Data processing agreementLast updated 2026-08-24

Data Processing Agreement (DPA)

Draft v1.0 — for AYVES BV review and adoption. Version: 1.0 · Last updated: 24 August 2026

Working draft prepared by the company for its own review and adoption. Not reviewed by external counsel. This DPA is a template AYVES BV signs with its customers. Placeholders in [square brackets] mark facts to confirm on execution.

This Data Processing Agreement ("DPA") forms part of the agreement between AYVES BV ("AYVES", "Processor"), Eindhoven, Netherlands, KvK [AYVES BV KvK registration number], and the customer identified in the applicable order or agreement ("Customer", "Controller"), together the "Parties", governing the Service (as defined in the Terms of Service). It gives effect to Article 28 GDPR where AYVES processes personal data on the Customer's behalf, and clarifies where AYVES acts as an independent controller.

Where this DPA conflicts with the Terms of Service on the subject of data processing, this DPA prevails.


1. Two distinct roles (read this first)

1.1 AYVES as Processor (this DPA governs). For the Customer's account data and the content the Customer creates in the Service — user identities, portfolios, watchlists, notes, monitors, briefings, engagement records, uploaded documents pending operator review, and configuration — AYVES processes on the Customer's documented instructions and acts as Processor. Articles 2–13 of this DPA govern that processing.

1.2 AYVES as independent Controller (this DPA clarifies, does not govern as processor). For the company-research database — the record of companies built from public filings and public registers, including the officer/role data and public-list annotations described in the Privacy Notice — AYVES determines the purposes and means and acts as an independent controller. The Customer does not instruct AYVES on that processing and cannot direct changes to the shared record other than through the corrections process. AYVES's obligations for that stream are set out in the Privacy Notice, not in the processor clauses below.

1.3 The purpose of stating both is that a Customer's due diligence sees a complete picture: AYVES is the Customer's processor for the Customer's own data, and a separate controller for the public-company research it independently maintains.


2. Subject-matter and duration

2.1 Subject-matter. Processing of Customer Personal Data by AYVES as Processor to provide the Service under the Terms of Service.

2.2 Duration. For the term of the Customer's access to the Service, plus the wind-down and deletion period in Section 11, plus any period AYVES is required to retain data by law.


3. Nature and purpose of processing

3.1 The nature of the processing is the hosting, storage, structuring, transmission, retrieval, and deletion of Customer Personal Data as necessary to operate the account, authenticate users, provide research features (analysis, portfolios, watchlists, monitors, engagement workspace, exports), take payment, secure the Service, and provide support.


4. Types of personal data and categories of data subject

4.1 Categories of data subject (as Processor):

  • the Customer's users (professional staff of an institutional investor);
  • colleagues the Customer invites;
  • individuals named in content the Customer creates (for example, contacts recorded in the Customer's own engagement notes).

4.2 Types of Customer Personal Data (as Processor):

  • identity and contact (name, email, optional image);
  • organisation and team membership;
  • account and security data (session, sign-in events, salted IP hash, user-agent);
  • usage data and content the Customer creates;
  • billing data (tier, payment references, payment-provider customer id, signup country);
  • encrypted bring-your-own-key credentials, where used.

4.3 Special categories. AYVES does not require special-category data from the Customer as part of ordinary use and instructs Customers not to upload it into free-text fields. Any special-category data the Customer chooses to place in its own content is processed as Customer Personal Data on the Customer's responsibility.

4.4 For completeness, the controller-stream personal data (officer/role records and public-list annotations built from public sources) is described in the Privacy Notice, Sections 3.2 and 5.


5. Controller instructions

5.1 AYVES processes Customer Personal Data only on the Customer's documented instructions, including regarding transfers, unless required to do otherwise by EU or Member-State law (in which case AYVES informs the Customer of that requirement before processing, unless the law prohibits it).

5.2 The Terms of Service, this DPA, the configuration options the Customer selects in the Service, and any written instructions the Customer gives constitute the Customer's complete documented instructions. Additional or different instructions must be agreed in writing and may be subject to a change in fees where they materially change the Service.

