Skip to content

Data Processing Agreement

Last Updated: August 9, 2026

Version 2.2.0 · Effective Date: August 9, 2026

GDPR Art. 28

Processor obligations covered

SCCs + UK Addendum

International transfers safeguarded

Sub-processor controls

Notice and objection rights

Operator & Data Controller

  • ShiftNode Digital s.r.o. (operator of the EM3A service at em3a.ai)
  • Registered office: Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic
  • Company ID (IČO): 249 06 123
  • Privacy contact: privacy@em3a.ai
  • Legal / procurement contact: legal@em3a.ai

English legal version controls. Localized routes may include summaries for visitor convenience, but the English text controls unless a separately signed agreement says otherwise.

Preamble

This public Data Processing Agreement ("DPA") is provided for transparency and procurement review. It applies between ShiftNode Digital s.r.o. ("Processor") and the customer ("Controller") when incorporated into, referenced by, or executed alongside a Master Service Agreement, Order Form, or the Terms of Service. It is drafted with reference to Regulation (EU) 2016/679 (GDPR), including Article 28, the UK GDPR, and Czech data protection law as supervised by the Úřad pro ochranu osobních údajů (ÚOOÚ). A signed version supplied on request controls over this public template.

1. Definitions

  • "Controller" — the customer that determines the purposes and means of processing Customer Personal Data.
  • "Processor"ShiftNode Digital s.r.o. (IČO 249 06 123),Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic.
  • "Customer Personal Data" — personal data that Controller, or its authorized users, upload, import, generate, or otherwise process through EM3A.
  • "Sub-Processor" — any third party engaged by Processor to process Customer Personal Data on Controller's behalf.
  • "Data Subject Request" — a request from an individual to exercise rights under applicable data protection law.
  • "Personal Data Breach" — as defined in GDPR Article 4(12).

2. Roles and Scope

Controller appoints Processor to process Customer Personal Data solely to provide, secure, support, and improve EM3A in accordance with the underlying agreement and Controller's documented instructions. Where Processor processes data as a controller (account, billing, security, marketing of its own service), the Privacy Policy applies.

3. Processor Obligations

  • Process Customer Personal Data only on documented instructions from Controller, including via the configuration of the Service, the underlying agreement, and this DPA. Processor will inform Controller if it believes an instruction infringes applicable data protection law.
  • Ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
  • Implement the technical and organizational measures described in Annex 2.
  • Engage Sub-Processors only in accordance with section 5.
  • Assist Controller in fulfilling its obligations to respond to Data Subject Requests.
  • Assist Controller with security, breach notification, data protection impact assessments, and prior consultation under GDPR Articles 32–36, taking into account the nature of processing and information available to Processor.
  • Return or delete Customer Personal Data at the end of the engagement in accordance with section 9.
  • Make available information necessary to demonstrate compliance with this DPA and allow for audits in accordance with section 8.

4. Controller Obligations

  • Establish and maintain a lawful basis for the processing carried out through the Service.
  • Provide required notices and obtain required consents from data subjects.
  • Issue instructions consistent with applicable law and not require Processor to act unlawfully.
  • Configure access controls, retention settings, and integrations appropriately.
  • Not upload special-category personal data, payment card numbers, or other regulated data unless authorized in a signed agreement.

5. Sub-Processors

Controller grants Processor a general authorization to engage Sub-Processors, subject to:

  • Processor maintaining a current list of Sub-Processor categories (Annex 3) and a detailed list available on request from privacy@em3a.ai.
  • Processor entering into written agreements with each Sub-Processor imposing data protection obligations no less protective than this DPA.
  • Processor providing Controller with at least 30 days' prior notice of new or replacement Sub-Processors (by email, in-product banner, or status page), during which Controller may object on reasonable data-protection grounds. If the objection cannot be resolved, Controller may terminate the affected portion of the Service.
  • Processor remaining liable to Controller for Sub-Processor performance to the same extent Processor would be liable for performing those services directly, subject to the liability cap in the underlying agreement.

6. International Transfers

Where Customer Personal Data is transferred outside the EEA, the UK, or Switzerland to a country without an adequacy decision, the parties rely on:

  • The EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (Controller-to-Processor) or Module 3 (Processor-to-Processor), incorporated by reference;
  • The UK International Data Transfer Addendum to the EU SCCs for UK data;
  • The Swiss addendum for Swiss data;
  • Supplementary measures appropriate to the destination country (encryption, pseudonymization, access controls, transparency reporting).

For the purposes of the SCCs the parties select the optional docking clause, Option 2 for sub-processor authorization, an 18-month notice period for new sub-processors not less than 30 days, governing law of the Czech Republic, and the courts of the Czech Republic as competent forum.

