Business Data Processing Agreement
Contract template — not active until parties and Annex 2 are completed and accepted.
Parties and priority
Customer: [DPA-01: legal name, registered address, registration details and contact]. Processor: Szegi Roland Attila E.V., 5000 Szolnok, Városmajor út 59/B, B épület, 2. emelet 24., Hungary; registration 61835722; hello@dropsite.hu.
This DPA applies where the Processor processes personal data on the Customer's behalf in providing resolvenengine. The Customer is controller or, if acting for another controller, a processor authorised to appoint us as subprocessor. Account, billing and security processing for our own purposes is governed separately by our Privacy Policy. In a conflict concerning processor obligations, this DPA prevails over general software terms. Mandatory law prevails over both.
1. Instructions and purpose
The Processor processes the data described in Annex 1 only on documented instructions, including instructions about international transfers, unless Union or Member State law requires otherwise. In that case it informs the Customer beforehand unless legally prohibited. Service configuration, authorised task requests and written support instructions form part of the instructions. The Processor promptly informs the Customer if an instruction appears to infringe applicable data protection law and may suspend that instruction pending resolution.
The Customer is responsible for lawful collection, applicable notices and bases, authorised use of connected accounts, and limiting data to what is necessary. This does not relieve the Processor of its own GDPR obligations.
2. Confidentiality and security
Access is limited to authorised persons bound by confidentiality obligations. The Processor implements appropriate technical and organisational measures under Article 32, taking account of processing risks, state of the art and implementation cost. Annex 3 records measures and gaps; an unimplemented item is not represented as an existing safeguard. Measures must not be materially reduced during the agreement without appropriate alternative protection.
3. Subprocessors
The Customer grants general written authorisation only for the subprocessors listed in the completed Annex 2. The Processor gives at least 30 days' prior written notice of intended additions or replacements and sufficient information for a reasoned data-protection objection. The parties will seek a reasonable alternative; if none is available, the affected processing may be terminated with appropriate treatment of unused paid service. Urgent security replacements require notice as soon as practicable and a lawful authorisation arrangement, not an unlimited exception.
The Processor imposes substantially equivalent Article 28 obligations on each subprocessor and remains responsible to the Customer for their performance. An unlisted custom AI endpoint must not receive Customer personal data until its role and authorisation are resolved.
4. Assistance, incidents and audits
Taking account of the nature of processing and available information, the Processor assists the Customer with data-subject requests and obligations under Articles 32–36. It promptly forwards requests concerning Customer-controlled data and does not independently respond beyond lawful instructions or legal obligations.
The Processor notifies the Customer without undue delay after becoming aware of a personal-data breach, giving available information about its nature, affected categories and approximate numbers, likely consequences, mitigation and a contact. Missing details may follow in phases; notification is not delayed until investigation is complete. The Customer determines its controller notifications, with assistance from the Processor.
The Processor makes available information needed to demonstrate compliance and allows and contributes to reasonable audits, including inspections, by the Customer or its mandated auditor. Reasonable arrangements protect other customers' information and system security without defeating Article 28 rights. Confidentiality or commercial terms cannot prevent disclosures to competent authorities.
5. Transfers
The Processor does not transfer data to a third country without documented instructions and compliance with GDPR Chapter V. Annex 2 must identify the actual transfer mechanism and any supplementary safeguards. This DPA is not itself a replacement for the Commission's Standard Contractual Clauses where those are required; the applicable modules and parties must be separately completed without modifying mandatory clauses.
6. End of service
At the Customer's choice, the Processor returns or deletes personal data after the processing services end and deletes existing copies unless applicable law requires retention. [DPA-02: agree operational return/deletion period and verified backup expiry before signature.] Retained backup data remains protected, outside ordinary use and subject to the agreed expiry; restoration must reapply deletion. The Processor confirms completion and explains any legally required retention.
Annex 1 — Processing description
- Subject: AI-assisted browser and connector tasks and account-linked conversation storage.
- Duration: service term and the agreed return/deletion period.
- Nature: receipt, retrieval, structuring, transmission to authorised AI providers, generation, storage, user-directed modification/deletion and export.
- Purposes: perform authorised tasks and maintain Customer conversation history.
- Data subjects: Customer staff, contractors, customers, correspondents, meeting participants and other people appearing in authorised content.
- Data types: identifiers, contact details, communications, files, calendar/task data, browser content, prompts/outputs and task metadata.
- Sensitive data: not intentionally supported as a special-category workflow under this standard template; incidental inclusion must be assessed and minimised. Intentional processing requires a documented basis and additional safeguards.
- Customer instructions/contact: [DPA-03].
Annex 2 — Authorised subprocessors and transfers
[DPA-04: for each actual subprocessor insert legal entity, address/country, duties, data categories, processing/support/backup locations, DPA and transfer mechanism. Complete the AI-provider chain and any Lovable-managed database chain. Do not sign with this annex blank.]
Annex 3 — Technical and organisational measures
Reviewed architecture: HTTPS; server-key encryption of stored credential and chat payloads; account-associated records; service-role database access; expiring sessions/OAuth state; single-use hand-offs; connector permissions; rate-limiting primitives. These observations are not a penetration-test certificate.
Required operational verification before signature: administrator MFA/least privilege; tenant-isolation tests; key storage and rotation; production cleanup; account export/deletion; backups and restore/deletion replay; incident process; access logging and redaction; subprocessors and transfers; support-access controls and staff confidentiality. [DPA-05: attach dated evidence and final implemented measures.]
Acceptance
For Customer: name, role, date, signature / recorded electronic acceptance. For Processor: name, role, date, signature / recorded electronic acceptance.