5.3 AYVES informs the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law.


6. Confidentiality

6.1 AYVES ensures that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality (contractual or statutory) and process the data only as necessary to provide the Service.

6.2 Access to Customer Personal Data is limited to personnel who need it, through role-based access controls and a restricted administrative surface.


7. Security of processing (Article 32)

7.1 AYVES implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including those in Schedule 2. Without limitation, these include:

  • encryption in transit and at rest;
  • envelope encryption of secrets and bring-your-own-key credentials (AES-256-GCM);
  • strong authentication (magic-link sign-in) and support for multi-factor authentication / one-time codes on privileged access [confirm TOTP scope on the admin surface at execution];
  • role-based access control, with an IP-allow-listed, fresh-session-gated administrative surface;
  • an append-only administrative audit trail of privileged actions;
  • network-isolated document extraction (no network egress from the extraction subprocess) and transient handling of raw uploaded bytes;
  • salted hashing of IP addresses;
  • encrypted, off-host backups with a weekly restore-verification drill; and
  • integrity controls including cross-provider divergence checks that hold uncertain analyses for human review.

7.2 AYVES keeps its measures under review and may update them provided the level of protection is not materially reduced.


8. Sub-processors

8.1 General authorisation. The Customer gives AYVES general written authorisation to engage sub-processors to provide the Service. The current sub-processors are published in the AYVES sub-processor register (the authoritative, version-controlled list, source of record src/data/subprocessors.ts; also published on the sub-processor page), which states each sub-processor's purpose, personal-data scope, processing region, and transfer mechanism.

8.2 Flow-down. AYVES imposes on each sub-processor, by contract, data-protection obligations no less protective than those in this DPA, and remains liable to the Customer for a sub-processor's performance of those obligations.

8.3 Changes and objection. AYVES will update the register and publish a change-log entry when it adds or replaces a sub-processor. The Customer may object on reasonable data-protection grounds within [30] days of the change. The Parties will work in good faith to resolve the objection; if they cannot, the Customer may terminate the affected part of the Service and receive a pro-rata refund of pre-paid unused fees. [Confirm whether advance email notice to a nominated address is offered in addition to the register change-log.]

8.4 At the date of this draft, sub-processors include Scaleway (EU hosting), Mollie (EU payments), Resend (EU email), Sentry and Umami (EU, consent-gated observability), Uptime Kuma (EU monitoring), and the AI providers MiniMax and Zhipu GLM (see Sections 8.5 and 10).

8.5 AI providers and Customer data. The AI providers process only the plain text extracted from filing PDFs. AYVES does not send Customer account data, billing data, or the Customer's private content to the AI providers as part of ordinary processing.


9. Assistance to the Controller

9.1 Data-subject requests. Taking into account the nature of the processing, AYVES assists the Customer by appropriate technical and organisational measures — including the in-app export and delete tools — to help the Customer fulfil its obligation to respond to data-subject requests. If a data subject contacts AYVES directly about Customer Personal Data, AYVES will (unless legally prohibited) refer them to the Customer or forward the request without undue delay.

9.2 DPIAs and prior consultation. AYVES provides reasonable assistance to the Customer with data-protection impact assessments and prior consultations with a supervisory authority under Articles 35–36, to the extent the Customer cannot reasonably obtain the necessary information itself and the information relates to AYVES's processing.

9.3 Personal data breaches. AYVES notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the information reasonably available to it (nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken or proposed) to help the Customer meet its own Article 33–34 obligations. AYVES does not make regulatory notifications on the Customer's behalf unless separately agreed.


10. International transfers

10.1 AYVES's hosting, database, payments and email are in the EU/EEA.

10.2 AI provider transfers. As stated in the Privacy Notice, AYVES's active and standby AI providers are, at the date of this draft, established in the People's Republic of China. Processing of the extracted filing text by those providers involves a transfer to a third country under Chapter V GDPR. AYVES relies on the European Commission's Standard Contractual Clauses with those providers, supplemented by the measures in Schedule 2 and by the operational safeguard that only extracted public-filing text (never raw bytes, and never Customer account or private data) is transferred. AYVES can switch the active provider at runtime and has an EU-hosted / self-hosted adapter on its roadmap as the standing fallback.

