Data Processing Policy
Considerations
This Data Processing Policy (hereinafter referred to as the “DPP”) hereinafter set forth, as amended from time to time, shall form a part of A&S’s General Terms and Conditions (the “Terms”) between Customer and A&S and are hereby incorporated by reference into the Terms. This DPP determines (i) the managing, securing and/or Processing of Personal Data (as defined further) and (ii) the Parties' obligation to comply with the Privacy Legislation (as defined further).
This DPP sets out the following
1. Definitions
Capitalized terms used, but not defined, in this DPP are defined in the Agreement, the other capitalized terms used in this DPP shall have the following meaning:
- Assignment
- All activities and services performed by the Processor under the Agreement, including the provision of the Platform and related Services;
- Controller
- The entity which determines the purposes and means of the Processing of Personal Data, in this case being the Customer;
- Data Subject
- Identified or identifiable natural person to whom the Personal Data relates, including the Customer's Users and any individuals referenced in the Customer Data or Context Layer;
- Data Breach
- Unauthorized disclosure, access, abuse, loss, theft or accidental or unlawful destruction of Personal Data while being processed by the Processor or any of its Sub-processors;
- Data Importer
- The recipient of Personal Data/Processor of the Processor in a third country, which is not subject to an adequacy decision of the European Commission;
- Personal data
- Any information relating to an identified or identifiable natural person;
- Privacy Legislation
- (i) The Belgian Privacy Law of 30 July 2018 concerning the protection of individuals with regard to the processing of personal data and/or (ii) the EU Regulation of 2016 concerning the protection of individuals with regards to the processing of personal data, regarding the free movement of such data and repealing Directive 95/46/EC (‘GDPR’) and/or (iii) all (future) Belgian laws regarding the implementation of this Regulation;
- Processor
- The entity which Processes Personal Data on behalf of the Controller, in this case being A&S;
- Process/Processing
- Any operation or set of operations which is performed upon Personal Data or sets of Personal Data, including, but not limited to: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data and
- Sub-processor
- The entity which Processes Personal Data on behalf of the Processor and the sub-processors on which it relies.
The DPP includes the following annexes:
- Annex I
- Overview of (i) the Personal Data, which Parties expect to be subject of the Processing, (ii) the categories of Data Subjects whose Personal Data shall be Processed, (iii) the use (i.e. the way(s) of Processing) of the Personal Data and the purposes and means of Processing, (iv) the term(s) during which the (different types of) Personal Data shall be stored;
- Annex II
- Overview and description of the technical and organizational measures taken by the Processor under this DPP;
- Annex III
- List of Sub-processors.
2. Roles of the Parties
2.1Parties acknowledge and agree that with regard to the Processing of Personal Data, the Customer shall be considered “Controller” and A&S “Processor”.
3. The Assignment
3.1The Customer acknowledges that the Processor shall Process Personal Data as provided by the Customer in the context of the Assignment:
- Operating and providing access to the Platform, including the Context Broker and Integrations;
- Capturing, structuring, and centralizing business context (documents, guidelines, tone of voice) submitted by the Customer into the Context Layer;
- Injecting Customer Data into AI Tool interactions via the Integrations configured for the Customer;
- Providing Set-Up, Support, and other Services under the Agreement;
- Invoicing and statutory accounting processing and reporting;
- Operational management:
- Customer relationship management;
- Administration of Users and authorized contacts;
- Protection of A&S’s business assets;
- Health and safety of A&S personnel.
4. Object
4.1The Customer acknowledges that as a consequence of making use of the Processor for the Assignment, the latter shall Process Personal Data as provided by the Customer and upon the instructions of the Customer.
4.2The Processor acknowledges and guarantees that:
- It shall Process the Personal Data in a proper and careful way and in accordance with the Privacy Legislation and/or other applicable rules concerning the Processing of Personal Data. More specifically, the Processor shall provide all its know-how in order to Process the Personal Data according to the rules of art, as it fits a specialized and "good" processor.
