Data processing agreement (DPA)
Language note. This is a courtesy translation. The agreement is governed by Spanish law and the Spanish version of this DPA is the legally binding one. If the two texts differ, the Spanish text prevails.
This agreement governs, in accordance with article 28 of the GDPR, the processing of personal data that Savia (Robert Nicuta, self-employed professional, with a professional address for notifications at Carrer de Jaume I, 31, 07860 Sant Francesc de Formentera, Illes Balears, Spain, the «Processor») carries out on behalf of the client company (the «Controller») when providing the Savia service. It forms part of the Terms of Service and applies from the moment the account is created.
The Processor's tax identification number appears in the contract signed with the Controller and is provided on written request to contacto@robertnicuta.com.
1. Subject matter, nature and purpose
The Processor processes the personal data contained in the information the Controller uploads to or generates in the service, for the sole purpose of providing it: storing, indexing, searching and generating answers about that content, capturing knowledge from the use of the tool itself and maintaining the audit log. Processing lasts for as long as the account exists.
2. Types of data and data subjects
Data subjects: the Controller's employees and collaborators, and the people who appear in the content it uploads.
Data: whatever the Controller decides to upload. Generally, identifying and professional data (name, email, job title, department), the content of work documents and conversations and, if the Controller uses the employee records feature, the fields its HR team decides to store (for example ID number, financial data or sick leave situations). The Controller decides what it uploads and is responsible for the lawfulness of that content.
3. Controller's instructions
The Processor processes the data solely on documented instructions from the Controller, which take the form of using the service's features. If we consider that an instruction infringes the GDPR or other data protection law, we will notify the Controller before carrying it out.
4. Confidentiality
The persons authorised by the Processor to process data are bound by confidentiality. Savia support's access to an account occurs only to resolve incidents, is recorded in the Controller's own audit log and expires automatically.
5. Security measures
The Processor applies, as a minimum, the following technical and organisational measures (art. 32 GDPR):
- Per-company isolation across two independent layers: row-level security policies in the database and a vector store with a separate collection per company, verified by automated tests.
- Per-department isolation within each company, likewise enforced at database level.
- Sensitive record data kept out of the semantic search: it is not vectorised; every query checks the exact permission on the server.
- Traffic encryption (TLS), passwords stored with a strong hash, two-step verification available and lockout after repeated access attempts.
- Audit log of relevant actions, including our own support sessions, visible to the Controller.
- Regular backups with a tested restore procedure.
- Complete and verifiable erasure when the service ends (see section 8).
6. Subprocessors
The Controller grants general authorisation for engaging the subprocessors necessary to provide the service. The current list is:
- OVHcloud (hosting of the application, the database, the vector index and the files; data centres in France, within the European Union).
- Anthropic (generation of chat answers; USA, with a processing agreement, valid transfer mechanisms and a commitment not to train on the data).
- MongoDB, Inc. (Voyage AI) (vector representation of text for search; USA, with a processing agreement and valid transfer mechanisms).
- OpenAI Ireland Ltd. (audio transcription: both of the videos that are indexed and of voice dictation in the chat; Ireland, with a processing agreement. A deployment option also exists in which transcription runs on our own infrastructure and no audio leaves it).
- Resend (delivery of service email: invitations, form links, password recovery, weekly digest and monthly report; processes users' name and email address and the content of those notices).
Any change to this list will be communicated to the Controller at least 15 days in advance, with a right to object on justified grounds; objecting may mean the affected service can no longer be provided. Payments are handled with Stripe, which processes the billing data described in the privacy policy.
7. Assistance to the Controller
The Processor assists the Controller, taking into account the nature of the processing, in responding to data subject rights (access, rectification, erasure and others) and in complying with its obligations regarding security, breach notification and impact assessments.
If the Processor becomes aware of a security breach affecting the Controller's personal data, it will notify the Controller without undue delay, with the available information about its nature, the data affected and the measures taken.
8. Erasure on termination
When the service ends, or whenever the Controller asks, the Processor completely and irreversibly erases all of the company's data across the three layers of the system (database, vector index and files) within a maximum of 30 days, keeping no copy except where legally required. A dated record of the deletion remains. No prior copy is provided unless the Controller requests it before erasure.
9. Information and audit
The Processor makes available to the Controller the information necessary to demonstrate compliance with this agreement. The Controller may request one review per year, with reasonable notice, without access to other clients' data and at its own cost.
10. International transfers
Data is hosted in the European Union, in data centres located in France. Audio transcription, both of videos and of voice dictation, is contracted with an entity in the European Union (OpenAI Ireland Ltd.). The US-based AI providers listed in section 6 process the fragments needed to answer each query under valid transfer mechanisms (standard contractual clauses or the EU-US Data Privacy Framework). There is also a deployment option with models running locally for clients who require that no data leaves their infrastructure.