Data processing agreement.
When we build or run something that touches your customers’ data, you stay in charge of it and we process it on your instructions. This is the agreement that says so, in the form Article 28 of the GDPR requires. It is annexed to the engagement letter, together with our consulting terms.
Last updated: 2 September 2026
This Data Processing Agreement (“DPA”) is annexed to and forms an integral part of the Engagement Letter between Ai-Mind BV, trading as Data Panda, Poortakkerstraat 93, 9051 Ghent, Belgium, CBE number BE 1040.220.674, acting as Processor, and the client named in the Engagement Letter, acting as Controller.
Terms defined in Regulation (EU) 2016/679 (“GDPR”) have the same meaning here. “Personal Data” means the personal data described in Annex 1 that the Processor processes on behalf of the Controller.
1. Roles and subject matter
The Controller determines the purposes and means of the processing of the Personal Data. The Processor processes the Personal Data only on the Controller’s behalf, for the purposes of performing the Services, and in accordance with this DPA.
Where the Processor determines the purposes and means of a processing operation itself, for example the processing of the Controller’s business contact details for relationship management, invoicing, and legal compliance, it acts as a controller for that operation and this DPA does not apply to it.
The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subjects are set out in Annex 1.
2. Instructions
The Processor processes the Personal Data only on documented instructions from the Controller, including on transfers to a third country, unless required to do otherwise by Union or Member State law to which it is subject. In that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
The Engagement Letter, this DPA, and the configuration of the systems agreed with the Controller together constitute the Controller’s initial documented instructions. Further instructions are given in writing to the contact in section 12.
The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law. The Processor may suspend the affected processing until the instruction is confirmed, amended, or withdrawn.
3. Confidentiality
The Processor ensures that persons authorised to process the Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it to perform the Services.
4. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risk to data subjects, the Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR.
The measures in place at the date of this DPA are described in Annex 2. The Processor may update them, provided the level of security is not reduced.
5. Sub-processors
The Controller gives the Processor general written authorisation to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex 3.
The Processor informs the Controller in writing at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the affected part of the Services without penalty, and owes fees for Services performed up to that point.
The Processor imposes on each sub-processor, by contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Controller for the performance of the sub-processor’s obligations.
Where the Controller’s own platform accounts are used, for example the Controller’s Microsoft tenant or its accounts with a source or target system, the provider of that platform is the Controller’s own processor and not a sub-processor of the Processor.
6. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller’s obligation to respond to requests to exercise data subject rights under Chapter III GDPR.
If a data subject contacts the Processor directly about Personal Data processed for the Controller, the Processor does not respond on the substance and forwards the request to the Controller without undue delay.
7. Assistance with security, breaches, and impact assessments
The Processor assists the Controller in ensuring compliance with the obligations in Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it.
The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Personal Data. The notification describes, as far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information that is not available at the time is provided in phases as it becomes available. The Processor does not notify the supervisory authority or data subjects on the Controller’s behalf unless the Controller instructs it to.
8. Return and deletion
On termination of the Services, at the Controller’s choice, the Processor deletes or returns the Personal Data and deletes existing copies, unless Union or Member State law requires storage.
The Controller makes that choice in writing within 30 days of termination. Absent a choice, the Processor deletes the Personal Data after that period. Deletion takes place within 30 days, subject to routine backup cycles, in which case the data remains protected by this DPA until the backup expires.
9. Audits and information
The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or by an auditor it mandates.
Audits take place at most once per calendar year, unless a personal data breach or a supervisory authority requires otherwise, on at least 30 days’ written notice, during business hours, without unreasonable disruption to the Processor’s operations, and subject to confidentiality. The auditor may not be a competitor of the Processor. The Processor may satisfy an audit request by providing a current third-party audit report or certification where one covers the scope of the request.
