Data Processing Agreement (DPA) — UPGREAT AI
Version 1.0 — Effective 12 June 2026
This Data Processing Agreement ("DPA") forms part of the agreement between SustAInable BV, registered office Lammerstraat 13, 9000 Gent, company number 1038.977.886 ("Processor", "UPGREAT") and the business customer ("Controller", "Customer") for the Services under the Terms of Service (the "Agreement"). It implements article 28 GDPR.
1. Subject matter, duration, nature and purpose
1.1. UPGREAT processes personal data on behalf of the Customer to the extent the Customer submits personal data as Input to the Inference API (and, when available, processes personal data on GPU VMs). The processing consists of the transient, automated processing of Input to generate Output, and the recording of usage metadata.
1.2. This DPA applies for the duration of the Agreement and until deletion of all Customer personal data under clause 9.
1.3. Details of the processing are set out in Annex 1.
2. Instructions
2.1. UPGREAT processes personal data only on documented instructions from the Customer. The Agreement, this DPA, and the Customer's use of the API (including model selection and request parameters) constitute the complete instructions. Additional instructions require written agreement.
2.2. UPGREAT informs the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law, and may suspend execution of that instruction.
2.3. If Union or Member State law to which UPGREAT is subject requires processing beyond the instructions, UPGREAT informs the Customer before processing, unless that law prohibits such information on important grounds of public interest.
3. Confidentiality
UPGREAT ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is necessary (need-to-know).
4. Security (art. 32 GDPR)
UPGREAT implements appropriate technical and organisational measures taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing. The measures are described in Annex 3. UPGREAT may update the measures provided the overall level of protection is not reduced.
5. Subprocessing
5.1. The Customer grants a general authorisation for engaging subprocessors. The current list is set out in Annex 2 and maintained at upgreat.ai/legal/subprocessors.
5.2. UPGREAT will inform the Customer of intended additions or replacements at least 30 days in advance (via the subprocessor page and/or e-mail). The Customer may object on reasonable, data-protection-related grounds within 14 days; if no solution is found, the Customer may terminate the affected Services as its sole remedy.
5.3. UPGREAT imposes data protection obligations on subprocessors that are substantially equivalent to those in this DPA and remains fully liable to the Customer for the performance of the subprocessor's obligations.
6. Data subject rights
Taking into account the nature of the processing, UPGREAT assists the Customer with appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to data subject requests (arts. 12–23 GDPR). Given that Input and Output are not stored, such assistance will in practice be limited to usage metadata and account data. If a data subject contacts UPGREAT directly regarding processing under this DPA, UPGREAT will refer the request to the Customer without undue delay.
7. Assistance with compliance
UPGREAT assists the Customer, taking into account the nature of the processing and the information available to it, in ensuring compliance with articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation). UPGREAT may charge reasonable costs for assistance exceeding what can reasonably be expected free of charge.
8. Personal data breach
UPGREAT notifies the Customer without undue delay, and at the latest within 48 hours after becoming aware of a personal data breach affecting Customer personal data, providing the information reasonably required under article 33(3) GDPR, supplemented as it becomes available. UPGREAT documents breaches and remediation. Notification is not an acknowledgement of fault or liability.
9. Deletion and return
Upon termination of the Agreement, UPGREAT deletes all personal data processed on behalf of the Customer within 90 days, unless Union or Member State law requires storage. Input and Output are not stored and therefore require no deletion. Billing-relevant metadata is retained as required by Belgian tax and accounting law and deleted thereafter. Upon request before termination, UPGREAT provides an export of available usage metadata in a structured, commonly used, machine-readable format.
10. Audits
10.1. UPGREAT makes available all information necessary to demonstrate compliance with article 28 GDPR, in the first instance through documentation, security descriptions and, where available, third-party attestations or audit reports.
10.2. If this is reasonably insufficient, the Customer may conduct (or mandate an independent auditor bound by confidentiality to conduct) an audit, maximum once per 12 months, with at least 30 days' written notice, during business hours, without disrupting operations. Each party bears its own costs. Access to other customers' data and to facilities of datacenter operators is excluded; for the latter, UPGREAT provides the relevant facility certifications.
11. Data location and transfers
All processing under this DPA takes place within the European Economic Area (Belgium and Iceland). UPGREAT will not transfer Customer personal data outside the EEA without the Customer's prior written consent and, where applicable, appropriate safeguards under Chapter V GDPR.
12. Liability and precedence
Liability under this DPA is governed by the liability provisions of the Agreement, without prejudice to article 82 GDPR. In case of conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.
Annex 1 — Description of the processing
| Item | Description |
|---|---|
| Subject matter | Provision of AI inference services (Inference API); when available, GPU VM infrastructure |
| Nature of processing | Transient, automated processing of Input to generate Output; recording of usage metadata (timestamp, model, account/user identifier, token counts); no storage of Input/Output content; no use for model training |
| Purpose | Delivery of the Services ordered by the Customer |
| Duration | Term of the Agreement |
| Categories of data subjects | Determined by the Customer; typically: Customer's end users, employees, customers and other persons whose data appears in Input |
| Categories of personal data | Determined by the Customer; any personal data contained in Input. The Customer must not submit special categories of data (art. 9 GDPR) or data relating to criminal convictions (art. 10 GDPR) unless agreed in writing |
| Storage | Input/Output: none. Usage metadata: per the Privacy Policy and clause 9 of this DPA |
Annex 2 — Authorised subprocessors
| Subprocessor | Company number | Location | Service |
|---|---|---|---|
| Limoengroen BV | BE 0840.067.015 | Belgium | Network and infrastructure operations (AS205924, connectivity, IP resources) |
| Upgrade Estate Group BV | BE 0400.927.922 | Belgium | Contracted personnel for platform operations and administration (administrative access to platform systems) |
| Upgrade Estate NV | BE 0840.066.124 | Belgium | Contracted personnel for platform operations and administration (administrative access to platform systems) |
Datacenter facility providers with physical hosting only and no logical access to personal data (not subprocessors, listed for transparency): professionally operated datacenter facilities in Belgium and Iceland (EEA), including edge deployments within Upgrade Estate group buildings. For physical security reasons, specific facility names and addresses are not published; they are available to the Customer under confidentiality upon reasonable request.
Annex 3 — Technical and organisational measures (summary)
- Encryption in transit: TLS 1.2+ on all public endpoints; encrypted internal service-to-service communication where applicable.
- No content persistence: Input/Output processed in volatile memory only; logging of request/response bodies disabled at gateway and serving layers.
- Access control: role-based access, strong authentication (MFA/SSO) for administrative access, least-privilege, periodic access reviews.
- Network security: segmentation between tenant-facing, management and storage networks; firewalling; DDoS mitigation at the network edge; secured and validated routing.
- Change management: version-controlled, reviewed and auditable change management for all infrastructure changes.
- Monitoring: centralised logging of system events (not content), alerting, capacity and anomaly monitoring.
- Physical security: hosting exclusively in professionally operated datacenter facilities with access control, surveillance and environmental protections.
- Resilience: redundant power, cooling and network paths at facility level; defined incident response procedures.
- Personnel: confidentiality undertakings; access limited to need-to-know.
- Data deletion: documented procedures for sanitisation or destruction of storage media at end of life.