7. Personal Data Breach

Processor will notify Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include the information reasonably available to Processor, updated as the investigation progresses. Processor will take reasonable steps to contain and mitigate the breach and will reasonably cooperate with Controller's notification obligations to authorities and data subjects.

8. Audit Rights

Processor will make available to Controller, upon reasonable written request, the information necessary to demonstrate compliance with this DPA, including:

  • summaries of independent third-party audit reports or certifications, where available;
  • responses to a reasonable security questionnaire no more than once per 12 months;
  • on-site audits only (a) for cause following a confirmed Personal Data Breach, (b) where required by a competent authority, or (c) where reasonably needed and not addressable through the items above. On-site audits are scheduled at least 30 days in advance, conducted during business hours, performed by a mutually approved independent auditor under confidentiality, designed to minimize disruption, and carried out at Controller's expense unless they reveal material non-compliance attributable to Processor.

9. Return or Deletion of Data

On termination or expiry of the engagement, Processor will, at Controller's choice, return or delete Customer Personal Data within 30 days, except where retention is required by applicable law. Backup copies are deleted in accordance with documented backup-retention schedules. Processor will provide written confirmation of deletion on request.

10. Liability

Each party's liability under this DPA is subject to the limitation-of-liability provisions of the underlying agreement (including the Terms of Service). This DPA does not increase or decrease the liability caps in the underlying agreement, except where mandatory data protection law requires otherwise.

11. Governing Law and Conflicts

This DPA is governed by the laws of the Czech Republic, except where the SCCs require a different governing law for transfer purposes. In case of conflict between this DPA and the underlying agreement regarding the processing of personal data, this DPA prevails. Where a signed DPA is executed, it controls over this public template.

Annex 1 — Description of Processing

  • Subject matter: provision of the EM3A B2B intelligence platform.
  • Duration: the term of the underlying agreement plus any retention required by law.
  • Nature and purpose: hosting, processing, AI-assisted analysis, research, enrichment, reporting, and storage of Customer Personal Data to deliver the Service.
  • Categories of personal data: business contact data (name, work email, role, employer), project and pipeline data, AI prompts and outputs, customer-uploaded documents, CRM-imported contacts, optional voice-rehearsal audio and transcripts, account and usage data.
  • Categories of data subjects: Controller's employees and authorized users; Controller's customers, prospects, and other business contacts; individuals referenced in customer-uploaded materials.
  • Special categories: none, unless expressly authorized by signed agreement.

Annex 2 — Technical and Organizational Measures

  • Access control: role-based access, least-privilege, mandatory MFA for administrative accounts, single-sign-on for Enterprise customers where configured, periodic access reviews.
  • Encryption: TLS in transit; encryption at rest provided by the underlying cloud infrastructure; secrets stored in a managed secret store.
  • Tenant isolation: row-level security in the database; per-account scoping in application code and edge functions.
  • Software development lifecycle: source-code review, dependency management, automated type-checking on changes, and version-controlled deployments that can be rolled back by redeploying a previous revision.
  • Logging and monitoring: centralized application and access logs with durable capture of backend errors for investigation.
  • Backup and recovery: regular automated backups; documented restore procedures.
  • Business continuity: reliance on resilient cloud providers, documented incident-response runbooks.
  • Personnel: confidentiality obligations, security-awareness expectations.
  • Vendor management: security and privacy review before engaging new Sub-Processors.

These measures are inspired by recognized frameworks such as ISO/IEC 27001 Annex A and SOC 2 Trust Service Criteria. ShiftNode Digital s.r.o. does not currently claim formal ISO 27001 or SOC 2 certification.

Annex 3 — Approved Sub-Processors

The following Sub-Processors are engaged to provide the Service. Providers instructed to process AI prompts or outputs are contractually directed not to use them to train their base models.

Sub-ProcessorPurpose
SupabaseDatabase, storage, authentication, and edge-function hosting
LovableApplication platform, hosting, and AI model gateway
OpenAILarge-language-model inference and text embeddings
OpenRouterLarge-language-model gateway (DeepSeek models)
AnthropicLarge-language-model inference
PerplexityGrounded web-search for cited research
GoogleGemini large-language-model inference
FirecrawlExtraction of content from public web URLs
ResendTransactional and marketing email delivery
SentryApplication error monitoring

We also rely on invoicing, tax, and accounting tooling and professional advisers (accounting, tax, legal) as needed. Processing locations and transfer mechanisms for each Sub-Processor are available on request from privacy@em3a.ai. We provide at least 30 days' notice of new or replacement Sub-Processors as described in section 5.

Contact

Procurement and DPA questions: legal@em3a.ai. Privacy operations: privacy@em3a.ai.