GDPR · AI Act · Art. 28Data Processing Agreement (DPA)
Last updated: March 1, 2026 · GDPR Art. 28 & EU AI Act 2024/1689 compliant
This DPA is concluded between CoreCtic AI SAS (processor) and you (controller). It governs the processing of personal data carried out by CoreCtic AI in the context of providing the analytics AI proxy service, in accordance with Article 28 of the GDPR and the European AI Regulation (AI Act).
Article 1 — Purpose and parties
This Data Processing Agreement (hereinafter the "DPA") is concluded between: • The Controller: any natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing (hereinafter "the Client"). • The Processor: CoreCtic AI SAS, a simplified joint-stock company with its registered office in France, registered with the Paris Trade and Companies Register (hereinafter "CoreCtic AI"). This DPA is an integral part of the Terms of Service (ToS) accepted by the Client upon account creation. It governs the processing of personal data carried out by CoreCtic AI on behalf of the Client in the context of providing the analytics AI proxy service.
Article 2 — Nature of the processing
CoreCtic AI processes personal data on behalf of the Client for the following purposes: • Routing the Client's API requests to third-party artificial intelligence providers (OpenAI, Anthropic, Google, Mistral, etc.) • Recording usage metadata (model used, number of tokens, cost, latency, timestamp) • Applying the filtering rules configured by the Client (guardrails, blocked words, PII detection) • Semantic caching of responses to reduce the Client's costs • Generating usage statistics and reports accessible via the dashboard • Triggering the cost alerts configured by the Client This processing is carried out solely on the Client's instructions, in accordance with Article 28 of the GDPR.
Article 3 — Categories of data processed
In the context of the service, CoreCtic AI may process the following categories of personal data: • Identification data: first name, last name, email address, company name, registration number • API usage data: prompts sent to AI models (unless the Client has disabled the "Prompt logging" option), generated responses, number of tokens, cost in USD, model used, timestamp • Technical data: pseudonymized IP address (SHA-256 hashed — never stored in plaintext), User-Agent, session and request identifiers • Billing data: billing details, transaction history (processed by Stripe) Data relating to natural persons contained in prompts falls under the Client's sole responsibility. CoreCtic AI does not control prompt content and cannot guarantee the absence of personal data therein.
Article 4 — Duration of the processing
This DPA applies for the entire duration of the contractual relationship between the Client and CoreCtic AI. Upon expiry or termination of the contract, CoreCtic AI undertakes to: • Delete or anonymize all of the Client's personal data within 30 days • Provide the Client, upon request made before the deadline expires, with a copy of their data in a standard format (JSON or CSV) • Retain only the data necessary to comply with legal and accounting obligations (up to 10 years for billing data, in accordance with the French Commercial Code) During the performance of the contract, usage logs are kept for a rolling 24 months. Guardrail logs (filtering incidents) are deleted after 90 days. Notifications are purged after 30 days.
Article 5 — Obligations of CoreCtic AI (Processor)
CoreCtic AI undertakes to: • Process personal data only on documented instructions from the Controller • Ensure that persons authorized to process the data commit to confidentiality • Take all appropriate security measures (Article 32 of the GDPR) • Not engage another processor without the Controller's prior written authorization, except for the processors listed in Article 6 • Assist the Controller, as far as possible, in fulfilling its obligation to respond to requests to exercise data subjects' rights • Assist the Controller in complying with the obligations set out in Articles 32 to 36 of the GDPR • Notify any personal data breach within 72 hours of becoming aware of it • Make available all information necessary to demonstrate compliance with the obligations of this DPA • Allow for and contribute to audits
Article 6 — Sub-processors
The Client authorizes CoreCtic AI to use the following sub-processors in the context of providing the service: • Supabase Inc. — Database hosting (AWS EU-West-1 servers, Frankfurt). DPA available. • Vercel Inc. — Next.js application hosting (global CDN, EU servers available). DPA available. • Stripe Inc. — Payment processing. PCI-DSS Level 1 certified. DPA available. • Tinybird S.L. — Real-time analytics (managed ClickHouse, AWS EU-West-1 servers). DPA available. • Upstash Inc. — Redis cache and vector store (EU servers available, EU-US Standard Contractual Clauses). DPA available. • Cloudflare Inc. — Edge proxy infrastructure (global network, DPA and SCCs available). • Resend Inc. — Transactional email delivery (US servers, SCCs). DPA available. • Sentry (Functional Software Inc.) — Technical error monitoring (US servers, SCCs). DPA available. • Microsoft Clarity — Audience measurement and heatmaps, loaded only after consent (US servers, Data Privacy Framework). • Google (Analytics & Tag Manager) — Audience measurement, loaded only after consent (US servers, Data Privacy Framework). • Third-party AI providers (OpenAI, Anthropic, Google, Mistral, etc.) — These providers receive the Client's prompts solely for the purpose of executing requests. Each provider has its own data processing policies. In the event of a change to this list, CoreCtic AI will inform the Client by email with 30 days' notice. The Client may object within this period.
