At a glance
- Processor only: NeuralShift acts solely on the Client’s documented instructions, and Personal Data is never used to train or fine-tune large language models or frontier models.
- Subprocessors: general authorization with 30 days’ prior notice of any change via the public Register, with a right to object and, ultimately, to terminate with a pro rata refund.
- Security: Article 32 GDPR compliance through published Technical and Organizational Measures, regularly reviewed and updated to the state of the art.
- Erasure and return: on expiry of the Subscription Term, Personal Data is erased or returned at the Controller’s choice, with backups and residual records purged within 45 days.
- Breach notification: Personal Data Breaches are notified without undue delay, with full cooperation for notifications to the Supervisory Authority and Data Subjects.
- Audits: one routine audit per calendar year on 15 Business Days’ notice; incident-driven audits on 5 Business Days’ notice, without an annual limit.
This Data Processing Addendum (the “DPA”) forms part of the Agreement under Clause 2.1(c) of the General Terms and Conditions (the “GTC”). It governs the Processing of Personal Data that NeuralShift, Deep Learning Services, Lda. (“NeuralShift” or the “Processor”) carries out solely as Processor on behalf of the Client (the “Controller”) in providing the Service.
§ 1Documents Incorporated by Reference
1.1 The following documents form part of this DPA, are published at a persistent URL in a form allowing their storage and reproduction, and apply in the version in force at the time of the Processing:
- The Description of Processing Activities (the “Description”), which sets out the categories of Personal Data, the categories of Data Subjects, and the purposes of Processing;
- The Subprocessor Register (the “Register”); and
- The Technical and Organizational Measures (the “Security Measures”).
§ 2Controller Obligations
2.1 The Controller undertakes to the Processor, for the benefit of the Data Subjects, to:
- Ensure that a lawful basis exists for the Processing of Personal Data it makes available to the Processor, in accordance with Applicable Law;
- Without prejudice to Clauses 6.2(h) and 11.5(c) of the GTC, refrain from making Personal Data available to the Processor where it does not meet the lawfulness requirements and other conditions under Applicable Law, including Article 9 of the GDPR for Special Categories of Personal Data;
- Give the Processor reasonable advance notice of any material change that may affect compliance with this DPA, whether to the Processing of Personal Data, to operational instructions, or to Applicable Law.
§ 3Processor Obligations
3.1 The Processor shall:
- Process Personal Data only on the Controller’s documented instructions, including as to transfers to a third country or an international organization. The Controller shall confirm any undocumented instruction in writing without undue delay. Where Applicable Law requires the Processor to Process Personal Data otherwise, it shall inform the Controller beforehand, unless that law prohibits this;
- Inform the Controller immediately if the Processor considers that an instruction would infringe Applicable Law or any other provision of Union or Member State law on the protection of personal data, and suspend that instruction until the Controller confirms, corrects, or withdraws it;
- Not use, retain, anonymize, aggregate, or otherwise Process Personal Data and User Content for purposes other than providing the Service or as this DPA allows. In particular, the Processor shall not:
- Use that data to train or fine-tune large language models or frontier models, whether proprietary or third-party;
- Create individual profiles of Authorized Users that permit their direct identification, other than usage and performance analytics carried out using pseudonymization in accordance with the Security Measures;
- Not engage a Subprocessor for Processing outside the general authorization granted under Clause 4 of this DPA without the Controller’s prior specific written authorization;
- Assist the Controller in complying with Articles 32 to 36 of the GDPR, including Data Protection Impact Assessments and prior consultation with the competent Supervisory Authority, taking into account the nature of the Processing and the information available to it;
- Maintain complete and up-to-date records of the Processing carried out on behalf of the Controller, and make them available to the Controller or the competent Supervisory Authority on request;
- Ensure that every person it authorizes to Process Personal Data under this DPA is bound by an appropriate contractual or statutory duty of confidentiality that survives the end of the Processing.
§ 4Subprocessors
4.1 The Controller grants the Processor a general authorization to engage Subprocessors to Process Personal Data in providing the Service, including those listed in the Register at the date of this DPA.
4.2 The Processor shall ensure that each Subprocessor is able to comply with the applicable data protection obligations under this DPA, is bound by those obligations by written contract, and complies with them throughout its engagement. The Processor remains fully liable to the Controller for their performance.
4.3 The Processor shall keep the Register current and publicly accessible here, identifying for each Subprocessor its name and place of establishment, the services provided, the categories of Personal Data and purposes of Processing, the location of its data centers, and the applicable transfer mechanism where Personal Data is transferred outside the EEA.
