Data Processing Agreement

Last updated: June 25, 2026

1. Definitions

In this Data Processing Agreement ("DPA"):

  • "Controller" means the entity which determines the purposes and means of processing Personal Data
  • "Processor" means Luris.ai, which processes Personal Data on behalf of the Controller
  • "Personal Data" means any information relating to an identified or identifiable natural person
  • "Data Subject" means the individual to whom Personal Data relates
  • "GDPR" means the General Data Protection Regulation (EU) 2016/679

2. Processing of Personal Data

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure that persons authorized to process Personal Data have committed to confidentiality
  • Take all measures required pursuant to Article 32 of the GDPR
  • Respect the conditions for engaging another processor
  • Assist the Controller in responding to Data Subject requests

3. Security of Processing

The Processor shall implement appropriate technical and organizational measures including:

  • Pseudonymization and encryption of Personal Data
  • Ability to ensure ongoing confidentiality, integrity, availability and resilience
  • Ability to restore availability and access to Personal Data in a timely manner
  • Regular testing, assessment and evaluation of security measures
  • ISO 27001 certification and SOC 2 Type II compliance

4. Sub-processors

The Controller provides general authorization for the Processor to engage sub-processors. The Processor shall:

  • Inform the Controller of any intended changes concerning sub-processors
  • Ensure sub-processors are bound by the same data protection obligations
  • Remain fully liable for sub-processor performance
  • Maintain a current list of sub-processors available upon request

5. International Data Transfers

For transfers of Personal Data outside the EEA, the Processor shall:

  • Only transfer data to countries with adequate protection decisions
  • Implement appropriate safeguards (Standard Contractual Clauses)
  • Ensure compliance with Chapter V of the GDPR
  • Notify the Controller of any transfer requirements

6. Data Subject Rights

The Processor shall assist the Controller in fulfilling obligations to respond to Data Subject requests for:

  • Access to Personal Data
  • Rectification or erasure of Personal Data
  • Restriction of processing
  • Data portability
  • Objection to processing

7. Data Breach Notification

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data breach, providing:

  • Nature of the breach including categories and number of Data Subjects
  • Name and contact details of the data protection officer
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

8. Audit and Inspection

The Processor shall:

  • Make available all information necessary to demonstrate compliance
  • Allow for and contribute to audits conducted by the Controller
  • Provide annual third-party audit reports (SOC 2 Type II)
  • Immediately inform the Controller if instructions infringe data protection law

9. Deletion and Return of Data

Upon termination of services, the Processor shall, at the choice of the Controller:

  • Delete all Personal Data and existing copies
  • Return all Personal Data to the Controller
  • Provide certification of deletion
  • Retain data only as required by applicable law

10. Liability and Indemnification

Each party shall be liable for damages caused by processing that infringes the GDPR. The Processor shall indemnify the Controller for damages arising from the Processor's breach of this DPA or applicable data protection laws.

11. Contact Information

For questions about this Data Processing Agreement:

  • Email: dpo@luris.ai
  • Data Protection Officer: [DPO Name]
  • Address: [Business Address]