Data Processing Agreement

Adatfeldolgozási Szerződés — GDPR Article 28 compliant.

Effective: 09 September 2026 · Version 1.0

Quick summary for the busy reader. This DPA is the legal contract between you (the data controller, e.g. an SMB owner using Auro AI) and us (the data processor, Evosolve KFT). By signing up to or continuing to use Auro AI, this DPA forms part of our service agreement. A counter-signed PDF copy is available on request: email [email protected].

1. Parties

Processor: Evosolve KFT, a company registered in Hungary, Cégjegyzékszám: 01-09-433209, Adószám: 32915617-2-43, registered office: 1023 Budapest, Úrbér utca 7., 14em. ("Auro AI", "we").
Controller: the natural or legal person identified by the email address registered with their Auro AI customer account ("Customer", "you").

2. Subject matter, duration, nature & purpose

Subject: the processing of personal data on behalf of the Customer in connection with the Customer's use of the Auro AI software-as-a-service (the "Service").
Duration: from account creation until 90 days after termination, at which point the deletion / return obligations in Section 10 apply.
Nature: automated electronic processing on Hetzner Cloud (Germany / Finland) infrastructure, plus the AI-inference sub-processors listed in /subprocessors.php.
Purpose: to deliver Auro AI features — CRM, Finance & Accounting, HR, communications inbox, AI staff member — to the Customer.

3. Categories of data subjects & types of personal data

Categories of data subjects: the Customer's employees; the Customer's end-customers (B2B contacts); the Customer's suppliers; visitors to the Customer's web properties when an Auro AI widget is embedded; job applicants where the Customer uses the recruitment module.

Types of personal data:

We do not process special-category data (Art. 9 GDPR) by default. Sick-leave records (medical category) are stored only as start/end dates with the leave-type label "sick"; no diagnosis, no clinical detail.

4. Processor's obligations (Art. 28(3) GDPR)

We undertake to:

  1. Process only on documented instructions. The instructions consist of (a) this DPA, (b) the Customer's configuration of the Service via the dashboard, (c) any individual instruction sent to [email protected]. We will not process for our own purposes; we will not sell, train AI on, or otherwise repurpose Customer data.
  2. Ensure confidentiality. All Auro AI personnel and contractors with access to personal data are bound by written confidentiality obligations.
  3. Implement appropriate security measures (Art. 32 GDPR). See Annex II below.
  4. Engage sub-processors only on the same terms. See Section 6 + /subprocessors.php.
  5. Assist the Controller with data subject requests (access / rectification / erasure / portability / objection) within 7 working days of receiving a request from the Customer.
  6. Notify breaches per Section 8.
  7. Delete or return data at end of processing per Section 10.
  8. Make available all information needed to demonstrate compliance, and allow audits per Section 9.

5. Customer's responsibilities

6. Sub-processors

Customer hereby grants general written authorisation for the engagement of sub-processors. The current list is published at /subprocessors.php and we update it before adding or replacing a sub-processor. You will receive notice of changes at least 30 days in advance via the email on file. You may object in that window; if we cannot accommodate your objection, you may terminate the contract with pro-rata refund of pre-paid fees.

7. International transfers

EU/EEA storage is the default. Where a sub-processor operates outside the EEA (specifically: Anthropic in the US for Claude API calls; Amazon Web Services for Bedrock-hosted Claude models in eu-central-1 / us-east-1 cross-region inference; Google for Gemini API calls in eu-west-1), transfers are governed by the EU Standard Contractual Clauses (Module 3, controller-to-processor) executed between Evosolve KFT and the sub-processor. Our incorporated SCCs are available on request.

8. Personal data breach notification

We will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach. Notification will include: nature of the breach; categories and approximate number of data subjects and records concerned; likely consequences; measures taken or proposed. Channel: email to the registered Customer email address + a status page entry at status.auroai.eu.

9. Audits & inspections

We will respond to a Customer audit request once per calendar year by providing: (a) the latest internal security review report, (b) the most recent penetration test summary, (c) responses to a written audit questionnaire. On-site audits are available on 30 days' written notice and at the Customer's expense, subject to reasonable confidentiality and scheduling constraints. Audits triggered by a documented breach are not subject to the once-per-year limit.

10. Return / deletion of data at end of processing

On termination of the service contract, the Customer may within 30 days request a full data export (CSV + JSON). After 30 days — or immediately on Customer instruction — we delete all personal data from active systems within 7 days, and from backups within 90 days. Records required to be retained by Hungarian law (e.g. invoice records, 8-year retention under Act C of 2000 §169) are kept in a sealed archive for the statutory period.

11. Liability

Liability under this DPA is limited as set out in the main service agreement. Each party indemnifies the other for damages arising from its own breach of GDPR obligations. Neither party limits liability where prohibited by Art. 82 GDPR (data subject's right to compensation).

12. Governing law & jurisdiction

This DPA is governed by Hungarian law. Disputes are subject to the exclusive jurisdiction of the competent Hungarian courts.


Annex I — Description of processing (summary)

Subject matterProvision of the Auro AI SaaS platform.
DurationTerm of the service agreement + 90-day return window.
Nature & purposeAutomated electronic processing for CRM, F&A, HR, communications, AI assistance.
Categories of data subjectsSee Section 3.
Types of personal dataSee Section 3.

Annex II — Technical & organisational measures (TOMs)

For a counter-signed PDF version of this DPA, email [email protected] with your company name, registered seat, and tax ID. We aim to return signed copies within 5 working days.