4.4 At least 30 (thirty) days before engaging a new Subprocessor, the Processor shall give the Controller notice by updating the Register and notifying the addresses the Controller registers for that purpose and keeps current.
4.5 Where necessary to ensure the security, availability, or continuity of the Service, the Processor may add or replace a Subprocessor without prior notice, provided that it gives the notice required under Clause 4.4 and the reasons for the change within 5 (five) Business Days.
4.6 The Controller may object to a new or replacement Subprocessor on reasonable grounds relating to the protection of Personal Data, within 30 (thirty) days of notice. Otherwise, the change is deemed accepted.
4.7 Following a timely objection under Clause 4.6, the Parties shall seek in good faith, for a period of 30 (thirty) days, a solution that addresses the grounds of the objection, which may include the Processor providing the Service without the Processing carried out by that Subprocessor.
4.8 If the Parties are unable to reach an agreed solution, the Controller may within a further 30 (thirty) days terminate the Agreement, with a pro rata refund of prepaid Fees for the remainder of the Subscription Term. Otherwise, the objection lapses and the change is deemed accepted.
§ 5Technical and Organizational Measures
5.1 Throughout the term of this DPA, the Processor shall implement and maintain all measures required by Article 32 of the GDPR, namely the technical and organizational measures described in the Security Measures and appropriate to the risk of the Processing it carries out.
5.2 The Processor shall regularly review and update the Security Measures to ensure a level of security appropriate to the state of the art, the nature of the Personal Data Processed, and the risks to the rights and freedoms of the Data Subjects.
5.3 The Controller may at any time, on reasonable grounds, request that the Processor revise or update the Security Measures, in particular where Applicable Law, guidance from a competent Supervisory Authority, or a material change in the Processing so requires.
5.4 The Processor shall assess the technical feasibility and proportionality of any change so requested, and is not required to implement one whose cost would be clearly disproportionate to the risk of the Processing.
§ 6Retention, Erasure, and Return of Personal Data
6.1 The Processor shall retain Personal Data only for as long as necessary to provide the Service and for the retention periods set out in Clause 6.4.
6.2 Unless Applicable Law requires retention, on expiry of the Subscription Term or at the Controller’s request the Processor shall, at the Controller’s choice, erase or return all Personal Data in its possession, delete any copies held in its own systems or those of its Subprocessors, and certify the erasure or return in writing.
6.3 The Processor shall securely erase the backups and residual records containing Personal Data held in its own systems, and shall instruct each Subprocessor to do the same, within 45 (forty-five) days after expiry of the Subscription Term or receipt of the Controller’s request, unless the Controller instructs otherwise or Applicable Law requires retention of that Personal Data.
6.4 The following retention periods apply to Personal Data processed by NeuralShift in its capacity as Processor:
| Data Category | Retention Period | Retention Criterion | Erasure Procedure |
|---|---|---|---|
| Identification and Access Data | 5 (five) years after expiry of the Subscription Term or, if earlier, after the permanent deactivation of the Authorized User’s account | Legitimate Interest | Automated erasure, with logging |
| User Content (including Private Data) | 30 (thirty) days from expiry of the Subscription Term, save where the data is stored in backups, in which case an additional period of 15 (fifteen) days applies | Legitimate Interest | Automated erasure, with logging |
| Service Operations and Security Data | 30 (thirty) days from expiry of the Subscription Term, save where the data is stored in backups, in which case an additional period of 15 (fifteen) days applies | Legitimate Interest | Automated erasure, with logging |
| Content-Associated Metadata | 30 (thirty) days from expiry of the Subscription Term, save where the data is stored in backups, in which case an additional period of 15 (fifteen) days applies | Legitimate Interest | Automated erasure, with logging |
| Technical Support Communications | 30 (thirty) days from expiry of the Subscription Term, save where the data is stored in backups, in which case an additional period of 15 (fifteen) days applies | Legitimate Interest | Automated erasure, with logging |
§ 7Assistance with Data Subject Rights
7.1 The Processor shall notify the Controller without undue delay of any request for the exercise of rights received directly from Data Subjects, and shall not respond to any such request unless the Controller expressly instructs it to do so.
7.2 Taking into account the nature of the Processing and insofar as possible, the Processor shall assist the Controller by appropriate technical and organizational measures in responding to requests from Data Subjects for the exercise of their rights, including by making available relevant information and carrying out the necessary technical operations, on the Controller’s request.
7.3 To the extent that the operations giving effect to Data Subject rights, in particular the rights to erasure, rectification, data portability, and access, fall within the scope of the Service, the Processor shall carry them out directly on the Controller’s documented instruction, within 10 (ten) Business Days of receipt or within any shorter period that the Controller reasonably specifies and the Processor confirms to be feasible.
