Conformant — Data Processing Agreement summary (informational)
==============================================================

Full standard DPA (live page):
  https://conformant.eu/dpa

This summary helps questionnaires. The live DPA page is the authoritative
standard text. A countersigned copy can be requested via:
  https://conformant.eu/contact?intent=dpa

Roles
  Customer agency = controller for personal data entered in the workspace.
  Conformant = processor for that workspace processing (except account,
  billing, and marketing data where Conformant is controller — see Privacy).

Subject matter
  EU AI Act compliance workflows: inventories, classifications, obligations,
  evidence, documents, deadlines, audit logs, and Advisor messages — for the
  term of the subscription or trial and as needed to delete data afterward.

Security measures (high level)
  EU hosting for primary workspace data, encryption in transit, role-based
  access, organization-scoped data access, private storage for evidence files,
  and admin audit logging. Details: https://conformant.eu/security

Sub-processors
  Listed at https://conformant.eu/subprocessors and in 03-subprocessors.txt.
  Customers authorize those providers as described in the DPA.

International transfers
  Where a sub-processor processes data outside the EEA, we rely on
  appropriate safeguards such as Standard Contractual Clauses or equivalent.

Breach notification
  We notify the customer without undue delay after becoming aware of a
  personal data breach affecting workspace data we process on their behalf.

Deletion / return
  On workspace deletion or contract end, we delete or return workspace
  personal data within a reasonable period, except where retention is
  required by law. Admins can export JSON from Settings before deletion.

Contact
  hello@conformant.eu

This file is not a signed agreement.

Last updated: July 2026
