AdmituraAdmitura

Data Processing Agreement

Last updated: 9 September 2026

You are the controller of the data in your workspace; we are your processor. We only act on your instructions, keep it in the EU, use the sub-processors listed below, tell you within 48 hours of a breach, and delete everything when you leave. Full text below.

1. Scope and roles

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Admitura – Pieter Beirnaert (“Admitura”, “Processor”) and the Customer (“Controller”). It applies whenever Admitura processes personal data on the Customer's behalf in providing the Service, and is intended to satisfy Article 28 of Regulation (EU) 2016/679 (“GDPR”).

The Customer is the controller of the personal data it and its requesters put into its workspace. Admitura is the processor. For account, billing, and usage data that Admitura collects for its own purposes, Admitura is an independent controller; that processing is described in the Privacy Policy.

2. Details of processing

  • Subject matter and purpose: hosting and operating the Admitura intake, review, and workflow platform for the Customer.
  • Nature: storage, retrieval, display, transmission, search, notification by email, export, deletion, and — only where the Customer enables AI features — automated drafting from request content.
  • Duration: the term of the Terms of Service plus the export and deletion periods described below.
  • Data subjects: the Customer's users (administrators, reviewers, members), people who submit requests to the Customer, and anyone mentioned in submitted content.
  • Categories of data: names, email addresses, roles, the content of intake forms and submissions (which the Customer designs and therefore controls), reviews, scores, comments, uploaded files, and audit and workflow history. The Customer must not collect special-category data (Art. 9 GDPR) or data of children through the Service unless it has a lawful basis and has told us in advance.

3. Instructions and confidentiality

Admitura will process personal data only on the Customer's documented instructions — the Terms of Service, this DPA, and the Customer's use of the Service's settings and features constitute those instructions — unless required otherwise by EU or member-state law, in which case Admitura will inform the Customer before processing unless the law prohibits it. Admitura will tell the Customer if it believes an instruction infringes data protection law.

Admitura ensures that every person authorized to process the personal data is bound by confidentiality. Access to production data is limited to the operator of the Service and is used only to run, secure, and support it.

4. Security measures

Admitura implements appropriate technical and organizational measures for the risk, including at least:

  • encryption in transit (TLS) for all connections, and encryption at rest by our hosting providers;
  • strict tenant isolation — every record carries the workspace it belongs to and every query is scoped to it at the data-access layer;
  • hashed passwords, email verification, optional SSO (OIDC) and SCIM provisioning for enterprise workspaces, and step-up authentication for privileged operations;
  • role-based access within a workspace, controlled by the Customer's administrators;
  • an audit log of significant actions inside the workspace;
  • rate limiting and abuse detection on public endpoints;
  • managed, redundant infrastructure with automated backups; and
  • a documented process for handling security incidents.

Admitura may update these measures over time provided the overall level of protection is not reduced.

5. Sub-processors

The Customer gives general authorization for Admitura to use the sub-processors below. Admitura imposes data-protection obligations on each sub-processor equivalent to this DPA and remains responsible for their performance.

Sub-processorPurposeLocation
Vercel Inc.Application hosting, edge network, file (blob) storage, and cookieless usage analyticsEU (Frankfurt) compute; US-headquartered
Railway Corp.Managed PostgreSQL database hostingEU (europe-west4) region; US-headquartered
Resend Inc.Transactional email delivery (verification codes, notifications)US-headquartered; EU sending region where available
Stripe Payments Europe Ltd.Subscription billing and payment processing (billing contact and payment data only)Ireland / US
OpenRouter Inc. and its underlying model providersOptional AI features (draft assessments, form-building assistance). Only used when an organization turns AI features on; only the content of the request being processed is sentUS; model providers vary — no data is used for model training

Changes. Admitura will give at least 14 days' notice (by email to workspace administrators or by updating this page and notifying in-app) before adding or replacing a sub-processor. If the Customer has reasonable data-protection grounds to object, it may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees; continued use after the notice period is acceptance.

6. International transfers

Customer Data is stored and processed in the EU/EEA. Some sub-processors are headquartered in, or may provide support from, the United States or other third countries. Where personal data is transferred outside the EEA, Admitura relies on the European Commission's Standard Contractual Clauses (or the EU–US Data Privacy Framework where the recipient is certified) and appropriate supplementary measures.

7. Assistance to the Controller

Taking into account the nature of the processing, Admitura will assist the Customer, by appropriate technical and organizational measures and insofar as possible, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). The Service already lets administrators view, edit, export, and delete most data directly; for the rest, requests to Admitura are handled within 10 business days.

If Admitura receives a request directly from a data subject about Customer Data, it will redirect the data subject to the Customer and not respond substantively unless the Customer instructs it to or the law requires it.

Admitura will also assist the Customer, on request and at reasonable cost where the effort is significant, with security, breach notification, data protection impact assessments, and prior consultation obligations under Articles 32–36 GDPR.

8. Personal data breaches

Admitura will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data, providing the information reasonably available at that time and updating it as the investigation progresses. The Customer is responsible for notifying its supervisory authority and data subjects where required.

9. Deletion and return of data

During the term the Customer can export its data through the Service; the Customer's right to retrieve its data and switch to another provider is set out in the Terms of Service (“Getting your data out and switching provider”). On termination or on written request, Admitura deletes Customer Data from production systems: a workspace deletion is scheduled with a short grace period (currently 7 days, to allow accidental deletions to be reversed) and then permanently erased; residual copies in encrypted backups are overwritten in the ordinary backup rotation (at most 30 days) and are not restored except to recover the Service as a whole. Admitura may retain data it is legally required to keep (for example invoicing records), subject to continued confidentiality.

10. Audit and information

Admitura will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR — this DPA, its security description, its sub-processor list, and, on request, summaries of any third-party assessments it holds — and will allow and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates: no more than once a year (unless a supervisory authority or a breach requires more), on at least 30 days' notice, during business hours, under confidentiality, without disrupting the Service, and at the Customer's cost. Written questionnaires are the default audit method.

11. Liability and precedence

The limitations and exclusions of liability in the Terms of Service apply to this DPA. Nothing in this DPA limits the parties' obligations or the data subjects' rights under the GDPR. If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA prevails. This DPA is governed by the same law and jurisdiction as the Terms of Service.

12. Contact

Data-protection questions and instructions: privacy@admitura.com. Enterprise customers who need a countersigned copy of this DPA can request one at the same address.

© 2026 Admitura · Home · Terms · Privacy · DPA