Dotika

    Data Processing Agreement

    Version 1.0 — in force since 10 August 2026

    Dotika S.à r.l. · 9, rue du Laboratoire, L-1911 Luxembourg · RCS Luxembourg B296675 · TVA LU36653351

    Document exported on 10 August 2026 — Source: http://127.0.0.1:4173/en/dpa

    Dotika S.à r.l. · 9, rue du Laboratoire, L-1911 Luxembourg · RCS Luxembourg B296675 · TVA LU36653351 · dotika.ai
    Dotika
    ·
    Article 28 of Regulation (EU) 2016/679 ⁠

    Data Processing Agreement⁠

    Version 1.0 — in force since 10 August 2026

    This agreement governs the processing of personal data that Dotika S.à r.l. (the "Processor") carries out on behalf of its client (the "Controller"), under an Assignment governed by Dotika's General Terms and Conditions or through use of the Bryf platform.

    It is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and forms an integral part of the main contract. It applies automatically wherever the Assignment involves processing personal data on the Client's behalf, without the need for a separate signature; the Client may nonetheless request a signed copy at privacy@dotika.ai.

    In the event of a conflict between this agreement and the main contract on a data protection matter, this agreement prevails.

    1. Roles of the parties

    The Client determines the purposes and means of the processing: it acts as controller. Dotika processes the data on its behalf: it acts as processor.

    Where Dotika processes data for its own purposes — managing the commercial relationship, invoicing, measuring its website audience — it acts as controller. Those activities are described in its privacy policy and fall outside the scope of this agreement.

    The Client warrants that it has a valid legal basis for the processing it entrusts to Dotika, that it has informed the data subjects, and that the data transmitted is adequate, relevant and limited to what is necessary.

    2. Documented instructions

    Dotika processes the data only on the Client's documented instructions. The following constitute documented instructions: the main contract, the accepted Offer, Annex 1 to this agreement, and any subsequent instruction sent in writing to privacy@dotika.ai.

    Dotika immediately informs the Client if an instruction appears to infringe the GDPR or another Union or Member State data protection provision. It may suspend performance of the instruction concerned until the matter is clarified.

    If Union or Member State law requires Dotika to carry out processing, it informs the Client beforehand, unless that law prohibits such information on important grounds of public interest.

    3. Confidentiality

    Dotika ensures that persons authorised to process the data are bound by an appropriate contractual or statutory confidentiality obligation, and that they receive the necessary data protection training.

    Access to the Client's data is limited to those staff and practitioners whose involvement is necessary to perform the Assignment, on a least-privilege basis.

    4. Security measures

    Dotika implements the appropriate technical and organisational measures required by Article 32 GDPR, set out in Annex 2. It may update them, provided the level of security is not degraded.

    5. Sub-processors

    The Client gives Dotika general authorisation to engage the sub-processors listed in Annex 3, which constitutes the prior written authorisation required by Article 28(2) GDPR.

    Dotika informs the Client of any addition or replacement of a sub-processor at least thirty (30) days before it goes live. The Client has that period to object in writing, giving reasons. If it objects, the parties will seek an alternative in good faith; failing agreement, either party may terminate the Assignment concerned without indemnity, the Client paying for services performed.

    Dotika imposes on each sub-processor, by contract, data protection obligations equivalent to those in this agreement. It remains fully liable to the Client for those sub-processors' performance of their obligations.

    6. Assistance with data subject rights

    Taking into account the nature of the processing, Dotika assists the Client through appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection).

    If a data subject contacts Dotika directly, Dotika does not respond on the substance and forwards the request to the Client within five (5) business days, unless the Client instructs otherwise.

    7. Personal data breach

    Dotika notifies the Client of any personal data breach without undue delay and no later than forty-eight (48) hours after becoming aware of it, so as to allow the Client to meet its own seventy-two (72) hour deadline under Article 33 GDPR.

    The notification describes, to the extent information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects.

    Dotika documents every breach and provides the Client with the reasonable assistance needed to notify the supervisory authority and, where applicable, to communicate with the data subjects. It makes no notification to the authority or to data subjects on the Client's behalf without the Client's written instruction.

    8. Impact assessment and prior consultation

    Dotika assists the Client, taking into account the nature of the processing and the information available to it, in carrying out data protection impact assessments (Article 35) and, where applicable, in conducting prior consultation of the supervisory authority (Article 36).

    This assistance is provided within reasonable limits; beyond that, it may be invoiced on terms agreed between the parties.

    9. Transfers outside the European Union

    Data is processed and stored within the European Union, subject to the sub-processors listed in Annex 3 whose location is indicated there.

    Any transfer to a third country is governed by the Standard Contractual Clauses adopted by the European Commission and, where required, by supplementary measures resulting from a transfer impact assessment.

    Dotika informs the Client of any binding request from a third-country authority concerning the Client's data, unless legally prohibited, and endeavours to challenge it where there are reasonable grounds to do so.

    10. Artificial intelligence

    Where the Assignment involves the use of artificial intelligence models supplied by third parties, data transmitted to those providers is sent solely to produce the requested output.

    Dotika contracts with those providers so that the Client's data is not used to train or improve their models. Any exception would be subject to prior notice and the Client's written agreement.

    The Client remains responsible for the lawfulness of the data it submits and for its use of the outputs produced, which must be subject to human verification before any decision producing effects concerning individuals.

