AIRepScore™ Data Processing Agreement (DPA)
Version 1.0Effective Date: Bussum, 15/06/2026
This Data Processing Agreement (“DPA”) forms part of the agreement between:
Customer (“Controller”)
and
AIRepScore™ / Asyntis (“Processor”)
and governs the processing of Personal Data under Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR).
1. Definitions
For the purposes of this DPA:Controller
means the entity that determines the purposes and means of processing Personal Data.
Processor
means the entity processing Personal Data on behalf of the Controller.
Personal Data
has the meaning given in Article 4 GDPR.
Data Subject
means an identified or identifiable natural person.
Subprocessor
means any third party engaged by Processor to process Personal Data.
Applicable Data Protection Laws
means GDPR and any applicable national data protection legislation.
2. Scope and Purpose
Processor provides the AIRepScore platform and related services.In performing these services, Processor may process Personal Data on behalf of Customer.
The subject matter, nature and purpose of processing are:
• User account administration
• Authentication and access management
• Subscription management
• Dashboard access
• Customer support
• Reporting and analytics
• Service operation and maintenance
Processor shall only process Personal Data in accordance with documented instructions from Controller unless required by law.
3. Categories of Personal Data
The following categories of Personal Data may be processed:User Account Data
• Name
• Business email address
• Job title
• Company name
• User identifier
Technical Data
• IP address
• Login information
• Session identifiers
• Browser information
• Device information
Customer Submitted Data
Information voluntarily submitted by Customer through the platform.
Customer shall not intentionally upload special categories of personal data unless explicitly agreed in writing.
4. Categories of Data Subjects
Data Subjects may include:• Customer employees
• Customer contractors
• Customer users
• Customer administrators
• Business contacts
5. Processor Obligations
Processor shall:5.1 Process Only on Instructions
Process Personal Data only on documented instructions from Controller.
5.2 Confidentiality
Ensure that persons authorised to process Personal Data are subject to confidentiality obligations.
5.3 Security
Implement appropriate technical and organisational security measures.
5.4 Compliance Assistance
Provide reasonable assistance to Controller regarding:
• Data subject requests
• Security obligations
• DPIAs
• Regulatory inquiries
6. Security Measures
Processor shall implement appropriate measures including:• Access controls
• Role-based permissions
• Secure authentication
• Encryption in transit
• Infrastructure monitoring
• Logging and audit controls
• Backup procedures
• Vulnerability management
Processor may update security measures provided that overall protection is not materially reduced.
7. Subprocessors
Controller authorises Processor to engage Subprocessors.Processor may use Subprocessors including:
• Cloud hosting providers
• Authentication providers
• Analytics providers
• Payment providers
• AI service providers
Examples may include:
• OpenAI
• Anthropic
• Google
• Perplexity
• Mistral AI
• Railway
• Cloudflare
Processor shall ensure that Subprocessors are bound by data protection obligations substantially equivalent to this DPA.
Processor shall maintain an up-to-date Subprocessor list upon request.
8. International Transfers
Where Personal Data is transferred outside the European Economic Area (EEA), Processor shall implement appropriate safeguards including:• Standard Contractual Clauses (SCCs)
• Adequacy Decisions
• Other GDPR-compliant transfer mechanisms
9. Data Subject Requests
If Processor receives a request directly from a Data Subject, Processor shall:• Promptly notify Controller
• Not respond directly unless authorised or legally required
Processor shall reasonably assist Controller in responding to requests.
10. Personal Data Breaches
Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.The notification shall include, where available:
• Nature of the breach
• Categories of affected data
• Likely consequences
• Mitigation measures taken
11. Audits
Controller may request reasonable information demonstrating Processor’s compliance with this DPA.Audits shall:
• Occur no more than once per year
• Be conducted during normal business hours
• Not interfere unreasonably with operations
• Be subject to confidentiality obligations
Processor may satisfy audit requests through independent security reports and certifications where available.
12. AI Processing
Customer acknowledges that AIRepScore uses third-party AI systems to generate analytical outputs.Processor may submit limited information necessary to perform analyses to authorised AI providers.
Processor shall not use Customer Personal Data to train public AI models unless explicitly authorised by Customer.
AIRepScore does not intentionally provide Customer Personal Data to AI providers for model training purposes.
13. Retention and Deletion
Upon termination of the Services:Processor shall, at Controller’s choice:
• Delete Personal Data; or
• Return Personal Data where technically feasible.
Processor may retain information where required by law or for legitimate security, accounting or compliance purposes.
Backups may persist for a limited period according to normal retention schedules.
14. Liability
Liability under this DPA shall be subject to the limitations of liability contained in the applicable customer agreement or Terms & Conditions.15. Governing Law
This DPA shall be governed by the laws of The Netherlands.Disputes arising under this DPA shall be submitted to the competent courts of The Netherlands.
Annex A – Processing Details
Subject MatterProvision of AIRepScore software and analytics services.
Duration
For the duration of the customer relationship and applicable retention periods.
Purpose
Brand reputation analysis, AI perception analysis, recommendation analysis, reporting, support and platform administration.
Categories of Data Subjects
• Users
• Administrators
• Customer personnel
Categories of Personal Data
• Names
• Business contact details
• Login information
• Technical identifiers
• Customer-submitted information
Special Categories
Not intentionally processed.
Frequency
Continuous during use of the Services.
Annex B – Technical and Organisational Measures
Processor maintains measures including:• Access management
• Authentication controls
• Network security
• Encryption in transit
• Infrastructure monitoring
• Backup procedures
• Incident response procedures
• Vendor management
• Employee confidentiality obligations
AIRepScore™ Data Processing Agreement v1.0
