Skip to main content

DPA · Draft 1.0 · Effective [insert date]

Data Processing Agreement

For business workspaces, the customer organisation is controller and Schmeitzke, operator of the Summa platform, is processor. This Article 28 GDPR agreement covers identity-verified, text-only conversational AI, billing administration, and security operations.

1. Scope and roles

This DPA applies where Summa (Schmeitzke) processes personal data on behalf of the customer in providing the business workspace. Terms such as controller, processor, personal data, processing and personal-data breach have the meanings given in the GDPR.

The customer is controller and Summa is processor for Customer Personal Data. Where the customer acts as processor for another controller, Summa acts as subprocessor and the customer confirms it is authorised to appoint Summa. This DPA prevails over conflicting general contractual provisions concerning personal-data processing.

2. Documented instructions

Summa processes Customer Personal Data only to provide and secure the service, as configured by authorised customer administrators, according to the Agreement and further lawful written instructions, and where required by applicable law. If law requires processing beyond the customer’s instructions, Summa will inform the customer before processing unless the law prohibits this. Summa will notify the customer where it believes an instruction infringes applicable data-protection law.

3. Confidentiality and security

Persons authorised by Summa to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where necessary. Summa maintains the technical and organisational measures in Annex B and will not materially reduce the overall level of security during the term.

4. Subprocessors

The customer gives general written authorisation for the subprocessors in the current Provider and Subprocessor Register. Summa will impose materially equivalent data-protection obligations on each subprocessor, remain responsible as required by law, and provide at least 30 days’ notice of an intended addition or replacement.

The customer may object on reasonable data-protection grounds during the notice period. The parties will attempt a reasonable alternative; if none is available, the customer may terminate the affected service without penalty and receive a proportionate refund of prepaid unused fees.

5. International transfers

Summa will not transfer Customer Personal Data outside the EEA without the customer’s documented authorisation through this DPA or another agreement and a lawful transfer mechanism with any required supplementary measures. Where appropriate, the applicable European Commission standard contractual clauses are incorporated.

6. Assistance with data-subject and compliance obligations

Taking account of the nature of processing, Summa provides reasonable technical and organisational assistance with data-subject requests (access, rectification, erasure, restriction, portability, objection, automated decisions) and with security of processing, breach assessment and notification, DPIAs, prior consultation, and accountability records. Summa will not independently respond concerning Customer Personal Data unless authorised or legally required.

7. Personal-data breaches

Summa will notify the customer without undue delay and, as an internal service target, within 24 hours after confirming a personal-data breach affecting Customer Personal Data. The initial notice includes available information on the nature of the incident, affected systems and data, likely consequences, containment and remediation, and a contact point. Summa preserves relevant evidence and avoids public statements identifying the customer without approval unless legally required.

8. Audit

Summa demonstrates compliance through available documentation (security descriptions, subprocessor information, policies, independent reports where available, and control evidence). If this is insufficient, the customer may request one audit per 12-month period, or an additional audit following a substantiated material incident. Audits must be proportionate, avoid access to other customers’ data, protect security, occur during business hours, use a qualified independent auditor, and provide reasonable notice. The customer bears ordinary audit costs unless the audit identifies a material Summa breach.

9. Return and deletion

  1. During the term, the customer can export available Customer Data.
  2. Following termination, the customer receives at least 30 days to retrieve exportable data, unless immediate deletion is requested or legally required.
  3. Summa deletes Customer Personal Data from active systems within 30 days after the retrieval period.
  4. Protected backup copies expire through the documented backup lifecycle, ordinarily within 35 additional days.
  5. Retained legal or security evidence is isolated, minimised and used only for the retention purpose. Summa provides deletion confirmation on request.

10. Government requests and duration

Summa assesses requests for access to Customer Personal Data, requires valid legal authority, challenges unlawful or disproportionate requests where reasonably possible, discloses only what is legally required, and notifies the customer unless prohibited. This DPA remains effective while Summa processes Customer Personal Data.

Annex A — Processing details

Subject matter
Provision of an organisation-managed, self-hosted AI chat and administration service.
Duration
For the term of the Agreement and the agreed deletion period.
Nature and purpose
Account/access administration, storing and retrieving conversation content, generating AI responses, workspace settings, usage and audit events, security and abuse prevention, support, export and deletion.
Data subjects
Customer employees, contractors, administrators, representatives, users, and individuals mentioned in Customer Data.
Data categories
Identity and contact details, organisation and role information, prompts and conversation content, AI-generated responses, custom instructions, usage/token data, audit and security information, IP addresses and request identifiers, support communications.
Sensitive data
Not required for ordinary operation but may be included by users. The customer must identify lawful sensitive-data use and apply necessary restrictions.

Annex B — Technical and organisational measures

  • Access control: unique accounts, role-based least-privilege permissions, MFA for privileged operational access, joiner/mover/leaver procedures, separation of user/tenant-admin/platform-admin roles.
  • Tenant isolation: tenant-scoped application policy, PostgreSQL row-level security, service-side authorisation checks, cross-tenant access tests.
  • Encryption: TLS in transit, encryption of designated sensitive fields, protected key material, encrypted production backups, key rotation.
  • Network security: external web protection, Kubernetes network policies, private databases/caches/model endpoints, no direct browser-to-model connection.
  • Secure development: source control and review, dependency/container/secret scanning, CI testing, environment separation, controlled production deployment.
  • Logging and audit: security/administrative event logging, encrypted and tamper-evident audit chaining, prompt/completion content excluded from ordinary observability.
  • Availability and recovery: encrypted off-cluster backups, documented RPO/RTO, restoration tests, capacity and health monitoring (see the Beta Schedule for current status).
  • AI-service protection: private authenticated inference endpoint, no undisclosed external model fallback, model/checkpoint change control, model licence and provenance register.
  • Incident management and disposal: detection, containment, evidence preservation, processor-to-controller notification target, active-system deletion, cache invalidation, identity deletion, observability deletion with retry, backup expiry, deletion verification.

Annex C — Data Act exit and switching

The customer may switch provider, move on-premises, export Customer Data and eligible digital assets, and terminate under the Agreement. The ordinary exit notice period will not exceed two months. Following notice, Summa supports a transition period of up to 30 calendar days, and the customer has at least 30 further days to retrieve exportable data.

Exports use structured, commonly used, machine-readable formats (JSON, CSV, documented archives) and cover users/roles, organisation settings, conversations and content, custom instructions, customer-visible usage and audit events, retention settings, and billing references. Export excludes Summa software, model weights, internal security rules, and data belonging exclusively to other customers. Ordinary export and switching are not subject to a punitive exit fee.

Annex D — Beta and availability schedule

The current beta service may have limited capacity, a single active inference replica, maintenance interruptions, lower durability, changing limits, test-mode payments, and no contractual uptime guarantee. Where off-cluster backup is not yet enabled, this is stated in the Order Form; a beta service must not be used as the sole storage location for business-critical information. Paid production status is not represented until encrypted backup and restoration testing are operational.

Versioning and acceptance

Changes to processing categories or material controls require a new DPA version and fresh acceptance by an authorised business representative. DPA acceptance is recorded separately from general platform consent and end-user login. Existing acceptances remain part of the audit history.