The Processor provides up to two working days of audit assistance per calendar year at no charge. Beyond that, and for the Controller’s own costs, the Controller bears the costs of an audit, and the Processor’s assistance is charged at its then-current daily rate. This does not apply where an audit reveals a material non-compliance by the Processor, in which case the Processor bears its own costs and those of the audit.
10. International transfers
The Processor does not transfer the Personal Data outside the European Economic Area without the Controller’s prior authorisation, except as set out in Annex 3. Access to the Personal Data from outside the EEA counts as a transfer, whether or not the data is copied.
Where a transfer takes place, it is covered by an adequacy decision under Article 45 GDPR, or by the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, together with any supplementary measures required following a transfer impact assessment.
Where the Processor engages personnel or subcontractors outside the EEA, that access is treated as a transfer and is covered by the same safeguards, as set out in Annex 3.
11. Liability
The liability of each party under this DPA is subject to the limitations and exclusions in the General Terms, to the extent permitted by law. Nothing in this DPA limits a data subject’s rights under the GDPR or the liability of either party towards a supervisory authority.
12. Contacts
Data protection contact at the Processor: privacy@datapanda.eu. Data protection contact at the Controller: as stated in the Engagement Letter.
The Processor has not appointed a Data Protection Officer, as it is not required to do so under Article 37(1) GDPR: its core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data. The contact above handles data protection correspondence. The Controller’s Data Protection Officer, if it has one, is stated in Annex 1.
13. Duration, precedence, and law
This DPA takes effect on the effective date of the Engagement Letter and lasts as long as the Processor processes Personal Data on the Controller’s behalf.
In the event of a conflict between this DPA and the General Terms or the Engagement Letter, this DPA prevails on matters concerning the processing of personal data. Where the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail.
This DPA is governed by Belgian law and the jurisdiction clause of the General Terms applies.
Annex 1: Details of the processing
Completed per engagement and attached to the Engagement Letter. Annex 1 records the concrete processing covered by the engagement: its subject matter, duration, nature and purpose, the personal data and data subjects involved, its frequency, and the authorised sub-processors. The values below are the standard description for a data integration engagement and are confirmed or replaced at signature.
| Item | Detail |
|---|---|
| Subject matter | Design, build, and operation of a data integration between the Controller’s systems, as described in the Engagement Letter. |
| Duration | The term of the Engagement Letter, plus the deletion period in section 8. |
| Nature and purpose | Reading personal data from a source system, transforming and mapping it, writing it to a target system, and monitoring, troubleshooting, and supporting that flow. |
| Categories of data subjects | The Controller’s customers and their contact persons; the Controller’s own staff who use the systems. |
| Types of personal data | Name, business contact details, customer and account identifiers, subscription and invoice data, payment status and reconciliation data, and system log data including user identifiers and IP addresses. |
| Special categories | None. The Controller does not instruct the Processor to process data under Article 9 or Article 10 GDPR. |
| Frequency | Continuous or scheduled, as configured. |
| Applicable sub-processors | The engagement-specific version of this Annex identifies every applicable sub-processor by legal name and states its role, processing location, and transfer safeguard before processing begins. If no sub-processors are required, it states “None”. A generic category does not authorise an unidentified sub-processor. |
| Data Protection Officer | Not appointed by the Processor. Controller: as stated in the Engagement Letter. |
Annex 2: Technical and organisational measures
Access control. Access to Controller systems and data is limited to the people working on the engagement, on a need-to-know basis, and is revoked when the engagement or the person’s involvement ends. Multi-factor authentication is enforced on the Processor’s accounts and on the platform accounts used to deliver the Services. Credentials for Controller systems are held in a shared password manager, and are never stored in code, in documents, or in chat. Where a platform supports it, access runs through the Controller’s own accounts and permission model, so the Controller can see and revoke it.
