1. Definitions
- "Controller" means the Customer who uses the Services and determines the purposes and means of the processing of Personal Data.
- "Processor" means Ksenoria OÜ, a private limited company registered in Estonia (Registration Code: 17546111, Legal Address: Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5, 10117, Estonia).
- "GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation).
- "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller through the Services.
- "Sub-processor" means any third-party data processor engaged by Ksenoria OÜ to help provide and maintain the infrastructure of the Services.
2. Scope and Compliance
2.1. This DPA applies exclusively to the situations where Ksenoria OÜ processes Personal Data as a Processor on behalf of the Customer within the uploaded customer documents, automated extraction workflows, and exports.
2.2. Both Parties agree to comply with all applicable provisions of the GDPR and other relevant Data Protection Laws.
3. Processor's Obligations
The Processor contractually commits to the following infrastructure and operational boundaries:
- Instructions: Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by European Union or Estonian law.
- Confidentiality: Processor ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security Measures: We use encryption in transit and at rest through our infrastructure and service providers, together with access controls and other appropriate technical safeguards.
- Data Subject Rights: Taking into account the nature of the processing, Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.
- Personal Data Breach: Processor shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Customer workflows.
- Deletion or Return: Customer content stored in Tremvio’s active systems is deleted or anonymised in accordance with the selected retention settings or following account closure. Limited copies may remain temporarily in backups, security logs, billing records, or systems operated by subprocessors, subject to their retention policies and applicable legal obligations.
4. Sub-processors
4.1. The Controller grants a general written authorization to the Processor to engage Sub-processors to run the cloud, storage, database, OCR, and AI infrastructure of the platform.
4.2. The current list of infrastructure sub-processors is available on request through support@tremvio.com.
4.3. Processor shall inform the Controller of any intended changes concerning the addition or replacement of other sub-processors at least 30 days in advance via email, thereby giving the Controller the opportunity to object to such changes.
5. Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (at the Controller's sole expense and with at least 4 weeks prior written notice).
6. Governing Law and Jurisdiction
This DPA shall be governed by, and construed in accordance with, the laws of Estonia. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the competent courts of Tallinn, Estonia.
Contact
For any data protection or DPA inquiries, please contact: support@tremvio.com.