ConformAI EU Compliance Documentation
This Data Processing Agreement (DPA) is entered into between ConformAI ("Data Processor") and the user/organization ("Data Controller"), and complements the Terms of Service. This DPA governs the processing of personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR).
ConformAI processes personal data on behalf of the Data Controller for the purpose of providing the ConformAI platform and its services. The processing continues for the duration of the service agreement and thereafter only for legally required retention periods.
ConformAI processes personal data including but not limited to:
The purpose is to provide AI Act compliance assessment, monitoring, and documentation services.
The data subjects whose personal data are processed include:
The Data Controller shall:
ConformAI implements the following security measures to protect personal data:
ConformAI currently processes data through the following third parties:
The Data Controller is notified of any changes to sub-processors and has the right to object within 30 days.
ConformAI will assist the Data Controller in fulfilling data subject rights requests within 10 business days, including:
All data processing occurs within the EU/EEA region, compliant with GDPR Chapter 5 requirements. ConformAI does not transfer personal data to third countries without appropriate legal mechanisms.
Upon termination of the service agreement, ConformAI will, at the Data Controller's choice:
ConformAI will provide reasonable assistance to the Data Controller in meeting their GDPR obligations, including:
ConformAI permits audits by the Data Controller or their authorized representatives upon reasonable notice to verify compliance with this DPA.
For questions about this Data Processing Agreement, please contact ConformAI's Data Protection team at [email protected].
This Data Processing Agreement is governed by EU data protection law. In the event of a conflict between this DPA and the Terms of Service, the provisions of this DPA shall prevail concerning personal data processing.
Last Updated: March 2026