My AI CouncilMy AI CouncilVolver al inicio

Data Processing Agreement (DPA)

Last updated: July 2026

Note: in case of any discrepancy between versions, the Spanish version prevails.

This Data Processing Agreement (the «DPA» or «Agreement») governs the relationship between the client engaging or using My AI Council (the «Controller») and My AI Council (the «Processor») where the Controller uses the service to process personal data of third parties: its employees, its customers or any person whose data it includes in its queries and documents. It complements the Terms of use and the Privacy policy, and is deemed accepted when the Controller first enters a third party’s personal data into the platform.

1. Parties and definitions

On the one hand, the Data Controller is the client, whether a natural or legal person, who engages or uses the service and places on the platform personal data of third parties over which it holds ownership or a legitimate interest in the processing.

On the other hand, the Data Processor is Tarraco App Lab, S.L.U. (in incorporation), owner of My AI Council (a registered trade mark owned by it), with registered office at C/ Pau Claris, 2 - 43005 Tarragona (Spain). Contact address: privacidad@tarracoapplab.com.

The definitions in Article 4 of Regulation (EU) 2016/679 (GDPR) and in Spanish Organic Law 3/2018 (LOPDGDD) apply.

2. Subject matter, duration and nature of the processing

Subject matter. Processing by the Processor, on behalf of the Controller, of the personal data the Controller places on the platform for the provision of the services engaged.

Duration. The duration of the processing coincides with the duration of the contractual service relationship, subject to any subsequent mandatory legal retention.

Nature. Automated processing on cloud infrastructure, with encryption in transit and at rest, in accordance with the technical and organisational measures described in clause 6.

Purpose. Solely the provision of the services engaged —querying the council of models, generating and storing conversations and documents, and the technical support requested by the Controller— without using the data for its own purposes or to train models.

3. Categories of data and of data subjects

The categories of personal data processed and the data subjects affected depend on the content the Controller chooses to include. The most common are:

  • User accounts. Data subjects: the people in the Controller’s organisation with access to the service. Data: name, email address, session identifiers and language and configuration preferences.
  • Query content. Data subjects: any person whose data appears in the text or documents the Controller sends to the council of models. Data: whatever the Controller chooses to include.
  • Billing. Data subjects: the contact person and the subscription holder. Data: name or company name, tax ID, registered address and payment history. Full card details are processed directly by the payment provider; the Processor does not receive them.

The Controller undertakes not to place on the platform special categories of data (racial origin, health, ideology, sex life or orientation, genetic or biometric data) except where strictly necessary and with an appropriate legal basis, and to notify the Processor in advance so that the corresponding enhanced measures can be activated. Note that query content is transmitted to the artificial intelligence model providers listed in clause 5.

4. Obligations of the Processor

The Processor undertakes to:

  • Process personal data only in accordance with the Controller’s documented instructions, including those relating to international transfers, unless required to do otherwise by Union or Member State law, in which case it will notify the Controller before processing, unless legally prohibited.
  • Ensure that personnel with access to the data have committed themselves to confidentiality, through a contractual undertaking and periodic training. The duty of confidentiality survives termination of the relationship.
  • Adopt the technical and organisational measures required by Article 32 GDPR, as detailed in clause 6.
  • Not subcontract the processing to third parties without the Controller’s prior authorisation, general or specific. Signature of this DPA constitutes general authorisation for the sub-processors in clause 5, with the right to object to the addition of new sub-processors.
  • Assist the Controller with appropriate technical and organisational measures in responding to data subjects’ rights (access, rectification, erasure, restriction, objection and portability). Where a data subject addresses a request to the Processor, it will be forwarded to the Controller within a maximum of 5 calendar days.
  • Assist the Controller in complying with its obligations under Articles 32 to 36 GDPR: security, breaches, impact assessments and prior consultation.
  • Notify the Controller, without undue delay and within a maximum of 48 hours of becoming aware, of any personal data breach, describing the nature of the breach, the data and categories of data subjects affected, the likely consequences and the measures taken or proposed.
  • Make available to the Controller, upon reasonable request and with at least 4 weeks’ notice, all information necessary to demonstrate compliance with Article 28 GDPR, and allow audits once a year, during business hours and without interrupting the service.
  • Return or delete, at the Controller’s choice, all personal data once the service has ended, except for copies strictly required by applicable law. Return will be made in a structured, commonly used format (JSON or Markdown) and deletion documented in writing, within a maximum of 90 calendar days from termination of the contract.