- It shall only Process the Personal Data in accordance with the instructions of the Customer (as described in Annex I), unless legislation requires the Processor to carry out a particular Processing operation. In that case, the Processor shall inform the Customer of the legal requirement before Processing, unless the law prohibits sharing such information on important grounds of public interest. The Processor shall inform the Customer in case it is unable to follow the instructions of the Customer or to comply with its responsibilities under this Article or the Privacy Legislation.
- The Processor shall in no event Process the Personal Data beyond what was agreed with the Customer, and in particular shall not use the non-anonymized Context Layer to train or improve any model or product other than for the direct benefit of the Customer. Hence, the Processor shall not Process the Personal Data for a different purpose than mentioned in Annex I, nor for its own purposes, for purposes outside of the Assignment, or for the benefit of any third party. The Processor shall inform the Customer in case it is unable to comply with its responsibilities under this Article or the Privacy Legislation.
4.3The Customer — as Controller — owns and retains full control concerning (i) the Processing of Personal Data, (ii) the types of Personal Data Processed, (iii) the purpose of Processing, and (iv) the fact whether such Processing is proportionate (non-limitative).
5. Security of Processing
5.1Taking into account the state of the art, the Processor implements appropriate technical and organizational measures for (i) the protection of Personal Data - including protection against unauthorized or unlawful Processing and against accidental loss, destruction or damage - and (ii) the confidentiality and integrity of Personal Data. The measures implemented by the Processor at the date of signing of this DPP are set forth in Annex II.
6. Sub-processors
6.1The Customer acknowledges and agrees that the Processor may engage third-party Sub-processors in connection with the Assignment. In such case, the Processor shall ensure that the Sub-processors are at least bound by the same obligations by which the Processor is bound under this DPP.
6.2The Customer agrees to the Sub-processors on which the Processor relies in connection with the Assignment, as set out in Annex III.
6.3The Customer hereby grants the Processor general written authorization to engage Sub-processors, subject to the following conditions. The Processor shall notify the Customer in writing at least fifteen (15) business days prior to engaging any new Sub-processor or replacing an existing Sub-processor. Such notification shall identify the Sub-processor, its country of incorporation, the location of processing, and the nature of the processing to be carried out. The Customer may object to the engagement of a new Sub-processor within ten (10) business days of receiving such notification by providing written notice to the Processor setting out the grounds for its objection. If the Customer does not raise an objection within that period, authorization shall be deemed granted.
6.4In the event the Customer objects to a new Sub-processor and such objection is not found unreasonable, the Processor will use reasonable efforts to (i) make available to the Customer an acceptable Sub-processor or (ii) recommend a commercially reasonable change to the Assignment to avoid processing of Personal Data by the objected new Sub-processor without unreasonably burdening the Customer.
6.5If the Processor is, however, unable to make available such change within a reasonable period, the Customer may terminate the Assignment (and thus the Agreement), by providing written notice thereof to the Processor within a reasonable time, if:
- The Assignment cannot be executed by the Processor without appealing to the objected new Sub-processor; and/or
- Such termination solely concerns part of the Assignment which cannot be provided by the Processor without appealing to the objected new Sub-processor.
6.6Without prejudice to any reliance that the Processor may have on any Sub-processors, the Processor shall at all times be the point of contact with respect to the Customer and shall be liable for the acts and omissions of its Sub-processors to the same extent as if it had itself performed the Assignment, provided by each Sub-processor directly, in accordance with the terms of this DPP.
7. Transfer of Personal Data outside the EEA
7.1Personal Data may only be disclosed by the Processor to a third party located outside the EEA (European Union + Iceland, Norway and Liechtenstein) or to an international organization if such transfer is subject to (i) an adequacy decision of the European Commission, or (ii) one of the following safeguards:
- Closing a data transfer agreement with the third country recipient, which shall contain valid standard contractual clauses (‘SCC’), as adopted by the European Commission. Before the transfer takes place, the Data Importer has to guarantee the Processor that an adequate level of privacy compliance is ensured in this third party country; and/or;
- Binding corporate rules. As it is the case for standard contractual clauses, the Data Importer has to guarantee the Processor that an adequate level of privacy compliance is ensured in the third party country; and/or;
- Certification mechanisms.