Article 7 — Security measures (Art. 32 GDPR)
CoreCtic AI implements the following technical and organizational measures: • Encryption of data in transit: HTTPS/TLS 1.3 on all communications • Encryption of sensitive data at rest: third-party API keys encrypted with AES-256-GCM (HKDF-SHA256, unique initialization vector per encryption) • IP pseudonymization: IP addresses stored as an irreversible SHA-256 hash • Row-level access control: Supabase Row Level Security (RLS) — each user can only access their own data • Role separation: the proxy_worker role is limited to write-only access on usage_logs • Multi-factor authentication available for administrator accounts • Access logging: all critical actions are recorded in audit_logs • Regular security testing: code review, annual penetration tests • Continuity plan: automatic Supabase backups, RPO < 1 hour • PII detection: automatic filtering of personal data in prompts (configurable by the Client)
Article 8 — Transfers outside the European Union
CoreCtic AI strives to keep data processing within the European Union. Some sub-processors (Cloudflare, Upstash, Vercel, Stripe, Resend, Sentry, Microsoft, Google) may carry out transfers to third countries (notably the United States) as part of their infrastructure. These transfers are governed by: • The Standard Contractual Clauses (SCCs) adopted by the European Commission on June 4, 2021 • The additional safeguards required following the Schrems II ruling • The EU-US Data Privacy Framework (DPF) where the sub-processor is certified under it Upon request, CoreCtic AI can provide the Client with a detailed list of transfers outside the EU and the applicable protection mechanisms.
Article 9 — Data subjects' rights
The Client, as Controller, is solely responsible for responding to requests to exercise rights made by data subjects (right of access, rectification, erasure, portability, objection, restriction). CoreCtic AI provides the Client with the following tools to facilitate the exercise of these rights: • Data export (API GET /api/gdpr/export) — structured JSON format • Account deletion and log anonymization (API DELETE /api/gdpr/delete) • Access to automated decisions (API GET /api/gdpr/ai-decisions) — in accordance with Article 22 of the GDPR • Disabling prompt logging ("Prompt logging" setting in Profile → Settings) If a request is received directly by CoreCtic AI from a data subject, CoreCtic AI undertakes to inform the Client without delay and to forward the request to them.
Article 10 — Personal data breach notification
In the event of a personal data security breach within the meaning of Article 4(12) of the GDPR, CoreCtic AI undertakes to: • Notify the Client within 72 hours of becoming aware of it • Provide in the notification: the nature of the breach, the categories and approximate number of data subjects concerned, the compromised data, the likely consequences and the measures taken • Fully cooperate with the Client in dealings with the competent authorities (CNIL) Notification will be sent to the email address of the Client's administrator account registered on the platform.
Article 11 — AI Act compliance
CoreCtic AI acts as a deployer of AI systems within the meaning of the European Artificial Intelligence Regulation (AI Act — Regulation EU 2024/1689), applicable from August 2026. In this context, CoreCtic AI undertakes to: • Not use Clients' data to train its own AI models • Inform end users when content is generated by an AI system (via the interface and API metadata) • Make available the logs of automated decisions (in accordance with the rights to explanation) • Apply the illegal-content filtering guardrails configured by the Client • Maintain a log of guardrail incidents for auditability purposes The Client, as an operator deploying AI systems to its end users, is responsible for complying with the obligations incumbent upon it under the AI Act.
Article 12 — Audit and compliance
The Client has the right to verify CoreCtic AI's compliance with its obligations under this DPA. For this purpose: • CoreCtic AI makes available the necessary information upon written request to privacy@corectic.ai • The Client may appoint an independent third-party auditor, at its own expense, with 30 business days' notice • CoreCtic AI may satisfy this audit obligation by providing recognized certifications or audit reports (ISO 27001, SOC 2 Type II) where available.
Article 13 — Governing law and jurisdiction
This DPA is governed by French and European law, in particular the GDPR (Regulation EU 2016/679) and, upon its entry into force, the AI Regulation (AI Act — Regulation EU 2024/1689). Any dispute relating to the interpretation or performance of this DPA shall be subject to the exclusive jurisdiction of the courts of Paris, unless otherwise mandated by applicable law. In the event of a conflict between this DPA and the ToS, the provisions of the DPA prevail with regard to the processing of personal data. Last updated: March 1, 2026.
Acceptance of the DPA
By creating an account or using the CoreCtic AI service, the Client accepts the terms of this DPA. This acceptance is recorded with a timestamp in our compliance system. For any question regarding this DPA, contact our Data Protection Officer: privacy@corectic.ai