Data Processing Agreement

Version 1.0, effective 8 September 2026.

This agreement (the "Agreement") is entered into between:

  • the Customer, being the company identified in the subscription contract or, failing that, in the account created on the Agentique platform (the "Controller"), and
  • ITAILORS - SOFT S.R.L., a Romanian limited liability company, tax ID (CUI) 48450662, Trade Register no. J2/1018/2023, registered office at Calea Aurel Vlaicu, Arad, Arad County, Romania ("iTailors" or the "Processor").

The Agreement supplements the contract for the provision of the Agentique platform (the "Main Contract") and governs the processing of personal data that iTailors carries out on the Controller's behalf, in accordance with Article 28 of Regulation (EU) 2016/679 (the "GDPR") and Romanian Law no. 190/2018.

1. Definitions

Terms defined in Article 4 GDPR have the same meaning in this Agreement. "Customer Data" means the personal data contained in the documents, conversations, memories, entities and other content that the Controller or its users upload to or generate in their Agentique workspace. "Sub-processor" means any third party engaged by iTailors to process Customer Data.

2. Roles of the parties

2.1. For Customer Data, the Controller determines the purposes and means of processing and iTailors processes solely on its behalf.

2.2. For user account data (name, email, role, language, activity logs) and billing data, iTailors is an independent controller under the Privacy Policy published at agentique.eu. Such data falls outside this Agreement.

3. Subject matter and duration

3.1. Subject matter: provision of the Agentique platform, which stores and indexes the documents uploaded by the Controller, reads them with the help of AI models and answers users' questions citing the source, extracts data into user-defined tables, runs scheduled workflows and keeps memories across conversations.

3.2. Duration: the term of the Main Contract, plus the period needed to delete or return the data under Section 12.

4. Nature and purpose of processing

4.1. Operations: collection (upload), storage, organisation, indexing, optical character recognition (OCR) of scanned documents, generation of vector representations (embeddings), retrieval, extraction, structuring, making available to the Controller's authorised users, and erasure.

4.2. The sole purpose is the provision of the service to the Controller. iTailors does not process Customer Data for its own purposes, does not use it to train AI models, does not sell it and does not make it available to third parties other than the sub-processors listed in Annex 1.

4.3. Optional modules. Google Drive / Google Sheets, SPV / e-Factura ANAF, the Tender Radar (SEAP/SICAP), the Company File, programmatic MCP access and messaging channels (WhatsApp, Messenger and Slack, connected through the Controller's own accounts; the data received consists of the messages the Controller's users send on that channel) are enabled only by the Controller. By default only the in-app chat and the embeddable assistant (iframe) are active. Enabling them constitutes a documented instruction within the meaning of Section 6.

5. Types of data and categories of data subjects

5.1. Types of data: any personal data in the Controller's documents (identification, contact, professional, contractual and financial data, CV and invoice data, correspondence) and data derived from it (table extractions, memories, assistant answers, recorded decisions). Special categories of data (Article 9 GDPR) may be uploaded only where the Controller has its own legal basis; iTailors neither requests nor specifically identifies them.

5.2. Data subjects: the Controller's employees, contractors, customers, suppliers and partners; representatives of contracting authorities whose contact details are published on SEAP/SICAP; any other person mentioned in the uploaded documents.

6. Controller's instructions

6.1. iTailors processes Customer Data only on the Controller's documented instructions: the Main Contract, this Agreement and the Controller's own workspace configuration (documents uploaded, modules enabled, scheduled workflows, users invited and their roles).

6.2. Further instructions are given in writing to the support address shown on the website. If iTailors considers that an instruction infringes the GDPR or other applicable law, it informs the Controller without delay and may suspend that instruction until the matter is clarified.

6.3. iTailors processes data outside the instructions only where required by Union or Romanian law, in which case it informs the Controller before processing unless the law prohibits such information.