Any disclosure may only take place subject to compliance by the Processor with all the other safeguards under this DPP.
7.2The Processor shall identify and implement appropriate supplementary measures to govern any data transfer to such international organization or a third country without adequacy decision to ensure the level of data protection as required by EU law.
7.3Furthermore, the Processor shall take all reasonable efforts to oblige the Data Importer to implement sufficient guarantees and measures to protect the Personal Data and ensure the effectiveness of the protection of the SCC’s, binding corporate rules and/or certification mechanisms.
8. Confidentiality
8.1The Processor shall maintain the Personal Data confidential and thus not disclose nor transfer any Personal Data to third parties, without the prior written agreement of the Customer, unless when:
- Explicit written deviation is provided for in this DPP;
- Such disclosure and/or announcement is required by law or by a court or other government decision (of any kind). In such case the Processor shall, prior to any disclosure and/or announcement, discuss the scope and manner thereof with the Customer.
8.2The Processor shall ensure that its personnel, engaged in the Processing of Personal Data, are informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities and have executed written confidentiality agreements. The Processor shall ensure that such confidentiality obligations survive the termination of the personnel engagement.
8.3The Processor shall ensure that its access to Personal Data is limited to such personnel appointed for the Processing of the Personal Data in accordance with the DPP.
9. Notification
9.1The Processor undertakes to inform the Customer as soon as reasonably possible when it:
- Receives a request for information, a subpoena or a request for inspection or audit from a competent public authority in relation to the Processing of Personal Data;
- Has the intention to disclose Personal Data to a competent public authority;
- Determines or reasonably suspects a Data Breach has occurred in relation to the Personal Data, to which the specific provisions as described below apply, subject to the provisions of Article 9.2.
9.2In case of a Data Breach, the Processor
- Notifies the Customer without undue delay after becoming aware of a Data Breach. Such notification shall contain the details of a contact point where more information can be obtained, a description of the nature of the breach (including, where possible, categories and approximate number of Data Subjects and Personal Data records concerned), its likely consequences and the measures taken or proposed to address the Data Breach.
Where, and in so far as, it is not possible to provide all information at the same time, the initial notification shall contain the information then available and further information shall be provided subsequently as it becomes available without undue delay;
- Provides – to the extent reasonably possible – assistance to the Customer with respect to its reporting obligation under the Privacy Legislation;
- Shall take appropriate remedial actions to make an end to the Data Breach and to prevent and/or limit any future Data Breach.
10. Rights of Data Subjects
10.1To the extent the Customer does not have the ability to correct, amend, block or delete Personal Data, as required by Privacy Legislation, the Processor shall comply with the Customer’s reasonable requests to execute such actions.
10.2The Processor shall promptly notify the Customer if it receives a request from a Data Subject for access to, correction, amendment or deletion of that Data Subject’s Personal Data. The Processor shall, however, not respond to any such Data Subject’s request without the Customer’s prior written consent. The Customer shall provide such consent or instructions within five (5) business days of the Processor’s notification, failing which the Processor shall be entitled to take such action as is strictly necessary to comply with a mandatory legal deadline, provided it first informs the Customer thereof.
10.3The Parties agree that if there is a dispute between a Data Subject and one of the Parties regarding compliance with this DPP, they shall keep each other informed about such proceedings and, where appropriate, cooperate in resolving the issue in a timely fashion.
11. Return and deletion of Personal Data
11.1Upon termination of the Assignment and/or termination of the Agreement, the Processor shall, upon Customer’s request, return the Personal Data to the Customer in a format agreed upon between Parties at such time.
11.2Upon termination of the Assignment and taking into the account the retention period stated in Annex I, the Processor shall delete the Personal Data it received or created, unless applicable legislation requires storage of the Personal Data.
