Data Processing Agreement

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Phi Consulting SRL ("Processor", "we"). It applies where we process personal data on your behalf to provide the ArchiMind service — namely the workspace, project and client content you enter, upload or generate. Our processing of your account, billing and security data (where we are the controller) is governed by the Privacy Policy, not this DPA.

2. Subject-matter, duration, nature and purpose

We process personal data only to provide and support the service, for the duration of your subscription and any wind-down period. Processing includes storage, hosting, structuring, retrieval, transmission, AI-assisted generation on your instruction, and deletion.

3. Types of data and categories of data subjects

  • Types of data: identification and contact details, project and specification content, and any other personal data you choose to include.
  • Data subjects: your clients, contacts, colleagues and other individuals whose data you enter.

You are responsible for having a lawful basis to provide this data. Do not upload special-category data unless it is necessary and lawful.

4. Our obligations

We will:

  • process the personal data only on your documented instructions (including as to transfers), unless required otherwise by EU or Belgian law — in which case we inform you, unless the law prohibits it;
  • ensure that persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (GDPR art. 32) — see section 7;
  • assist you, taking into account the nature of processing, in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection);
  • assist you with security, breach-notification (art. 33/34) and data-protection-impact-assessment (art. 35/36) obligations;
  • at your choice, delete or return the personal data at the end of the service — by default at the end of the retrieval period in the Terms (30 days after the transition period), or earlier on your instruction — and delete existing copies — database recovery points within 35 days, stored object versions together with the objects — unless retention is legally required;
  • make available the information necessary to demonstrate compliance and allow for and contribute to audits (see section 8);
  • immediately inform you if, in our opinion, an instruction infringes the GDPR or other applicable data-protection law.

5. Sub-processors

You give general authorisation for us to engage sub-processors. Our current sub-processors are listed on the Sub-processors page. We impose data-protection obligations on each sub-processor equivalent to those in this DPA and remain responsible for their performance. We will automatically notify the Customer's workspace owner and designated legal contact by email at least 30 days before engaging a new or replacement sub-processor (no subscription required), and update the sub-processor page. You have 30 days to object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected service.

6. International transfers

Our core hosting is in the EU/EEA. Some processing may occur outside the EU/EEA — notably AI-assisted generation via Google's Gemini API — in which case the transfer relies on a European Commission adequacy decision or on the Commission's Standard Contractual Clauses with supplementary measures as needed. Our US-headquartered sub-processors that host data in the EU (see /subprocessors) rely on the EU-US Data Privacy Framework where certified and otherwise on the Standard Contractual Clauses for any access from the United States. You may request a copy of the relevant safeguards.

7. Security

We maintain the following measures, appropriate to the risk (art. 32 GDPR), and may improve them provided the level of protection is not materially reduced:

  • Encryption — all traffic over TLS; all stored data encrypted at rest, with keys managed in the EU region.
  • Access control — every request is authenticated and authorised against your workspace; infrastructure administration is limited to named staff, protected by multi-factor authentication and least-privilege roles; production changes go through reviewed, versioned infrastructure code.
  • Workspace isolation — your data is partitioned by workspace identifier and never served to another workspace.
  • Logging and diagnostics — operational logs are minimised: specification content and project data are never written to logs; identifiers, counts, technical error context and, for security events, the e-mail address concerned may appear. They are kept 90 days (API access logs 7 days); error diagnostics use pseudonymous identifiers.
  • Backup and recovery — point-in-time recovery for the database (35-day window) and versioned object storage; prior object versions are removed together with the objects when content is erased.
  • Vulnerability management — dependencies are pinned and integrity-checked; security updates ship through the release process; automated test suites run before every release.
  • Sub-processors — each is bound by a data-processing agreement and listed at /subprocessors.
  • Incidents and people — security incidents are triaged on detection and personal-data breaches reported under section 9; persons with access are bound by confidentiality.

8. Audits

On reasonable prior request, and no more than once a year (unless required by a supervisory authority or following a breach), we will provide the information reasonably necessary to demonstrate compliance with this DPA and support audits by you or your mandated auditor, under confidentiality and without unreasonable disruption to the service.

9. Personal-data breach

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification obligations.

10. Liability, precedence and law

Liability under this DPA is subject to the limitations in the Terms of Service. If there is a conflict between this DPA and the Terms on the processing of personal data, this DPA prevails. This DPA is governed by Belgian law; disputes fall under the jurisdiction of the courts of Brussels.