5. Authorised sub-processors

The Controller grants the Processor general authorisation to use the following sub-processors, all bound by a GDPR-compatible contract:

  • Artificial intelligence model providers (including Anthropic, OpenAI and Google), which process the content of each query in order to return the response. They are engaged under enterprise terms that exclude the use of content to train models.
  • Supabase Inc.: authentication, database and storage. Data hosted in the EU region (Frankfurt). Company located in the United States, under standard contractual clauses.
  • Netlify Inc.: hosting and serverless functions. Located in the United States, under standard contractual clauses and supplementary measures.
  • Stripe Payments Europe Ltd.: subscription payment processing. Located in Ireland (EEA).
  • Brevo SAS: transactional email delivery. Located in France (EEA).

The Processor will give the Controller at least 30 calendar days’ notice of any addition or replacement of a sub-processor. The Controller may object on reasoned grounds within that period and, if the objection is reasonable, the Processor must offer an alternative or the Controller may terminate the contract without penalty. The current list of model providers appears in the Privacy policy.

6. Technical and organisational measures (Art. 32 GDPR)

Encryption. TLS 1.2/1.3 mandatory on all communications, with HSTS enabled. AES-256 at rest for the database and storage. Passwords hashed with bcrypt or equivalent.

Access control. Row-Level Security in the database: each user can only access their organisation’s data. Rotatable and revocable API keys, session tokens with expiry, administrative access with mandatory multi-factor authentication and least-privilege principle. Credentials and secrets kept out of the codebase, in the provider’s encrypted environment variables.

Resilience and availability. Automatic backups with 7 to 30 days’ retention depending on plan, infrastructure with the cloud provider’s availability SLA, and a basic continuity plan with recovery time and recovery point objectives under 24 hours.

Staff confidentiality. Perpetual confidentiality undertaking signed by anyone with access to systems, periodic data protection and security training, and revocation of access upon termination of the employment relationship.

Verification and auditing. Periodic review of logs and dependencies, penetration testing whenever a new critical component is introduced, and an internal register of incidents and breaches with analysis and corrective measures.

7. International transfers

Where a sub-processor is located outside the European Economic Area, the Processor will apply the safeguards provided for in Chapter V GDPR: in particular, the standard contractual clauses approved by the European Commission in Decision 2021/914, supplemented by the additional measures derived from the impact assessment required by the Schrems II judgment. The Processor will make available to the Controller a copy of the safeguards applied to any international transfer, upon reasonable request.

8. Security breach: detailed procedure

In the event of a breach affecting the Controller’s personal data:

  1. The Processor makes an internal record of the incident with a detection timestamp.
  2. Within a maximum of 48 hours it notifies the Controller by email at the designated contact, with a full description of the incident.
  3. The Processor immediately adopts reasonable corrective measures and keeps the Controller informed of developments.
  4. The Controller decides whether notification to the Spanish Data Protection Agency (Art. 33 GDPR) and to data subjects (Art. 34 GDPR) is appropriate. The Processor provides technical and documentary assistance for that notification.
  5. Following resolution, both parties document the lessons learned and any additional measures adopted.

9. Audit

The Controller may audit compliance with this DPA once a year, with at least 4 weeks’ prior written notice, during business hours and without interrupting service provision. The audit may not, under any circumstances, extend to the data of other client organisations.

To minimise the impact, the Processor may offer a current external audit report (ISO 27001, SOC 2 or equivalent). Costs are borne by the Controller, unless the audit reveals material breaches by the Processor, in which case the Processor bears them.

10. Liability and financial arrangements

Each party is liable for damage arising from a breach of its obligations, in accordance with Article 82 GDPR and other applicable legislation. The limitation of liability and indemnity regime is governed by the general terms of service. The Processor will maintain professional civil liability insurance appropriate to the volume of the service.

11. Duration and termination

This DPA remains in force for as long as the Controller’s contractual relationship with My AI Council for the processing of third-party personal data continues. Termination of the main contract entails termination of the DPA, without prejudice to obligations that by their nature survive: perpetual staff confidentiality and legal data retention.

12. Changes

The Processor may modify this DPA where required by a change in legislation or a substantial improvement in security measures. Changes will be published on this page with the revision date and notified to the Controller with reasonable notice. The Controller may object on reasoned grounds; if the objection is not resolved by agreement, it may terminate the contract without penalty.

13. Applicable law and jurisdiction

This DPA is governed by Spanish law (GDPR, LOPDGDD and other applicable legislation). The parties submit, expressly waiving any other jurisdiction, to the competent Courts and Tribunals of Spain in accordance with the applicable procedural rules.

My AI Council
Legal noticePrivacyCookiesTermsData Processing AgreementContactDownloadsUser guideNewsletter

© 2026 My AI Council · All rights reserved · Web/App developed, using AI tools, by the Tarraco App Lab web-design team, in the EU.

C/ Pau Claris, 2 - 43005 Tarragona (Spain)·(+34) 877 64 12 52