Last reviewed 2026-05-17. Served live at /legal/dpa.
Template Data Processing Agreement under Art. 28(3) GDPR between the Customer (controller) and Vortx AI Private Limited (processor) for use of the hosted eudr.dev instance at eudr.dev. A signable PDF version is available on request to avijeet@vortx.ai.
eudr.dev service.emem.dev, operated by Vortx AI Private Limited, India, is a sub-processor for satellite-derived signal lookup (Art. 28(2) and 28(4) GDPR).The Processor will process operator, supplier, plot, and product data on the Customer's instructions in order to:
No special categories of personal data under Art. 9 GDPR are processed. No data concerning criminal convictions or offences under Art. 10 GDPR are processed.
The Processor will, in accordance with Art. 28(3)(a) to (h) GDPR:
/privacy.The Processor will notify the Customer of a personal-data breach without undue delay, and in any event within 72 hours after becoming aware of it, to enable the Customer's notification to the competent supervisory authority under Art. 33(1) GDPR. The notification will contain the elements listed in Art. 33(3) GDPR to the extent then known.
Current sub-processors are listed at /legal/subprocessors. The Customer's signature on this Agreement constitutes prior general written authorisation under Art. 28(2) GDPR for those sub-processors. The Processor will give the Customer at least 30 days' notice of any intended change to the list and the Customer may object on data-protection grounds within that period (Annex 3).
eu-central-1 compute, eu-north-1 SES).emem.dev for satellite-signal lookup are intra-entity remote processing: eudr.dev and emem.dev are operated by the same legal person (Vortx AI Private Limited), so under EDPB Guidelines 05/2021 the flow is not a Chapter V transfer to another controller or processor and SCCs are structurally unavailable for it. The full analysis, including the supplementary measures protecting the flow (identity stripping at source, TLS, signed content-addressed responses, 5-ha DPIA observability), is the Transfer impact assessment, reviewed annually. The data is restricted to plot geometry, HS code, country, and quantity; no operator or supplier identity is sent. Art. 6(1)(c) GDPR (the EUDR due-diligence duty) remains the processing basis; Art. 49(1)(d) is retired as the transfer basis and cited only for completeness should a supervisory authority take a broader view of "transfer".Any liability of the Processor under this DPA is subject to the limitation-of-liability clause in the Terms of Service. Liability under this DPA does not aggregate with liability under the Terms — the cap stated in the Terms applies to the entire commercial relationship between the Customer and the Provider, including all claims under or in connection with this DPA.
For the avoidance of doubt, and consistent with Art. 28 and Art. 4(7) and 4(8) GDPR: the Customer is the controller of the personal data processed under this Agreement and bears the controller's obligations under Art. 5, 6, 13, 14, 24 and 35 GDPR. The Processor is a processor only and acts solely on the Customer's documented instructions under § 5(a) above. The Processor is not a joint controller within the meaning of Art. 26 GDPR.
This Agreement terminates with the underlying subscription.
This Agreement is governed by the same law and jurisdiction as the Terms of Service (Section 7): Indian law, exclusive jurisdiction of the competent courts of Jharkhand, India. EEA-based Customers retain all non-waivable rights under GDPR (Arts. 12–22, 77–79) regardless of this choice.
| Item | Value |
|---|---|
| Subject matter | Compilation of an Annex II Due Diligence Statement under Reg. (EU) 2023/1115 |
| Duration | Term of subscription + retention under § 7 of this Annex |
| Nature and purpose | Validation, satellite-signal lookup, risk computation, signed receipt issuance |
| Type of personal data | Operator details, plot geolocation, supplier contacts, account-management data |
| Categories of data subjects | Operators, smallholders, suppliers, downstream contacts, authorised users |
| Lawful basis (Customer side) | Art. 6(1)(c) GDPR — legal obligation under Reg. 2023/1115 |
| Place of processing | AWS eu-central-1 (compute, primary data store), AWS eu-north-1 (transactional email via SES) |
| Retention | 7 days default in the engine's working memory (EUDR_TASK_RETENTION_DAYS); the Customer's regulatory archive sits outside the engine and is retained for 5 years under Reg. 2023/1115 Art. 4(3) |
| Control | Measure |
|---|---|
| Transport | TLS 1.2+ enforced on every external endpoint |
| At-rest encryption | AWS KMS-managed keys for the primary store and for SES message storage |
| Authenticity of output | ed25519-signed receipts over canonical JSON; CID re-derivable; offline verify path documented in PRIVACY.md |
| Authentication | Magic-link sign-in only (no password vault); 32-byte CSPRNG token, SHA-256 at rest, 15-minute TTL, single use |
| Session security | __Host- prefix cookie, HttpOnly, Secure, SameSite=Lax; IP-drift detection |
| CSRF | Double-submit X-Requested-With: eudr-app header required for cookie-authenticated mutations |
| Rate-limit | 5 magic links per email / 30 per IP per hour |
| Audit log | Append-only audit_log table; subjects pseudonymised under a server-pinned salt; no PII in free text |
| Retention sweep | Hourly background sweep enforces task-memory horizon and deletes already-erased shipment rows |
| Principle of least privilege | Account-scoped API keys; per-org isolation; production-key boot refusal when dev key is present |
| Data residency (primary) | EU (Frankfurt, eu-central-1) for the primary store; AWS SES in Stockholm (eu-north-1) for outbound mail |
| Backups | KMS-encrypted, retention aligned to § 7; restore tested at least annually |
| Vulnerability handling | avijeet@vortx.ai per /.well-known/security.txt; CVE intake and triage logged |
The list of approved sub-processors is maintained at /legal/subprocessors and re-published with each change.