Skip to content
Eniteo
  • Monitoring See which AI answers name you Content Articles grounded in verified facts Distribution Publish, then watch for drift Talk to a specialist Scope a programme with a human
  • Pricing
  • Insurance 8 subsectors Finance 6 subsectors Legal 7 subsectors Healthcare 6 subsectors Technology 6 subsectors Professional services 5 subsectors Manufacturing 6 subsectors
  • Blog Research and practice Methodology Our scoring rubric, published in full EU AI Act What the regulation actually requires AI instructions Canonical facts for AI assistants
  • Security How we protect your data Status Live system status Work with us Partners and collaboration Contact Talk to the team
  • 🇮🇹 IT
  • 🇬🇧 EN
  • 🇪🇸 ES
  • 🇫🇷 FR
  • 🇵🇹 PT
Log in Try free
  • Product
  • Monitoring
  • Content
  • Distribution
  • Talk to a specialist
  • Sectors
  • Insurance
  • Finance
  • Legal
  • Healthcare
  • Technology
  • Professional services
  • Manufacturing
  • Resources
  • Blog
  • Methodology
  • EU AI Act
  • AI instructions
  • Company
  • Security
  • Status
  • Work with us
  • Contact
  • Pricing
Log in
🇮🇹 🇬🇧 🇪🇸 🇫🇷 🇵🇹

Data Processing Agreement (DPA)

Version: 3.0  |  Last updated: April 2026  |  Art. 28 GDPR (EU) 2016/679  |  Contact: [email protected]

Note on company incorporation: Eniteo AI is being incorporated as an Estonian company (OÜ — Osaühing). This DPA is operative and binding. Full company details will be updated on completion of registration.

This Data Processing Agreement ("DPA") is entered into between Eniteo AI OÜ (company being incorporated in Estonia) acting as Data Processor (Art. 28 GDPR) and the Client using the Eniteo AI Services as Data Controller. The DPA supplements the Terms of Service and is activated automatically upon acceptance of the Terms. Consent to the DPA is recorded at registration and — for AI processing — at onboarding.

Art. 1 — Parties and Roles

GDPR RolePartyPrimary responsibility
Data Controller
(Art. 4.7 GDPR)
The Client (legal entity or professional registered for the service) Determines purposes and means of processing personal data within its own business activities
Data Processor
(Art. 4.8 GDPR)
Eniteo AI OÜ (company being incorporated in Estonia) Processes personal data on behalf of the Client exclusively for the purpose of providing the Services and in accordance with the Controller's documented instructions

Art. 2 — Scope and Nature of Processing

AspectDescription
Subject matterAI-optimised content generation (AEO/GEO), domain analysis, knowledge base management, AI citation monitoring
DurationDuration of the service contract; termination on account deletion
Nature of processingCollection, storage, analysis, structuring, AI processing, transmission to sub-processors
PurposeExclusive: provision of Eniteo AI Services as described in the Terms
Categories of dataCompany data (name, sector, domain, description, products, competitors), generated content (articles, answers, questions)
Data subjectsClients' authorised users (employees, collaborators) and — indirectly — company reference contacts

Art. 3 — Processor Obligations

Eniteo AI undertakes to:

  • Process personal data only on documented instructions from the Controller, including for transfers to third countries.
  • Ensure that persons authorised to process personal data have committed to confidentiality or are under appropriate statutory obligations.
  • Implement technical and organisational security measures pursuant to Art. 32 GDPR.
  • Respect the conditions for engaging sub-processors pursuant to Art. 28.2-3 GDPR.
  • Assist the Controller in responding to requests to exercise data subject rights.
  • Assist the Controller in ensuring compliance with Arts. 32–36 GDPR (security, breach notification, DPIA).
  • Delete or return all personal data at the choice of the Controller upon termination of the service.
  • Provide all information necessary to demonstrate compliance with Art. 28 GDPR.

Art. 4 — Sub-processors

The Client grants Eniteo AI general authorisation to engage the following sub-processors:

Sub-processorCountryProcessingSafeguard
Anthropic PBCUSAAI content generation (Claude API)SCCs Art. 46 GDPR
OpenAI LLCUSAQuestion generation, embeddingsSCCs Art. 46 GDPR
Hetzner Online GmbHGermany (EU)Hosting, database, storageNo extra-EU transfer
Stripe Inc. / Stripe Payments Europe Ltd.USA / Ireland (EU)Payment processingSCCs; supervised by Central Bank of Ireland
Resend Inc.USATransactional emailsSCCs Art. 46 GDPR

Eniteo will notify the Client of any intended changes to sub-processors at least 14 days in advance, giving the Client the opportunity to object. Sub-processor contracts impose data protection obligations equivalent to those in this DPA.

Art. 5 — Security Measures (Art. 32 GDPR)

  • TLS 1.3 encryption in transit for all endpoints.
  • AES-256 encryption for backups and data at rest.
  • Bcrypt hashing (cost 12) for passwords.
  • TOTP two-factor authentication available for all accounts.
  • Role-based access control (RBAC) with least privilege.
  • Daily automated backups with integrity verification.
  • Audit logging for data access and modifications.
  • Rate limiting and DDoS protection on all endpoints.

Art. 6 — Data Breach Notification

In the event of a personal data breach, Eniteo will notify the Controller without undue delay and, where possible, within 72 hours of becoming aware, in accordance with Art. 33 GDPR. The notification will include, to the extent available: the nature of the breach, categories and approximate number of data subjects concerned, likely consequences, and measures taken or proposed.

Art. 7 — Transfers Outside the EEA

Where personal data is transferred outside the European Economic Area to sub-processors in third countries (Anthropic, OpenAI, Resend, Stripe Inc.), transfers are subject to Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46 GDPR, providing appropriate safeguards for the rights of data subjects.

Art. 8 — Governing Law

This DPA is governed by Estonian law and GDPR Regulation (EU) 2016/679. Disputes are subject to the exclusive jurisdiction of Estonian courts.

Art. 9 — Contact

Eniteo AI OÜ
Email: [email protected]
DPA requests: [email protected]

Eniteo

GEO & AEO for companies in regulated industries.

[email protected]
© 2026 Eniteo AI OÜ Eniteo AI OÜ — Estonia
[email protected]
Product
Monitoring Content Distribution Pricing Sectors Talk to a specialist FAQ Blog Methodology EU AI Act AI instructions
Company
Status Security Work with us
Legal
Privacy Policy Cookie Policy Terms of Service DPA GDPR Rights Contact

We use cookies

We use technical cookies necessary for the site to work and, with your consent, analytics cookies to improve your experience. Read our Cookie Policy and Privacy Policy.