Independent AI agent for EU Deforestation Regulation compliance, not affiliated with the EU. Scope & disclaimer →
eudr.dev

Data Processing Agreement

Last reviewed 2026-05-17. Served live at /legal/dpa.

Template Data Processing Agreement under Art. 28(3) GDPR between the Customer (controller) and Vortx AI Private Limited (processor) for use of the hosted eudr.dev instance at eudr.dev. A signable PDF version is available on request to avijeet@vortx.ai.

Preamble

1. Subject matter and duration

2. Nature and purpose of processing

The Processor will process operator, supplier, plot, and product data on the Customer's instructions in order to:

3. Type of personal data

No special categories of personal data under Art. 9 GDPR are processed. No data concerning criminal convictions or offences under Art. 10 GDPR are processed.

4. Categories of data subjects

5. Processor's obligations

The Processor will, in accordance with Art. 28(3)(a) to (h) GDPR:

Breach notification

The Processor will notify the Customer of a personal-data breach without undue delay, and in any event within 72 hours after becoming aware of it, to enable the Customer's notification to the competent supervisory authority under Art. 33(1) GDPR. The notification will contain the elements listed in Art. 33(3) GDPR to the extent then known.

6. Sub-processors

Current sub-processors are listed at /legal/subprocessors. The Customer's signature on this Agreement constitutes prior general written authorisation under Art. 28(2) GDPR for those sub-processors. The Processor will give the Customer at least 30 days' notice of any intended change to the list and the Customer may object on data-protection grounds within that period (Annex 3).

7. International transfers

8. Liability and term

Any liability of the Processor under this DPA is subject to the limitation-of-liability clause in the Terms of Service. Liability under this DPA does not aggregate with liability under the Terms — the cap stated in the Terms applies to the entire commercial relationship between the Customer and the Provider, including all claims under or in connection with this DPA.

For the avoidance of doubt, and consistent with Art. 28 and Art. 4(7) and 4(8) GDPR: the Customer is the controller of the personal data processed under this Agreement and bears the controller's obligations under Art. 5, 6, 13, 14, 24 and 35 GDPR. The Processor is a processor only and acts solely on the Customer's documented instructions under § 5(a) above. The Processor is not a joint controller within the meaning of Art. 26 GDPR.

This Agreement terminates with the underlying subscription.

9. Governing law

This Agreement is governed by the same law and jurisdiction as the Terms of Service (Section 7): Indian law, exclusive jurisdiction of the competent courts of Jharkhand, India. EEA-based Customers retain all non-waivable rights under GDPR (Arts. 12–22, 77–79) regardless of this choice.


Annex 1 — Details of processing

ItemValue
Subject matterCompilation of an Annex II Due Diligence Statement under Reg. (EU) 2023/1115
DurationTerm of subscription + retention under § 7 of this Annex
Nature and purposeValidation, satellite-signal lookup, risk computation, signed receipt issuance
Type of personal dataOperator details, plot geolocation, supplier contacts, account-management data
Categories of data subjectsOperators, smallholders, suppliers, downstream contacts, authorised users
Lawful basis (Customer side)Art. 6(1)(c) GDPR — legal obligation under Reg. 2023/1115
Place of processingAWS eu-central-1 (compute, primary data store), AWS eu-north-1 (transactional email via SES)
Retention7 days default in the engine's working memory (EUDR_TASK_RETENTION_DAYS); the Customer's regulatory archive sits outside the engine and is retained for 5 years under Reg. 2023/1115 Art. 4(3)

Annex 2 — Technical and organisational measures (Art. 32 GDPR)

ControlMeasure
TransportTLS 1.2+ enforced on every external endpoint
At-rest encryptionAWS KMS-managed keys for the primary store and for SES message storage
Authenticity of outputed25519-signed receipts over canonical JSON; CID re-derivable; offline verify path documented in PRIVACY.md
AuthenticationMagic-link sign-in only (no password vault); 32-byte CSPRNG token, SHA-256 at rest, 15-minute TTL, single use
Session security__Host- prefix cookie, HttpOnly, Secure, SameSite=Lax; IP-drift detection
CSRFDouble-submit X-Requested-With: eudr-app header required for cookie-authenticated mutations
Rate-limit5 magic links per email / 30 per IP per hour
Audit logAppend-only audit_log table; subjects pseudonymised under a server-pinned salt; no PII in free text
Retention sweepHourly background sweep enforces task-memory horizon and deletes already-erased shipment rows
Principle of least privilegeAccount-scoped API keys; per-org isolation; production-key boot refusal when dev key is present
Data residency (primary)EU (Frankfurt, eu-central-1) for the primary store; AWS SES in Stockholm (eu-north-1) for outbound mail
BackupsKMS-encrypted, retention aligned to § 7; restore tested at least annually
Vulnerability handlingavijeet@vortx.ai per /.well-known/security.txt; CVE intake and triage logged

Annex 3 — Approved sub-processors and change-notice policy

The list of approved sub-processors is maintained at /legal/subprocessors and re-published with each change.