12. Control
12.1The Processor shall promptly and properly deal with inquiries from the Customer that relate to the Processing in connection with the Assignment.
12.2The Parties shall be able to demonstrate compliance with this DPP. The Processor undertakes to provide the Customer with all information reasonably required by the latter to allow verification whether the Processor complies with the provisions of this DPP. In this respect, the Customer (or a third party on which the Customer relies) is allowed to undertake inspections – such as but not limited to an audit – and shall be provided with the necessary assistance thereto by the Processor, subject to the following conditions. Customer must request an audit in writing with prior notice of thirty (30) calendar days and may instruct acknowledged audit professionals at its own expense to execute such audit in following cases.
- once every twelve (12) months provided that such additional audit inquiries shall not unreasonably impact A&S’s regular operations in an adverse manner and do not prove to be incompatible with applicable Privacy Legislation or with the instructions of a competent authority;
- where an audit is reasonably considered necessary because of genuine concerns as to A&S’s compliance with this DPP;
- where a competent data protection authority requires this under applicable Privacy Legislation;
- following a Data Breach.
13. Term
13.1This DPP remains into force for the term of the Agreement.
14. Liability
14.1Parties shall be liable for and indemnify each other for all damages resulting from a Party's failure to comply with (i) the provisions of this DPP, (ii) the internal policies, procedures and best practices of the Customer and/or (iii) the Privacy Legislation and any other applicable regulations regarding the Processing of Personal Data.
14.2The Parties shall, inter alia, be liable for (i) the payment of an administrative fine imposed by the supervisory authority and/or (ii) the damages suffered by the Data Subject(s) and/or the Party suffering damages.
14.3In the event that the Processor is in breach of this DPP or unable to comply with this DPP, the Customer shall suspend the transfer of Personal Data to the Processor until compliance is again ensured or the Agreement is terminated.
14.4The Parties agree that if one Party is held jointly and severally liable for a breach of the DPP together with another Party, it is entitled to claim back as indemnification that part of the liability that corresponds to the other Party’s part of responsibility.
15. Miscellaneous
15.1The provisions of this DPP shall apply to the extent necessary for the completion of this DPP and to the extent intended to survive the end of this DPP (such as but not limited to Article 8 and 14).
15.2If one or more provisions of this DPP are found to be invalid, illegal or unenforceable, in whole or in part, the remainder of that provision and of this DPP shall remain in full force and effect as if such invalid, illegal or unenforceable provision had never been contained herein. In such event, the competent court may mitigate the invalid provision to what is (legally) permitted.
15.3The Processor may amend this DPP from time to time, including to reflect changes in the Privacy Legislation, the Agreement or the Processor’s processing activities. The version published or communicated by A&S shall apply as of its stated update date.
15.4This DPP and the corresponding rights and obligations that exist in respect of the Parties, cannot be transferred, directly or indirectly, without the prior written consent of the other Party.
15.5(Repeated) non-enforcement by a Party or by both Parties of any right or provision of this DPP, can only be regarded as a toleration of a certain state, and does not lead to forfeiture.
15.6In case of a conflict between this DPP and the Agreement, this DPP shall prevail. For all matters not covered by this DPP, the Agreement shall be applicable.
16. Applicable law and jurisdiction
16.1All issues, questions and disputes concerning the validity, interpretation, enforcement, performance or termination of this DPP shall be governed by and construed in accordance with Belgian law, without giving effect to any other choice of law or conflict-of-laws rules or provisions (Belgian, foreign or international) that would cause the laws of any country other than Belgium to be applicable.
16.2Any dispute concerning the validity, interpretation, enforcement, performance or termination of this DPP shall be submitted to the exclusive jurisdiction of the courts of the Processor's registered office.
Annexes
- Annex I – Overview of Personal Data
- Annex II – Description of Technical and Organizational Measures
- Annex III – List of Sub-processors
Annex I – Overview of Personal Data
The Processor and the Customer hereby set out, for the purpose of the execution of the DPP, the Processing activities the Processor is allowed to perform on the Personal Data listed below, with an overview per Processing activity of the Personal Data and categories of Data Subjects involved, use of the Personal Data, the purpose and means of the Processing, as well as the retention periods to be taken into account.
