Data Processing Agreement (DPA)

Version 2026-08-10. Annex to the Terms of Service.

1. Parties and roles

This Data Processing Agreement ("DPA") is entered into between the Customer (controller) and AIfabrikken ApS, CVR no. 45010694 (processor) as an annex to the Terms of Service, cf. Article 28 GDPR. The DPA covers Fabrikken's processing of personal data on the Customer's behalf in connection with the chatbot service. Where Fabrikken is itself the controller (the Customer's account, billing, support), the privacy policy applies. The Terms are available in Danish and English; in case of discrepancy, the Danish version prevails.

2. Instructions

Fabrikken processes personal data solely to provide the Service — indexing the Customer's sources, generating chatbot answers, scans, access control and support — and solely on the Customer's documented instructions. The instructions consist of the agreement and the Customer's configuration in the administration panel (choice of sources and scan scope, access modes, retention settings, etc.). Fabrikken informs the Customer if, in our assessment, an instruction infringes the GDPR.

3. Categories of data subjects and data

  • Data subjects: the Customer's end users (chat conversations), the Customer's employees (administrator and chatbot logins), and persons mentioned in the Customer's indexed material.
  • Data types: conversation content (free text — may contain anything the end user writes), indexed source and document content, voice input (speech-to-text), name/email/password hash for logins, IP addresses and user agent, upload metadata.
  • Special categories (Art. 9) are not processed intentionally but may occur in free text. The Customer endeavours to minimise such data in its material and use.

4. Duration

The DPA applies for as long as Fabrikken processes personal data on the Customer's behalf, i.e. for the term of the agreement and until deletion pursuant to section 9.

5. Technical and organisational measures (TOMs)

Fabrikken has implemented measures including:

  • Tenant isolation: separate vector collection per customer, customer key on all data rows, and fail-closed domain resolution (unknown domains are rejected without data access) with automatic alerting.
  • Encryption in transit: TLS on all traffic (edge and origin certificates).
  • Encryption at rest: knowledge bases, conversation data and files are stored encrypted at rest; documentation of the measures applied is provided on request, cf. section 10.
  • Encryption of credentials: customers' API keys and OAuth tokens are stored with AES-256-GCM envelope encryption (per-row key + master key).
  • Access control: role-based administrator access, audit log of administrative actions, optional IP restriction, session management.
  • Operations: EU hosting, automated source health monitoring notifying the Customer's administrators of source failures, isolated scan pipelines.
  • Deletion: technically supported deletion per source and full customer offboarding (database, vector index, files, domains and configuration).

6. Sub-processors

The Customer grants general authorisation for Fabrikken's use of sub-processors. The current list of sub-processors is available at fabrikken.ai/subprocessors and forms an integral part of this DPA. At the conclusion of the DPA, all sub-processors are based in the EU with two exceptions resting on an EU-recognised transfer basis: speech-to-text is processed in the United Kingdom (adequacy decision), and the network layer is provided by Cloudflare, Inc. (USA) under the EU-US Data Privacy Framework, cf. section 11.

Cloud sources connected by the Customer (Google Drive, OneDrive, Dropbox, NextCloud) are not sub-processors: the Customer chooses and holds the contractual relationship with the provider; Fabrikken reads only the folders designated by the Customer.

7. Changes of sub-processors

Fabrikken gives at least 30 days' prior notice of the addition or replacement of sub-processors by email to the Customer's administrators. The Customer may raise a reasoned objection; failing resolution, the Customer may terminate the agreement with effect from the date the change takes effect.

8. Assistance and personal data breaches

Taking into account the nature of the processing, Fabrikken assists the Customer in responding to requests from data subjects (access, erasure etc. in conversation data and the knowledge base), and with security, impact assessments and prior consultations. Fabrikken notifies the Customer without undue delay, and no later than 48 hours, after becoming aware of a personal data breach, with the information necessary for the Customer's own notification to the Danish Data Protection Agency within 72 hours.

9. Deletion and return

Upon termination of the agreement, Fabrikken deletes all personal data processed on the Customer's behalf: the knowledge base, conversation data and configuration are deleted no later than 30 days after termination, and trial data no later than 90 days after the trial expires, cf. section 3 of the Terms. Backup copies subsequently rotate out of the backup cycle automatically no later than 21 days after deletion. Information which Fabrikken is legally required to retain for longer (e.g. accounting and invoicing records, which must be kept for 5 years under the Danish Bookkeeping Act) is retained only for as long as, and for the purpose, the obligation requires, and is then deleted. Prior to deletion, the Customer may request delivery of its material in a commonly used format. Completed deletion is confirmed on request.

10. Documentation and audits

On request, Fabrikken makes available the documentation necessary to demonstrate compliance with Article 28 — including the description of the measures in section 5 and the list in section 6 — and allows for and contributes to audits. On-site audits require reasonable notice, are conducted without undue disruption of operations and at the Customer's expense.

11. Third-country transfers

Processing takes place in the EU as a general rule. Exceptions: speech-to-text is processed in the United Kingdom (adequacy decision), and the network layer is provided by Cloudflare, Inc. (USA) under the EU-US Data Privacy Framework, cf. section 6 — traffic is primarily processed in EU data centres. No other third-country transfers occur in the standard setup. If the Customer connects a cloud source with a provider outside the EU/EEA, this is the Customer's own choice and responsibility.