§ 8Notification and Management of Personal Data Breaches
8.1 The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach. The notification shall include at least:
- A description of the nature of the Personal Data Breach;
- The categories and approximate number of Data Subjects concerned, and the systems affected;
- A preliminary assessment of the likely consequences of the Personal Data Breach, including the level of risk to the rights and freedoms of the Data Subjects concerned;
- The measures taken or proposed to contain the Personal Data Breach and to mitigate its effects;
- The contact point for following up and monitoring the incident.
8.2 The Processor shall cooperate with the Controller and shall provide without undue delay all information necessary for the Controller to fulfill its legal obligations to notify the Personal Data Breach to the competent Supervisory Authority and, where applicable, to communicate it to the Data Subjects.
8.3 The Processor shall inform the Controller without undue delay after becoming formally aware that a Supervisory Authority has opened an inspection or enforcement proceeding directly concerning the Processing of Personal Data carried out on behalf of the Controller.
8.4 Apart from the proceedings referred to in Clause 8.3, the Processor shall inform the Controller whenever an operational disruption or a proven breach of Applicable Law relating to data protection has an actual and confirmed effect on the Processing of Personal Data carried out on behalf of the Controller.
§ 9Audits, Impact Assessments, and Cooperation
9.1 The Controller, itself or through external auditors it appoints, may carry out routine or extraordinary audits or inspections of the Processor’s systems, processes, and procedures relating to the Processing it carries out. The Controller shall give reasons and at least 15 (fifteen) Business Days’ prior written notice. For an audit prompted by a security incident or Personal Data Breach affecting the Controller’s own Personal Data, at least 5 (five) Business Days’ prior written notice is required instead.
9.2 Before an audit or inspection begins, the Processor may require the Controller and any external auditors or other third parties it appoints to sign a non-disclosure agreement on terms no more restrictive than the confidentiality obligations set out in Clause 9 of the GTC. That requirement may not be used to delay unreasonably the exercise of the Controller’s audit right, or to restrict a Supervisory Authority, or any other competent national supervisory or control authority, in the exercise of its powers under Applicable Law.
9.3 Where Applicable Law requires or the Controller reasonably requests, the Processor shall cooperate with the Controller and with the external auditors it appoints. Subject where applicable to a non-disclosure agreement under Clause 9.2, the Processor shall make available to them all documentation, information, and resources reasonably necessary for audits, inspections, or Data Protection Impact Assessments, in particular in relation to the Processing carried out on behalf of the Controller, the technical and organizational measures implemented, and the identified risks to the rights and freedoms of the Data Subjects.
9.4 Routine audits shall not exceed one per calendar year. Audits prompted by security incidents or Personal Data Breaches are not subject to that limit, provided that the Controller’s request specifically identifies the incident on which they are based.
9.5 The Controller shall bear the costs of audits. Where an audit reveals a material breach by the Processor that is directly related to the obligations set out in this DPA and that has caused actual damage to Data Subjects, the Processor shall instead bear the reasonable and documented costs of that audit, subject to the liability cap in Clause 11.2 of the GTC.
9.6 Without prejudice to Clause 9.2, the results of audits conducted under this DPA are Confidential Information within the meaning of Clause 9 of the GTC.
9.7 The Processor shall provide reasonable assistance, taking into account the information available to it, where the Controller is subject to an inspection or enforcement proceeding by the competent Supervisory Authority concerning the Processing carried out on the Controller’s behalf.
9.8 Without prejudice to the audit right under this Clause 9, the Processor may demonstrate compliance with its obligations under this DPA or Applicable Law by, in particular, recognized information security certifications (ISO/IEC 27001 or SOC 2 Type II), codes of conduct approved under Article 40 of the GDPR, or audit reports prepared by independent third parties.
§ 10Material Breach, Suspension, and Termination
10.1 Where the Processor materially breaches its obligations under this DPA or Applicable Law, or fails to comply with an order of a court or competent Supervisory Authority in that regard, the Controller may instruct the Processor to suspend the affected Processing operations until the breach or failure is remedied. The Controller may do so only if it demonstrates the breach or failure and the Processor does not remedy it within 15 (fifteen) Business Days of written notice specifying it.
10.2 During the period of suspension of Personal Data Processing operations:
- The Processor may suspend the provision of the Service that depends directly on the suspended Processing operations, and shall notify the Controller of that decision;
- Where the suspension results from the Processor’s material breach, the Controller’s payment obligations shall be adjusted in proportion to the reduction in the Service during the suspension period.
