Data Processing Agreement
Version 1.2 — Effective 2026-09-22
This Data Processing Agreement ("DPA") forms part of the contract between Apex Academy d.o.o., Stepinčeva 79, 21000 Split, Croatia, OIB 77296720425 (the "Processor") and the Customer named in the Order Form or account (the "Controller"), and governs the Processor's processing of personal data on the Controller's behalf under GDPR Article 28. Capitalised terms not defined here have the meaning given in the Terms of Service.
The Controller accepts this DPA together with the Terms of Service. For a signed copy, write to legal@apexacademy.hr. If the Croatian and English versions differ, the Croatian version prevails.
1. Subject matter and duration
The Processor processes personal data on behalf of the Controller solely to provide the Service. Processing lasts for the term of the contract plus the wind-down period in clause 9.
2. Nature and purpose of processing
Hosting and operating a dedicated Instance of an AI agent platform for the Controller: storing user accounts, agent configurations, conversation transcripts, files, knowledge and vector embeddings, apps and their data, tool executions, and associated security and audit logs; transmitting data to the AI model providers and other services the Controller connects; and providing support and advisory services.
3. Categories of data subjects
- The Controller's own employees, contractors and other Authorised Users
- The Controller's customers and end users who interact with agents and apps published by the Controller
- Other natural persons whose data the Controller chooses to put into the Service
4. Categories of personal data
- Identification and contact data (name, email, phone, address)
- Authentication data (password hash, session tokens, MFA factors)
- Conversation content (transcripts, voice recordings where enabled, uploaded files, images, tool inputs and outputs)
- Usage metadata (IP address, user agent, timestamps, agent identifiers)
- Any further data the Controller instructs the Processor to process through configuration
Special categories of personal data. The platform is not configured, and its sub-processors are not contracted, for processing special categories of personal data (GDPR Art. 9) or personal data relating to criminal convictions and offences (Art. 10). The Controller must not submit such data — including through agent prompts, uploaded files, knowledge bases or tool payloads — unless the parties have first agreed it in writing, completed a data protection impact assessment where Art. 35 requires one, and updated this DPA accordingly. The Controller remains responsible for the data it and its users choose to submit.
5. Processor obligations
The Processor shall:
- process personal data only on the Controller's documented instructions, including the configuration the Controller sets in the platform's interface and API, unless EU or Member State law requires otherwise (in which case the Processor informs the Controller of that requirement before processing, unless the law prohibits it), and inform the Controller if it considers an instruction to infringe data-protection law;
- ensure that persons authorised to process personal data are bound by confidentiality;
- implement the technical and organisational measures in Annex 1 (GDPR Art. 32);
- engage sub-processors only under clause 6;
- assist the Controller in responding to data-subject requests (Arts. 12–22) and, taking into account the nature of processing and the information available to the Processor, in ensuring compliance with Arts. 32–36 (security, breach notification to the supervisory authority and to data subjects, data protection impact assessments and prior consultation), and cooperate with supervisory authorities (Art. 31);
- notify the Controller of a personal-data breach without undue delay and in any event within 48 hours of becoming aware of it, so that the Controller can meet its own 72-hour deadline under Art. 33;
- delete or return personal data at the end of the contract under clause 9;
- make available the information needed to demonstrate compliance and allow audits under clause 8.
6. Sub-processors
- The Controller grants general authorisation for the Processor to engage the sub-processors listed at /legal/sub-processors.html. The Processor imposes on each of them data-protection obligations equivalent to this DPA and remains fully liable to the Controller for their performance (GDPR Art. 28(4)).
- The Processor gives at least 30 days' prior notice by email of any addition or replacement that is within its control. Some upstream providers reserve shorter notice periods for changes to their own sub-processors; the Processor passes such notices on as soon as practicable and in any event within the period available to it.
- The Controller may object on reasonable data-protection grounds within the notice period. If the parties cannot agree on a solution, the Controller may terminate the affected service.
- Where the Order Form provides that the Processor supplies AI usage, the AI model provider named in the Order Form is a sub-processor for the period stated there, and the Controller authorises it by signing the Order Form.
7. Providers chosen by the Controller
AI model providers, messaging channels, identity providers and other services that the Controller connects to its Instance with its own keys or accounts are engaged by the Controller under its own contract with them. They are not sub-processors of the Processor. Transmitting data to them is processing on the Controller's instruction, and the Controller is responsible for having a lawful basis, an appropriate agreement with the provider and, where data leaves the EEA, a valid transfer mechanism.
8. International transfers and audits
The Processor hosts Instances in the European Union and does not transfer personal data outside the EEA except on the Controller's instruction (clause 7) or through an AI provider named in an Order Form under clause 6.4, in which case the transfer is covered by EU Standard Contractual Clauses (Decision (EU) 2021/914) or another mechanism under GDPR Chapter V, and the Order Form states which.
The Processor makes available security documentation and summaries of relevant audits and tests on request. The Controller may carry out an audit, including on-site, no more than once per calendar year, at its own cost, with at least 30 days' written notice and subject to a reasonable confidentiality undertaking. Audits ordered by a supervisory authority or following a personal-data breach are not limited in frequency.
9. Return or deletion of data
For 30 days after the contract ends, the Instance remains available
read-only so the Controller can export its data, including through
the data-export function (GET /api/user/data-export) and
template export. On request made within that period, the Processor
provides one complete export of the Instance's database and files
free of charge. The Processor then deletes the Instance; hosting-level
snapshots expire within a further 90 days. The Processor confirms
deletion in writing on request. Data the Processor must retain by
law is kept for the statutory period only.
10. Partners
Where the Customer acts under a Partner Agreement and processes personal data on behalf of its own client, the Customer is that client's processor and the Processor acts as its sub-processor. This DPA then applies between the Customer and the Processor as the sub-processing agreement required by GDPR Art. 28(4), and the Customer must bind its client to terms consistent with it.
11. Liability and term
This DPA remains in force as long as the Processor processes personal data for the Controller. Liability under this DPA is governed by clause 18 of the Terms of Service, except where the GDPR requires otherwise.
Annex 1 — Technical and organisational measures
- Encryption — TLS 1.2+ in transit; AES-256-GCM for stored credentials and integration secrets.
- Separation — a separate Instance (application, database and storage) for each customer; per-user scoping of resources inside an Instance; isolated-vm sandboxing for customer-authored tool code.
- Access control — role-based access, MFA for administrative accounts where configured, session timeout, deactivation propagates within 60 seconds.
- Authentication — bcrypt password hashing; SSO (SAML/OIDC) and SCIM provisioning supported.
- Network protection — TLS termination, security headers (HSTS, X-Frame-Options, Referrer-Policy), rate limiting, reverse-proxy hardening, firewalling of internal services.
- Logging — audit log of administrative actions and security events.
- Personnel and process — confidentiality undertakings, least privilege, change management, breach-response procedure.
- Backups — backup of the platform database, data volumes and configuration, checksummed, taken before every platform upgrade and retained on a rolling window on the deployment host; infrastructure snapshots at the hosting layer.
- Sub-processors — hosting in the EU only, under data-processing agreements; see the sub-processor list.
Annex 2 — Controller information
The Controller is the legal entity named in the Order Form or, where there is none, in the account. Its data-protection contact is the contact named in the Order Form or, where there is none, the primary administrator of the Instance.