOC 2, ISO 27001/27701, DPA, GDPR |
| Netlify, Inc. | Frontend delivery (CDN) — no business data | Customer’s Users | IP addresses, technical metadata, static site traffic | Duration of contract | Global CDN (USA) | SOC 2, DPA, SCCs |
| WorkOS, Inc. | Identity federation (SSO SAML/OIDC) | Customer’s Users | Names, emails, identity provider identifiers | Duration of contract | USA | SOC 2, DPA, SCCs |
| Anthropic | AI assistant (Julia) | Customer’s Users, individuals mentioned in queried data | Text prompts, user identifiers, conversational logs | API inputs/outputs retained up to ~30 days (abuse detection only), then deleted | USA | SOC 2, DPA, no training on API data |
| Amazon Web Services (Bedrock) | Document OCR (Claude models via Bedrock) | Individuals mentioned in purchasing documents | Scanned documents, invoice data, image metadata | Not retained beyond processing of the request | USA | ISO 27001, SOC 2, DPA, no training on data |
| Google Cloud (Vertex AI) | AI services (Claude models via Vertex AI) | Customer’s Users, individuals mentioned in purchasing documents | Text prompts, document contents | Not retained beyond processing of the request | USA | ISO 27001, SOC 2, DPA, no training on data |
| OpenAI | Semantic search (embeddings) | — | Product labels from the purchasing catalogue (no personal data) | API inputs/outputs retained up to ~30 days (abuse detection only), then deleted | USA | SOC 2, DPA, no training on API data |
| Postmark (ActiveCampaign) | Transactional emails | Customer’s Users | Names, email addresses, message content | Duration of contract | USA | DPA, SCCs |
Annex 4: Assistance with Data Subject Rights and Breach Notifications
Eqolux assists the Customer in fulfilling its obligations under GDPR Chapter III (Rights of the Data Subject) and Article 33 (Notification of a Personal Data Breach), including:
1. Data Subject Rights Assistance
- Upon the Customer’s written request, Eqolux shall assist in responding to requests from Data Subjects, including:
- Right of access
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to data portability
- Right to restrict or object to processing
- Such requests will be handled promptly and within reasonable timeframes. Eqolux will not respond directly to any data subject request without prior written authorization from the Customer, unless legally required.
2. Personal Data Breach Notification
- Eqolux will notify the Customer without undue delay and within 24–48 hours of becoming aware of a breach affecting Personal Data.
- Notifications must include:
- Nature of the breach (what happened, categories of data affected)
- Number of data subjects and records affected
- Likely consequences and risks
- Mitigation and remedial measures taken
- Contact details for further information
- Eqolux shall assist the Customer in communicating the breach to supervisory authorities and/or data subjects where required.