7. Confidentiality of personnel

Persons authorised by iTailors to process Customer Data are bound by contractual confidentiality obligations or an appropriate statutory duty of confidentiality. Their access is limited to what is strictly necessary to operate, maintain and troubleshoot the platform or to provide support requested by the Controller.

8. Security of processing

iTailors implements the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks to data subjects (Article 32 GDPR). The measures may be updated provided the overall level of security is not reduced.

9. Sub-processors

9.1. The Controller gives general authorisation for the sub-processors listed in Annex 1.

9.2. iTailors gives the Controller at least 30 days' notice, by email or in the application, before adding or replacing a sub-processor. The Controller may object in writing, stating its reasons, within that period. If the parties cannot find a reasonable solution, the Controller may terminate the Main Contract for the affected feature without penalty, with a pro rata refund of any fees paid in advance.

9.3. iTailors imposes on each sub-processor, by contract, data protection obligations at least equivalent to those in this Agreement and remains liable to the Controller for the sub-processor's performance.

9.4. Sub-processors enabled at the Controller's choice (for example Google, for Drive / Sheets) process data only between connection and revocation of access, which can be done at any time.

10. Assistance with data subject rights

10.1. Taking into account the nature of the processing, iTailors assists the Controller with appropriate technical and organisational measures in responding to data subject requests (access, rectification, erasure, restriction, portability, objection).

10.2. The Controller can itself search, export and delete documents, conversations, memories and entities from the application. For requests that cannot be handled in the application, iTailors responds to the Controller within 10 business days.

10.3. If a data subject contacts iTailors directly about Customer Data, iTailors refers them to the Controller, informs the Controller without delay and does not respond on the merits except on its instruction.

11. Personal data breaches and other assistance

11.1. iTailors notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data. The notice goes to the workspace owner's email address (owner role) and includes, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases.

11.2. iTailors cooperates with the Controller in investigating, containing and remedying the breach and in any communications to the Romanian supervisory authority (ANSPDCP) and to data subjects that the Controller deems necessary.

11.3. On request, iTailors provides the information reasonably needed for a data protection impact assessment (Article 35 GDPR) and prior consultation with the authority (Article 36 GDPR), insofar as it relates to the platform.

12. Deletion and return of data

12.1. During the term, the Controller may at any time delete documents, conversations, memories and entities from the application.

12.2. On termination of the Main Contract, iTailors deletes Customer Data from production systems within 30 days of termination, except for data it is legally required to retain (billing documents, 10 years under Romanian Accounting Law no. 82/1991). Before deletion, the Controller may request an export of its documents and structured data in the formats available in the application.

12.3. Backup copies are removed according to the backup rotation cycle, within a further 7 days after deletion from production; until then they remain protected by the measures in Annex 2 and are not used for any other purpose.

12.4. On request, iTailors confirms deletion in writing.

13. Audit and information

13.1. iTailors makes available the information necessary to demonstrate compliance with Article 28 GDPR: the measures in Annex 2, the sub-processor list, AWS compliance reports (through AWS Artifact) and answers to the Controller's security questionnaires.

13.2. The Controller, or an independent auditor bound by confidentiality, may carry out an audit at most once a year, and additionally when a supervisory authority requires it or after a personal data breach, on 30 days' prior notice, during business hours and without compromising the security of other customers. Audits are conducted through document review and interviews; physical access to AWS infrastructure is replaced by AWS compliance reports.

13.3. Audit costs are borne by the Controller unless the audit reveals a material non-compliance on the part of iTailors.

14. International transfers

14.1. In normal operation, Customer Data is stored and processed exclusively within the European Union: infrastructure in the AWS eu-central-1 region (Frankfurt, Germany) and AI models through Amazon Bedrock in EU AWS regions. No transfer to a third country takes place.

14.2. If the Controller connects Google Drive or Google Sheets, data accessed through that integration may be transferred to Google in the United States under Google's standard contractual clauses and its certification under the EU-US Data Privacy Framework. The Controller alone decides whether to enable the integration and is responsible for assessing the transfer.

