AIRepScore AIRepScore
Book a demo
Copied
Legal

Data Processing Agreement AIRepScore™

15 June 2026

AT

The Asyntis Team

Strategic Intelligence

AIRepScore™ Data Processing Agreement (DPA)

Version 1.0
Effective Date: Bussum, 15/06/2026


This Data Processing Agreement (“DPA”) forms part of the agreement between:
Customer (“Controller”)
and
AIRepScore™ / Asyntis (“Processor”)
and governs the processing of Personal Data under Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR).

1. Definitions

For the purposes of this DPA:

Controller
means the entity that determines the purposes and means of processing Personal Data.
Processor
means the entity processing Personal Data on behalf of the Controller.
Personal Data
has the meaning given in Article 4 GDPR.
Data Subject
means an identified or identifiable natural person.
Subprocessor
means any third party engaged by Processor to process Personal Data.
Applicable Data Protection Laws
means GDPR and any applicable national data protection legislation.

2. Scope and Purpose

Processor provides the AIRepScore platform and related services.
In performing these services, Processor may process Personal Data on behalf of Customer.
The subject matter, nature and purpose of processing are:
• User account administration
• Authentication and access management
• Subscription management
• Dashboard access
• Customer support
• Reporting and analytics
• Service operation and maintenance
Processor shall only process Personal Data in accordance with documented instructions from Controller unless required by law.

3. Categories of Personal Data

The following categories of Personal Data may be processed:
User Account Data
• Name
• Business email address
• Job title
• Company name
• User identifier
Technical Data
• IP address
• Login information
• Session identifiers
• Browser information
• Device information

Customer Submitted Data
Information voluntarily submitted by Customer through the platform.
Customer shall not intentionally upload special categories of personal data unless explicitly agreed in writing.

4. Categories of Data Subjects

Data Subjects may include:
• Customer employees
• Customer contractors
• Customer users
• Customer administrators
• Business contacts

5. Processor Obligations

Processor shall:
5.1 Process Only on Instructions
Process Personal Data only on documented instructions from Controller.
5.2 Confidentiality
Ensure that persons authorised to process Personal Data are subject to confidentiality obligations.
5.3 Security
Implement appropriate technical and organisational security measures.
5.4 Compliance Assistance
Provide reasonable assistance to Controller regarding:
• Data subject requests
• Security obligations
• DPIAs
• Regulatory inquiries

6. Security Measures

Processor shall implement appropriate measures including:
• Access controls
• Role-based permissions
• Secure authentication
• Encryption in transit
• Infrastructure monitoring
• Logging and audit controls
• Backup procedures
• Vulnerability management
Processor may update security measures provided that overall protection is not materially reduced.

7. Subprocessors

Controller authorises Processor to engage Subprocessors.
Processor may use Subprocessors including:
• Cloud hosting providers
• Authentication providers
• Analytics providers
• Payment providers
• AI service providers


Examples may include:
• OpenAI
• Anthropic
• Google
• Perplexity
• Mistral AI
• Railway
• Cloudflare
Processor shall ensure that Subprocessors are bound by data protection obligations substantially equivalent to this DPA.
Processor shall maintain an up-to-date Subprocessor list upon request.


8. International Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), Processor shall implement appropriate safeguards including:
• Standard Contractual Clauses (SCCs)
• Adequacy Decisions
• Other GDPR-compliant transfer mechanisms

9. Data Subject Requests

If Processor receives a request directly from a Data Subject, Processor shall:
• Promptly notify Controller
• Not respond directly unless authorised or legally required
Processor shall reasonably assist Controller in responding to requests.

10. Personal Data Breaches

Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.
The notification shall include, where available:
• Nature of the breach
• Categories of affected data
• Likely consequences
• Mitigation measures taken

11. Audits

Controller may request reasonable information demonstrating Processor’s compliance with this DPA.

Audits shall:
• Occur no more than once per year
• Be conducted during normal business hours
• Not interfere unreasonably with operations
• Be subject to confidentiality obligations
Processor may satisfy audit requests through independent security reports and certifications where available.

12. AI Processing

Customer acknowledges that AIRepScore uses third-party AI systems to generate analytical outputs.
Processor may submit limited information necessary to perform analyses to authorised AI providers.
Processor shall not use Customer Personal Data to train public AI models unless explicitly authorised by Customer.
AIRepScore does not intentionally provide Customer Personal Data to AI providers for model training purposes.

13. Retention and Deletion

Upon termination of the Services:
Processor shall, at Controller’s choice:
• Delete Personal Data; or
• Return Personal Data where technically feasible.
Processor may retain information where required by law or for legitimate security, accounting or compliance purposes.
Backups may persist for a limited period according to normal retention schedules.

 

14. Liability

Liability under this DPA shall be subject to the limitations of liability contained in the applicable customer agreement or Terms & Conditions.

15. Governing Law

This DPA shall be governed by the laws of The Netherlands.
Disputes arising under this DPA shall be submitted to the competent courts of The Netherlands.

Annex A – Processing Details

Subject Matter
Provision of AIRepScore software and analytics services.
Duration
For the duration of the customer relationship and applicable retention periods.
Purpose
Brand reputation analysis, AI perception analysis, recommendation analysis, reporting, support and platform administration.
Categories of Data Subjects
• Users
• Administrators
• Customer personnel
Categories of Personal Data
• Names
• Business contact details
• Login information
• Technical identifiers
• Customer-submitted information
 
Special Categories
Not intentionally processed.
Frequency
Continuous during use of the Services.

Annex B – Technical and Organisational Measures

Processor maintains measures including:
• Access management
• Authentication controls
• Network security
• Encryption in transit
• Infrastructure monitoring
• Backup procedures
• Incident response procedures
• Vendor management
• Employee confidentiality obligations

AIRepScore™ Data Processing Agreement v1.0