10.3 Where the Processor has informed the Controller that an instruction infringes Applicable Law and the Controller insists on it, the Processor may terminate the Agreement by written notice in accordance with the notice provisions set out in the Order Form.
10.4 Until the Personal Data is erased or returned, the Processor shall continue to comply with this DPA.
10.5 Each Party acknowledges that it is responsible for complying with its obligations under this DPA, and shall compensate the other Party for any material or non-material damage caused by its own failure to comply with its legal or contractual obligations, subject to the limits in Clause 11 of the GTC.
§ 11Amendments
11.1 This DPA may be amended only in writing signed by both Parties, except that the Processor may update the documents listed in Clause 1.1 under Clauses 4.3 and 5.2, provided that no such update materially reduces the level of protection for Personal Data.
§ 12Contact Details for Notifications
12.1 NeuralShift is not required to designate a Data Protection Officer, because the conditions for mandatory designation under Article 37 of the GDPR are not met. The notice provisions set out in the Order Form apply to communications relating to data protection matters under this DPA, which shall be addressed to the contacts below:
Registered post: NeuralShift, Deep Learning Services, Lda. Rua João Saraiva 38, 4th floor, room 405 AI HUB 1700-051 Lisbon Attn: António Lopes dos Santos | Email: |
§ 13Integrations with Third-Party Services
13.1 Where the Controller uses an Integration, Personal Data may be exchanged between the Software and the relevant Third-Party Service through Integration Requests and Integration Responses. The Controller’s arrangements with the provider of that Third-Party Service govern Processing carried out within the Third-Party Service before transmission of an Integration Request to the Software or after receipt of an Integration Response.
13.2 For the purposes of Clause 3.1(a), where the Controller enables an Integration, each Integration Request transmitted through that Integration is a documented instruction to Process that Integration Request and return the corresponding Integration Response. No separate written instruction is required.
13.3 The Processor and the provider of the Third-Party Service act as separate processors appointed by the Controller in respect of their respective Processing in connection with an Integration. Neither Processes Personal Data on behalf of the other. The provider does not become a Subprocessor of the Processor through the availability or operation of an Integration or any technical or commercial arrangement between them.
13.4 The Processor’s obligations under this DPA apply to the Processing of Personal Data within its systems and those of its Subprocessors, and to any later Processing, including Integration Requests and Integration Responses. Disabling an Integration prevents future exchanges but does not erase copies already held within the Third-Party Service.
13.5 The Controller and the Processor each remain responsible for complying with Chapter V of the GDPR for transfers made through their respective Processing. In particular:
- The Controller is responsible for any transfer arising from making Personal Data available to the Third-Party Service under its arrangements with the relevant provider; and
- Where returning an Integration Response involves a transfer subject to Chapter V of the GDPR, the Controller shall ensure that the required transfer mechanism covers that transfer, and the Processor shall comply with any Chapter V obligations directly applicable to its transmission.
13.6 The notification and assistance obligations of this DPA apply to a Personal Data Breach within the systems or operations of the Processor or its Subprocessors, including an unauthorized or misdirected Integration Response. An incident affecting a copy held solely within a Third-Party Service does not by itself constitute a Personal Data Breach arising from Processing by the Processor. If the Processor has credible information that such an incident affects Personal Data exchanged through an Integration, it shall inform the Controller without undue delay and may share with the provider the technical and security information reasonably necessary to investigate, contain, or remedy the incident. The Processor is not required to monitor a Third-Party Service.
13.7 The Controller shall:
- Ensure that it is entitled to Process, and instruct the Processor to Process, the Personal Data exchanged through an Integration;
- Ensure that its use of an Integration and the exchange of Personal Data with the relevant Third-Party Service are permitted under its arrangements with the relevant provider; and
- Comply with its obligations under Articles 13 and 14 of the GDPR in relation to the Processing of Personal Data through an Integration.
§ 14General Provisions
14.1 All terms defined in the GTC have the same meaning in this DPA. Terms capitalized in this DPA but not defined in the GTC have the meaning given to them in the GDPR or, failing that, in Applicable Law, unless expressly provided otherwise.
14.2 If this DPA conflicts with the GTC, this DPA prevails in relation to Personal Data Processed by NeuralShift on the Client’s behalf.
14.3 In all matters not expressly governed by this DPA, the GTC applies, in particular as to the liability of the Parties, dispute resolution, governing law, and general provisions.
14.4 This DPA takes effect on the start date of the Subscription Term and remains in force until its expiry, without prejudice to obligations that survive that date by their nature or by express provision, in particular those relating to confidentiality, liability, retention and erasure of Personal Data, and cooperation with the competent Supervisory Authority.