Pursuant to Article 28 GDPR
Data Controller: The customer ("Controller")
Data Processor: [COMPANY_NAME], [ADDRESS] ("Processor", "dunpai")
The Processor processes personal data on behalf of the Controller to provide AI inference with PII protection, as described in the service agreement. Processing continues for the duration of the service agreement.
Individuals whose personal data is contained in the Controller's AI prompts (e.g., customers, employees, business contacts of the Controller).
Email addresses, phone numbers, IBANs, credit card numbers, tax identification numbers, IP addresses, dates, postal codes, and any other personal data present in prompts that is detected by the PII engine.
The Processor shall process personal data only on documented instructions from the Controller, unless required by EU or Member State law.
All persons authorized to process personal data have committed themselves to confidentiality.
Current sub-processors:
The Processor shall inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.
The Processor shall assist the Controller in fulfilling data subject requests (access, rectification, erasure, restriction, portability, objection) through the DSAR API endpoint and compliance reporting tools.
The Processor shall notify the Controller without undue delay (within 48 hours) after becoming aware of a personal data breach.
Upon termination of the service, the Processor shall delete all personal data within the configured retention period (default: 90 days), unless retention is required by law.
No personal data is transferred outside the EU/EEA. All processing occurs on EU infrastructure.
The Controller has the right to conduct audits, including inspections, to verify the Processor's compliance with this agreement. The Processor shall contribute to such audits and provide necessary information.
dpa@dunpai.eu