10.3 On request, AYVES makes available to the Customer the relevant transfer mechanism and a summary of the supplementary measures.


11. Deletion and return

11.1 On termination of the Customer's access, and at the Customer's choice, AYVES deletes or returns the Customer Personal Data it processes as Processor, and deletes existing copies, save to the extent EU or Member-State law requires retention.

11.2 The Customer may export its account data using the in-app export tool before termination. After a reasonable wind-down period, AYVES runs its erasure routine, which hard-deletes or de-identifies Customer Personal Data.

11.3 Deliberate retentions. AYVES retains, with a documented basis stated in the Privacy Notice: analysis, model-call, agent-invocation and analysis-audit records (integrity, reproducibility and auditability, Article 6(1)(f)) and payment records (Dutch statutory fiscal retention, Article 6(1)(c)). Cited data derived from public filings that has entered the shared research record is controller-stream data (Section 1.2) and is not deleted as Customer Personal Data. Backups are deleted on their rotation cycle.


12. Audit rights

12.1 AYVES makes available to the Customer the information necessary to demonstrate compliance with Article 28 and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.

12.2 Reasonable conduct. To respect confidentiality, security and the rights of other customers, the Parties agree that: audits occur on reasonable prior notice (at least [30] days, save for an audit prompted by a substantiated breach), no more than once per year unless a supervisory authority or a substantiated breach requires otherwise, during business hours, subject to confidentiality undertakings, and in a manner that does not unreasonably disrupt the Service. AYVES may satisfy an audit request in the first instance by providing its security documentation, sub-processor register, and responses to a reasonable security questionnaire.

12.3 The Customer bears its own audit costs; AYVES bears the cost of remediating any material non-compliance the audit reveals.


13. General

13.1 Liability. The liability provisions of the Terms of Service apply to this DPA. Nothing in this DPA limits liability that cannot be limited under applicable law.

13.2 Order of precedence. For data-processing matters: this DPA prevails over the Terms of Service; a mandatory data-protection law prevails over both.

13.3 Governing law and jurisdiction. As stated in the Terms of Service (the Netherlands), save where mandatory data-protection law provides otherwise.

13.4 Term. This DPA is effective for as long as AYVES processes Customer Personal Data as Processor.


Schedule 1 — Processing particulars (Article 28(3))

Item Detail
Controller The Customer
Processor AYVES BV, Eindhoven, Netherlands
Subject-matter Provision of the AYVES Service
Duration Term of access + wind-down + legal retention
Nature and purpose Hosting, storage, structuring, transmission, retrieval, deletion of Customer data to operate the Service
Types of personal data Identity/contact; org/team; account/security; usage and created content; billing; encrypted BYOK credentials
Categories of data subject Customer's users; invited colleagues; individuals named in Customer-created content
Sub-processors Per the AYVES sub-processor register
Transfers EU/EEA, except AI-provider processing of extracted filing text (SCCs; see Section 10)

Schedule 2 — Technical and organisational measures (Article 32)

  • Encryption in transit (TLS) and at rest.
  • Envelope encryption of secrets and BYOK credentials (AES-256-GCM).
  • Magic-link authentication; MFA/one-time codes on privileged access [confirm scope].
  • Role-based access control; IP-allow-listed, fresh-session-gated admin surface.
  • Append-only administrative audit trail.
  • Network-isolated PDF extraction subprocess; transient handling of raw uploaded bytes.
  • Salted (daily-rotating) hashing of IP addresses.
  • Postgres-backed rate limiting and an anonymous-tier kill-switch.
  • Encrypted off-host backups (30 daily / 12 monthly / 5 yearly) with weekly restore-verification.
  • Cross-provider divergence checks; uncertain analyses held for human review.
  • Data-minimised, entity-role-level modelling of officer data; hedged, non-accusatory narrative with an automated language filter.

AYVES BV · Data Processing Agreement · Draft v1.0 · 24 August 2026.