Data Processing Agreement

Standard processing terms to incorporate into an Invertix customer agreement with a completed deployment-specific processing schedule.

Version: October 4, 2026 · Published in English

1. Application and processing schedule

These terms apply only when incorporated into an agreement between the customer and the Invertix entity named in it. Publication does not replace an existing signed DPA. The customer is controller, or an authorized processor instructing Invertix as subprocessor; Invertix processes customer personal data on its behalf.

Before incorporation, complete a schedule identifying parties and contacts, subject matter and duration, nature and purposes, personal-data and data-subject categories, controller rights and obligations, security measures, authorized subprocessors, locations, transfer safeguards and return/deletion arrangements. Contact simon.karan@invertix.ai to arrange it.

Depending on agreed services, processing includes receiving and storing records, extracting and retrieving documents, generating reports and AI outputs, and authorized workflows. Subjects can include customer staff, contractors and people identified in records; data can include contact, account, communication, document and workflow information. Only categories and purposes expressly agreed in the schedule are authorized.

2. Instructions and confidentiality

Invertix processes data only on documented instructions, including for international transfers, unless EU or Member State law requires otherwise. It informs the customer before legally required processing unless prohibited. It immediately informs the customer if an instruction appears to infringe applicable data protection law.

The customer is responsible for its lawful basis, notices and authority to instruct processing. Invertix ensures authorized personnel are bound by confidentiality or an appropriate statutory duty.

3. Security

Invertix implements measures appropriate to processing risks under Article 32 GDPR, documented in the agreed security schedule. The schedule covers relevant access control, confidentiality, integrity, availability, protected transfer/storage, recovery and testing. Hosting and model boundaries form part of instructions. Measures may evolve while maintaining required protection; marketing statements do not substitute for documented deployment measures.

4. Subprocessors and transfers

Subprocessors require prior specific or general written customer authorization. The schedule identifies authorized entities, services and locations. Under general authorization, Invertix provides advance notice of intended additions/replacements and a meaningful opportunity to object before implementation under the agreed procedure.

Invertix imposes obligations providing the same data protection required by this DPA and remains responsible to the customer for subprocessor performance. A customer acting as processor must have its controller's authorization for the chain.

Transfers require documented instructions and a valid mechanism. Where Standard Contractual Clauses are required, parties execute the appropriate clauses and annexes. This public DPA is not executed transfer clauses or authorization of every supported provider.

5. Rights and compliance assistance

Considering the nature of processing, Invertix assists through appropriate technical and organizational measures, insofar as possible, with data-subject rights. Direct requests about customer-controlled data are referred to the customer without undue delay unless law requires otherwise.

Considering the nature of processing and available information, Invertix assists with Articles 32–36 security, breach notifications, impact assessments and prior consultation. The schedule identifies secure channels and procedures.

6. Breach notification

Invertix notifies the customer without undue delay after becoming aware of a breach affecting customer personal data. It provides available information on its nature, affected categories and approximate numbers where known, likely consequences, mitigation and a follow-up contact, in stages if necessary. It cooperates in investigation and mitigation. The customer assesses notifications required of it; processor notification is not delayed until that assessment is complete.

7. Return and deletion

At the customer's choice, Invertix returns or deletes personal data after processing services end and deletes existing copies unless EU or Member State law requires retention. The schedule defines format, timing, backup lifecycle and legal-retention arrangements. Backups awaiting expiry remain protected and isolated from ordinary use; required deletions are reapplied after restoration.

Retention during service follows instructions and agreed settings. Invertix does not use customer data for independent purposes under this DPA. Any separate controller activity needs its own lawful basis and transparency.

8. Accountability and audits

Invertix provides information necessary to demonstrate Article 28 compliance and allows and contributes to audits, including inspections, by the customer or its mandated auditor. Proportionate arrangements protect security and other customers without preventing mandatory audit rights.

This DPA and completed schedule govern processing responsibilities; the customer agreement governs commercial terms. Mandatory law and executed transfer clauses prevail where required.

Contact and requests

Privacy contact: simon.karan@invertix.ai. For data deletion, use /data-deletion or email the privacy contact.