Przejdź do treści

Data Processing Agreement

Last updated: 2026-03-21
01

1. Scope and Purpose

This Data Processing Agreement ("DPA") is entered into between the entity using the ANOXY platform ("Controller") and ESKOM AI Sp. z o.o., ul. Zimna 2/24, 00-138 Warszawa, Poland, NIP: 5253040096 ("Processor"), pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR").

This DPA governs the processing of personal data by the Processor on behalf of the Controller when using the ANOXY anonymization platform. It supplements and forms an integral part of the Terms of Service.

02

2. Definitions

For the purposes of this DPA:

  • Personal Data — any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
  • Processing — any operation performed on personal data, including anonymization, pseudonymization, collection, storage, and erasure.
  • Data Subject — the identified or identifiable natural person to whom the personal data relates.
  • Sub-processor — any third party engaged by the Processor to process personal data on behalf of the Controller.
  • Anonymization — the irreversible transformation of personal data such that the data subject is no longer identifiable.
  • Pseudonymization — the processing of personal data in such a manner that it can no longer be attributed to a specific data subject without the use of additional information.
03

3. Subject Matter and Duration of Processing

Subject matter: The Processor provides the ANOXY platform, which performs automated anonymization and pseudonymization of documents and text containing personal data.

Nature of processing: Automated detection and replacement of personal data entities (names, identification numbers, addresses, financial data, and other PII) using NLP models, pattern recognition, and rule-based systems.

Duration: Processing continues for the duration of the Controller's use of the ANOXY platform. Upon termination, the provisions of Section 12 (Termination) apply.

Categories of data subjects: Individuals whose personal data appears in documents or text submitted by the Controller for anonymization.

Types of personal data: Names, identification numbers (e.g., PESEL, NIP, passport), addresses, email addresses, phone numbers, financial data (IBAN, account numbers), dates of birth, and any other personal data contained in submitted documents.

04

4. Controller Obligations

The Controller shall:

  • Ensure that a lawful basis exists under Article 6 GDPR for the processing of personal data submitted to the ANOXY platform.
  • Provide documented instructions for the processing of personal data, including the selection of anonymization profiles and entity types.
  • Ensure that data subjects have been informed about the processing in accordance with Articles 13 and 14 GDPR, where applicable.
  • Promptly notify the Processor of any changes to processing instructions or applicable legal requirements.
  • Conduct a Data Protection Impact Assessment (DPIA) under Article 35 GDPR where required, particularly when processing special categories of data or large-scale systematic processing.
05

5. Processor Obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required by EU or Member State law.
  • Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Take all measures required pursuant to Article 32 GDPR (security of processing).
  • Respect the conditions for engaging sub-processors as set out in Section 7.
  • Assist the Controller in responding to data subject requests as set out in Section 9.
  • Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor.
  • At the choice of the Controller, delete or return all personal data after the end of the provision of services, and delete existing copies unless EU or Member State law requires storage.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.

6. Technical and Organizational Security Measures

The Processor implements the following measures pursuant to Article 32 GDPR:

  • Encryption: All data in transit is encrypted using TLS 1.2+. Persistent anonymization mappings use AES-256-GCM encryption with HKDF key derivation.
  • Access control: Role-based access control (RBAC) via Keycloak SSO. API access secured with hashed API keys and JWT tokens (RS256).
  • Data minimization: Personal data is processed in memory and not persisted beyond the processing session unless explicitly enabled by the Controller (persistent mappings feature).
  • Pseudonymization: The platform's core function is the pseudonymization and anonymization of personal data, reducing risk by design.
  • Monitoring: Application-level monitoring via Sentry (EU region), Prometheus metrics, and audit logging.
  • Infrastructure security: Services deployed on dedicated infrastructure within the EU, access restricted via Tailscale VPN and firewall rules.
  • Regular testing: Automated security testing (OWASP Top 10 suite), rate limiting, input sanitization, and PII leak prevention in HTTP headers and logs.

7. Sub-processors

The Controller grants the Processor general written authorization to engage sub-processors. The Processor shall:

  • Maintain a current list of sub-processors and make it available to the Controller upon request.
  • Inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes within 14 days.
  • Impose on any sub-processor, by way of a contract, the same data protection obligations as set out in this DPA.
  • Remain fully liable to the Controller for the performance of any sub-processor's obligations.

