Data Processing Agreement

ConformAI EU Compliance Documentation

1. Introduction

This Data Processing Agreement (DPA) is entered into between ConformAI ("Data Processor") and the user/organization ("Data Controller"), and complements the Terms of Service. This DPA governs the processing of personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR).

2. Subject Matter and Duration

ConformAI processes personal data on behalf of the Data Controller for the purpose of providing the ConformAI platform and its services. The processing continues for the duration of the service agreement and thereafter only for legally required retention periods.

3. Nature and Purpose of Processing

ConformAI processes personal data including but not limited to:

The purpose is to provide AI Act compliance assessment, monitoring, and documentation services.

4. Categories of Personal Data

5. Data Subject Categories

The data subjects whose personal data are processed include:

6. Controller Obligations

The Data Controller shall:

7. Security Measures

ConformAI implements the following security measures to protect personal data:

8. Sub-processors

ConformAI currently processes data through the following third parties:

The Data Controller is notified of any changes to sub-processors and has the right to object within 30 days.

9. Data Subject Rights

ConformAI will assist the Data Controller in fulfilling data subject rights requests within 10 business days, including:

10. Data Transfers

All data processing occurs within the EU/EEA region, compliant with GDPR Chapter 5 requirements. ConformAI does not transfer personal data to third countries without appropriate legal mechanisms.

11. Return or Deletion of Data

Upon termination of the service agreement, ConformAI will, at the Data Controller's choice:

12. Assistance with Compliance

ConformAI will provide reasonable assistance to the Data Controller in meeting their GDPR obligations, including:

13. Audit and Inspection

ConformAI permits audits by the Data Controller or their authorized representatives upon reasonable notice to verify compliance with this DPA.

14. Contact and Questions

For questions about this Data Processing Agreement, please contact ConformAI's Data Protection team at [email protected].

15. Governance

This Data Processing Agreement is governed by EU data protection law. In the event of a conflict between this DPA and the Terms of Service, the provisions of this DPA shall prevail concerning personal data processing.

Last Updated: March 2026