Data Processing Agreement
Effective Date: pending activation (not set reserved for release).
Last Updated: pending activation (not set reserved for release).
Draft prepared: 6 October 2026. This instrument is not yet in force. Its annexes and deployment particulars must be completed before acceptance.
Draft revised: 7 October 2026. Activation remains pending.
Non-binding summary. When we process personal data for your project or hosted application, you give the instructions. This agreement sets confidentiality, security, supplier and deletion duties. It does not permit marketing or training on your application data. This summary is outside the operative agreement.
1. Parties and instructions
1.1. The accepting customer identified in its account/order (“Controller”) and Igor Tkachenko OwlMeans Software (trading as “OwlMeans Software, JDG”), NIP 6772507251, EU VAT identifier PL6772507251, REGON 527979906, ul. Ariańska 9/5, 31-505 Kraków, Poland; support@owlmeans.com; telephone +48 780 256 571 (“Processor”), conclude this DPA under GDPR Article 28. Where the Customer is itself a processor, it shall have authority to appoint OwlMeans and convey lawful instructions; role references apply accordingly. This DPA prevails over conflicting service terms for Customer Personal Data. Statutory transfer clauses prevail where applicable.
1.2. Processor shall process only documented instructions in the order, enabled features and Annex A, including international transfers, unless legally required otherwise. It shall inform Controller of such a requirement before processing unless prohibited, and promptly flag an instruction it considers unlawful. Controller determines lawful bases, notices, permissions and minimisation; neither party is excused from its own statutory duties.
1.3. OwlMeans controls its own prospect/contact administration, service correspondence and statutory-request records as described in the Privacy Policy. Customer-controlled personal data supplied for instructed project support, including a necessary attachment, remains within this DPA; sending it through an inquiry does not convert it into independent OwlMeans marketing or training data. Before using that channel for such data, the parties must ensure appropriate instructions, minimisation, authorised email/mailbox recipients and transfer/security particulars. The inquiry service’s temporary database deletion does not erase delivered email, attachments or backups; those copies remain subject to the applicable instructions and clause 4.2. Forward requests relating to customer-controlled data to the relevant Controller as required by clause 2.2.
1.4. “Customer Personal Data” means personal data processed by OwlMeans on the Customer’s documented instructions for the Customer’s project, repository, application or instructed support, including data for which the Customer is an authorised processor for another controller. It excludes data OwlMeans lawfully controls for its own account, billing, security or correspondence administration, whose roles and purposes follow the Privacy Policy. A data item’s receipt through a support channel does not alone change its controller/processor role.
2. Personnel, security and assistance
2.1. Access is limited to authorised persons bound to confidentiality. Processor shall implement and maintain risk-appropriate Article 32 measures, described in Annex B, considering confidentiality, integrity, availability, restoration and regular assessment. A feature name or contractual promise is not a certification of implementation.
2.2. Processor shall assist Controller with rights requests, security obligations, impact assessments and supervisory consultations, having regard to the processing and available information. It shall forward relevant requests without responding substantively except on instructions or legal obligation. Necessary assistance shall not be blocked by unreasonable charges; exceptional separately requested work may be agreed in advance.
2.3. Processor shall notify Controller without undue delay after becoming aware of a personal data breach, with available nature, affected categories/numbers, contact, likely consequences and containment details, and provide phased updates. This does not replace Controller’s applicable 72-hour notification duty. No unsupported shorter operational SLA is claimed.
3. Subprocessing and transfers
3.1. Controller grants general authorisation only for the confirmed subprocessors in Annex C and their stated processing. Processor shall notify intended additions or replacements in advance, allowing a reasonable objection period stated in the completed order. It shall resolve justified objections, offer a feasible alternative or permit ending affected processing with appropriate prepaid-fee adjustment. No unidentified fallback recipient is authorised.
3.2. Each subprocessor must be bound by equivalent Article 28 duties; Processor remains responsible for their performance. Restricted transfers require a valid Chapter V basis before they occur, and an assessment and supplementary measures where required. No unsigned SCC or unverified adequacy claim is incorporated by implication. For UK-regulated data, the applicable UK mechanism shall be separately established. Customer-selected independent services must have their role expressly assessed.
4. Records, audit and ending processing
4.1. Processor shall provide information necessary to demonstrate compliance and allow Controller or its independent auditor reasonable audits, including inspections where necessary, under confidentiality and security safeguards. Reasonable scheduling shall not frustrate an incident, authority request or statutory audit right. Processor shall maintain applicable processing records and cooperate with authorities.
4.2. At the end of processing, Controller chooses return or deletion of Customer Personal Data and existing copies, except legally required retention. The completed annex shall identify export formats, backup handling and deletion schedule. Retained data remains protected and restricted. Account closure or project deletion alone shall not be represented as erasing all traces or backups. Processor shall confirm completion on request.
Annex A. Processing description and instructions
Subject: requested AI software development, repository operations, project support and optional hosting/IAM. Duration: the instructed service relationship plus documented return/deletion and lawful retention. Nature: collection, storage, analysis/inference, generation, retrieval, transmission to authorised suppliers, access administration, hosting, export and deletion. Purpose: provide Customer’s specified project/application; no independent marketing, profiling, partner use, agent/pipeline-improvement dataset or own-model training.
Data subjects: Customer staff, contributors and application users whose data Customer lawfully submits. Data: identifiers, contact/account and role data, customer-submitted prompt/code/content, histories, operational metadata and instructed application records. Special-category, criminal-offence and children’s data require a separate documented assessment and safeguards before acceptance; these are not default optional-training inputs. Frequency: on request and during enabled hosting. Controller’s contact, actual dataset/categories, retention and geographic instructions shall be entered in the account/order annex before processing begins.
Annex B. Required security schedule
The completed deployment schedule shall identify tenant/project access separation, least privilege and authentication; secret handling and rotation; transport and storage protection; trace/content access and minimisation; vulnerability/update management; incident escalation; backup/restoration testing; and deletion/rights procedures. For each, it shall record the actual implemented measure, responsible contact and relevant limitations. Neither this list nor an alpha label proves a control exists. Processing requiring an absent control shall not activate until remediated or lawfully scoped out.
Annex C. Authorised supplier and transfer schedule
The Subprocessor schedule, completed with actual contracting entities, functions, locations, transfer grounds, supplier retention and objection notice period, forms this annex once accepted. Its active-service inventory identifies current use, rather than blanket Controller approval of every recipient or processing role. Authorisation applies only to the customer-data processing actually identified in the completed annex. Google reCAPTCHA is a disclosed security recipient for bot, fraud and abuse prevention. Its use for OwlMeans-controlled account or website data does not by itself appoint it as a subprocessor for customer data; any instructed customer-data processing requires the relevant completed supplier and transfer particulars. Controller contact and request channel: the order/account contact; Processor: support@owlmeans.com. Mandatory regional privacy rights and supervisory powers remain unaffected.