14.3. Any other transfer takes place only on the Controller's instruction and in compliance with Chapter V GDPR.

15. Liability

15.1. Each party is liable for damage caused by its own breach of the GDPR and of this Agreement, in accordance with Article 82 GDPR.

15.2. The limitation of liability in the Main Contract (the amount paid by the Controller in the 12 months preceding the event giving rise to the claim) also applies to this Agreement, except for liability for wilful misconduct or gross negligence and where the law does not permit limitation.

15.3. The Controller warrants that it has a legal basis for the data it uploads and that it has informed data subjects in accordance with Articles 13 and 14 GDPR.

16. Final provisions

16.1. The Agreement is governed by Romanian law; disputes fall under the jurisdiction of the Romanian courts.

16.2. In case of conflict between the Agreement and the Main Contract, the Agreement prevails on data protection matters.

16.3. The Agreement is accepted together with the Main Contract when the workspace is created; the version and date of acceptance are recorded. Changes are notified 30 days in advance by email or in the application.

16.4. Data protection contact: the address shown at agentique.eu under "Support contact". iTailors has not appointed a data protection officer, as its activities do not require one.

Annex 1. Authorised sub-processors

Sub-processorServiceProcessing locationCondition
Amazon Web Services EMEA SARLHosting (S3, RDS MySQL, OpenSearch, ECS, Redis, CloudWatch) and AI models through Amazon BedrockEU: eu-central-1 region (Frankfurt); Bedrock inference in EU AWS regionsPermanent
Google (Google Ireland Limited / Google LLC)Google Drive and Google SheetsEU and USA (standard contractual clauses, EU-US Data Privacy Framework)Only if the Controller connects the integration
SMTP server configured by iTailorsTransactional email (invitations, digests, alerts); the sender is the address shown in the messagesAs per iTailors' SMTP configurationPermanent

Annex 2. Technical and organisational measures

  1. Tenant isolation. Each Controller has its own workspace with a separate search index, a separate prefix in file storage and separate database records. Users of one customer cannot access another customer's data.

  2. Infrastructure. The platform runs in AWS, eu-central-1 region (Frankfurt), on the services listed in Annex 1. AWS compliance reports (ISO 27001, SOC 2) are available through AWS Artifact.

  3. Encryption. All traffic is encrypted with TLS. Data at rest is encrypted: files in S3 with server-side encryption (AES-256) on all buckets, the RDS database is encrypted, and application secrets are protected with AWS KMS.

  4. User access control. Access by account and invitation code; passwords are stored only as hashes. Workspace roles: owner, admin, member, viewer, with differentiated permissions. The Controller invites users and revokes access from the application.

  5. API keys (MCP access). Issued by the Controller and stored only as hashes; they cannot be recovered from the system afterwards and can be revoked at any time.

  6. AI processing. Anthropic Claude and Amazon Titan models are called through Amazon Bedrock in EU regions. Bedrock does not store prompts or responses and does not use them for training; data does not reach Anthropic. iTailors does not train models on Customer Data.

  7. Logging. Technical logs are kept in AWS CloudWatch with a retention of 7 days. The application keeps user activity logs (questions, documents uploaded, decisions recorded with user name and date), visible to the Controller.

  8. Backups. The database has automated daily backups, retained for 7 days; files are kept in AWS S3, durable storage replicated across several availability zones of the Frankfurt region. Backups remain in the eu-central-1 region.

  9. iTailors staff access. Restricted to the people who operate the platform, on a need-to-know basis, under a duty of confidentiality. Document content is not accessed except for troubleshooting or at the customer's request.

  10. Integrations and automation. Google Drive / Sheets use OAuth in the Controller's own Google account; SPV / e-Factura uses the Controller's qualified certificate. Automated actions are enabled explicitly by the Controller and can be stopped at any time.