1. Providing access to and use of the Platform (User accounts and authentication)
Overview of the Personal Data, which Parties expect to Process
- First name
- Last name
- Business email address
- Business telephone number (optional)
- Job title/ role within the Customer’s organisation
- User login credentials and Identity Provider identifiers
- IP address and technical log data relating to Platform access
Sensitive data: No
The categories of Data Subjects whose Personal Data shall be Processed
- Users (employees, contractors or representatives of the Customer authorized to access the Platform)
- Customer’s designated administrator(s)
The use (= way(s) of Processing) of the Personal Data and the purposes and means of Processing
Use of the Personal Data and means of Processing
- Collecting
- Structuring
- Interconnecting
- Saving
- Deleting
- Consulting
- Comparing
- Modifying
- Communicating
- Restricting
Purpose of Processing
- Creating and managing User accounts and access rights to the Platform
- Authenticating Users via the Identity Provider (single sign-on)
- Ensuring the security, integrity and proper functioning of the Platform
The term(s) during which the (different types of) Personal Data shall be stored
- For the term of the Agreement, and for thirty (30) days thereafter, unless a longer retention period is required by applicable law
2. Operating the Context Broker and Context Layer
Overview of the Personal Data, which Parties expect to Process
- First name
- Last name
- Email address
- Job title, department or team affiliation
- Any other personal data voluntarily included by the Customer or its Users in documents, guidelines, tone-of-voice materials or other content uploaded to or generated within the Context Layer
Sensitive data: No
The categories of Data Subjects whose Personal Data shall be Processed
- Users
- Employees, contractors, customers, or other third parties of the customer whose personal data may be contained within the Customer Data uploaded to the Platform
The use (= way(s) of Processing) of the Personal Data and the purposes and means of Processing
Use of the Personal Data and means of Processing
- Collecting
- Sorting
- Structuring
- Modifying
- Saving
- Transferring
- Consulting
- Comparing
- Interconnecting
- Communicating
- Restricting
- Deleting
Purpose of Processing
- Capturing, structuring and centrally storing the Customer’s business context within the Context Broker
- Injecting the Context Layer automatically into AI Tool interactions via Integrations, to generate output for the Customer’s internal business purposes
- Maintaining, operating and improving the Platform for the benefit of the Customer
The term(s) during which the (different types of) Personal Data shall be stored
- For the term of the Agreement; upon expiry or termination, identifiable Customer Data shall be retained for thirty (30) days to allow export by the Customer, after which it shall be irrevocably deleted, unless retention is required by applicable law
3. Support requests and account/ contract administration
Overview of the Personal Data, which Parties expect to Process
- First name
- Last name
- Business email address
- Business telephone number
- Company name and role of the requester
- Content of the support request or inquiry (including any information voluntarily provided about the issue and the circumstances in which it occurred)
- Billing and invoicing contact details
Sensitive data: No
The categories of Data Subjects whose Personal Data shall be Processed
- Users
- Customer’s designated contact(s) for notices and billing
The use (= way(s) of Processing) of the Personal Data and the purposes and means of Processing
Use of the Personal Data and means of Processing
- Collecting
- Sorting
- Structuring
- Modifying
- Saving
- Transferring
- Consulting
- Comparing
- Interconnecting
- Communicating
- Restricting
- Deleting
Purpose of Processing
- Handling and resolving support requests submitted by the Customer or its Users
- Administering the Agreement, Order Form and Fees, including invoicing and payment follow-up
The term(s) during which the (different types of) Personal Data shall be stored
- For the term of the Assignment, and thereafter only as long as necessary to handle the relevant request or as required for accounting, tax or other legal obligations
Annex II – Description of Technical and Organizational Measures
Description of the technical and organizational security measures taken by the Processor.
The Processor shall implement appropriate technical and organizational measures in order to protect the Personal Data, which will be made available to the Customer upon request.