    11. Fate of the data at the end of the contract

    At the end of the Assignment, Dotika will, at the Client's written election, return the data in a structured, commonly used format, or delete it.

    Failing an instruction from the Client within thirty (30) days of the end date, Dotika deletes the data within ninety (90) days, except for data whose retention is required by Union or Member State law, which then remains protected by this agreement until it is actually deleted.

    Dotika certifies deletion in writing at the Client's request. Encrypted backups are purged in line with their rotation cycle, within a maximum of six (6) months.

    12. Audit and documentation

    Dotika makes available to the Client all information necessary to demonstrate compliance with the obligations of Article 28 GDPR.

    The Client may carry out an audit, including an inspection, once in any twelve (12) month period, subject to thirty (30) days' written notice, during business hours, without disrupting Dotika's activity and subject to confidentiality. An additional audit may be carried out following a confirmed data breach or at the reasoned request of a supervisory authority.

    Dotika may satisfy this obligation by providing the audit reports, certifications or security questionnaires available to it, where these reasonably answer the Client's questions.

    Audit costs are borne by the Client, unless the audit reveals a material failure by Dotika to meet its obligations.

    13. Term, liability and governing law

    This agreement takes effect when the Assignment begins and ends on completion of the processing operations and deletion or return of the data.

    Each party is liable for damage caused by processing which infringes the GDPR, under the conditions set out in Article 82. The limitations of liability stipulated in the main contract apply to this agreement to the extent permitted by law.

    This agreement is governed by Luxembourg law. The supervisory authority competent for Dotika is the Commission nationale pour la protection des données (CNPD), Luxembourg.

    Annex 1 — Description of the processing

    Subject matter
    Performance of the Assignment described in the accepted Offer, or provision of the Bryf platform.
    Nature of the operations
    Collection, recording, organisation, structuring, storage, consultation, adaptation, retrieval, use, disclosure by transmission, erasure.
    Purposes
    Those defined by the Client in the main contract: consulting and audit, development and integration of solutions, training, hosting and operation of the Bryf platform.
    Duration
    The duration of the Assignment, plus the return or deletion periods set out in Article 11.
    Categories of data subjects
    Depending on the Assignment: the Client's staff, its customers and prospects, its candidates, its newsletter subscribers, the users of its services.
    Categories of data
    Depending on the Assignment: identification and contact data, professional data, connection and usage data, content transmitted by the Client. Processing of special categories of data (Article 9) is excluded, save under a specific prior written agreement.

    Where the Assignment warrants it, this annex is refined in the Offer or in an attached document signed by both parties, which then prevails over this general description.

    Annex 2 — Technical and organisational measures

    • Encryption of data in transit (TLS 1.2 minimum) and at rest on the hosting infrastructure.
    • Named access control, least-privilege principle, strong authentication on administration consoles.
    • Separation of development, staging and production environments.
    • Logging of access and sensitive operations, retained to allow incident investigation.
    • Regular, encrypted backups, with restore testing.
    • Pseudonymisation or anonymisation of data where the purpose pursued allows it.
    • Automatic filtering of direct identifiers (e-mail addresses, phone numbers) in exchanges with the conversational assistant before storage.
    • IP addresses processed as a salted cryptographic hash, never in clear text.
    • Request rate limiting and abuse logging on public endpoints.
    • Signed confidentiality undertakings from staff and data protection awareness training.
    • Documented data breach management procedure, with a single point of contact: privacy@dotika.ai.
    • Regular access reviews and revocation of permissions when a staff member leaves or an assignment ends.

    Annex 3 — Authorised sub-processors

    Sub-processorRoleData locationSafeguards
    Supabase Inc.Database, server functions and file storageEuropean UnionData processing agreement, Art. 28 GDPR
    Netlify, Inc.Hosting and delivery of the website pagesUnited StatesStandard Contractual Clauses
    Anthropic PBCLanguage model behind the conversational assistantUnited StatesStandard Contractual Clauses — no training on the data
    Resend, Inc.Delivery of transactional and confirmation e-mailsUnited StatesStandard Contractual Clauses
    Stripe Payments Europe, Ltd.Payment processing for the Bryf platformEuropean Union (Ireland)Data processing agreement, Art. 28 GDPR

    Sub-processors specific to a particular Assignment (the Client's own tools, infrastructure it mandates, specialist providers) are added to this list in the corresponding Offer. The current version of this annex is available at this address; any change is notified in accordance with Article 5.

    Acceptance

    This agreement is accepted by the Client when it accepts the Offer. A named copy, ready to sign and completed with the details specific to your Assignment, is available on request at privacy@dotika.ai.

    Dotika

    Leading AI Consulting in Luxembourg. From Knowledge to Strategy. From AI to Impact.

    Dotika - Your trusted AI partner in Luxembourg. Expert consulting in Artificial Intelligence, Machine Learning, and Data Science solutions for digital transformation.

    9, rue du Laboratoire, L-1911 Luxembourg Luxembourg
    +352 621 786 827

    AI Services

    • Dotika.Insight
    • Dotika.Campus
    • Dotika.Advisory
    • Dotika.Delivery
    • Check my certificate ↗

    Explore

    • Approach
    • Case studies
    • Journal
    • Newsletter

    Company

    • Manifesto
    • Life @ Dotika
    • Press
    • Careers
    • Contact
    © 2026 Dotika · AI Consulting & Solutions Luxembourg · All rights reserved
    Legal NoticePrivacy PolicyTerms of UseCookie PolicyGDPR Processing
    ·