Data Processing Agreement (DPA)
Note on company incorporation: Eniteo AI is being incorporated as an Estonian company (OÜ — Osaühing). This DPA is operative and binding. Full company details will be updated on completion of registration.
This Data Processing Agreement ("DPA") is entered into between Eniteo AI OÜ (company being incorporated in Estonia) acting as Data Processor (Art. 28 GDPR) and the Client using the Eniteo AI Services as Data Controller. The DPA supplements the Terms of Service and is activated automatically upon acceptance of the Terms. Consent to the DPA is recorded at registration and — for AI processing — at onboarding.
Art. 1 — Parties and Roles
| GDPR Role | Party | Primary responsibility |
|---|---|---|
| Data Controller (Art. 4.7 GDPR) |
The Client (legal entity or professional registered for the service) | Determines purposes and means of processing personal data within its own business activities |
| Data Processor (Art. 4.8 GDPR) |
Eniteo AI OÜ (company being incorporated in Estonia) | Processes personal data on behalf of the Client exclusively for the purpose of providing the Services and in accordance with the Controller's documented instructions |
Art. 2 — Scope and Nature of Processing
| Aspect | Description |
|---|---|
| Subject matter | AI-optimised content generation (AEO/GEO), domain analysis, knowledge base management, AI citation monitoring |
| Duration | Duration of the service contract; termination on account deletion |
| Nature of processing | Collection, storage, analysis, structuring, AI processing, transmission to sub-processors |
| Purpose | Exclusive: provision of Eniteo AI Services as described in the Terms |
| Categories of data | Company data (name, sector, domain, description, products, competitors), generated content (articles, answers, questions) |
| Data subjects | Clients' authorised users (employees, collaborators) and — indirectly — company reference contacts |
Art. 3 — Processor Obligations
Eniteo AI undertakes to:
- Process personal data only on documented instructions from the Controller, including for transfers to third countries.
- Ensure that persons authorised to process personal data have committed to confidentiality or are under appropriate statutory obligations.
- Implement technical and organisational security measures pursuant to Art. 32 GDPR.
- Respect the conditions for engaging sub-processors pursuant to Art. 28.2-3 GDPR.
- Assist the Controller in responding to requests to exercise data subject rights.
- Assist the Controller in ensuring compliance with Arts. 32–36 GDPR (security, breach notification, DPIA).
- Delete or return all personal data at the choice of the Controller upon termination of the service.
- Provide all information necessary to demonstrate compliance with Art. 28 GDPR.
Art. 4 — Sub-processors
The Client grants Eniteo AI general authorisation to engage the following sub-processors:
| Sub-processor | Country | Processing | Safeguard |
|---|---|---|---|
| Anthropic PBC | USA | AI content generation (Claude API) | SCCs Art. 46 GDPR |
| OpenAI LLC | USA | Question generation, embeddings | SCCs Art. 46 GDPR |
| Hetzner Online GmbH | Germany (EU) | Hosting, database, storage | No extra-EU transfer |
| Stripe Inc. / Stripe Payments Europe Ltd. | USA / Ireland (EU) | Payment processing | SCCs; supervised by Central Bank of Ireland |
| Resend Inc. | USA | Transactional emails | SCCs Art. 46 GDPR |
Eniteo will notify the Client of any intended changes to sub-processors at least 14 days in advance, giving the Client the opportunity to object. Sub-processor contracts impose data protection obligations equivalent to those in this DPA.
Art. 5 — Security Measures (Art. 32 GDPR)
- TLS 1.3 encryption in transit for all endpoints.
- AES-256 encryption for backups and data at rest.
- Bcrypt hashing (cost 12) for passwords.
- TOTP two-factor authentication available for all accounts.
- Role-based access control (RBAC) with least privilege.
- Daily automated backups with integrity verification.
- Audit logging for data access and modifications.
- Rate limiting and DDoS protection on all endpoints.
Art. 6 — Data Breach Notification
In the event of a personal data breach, Eniteo will notify the Controller without undue delay and, where possible, within 72 hours of becoming aware, in accordance with Art. 33 GDPR. The notification will include, to the extent available: the nature of the breach, categories and approximate number of data subjects concerned, likely consequences, and measures taken or proposed.
Art. 7 — Transfers Outside the EEA
Where personal data is transferred outside the European Economic Area to sub-processors in third countries (Anthropic, OpenAI, Resend, Stripe Inc.), transfers are subject to Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46 GDPR, providing appropriate safeguards for the rights of data subjects.
Art. 8 — Governing Law
This DPA is governed by Estonian law and GDPR Regulation (EU) 2016/679. Disputes are subject to the exclusive jurisdiction of Estonian courts.
Art. 9 — Contact
Eniteo AI OÜ
Email: [email protected]
DPA requests: [email protected]