Data handling. Personal Data is processed inside the Controller’s platforms and the integration platform named in Annex 3. Local copies are avoided. Where one is unavoidable to diagnose a fault, it is kept to the minimum, held on an encrypted device, and deleted once the issue is closed. Personal Data sent to the Processor during an engagement, such as a data sample or a log file, is held in the Processor’s Microsoft 365 environment, listed in Annex 3; it is retained only as long as the issue requires, is never copied to personal accounts or unmanaged devices, and is deleted once the issue is closed. Data in transit is encrypted with TLS, and data at rest is encrypted by the platforms used. Development and testing use anonymised, pseudonymised, or synthetic data wherever the work allows.
Devices. Devices used to reach Controller systems or Controller data have full-disk encryption, automatic screen lock, a supported and updated operating system, endpoint protection, and a work account that is not shared. Where someone works on equipment the Processor does not own, they confirm these requirements in writing before access is granted and report any change, and the Processor keeps the confirmation on file. Personal Data is not stored on end-user devices: access runs through named accounts with multi-factor authentication, is granted per assignment at the minimum scope required, is logged, and is revoked as soon as the assignment or the engagement ends.
People and process. Everyone with access, employees and contractors alike, is bound by written confidentiality obligations. Everyone with access receives instruction on data protection and on handling Controller data, and the Processor records when that instruction was given. Personal data breaches are escalated internally on discovery and reported to the Controller within the deadline in section 7. Source code and configuration are held in private version-controlled repositories with access limited to the engagement team.
Resilience. The Processor relies on the availability, backup, and restoration capabilities of the platforms named in Annex 3, and never holds the only copy of the Controller’s production data. The Controller remains responsible for backup and recovery of its own systems.
Annex 3: Sub-processors
The providers below are the Processor’s standard sub-processors. Only those identified in the engagement-specific Annex 1 are authorised for that engagement. Additions and replacements follow the notice and objection procedure in section 5.
| Sub-processor | Entity | Role | Processing location | Transfer safeguard |
|---|---|---|---|---|
| Peliqan | Peliqan BV, Grauwpoort 1, 9000 Ghent, Belgium, CBE BE 0784446918 | Integration platform on which the connectors are built and run | European Union where the engagement is configured for Peliqan’s EU region. Any other approved region is identified in the engagement-specific Annex 1 | Peliqan’s Data Processing Agreement, including the Standard Contractual Clauses for its own sub-processors outside the EEA |
| Microsoft | Microsoft Ireland Operations Ltd, Ireland | The Processor’s Microsoft 365 environment, where Personal Data sent during an engagement is received and held, and Azure or Fabric services where an engagement uses them | European Union and EFTA for services within the EU Data Boundary, subject to the limited transfers documented in Microsoft’s terms | Microsoft Products and Services Data Protection Addendum, including the Standard Contractual Clauses it incorporates |
| Anthropic | Anthropic Ireland, Limited | Claude and Claude Code, used as development and analysis tools on engagement work under Anthropic’s commercial terms. Customer content is not used to train models | United States for storage; processing may also occur in the United States, Europe, Asia, and Australia, subject to the selected routing configuration and Anthropic’s current documentation | Anthropic’s Data Processing Addendum, including the Standard Contractual Clauses it incorporates |
| Individual contractor, where applicable | Independent developer identified by legal name in the engagement-specific Annex 1 before access is granted | Development, testing, and support on the integration, with access to Personal Data only where a task requires it | Pakistan | Standard Contractual Clauses, Module 3, and a documented transfer impact assessment. Access is remote and granted per assignment, and no Personal Data is stored on the contractor’s device |
Microsoft 365 Copilot runs inside the Microsoft 365 environment listed above and is not a separate entry. No tool outside the Processor’s approved list may be used on Personal Data.
Microsoft appears above only for Personal Data processed on the Controller’s behalf. Where the Processor uses the same tools for its own purposes, such as correspondence with the Controller’s staff and invoicing records, that processing falls under section 1 and under the Processor’s privacy policy.
The providers of the Processor’s website analytics, newsletter, and content delivery are not sub-processors under this DPA, because they do not process the Personal Data. They are listed in the privacy policy.