← Back to home

Data Processing Agreement (DPA)

Last updated: 24 April 2026

This DPA forms part of the terms for business use of FileGPT.dev where the Customer acts as controller and FileGPT acts as processor under Article 28 GDPR.

1. Parties and role allocation

  • Customer: controller (or processor acting on behalf of a controller, with required authority).
  • FileGPT.dev operator: processor for Customer Personal Data processed through the project.

2. Subject matter and duration

Processing covers the design, implementation, and operation of private RAG systems for technical document workflows — exclusively within the contractually agreed infrastructure (on-premise, private cloud, or isolated environment). This DPA applies for the duration of the project agreement and survives as long as Customer Personal Data is processed on Customer's behalf.

3. Nature and purpose of processing

  • Ingestion and processing of documents from approved sources (DMS, file system, SharePoint export).
  • Parsing, OCR, normalisation, and embedding generation within the defined environment.
  • Construction and operation of the vector index for semantic retrieval with role-based access control.
  • Processing of user queries and generation of source-grounded responses via the agreed language model.
  • Logging of access events, changes, and system events for audit and security purposes.

4. Categories of data and data subjects

Categories may include contact identifiers of users, contents of technical documents (specifications, RFQs, manuals, quality documents), user queries, and technical metadata. Data subjects may include Customer employees, contractors, and other persons whose data is contained in processed documents.

5. Processor obligations

FileGPT will:

  • process Customer Personal Data only on documented instructions from Customer;
  • ensure personnel with access are subject to confidentiality obligations;
  • implement technical and organisational security measures appropriate to risk;
  • assist Customer with data subject requests where technically feasible;
  • assist with DPIA or consultation requests where required and feasible; and
  • notify Customer of personal data breaches without undue delay.

6. Customer obligations

  • Provide lawful instructions and a legal basis for processing.
  • Ensure processed data has been lawfully collected and made available.
  • Configure the system in line with Customer's own compliance requirements.
  • Handle data subject rights requests directed to Customer as controller.

7. Subprocessors

Customer grants a general authorisation for subprocessors used to operate the project. The exact infrastructure — model, vector database, hosting, embedding service — is jointly defined during the assessment phase and documented in writing.

Material subprocessor changes will be communicated to Customer. Customer may raise reasonable objections for data protection reasons via info@filegpt.dev.

8. International transfers

For on-premise and private cloud deployments, data remains within the customer-controlled infrastructure. Where subprocessors for website operation are located outside the EEA, appropriate transfer mechanisms such as EU Standard Contractual Clauses are used.

9. Security measures (Annex II summary)

  • Authenticated API access and role-based access controls.
  • Local or tenant-controlled embedding generation and vector storage.
  • Input validation, rate limiting, and abuse safeguards.
  • Logical tenant separation by user, project, and permission model.
  • Encryption in transit via TLS and at rest through infrastructure providers.
  • Operational monitoring, logging, and incident response procedures.

A technical overview with known limitations is published on the Security page.

10. Personal data breach notifications

If we become aware of a confirmed personal data breach affecting Customer Personal Data, we will notify Customer without undue delay and provide available information reasonably required for Customer's own notification obligations.

11. Audit and information rights

Customer may request information reasonably necessary to demonstrate compliance with this DPA. Audits are limited to reasonable frequency, scope, confidentiality protections, and security safeguards.

12. Return or deletion at termination

Upon project completion or documented instruction, Customer data is deleted or returned in accordance with contractual agreements and any applicable statutory retention obligations.

13. Priority and conflict

If this DPA conflicts with other service terms regarding data protection, this DPA prevails for the processing of personal data. This DPA may be replaced by a signed negotiated agreement for enterprise customers.

14. Contact and signed copies

For enterprise procurement, signed DPA requests, or compliance questionnaires, contact info@filegpt.dev.