Access control and authentication
- Role-based access control, ensuring that access to Personal Data is limited to personnel who require it for the performance of the Services;
- Unique user accounts and authentication for all personnel accessing the Platform's underlying systems, including single sign-on integration via the Customer's Identity Provider where configured;
- Multi-factor authentication for administrative and privileged access to the Platform's infrastructure that is managed by the Processor. Where the Customer's Users authenticate via the Customer's own Identity Provider (e.g. Microsoft Entra, Google Workspace) through Single Sign-On, the enforcement of multi-factor authentication for such Users falls within the Customer's own responsibility as Controller and is governed by the Customer's identity and access management policies;
- Periodic review and revocation of access rights, including prompt removal of access for personnel who no longer require it (e.g. upon termination of employment).
Encryption and data protection
- Encryption of Personal Data in transit, using industry-standard protocols (e.g. TLS);
- Encryption of Personal Data at rest, where supported by the underlying hosting and cloud infrastructure;
- Logical segregation of Customer Data, including the Context Layer, from the data of other customers of the Processor.
Infrastructure and network security
- Hosting of the Platform on reputable cloud infrastructure providers, with data centres located within the European Economic Area unless otherwise agreed or required (e.g. in connection with a specific AI Tool or Inference provider);
- Firewalls, network segmentation and intrusion detection/prevention measures to protect the Platform's infrastructure;
- Regular security patching and vulnerability management for systems supporting the Platform;
- Protection against malicious code, including malware and virus scanning where applicable to the Processor's systems.
Availability and resilience
- Regular back-ups of Personal Data processed on the Platform, performed at intervals appropriate to the volume and criticality of the data, and stored on systems independent of the primary production environment;
- Periodic testing of back-up restoration procedures to verify data integrity and recoverability;
- Business continuity and disaster recovery measures designed to restore availability of the Platform and Personal Data within a reasonable timeframe following an incident.
Organizational measures
- Confidentiality undertakings binding on all personnel, agents and contractors of the Processor with access to Personal Data, consistent with Article 11 of the Terms;
- Internal policies and training for personnel on data protection and information security practices;
- Due diligence and contractual data protection obligations imposed on any Sub-processor engaged by the Processor, including AI Tool and Inference providers, prior to granting such Sub-processor access to Personal Data;
- A documented incident response procedure enabling the Processor to detect, assess and notify the Customer of any Personal Data breach without undue delay.
Data minimization and retention
- Retention of Personal Data only for the duration of the Agreement and any applicable post-termination retention period set out in Annex I;
- Secure deletion or anonymization of Personal Data upon expiry of the applicable retention period.
Monitoring and accountability
- Logging and monitoring of access to systems processing Personal Data, to the extent technically feasible;
- Maintenance of records of Processing activities carried out on behalf of the Customer;
- Cooperation with the Customer's verification and audit rights under Article 12.2 of the DPP.
Annex III – List of Sub-processors
| Sub-processor | Purpose | Incorporation Location | Processing Location | Transfer Justification |
|---|---|---|---|---|
| Scaleway S.A.S. | Cloud hosting and infrastructure services, including hosting of the Platform, databases, object storage and Customer Data | France | EEA | Not applicable — processing occurs within the EEA |
| Google Cloud EMEA Limited (Google Workspace) | Business email and collaboration services used for customer support and service administration | Ireland | EEA | Not applicable — processing occurs within the EEA |
| Slack Technologies LLC | Customer support and operational communication | Ireland | US | EU-U.S. Data Privacy Framework |
| OpenAI Ireland Ltd. | AI inference for processing, extracting, structuring and/or evaluating Customer Data | Ireland | United States and other locations used by OpenAI and its sub-processors, unless regional processing is configured | Standard Contractual Clauses (EU Commission Decision 2021/914), supplemented as required |
| Granola, Inc. | AI-assisted meeting transcription and note-taking for customer meetings, support and operational communication | US | US | Standard Contractual Clauses (EU Commission Decision 2021/914), supplemented as required |