Current sub-processors:

  • Infrastructure hosting provider (EU-based servers)
  • Sentry (error monitoring, EU region — Frankfurt, Germany)

8. International Data Transfers

The Processor stores and processes all personal data within the European Economic Area (EEA).

Should any transfer of personal data to a third country become necessary, the Processor shall ensure that appropriate safeguards are in place in accordance with Chapter V GDPR, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • An adequacy decision by the European Commission under Article 45 GDPR.
  • Binding Corporate Rules approved under Article 47 GDPR.

The Processor shall inform the Controller prior to any such transfer and obtain the Controller's prior approval.

06

9. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to data subject requests under Articles 15–22 GDPR, including:

  • Right of access (Article 15) — providing information about processed personal data.
  • Right to rectification (Article 16) — correcting inaccurate personal data.
  • Right to erasure (Article 17) — deleting personal data when legally required.
  • Right to restriction of processing (Article 18) — limiting the processing of personal data.
  • Right to data portability (Article 20) — providing personal data in a structured, machine-readable format.
  • Right to object (Article 21) — ceasing processing where the data subject objects.

The Processor shall promptly notify the Controller of any data subject request received directly, without responding to the request unless authorized by the Controller.

07

10. Personal Data Breach Notification

In the event of a personal data breach as defined in Article 4(12) GDPR, the Processor shall:

  • Notify the Controller without undue delay and no later than 24 hours after becoming aware of the breach.
  • Provide the Controller with sufficient information to enable the Controller to fulfill its obligations under Articles 33 and 34 GDPR, including:
    • The nature of the personal data breach, including the categories and approximate number of data subjects and records concerned.
    • The likely consequences of the breach.
    • The measures taken or proposed to address the breach and mitigate its effects.
  • Document all personal data breaches, including the facts, effects, and remedial actions taken.
  • Cooperate with the Controller and any supervisory authority in the investigation of the breach.
08

11. Audit Rights

The Controller shall have the right to conduct audits and inspections to verify the Processor's compliance with this DPA, subject to the following conditions:

  • The Controller shall provide at least 30 days' written notice of any planned audit.
  • Audits shall be conducted during normal business hours and shall not unreasonably disrupt the Processor's operations.
  • The Controller may engage a qualified, independent third-party auditor, subject to confidentiality obligations.
  • The Processor shall cooperate fully with the audit and provide access to relevant documentation, systems, and personnel.
  • The Processor may satisfy audit requests by providing recent audit reports, certifications, or compliance documentation where available.
09

12. Termination and Data Return

Upon termination or expiry of the service agreement:

  • The Processor shall, at the Controller's choice, return all personal data to the Controller in a standard, machine-readable format or securely delete all personal data within 30 days.
  • The Processor shall delete all existing copies of personal data unless EU or Member State law requires continued storage.
  • The Processor shall provide written confirmation of the deletion of personal data upon the Controller's request.
  • Persistent anonymization mappings, if enabled, shall be deleted in accordance with the retention period configured by the Controller or within 30 days of termination, whichever comes first.
  • Anonymized data (i.e., data that has been irreversibly transformed and can no longer identify data subjects) is not considered personal data and is not subject to the return or deletion obligations above.
10

13. Liability

Each party shall be liable for damages caused by processing that infringes the GDPR in accordance with Article 82 GDPR.

The Processor shall be liable for damages caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the lawful instructions of the Controller.

A party shall be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage, in accordance with Article 82(3) GDPR.

11

14. Governing Law and Jurisdiction

This DPA shall be governed by and construed in accordance with the laws of the Republic of Poland, without regard to its conflict of law provisions.

Any disputes arising from or in connection with this DPA shall be submitted to the exclusive jurisdiction of the competent courts in Warsaw, Poland.

Where any provision of this DPA conflicts with applicable data protection legislation, the provisions of such legislation shall prevail.

ESKOM AI Sp. z o.o.
ul. Zimna 2/24, 00-138 Warszawa, Poland
NIP: 5253040096 | KRS: 0001163211
Email: dpo@eskom.ai

This Data Processing Agreement is an integral part of the Terms of Service of the ANOXY platform operated by ESKOM AI Sp. z o.o.

Data Processing Officer: dpo@eskom.ai

v4.13.111 (dev)Data Processing Agreement | ANOXY