🏆 Download your copy of EU Compliance Landscape: What You Need to Know in 2025 [With Calendar] – Click here
This Data Protection Agreement (“Agreement”) is entered into by and between:
(1) [Customer Name], with registered office at [Customer Address] (“Controller”),
and
(2) Eyre AI Limited, trading as European Compliance Suite, with registered office at 19 Lake Court, Medway Drive, Tunbridge Wells TN12FH Kent, United Kingdom (“Processor”).
Together, the “Parties”.
This Agreement forms part of the Main Service Agreement between the Parties and sets out the Parties’ obligations with respect to the processing of personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).
1.1 This DPA governs the Processor’s processing of personal data on behalf of the Controller in connection with the services provided under the Main Service Agreement.
1.2 The nature, purpose, and duration of processing, along with the types of personal data and categories of data subjects, are described in Annex I.
2.1 The Controller determines the purposes and means of the processing of personal data.
2.2 The Processor shall only process personal data on documented instructions from the Controller, unless required to do so by EU or Member State law.
The Processor agrees to:
Process personal data only on the Controller’s documented instructions
Ensure confidentiality of persons authorized to process personal data
Implement appropriate technical and organizational security measures
Assist the Controller in fulfilling its obligations under GDPR Articles 32–36
Notify the Controller without undue delay after becoming aware of a personal data breach
Make available all information necessary to demonstrate compliance with this DPA
Cooperate with audits, inspections, or assessments initiated by the Controller or its delegates
4.1 The Processor shall implement appropriate security measures as required by Article 32 of the GDPR, including:
Encryption of data in transit and at rest
Role-based access controls
Logging and monitoring of data access
Secure hosting in EU-based data centers
Details are described in Annex II.
5.1 The Processor shall not engage any subprocessor without the prior written authorization of the Controller.
5.2 The current list of authorized subprocessors is provided in Annex III.
5.3 The Processor shall ensure that all subprocessors are contractually bound to obligations no less protective than those in this DPA.
6.1 The Processor shall not transfer personal data outside the European Economic Area (EEA) without:
The Controller’s written consent, and
An appropriate legal mechanism under Chapter V of the GDPR (e.g., Standard Contractual Clauses)
7.1 The Processor shall assist the Controller in fulfilling its obligations to respond to data subject requests, including:
Access
Rectification
Erasure
Restriction
Data portability
Objection
7.2 The Processor will not respond to requests directly unless authorized by the Controller.
8.1 The Processor shall notify the Controller without undue delay and no later than 48 hours after becoming aware of a personal data breach.
8.2 The notification will include, at a minimum:
Nature of the breach
Categories and number of data subjects affected
Likely consequences
Mitigation steps taken or planned
Upon termination or expiration of the Main Service Agreement, the Processor shall:
Return all personal data to the Controller, or
Delete all personal data securely,
unless EU law requires continued storage.
Each Party shall be liable for its respective acts or omissions under this Agreement in accordance with applicable law and the Main Service Agreement.
This DPA remains in effect as long as the Processor processes personal data on behalf of the Controller.
This Agreement is governed by the laws of [Insert Country].
Disputes shall be submitted to the exclusive jurisdiction of the courts of [Insert City].
For the Controller
Company: ___________________________
Name: _____________________________
Title: _____________________________
Date: _____________________________
Signature: __________________________
For the Processor (European Compliance Suite)
Company: ___________________________
Name: _____________________________
Title: _____________________________
Date: _____________________________
Signature: __________________________
Purpose of Processing: Documentation, summarisation, redaction, audit logging
Categories of Data Subjects: Employees, clients, meeting participants
Types of Personal Data: Names, contact info, recorded speech, chat transcripts, metadata
Special Categories: Only when explicitly provided and consented
Retention Period: Defined by the Controller or 30 days post-termination
TLS 1.3 encryption for all data in transit
AES-256 encryption for data at rest
EU-based ISO 27001–certified data centers
Immutable audit logs
Two-factor authentication
Principle of least privilege enforced for access
IONOS – EU-based cloud infrastructure provider
Sentry – EU-based performance monitoring
P-Cloud – Encrypted backups stored within the EU
A full and up-to-date list is available upon request or via our Trust Center.
Partners and advisors from:
Finally, a way to generate documentation we can actually use in an audit.
As a legal counsel in a public sector agency, I’m constantly balancing speed with compliance. European Compliance Suite gives us structured records, full traceability, and consent-first workflows—without slowing our team down.
Gus Kronenberg
Head of Legal
Financial Services Company
It’s the first tool we’ve used that respects both our data and our workflow.
Most platforms feel like they were built for someone else. With European Compliance Suite, everything—from redaction to access logs—is built around the realities of European healthcare compliance.
Kate Kälin
Clinical Operations Lead
EU Healthcare Provider
We didn’t need to train people on how to be compliant—the platform already is.
Our team used to spend hours cleaning up meeting notes and transcripts. Now, ECS gives us policy-aligned summaries, automatic logging, and auditable exports, right out of the box.
Dmytro Shepitko
IT & Compliance Manager
Public Sector Agency
Data hosted in the EU,
on-premise, or private cloud
GDPR, ISO, AI Act compliant + HIPAA module
Data Processing Agreements (DPA) in line with GDPR requirements.
Our partners: Eyre
Copyright © Eyre AI Limited. 2024-2025. All rights reserved.
Registered in England and Wales with company number: 15781228