Last updated: 24 April 2026
This DPA forms part of the terms for business use of FileGPT.dev where the Customer acts as controller and FileGPT acts as processor under Article 28 GDPR.
Processing covers the design, implementation, and operation of private RAG systems for technical document workflows — exclusively within the contractually agreed infrastructure (on-premise, private cloud, or isolated environment). This DPA applies for the duration of the project agreement and survives as long as Customer Personal Data is processed on Customer's behalf.
Categories may include contact identifiers of users, contents of technical documents (specifications, RFQs, manuals, quality documents), user queries, and technical metadata. Data subjects may include Customer employees, contractors, and other persons whose data is contained in processed documents.
FileGPT will:
Customer grants a general authorisation for subprocessors used to operate the project. The exact infrastructure — model, vector database, hosting, embedding service — is jointly defined during the assessment phase and documented in writing.
Material subprocessor changes will be communicated to Customer. Customer may raise reasonable objections for data protection reasons via info@filegpt.dev.
For on-premise and private cloud deployments, data remains within the customer-controlled infrastructure. Where subprocessors for website operation are located outside the EEA, appropriate transfer mechanisms such as EU Standard Contractual Clauses are used.
A technical overview with known limitations is published on the Security page.
If we become aware of a confirmed personal data breach affecting Customer Personal Data, we will notify Customer without undue delay and provide available information reasonably required for Customer's own notification obligations.
Customer may request information reasonably necessary to demonstrate compliance with this DPA. Audits are limited to reasonable frequency, scope, confidentiality protections, and security safeguards.
Upon project completion or documented instruction, Customer data is deleted or returned in accordance with contractual agreements and any applicable statutory retention obligations.
If this DPA conflicts with other service terms regarding data protection, this DPA prevails for the processing of personal data. This DPA may be replaced by a signed negotiated agreement for enterprise customers.
For enterprise procurement, signed DPA requests, or compliance questionnaires, contact info@filegpt.dev.