Data processing agreement
Last updated: 30 June 2026
This agreement, the DPA, forms part of the contract between the customer, the controller, and Eixos Inteligentes, Lda., operating foraudits, the processor, and applies to the processing of personal data on the platform on behalf of the customer, under Article 28 GDPR.
1. Subject matter and instructions
foraudits processes personal data only to provide the platform and only on the customer's documented instructions, including those in the contract. foraudits informs the customer if it considers an instruction infringes data protection law.
2. Duration, nature and purpose
Processing lasts for the term of the contract. The nature and purpose are the provision of the audit platform, including data extraction from documents and AI review of reports. Data types and categories of data subjects are in Annex 1.
3. Confidentiality
foraudits ensures that persons processing the data are bound by confidentiality.
4. Security
foraudits applies the technical and organisational measures in Annex 2, appropriate to the risk, under Article 32 GDPR.
5. Sub-processors
The customer gives general authorisation to use the sub-processors listed on the sub-processors page. foraudits imposes equivalent data protection obligations on them and informs the customer of changes with reasonable notice, and the customer may object on reasonable grounds.
6. Assistance to the controller
foraudits assists the customer, to a reasonable extent, with data subject requests, impact assessments and consultations with the supervisory authority.
7. Data breaches
foraudits notifies the customer without undue delay after becoming aware of a personal data breach, with the information available for the customer to meet its obligations.
8. Deletion or return
At the end of the contract, foraudits deletes or returns personal data, at the customer's choice, unless legally required to retain it.
9. Audit and information
foraudits makes available to the customer the information needed to demonstrate compliance with this agreement and allows reasonable audits, directly or by a mandated third party, with prior notice.
10. International transfers
foraudits processes data in the European Union. Where a sub-processor processes data outside the European Union, appropriate safeguards apply, for example the European Commission standard contractual clauses. [Confirm based on the AI provider and regions.]
11. No model training
foraudits does not use the customer's personal data to train its AI models or those of third parties. Configurations with AI providers reflect this rule. [Confirm that the configuration with the AI provider ensures this.]
Annex 1, processing details
- Categories of data subjects: contacts and staff of the customer and of the customer's customers, and individuals identified in uploaded documents.
- Data types: identification and contact data, data contained in bills and audit reports, and other data the customer chooses to upload. [Confirm and refine.]
- Operations: collection, storage, extraction, AI analysis and provision to the customer.
Annex 2, security measures
- Hosting in the European Union.
- Encryption in transit and at rest.
- Logical isolation of each customer's data.
- Access control and authentication.
- Activity logs and backups.
- [Complete with the actual measures, for example schema isolation and row level access rules in the database.]
Annex 3, sub-processors
See the sub-processors page, which forms an integral part of this agreement.