{-- Shared page body for /legal/dpa and its localized URLs. The copy is English-only for now -- translating legal text needs counsel, not a content pass -- but each locale serves it from its own URL so the nav, footer and language switcher stay in the visitor's language instead of the whole site flipping to English. Same shape as the blog, whose localized pages render English posts in the localized layout. --} Data Processing Agreement | Akumi
The EU AI Act arrives August 2. Can you prove where your AI data goes?

Data Processing Agreement

Last updated: 28 June 2026

About this summary

This page summarizes Akumi's Data Processing Agreement (DPA) in plain language so you can see how we handle personal data. It is not the agreement itself. The signed DPA, including its annexes, is the binding document, and you can request it to execute alongside your contract. Where this summary and the signed DPA differ, the signed DPA governs.

Roles and definitions

For personal data contained in the content you send through the platform, you are the controller and Akumi is the processor, processing that data on your behalf. Terms such as personal data, processing, controller, processor, and personal data breach have the meanings given in the GDPR.

Subject matter and details of processing

The DPA covers the processing carried out to provide the Service. The specifics are set out in Annex A and include:

  • Subject matter: provision of EU-sovereign inference and the governance modules you enable.
  • Duration: for the term of your agreement and any agreed wind-down period.
  • Nature and purpose: inference, retrieval, memory, caching, safety, and metering, as configured by you.
  • Types of personal data and categories of data subjects: as determined by the content you choose to send.

Processing on your instructions

We process personal data only on your documented instructions, which include your use of the platform and its settings, unless required to act otherwise by EU or member-state law (in which case we will inform you, unless the law prohibits it). We will tell you if, in our opinion, an instruction infringes data protection law.

Confidentiality

We ensure that personnel authorized to process personal data are bound by an appropriate duty of confidentiality and process the data only as needed to provide the Service.

Security measures

We implement appropriate technical and organizational measures under Article 32, taking into account the state of the art, the costs, and the risks. These are described in Annex B and on our Security and Trust page, and include:

  • EU residency of the application, models, and data.
  • Tenant isolation between organizations.
  • Encryption of data in transit and at rest.
  • Role-based access control, with SSO and SCIM available on Enterprise.
  • A metadata-only audit trail, with bounded retention.
  • Pseudonymization of personal data before any permitted external routing.

Sub-processors

You give general authorization for us to engage sub-processors to provide the Service. We:

  • Maintain a current list of sub-processors, published at akumi.cloud/legal/sub-processors and listed in Annex C.
  • Impose data protection obligations on each sub-processor that are equivalent to those in the DPA.
  • Remain liable to you for a sub-processor's performance of those obligations.
  • Give you advance notice of any intended addition or replacement of a sub-processor, so you can object on reasonable data protection grounds.

Assisting with data subject rights

Taking into account the nature of the processing, we assist you with appropriate technical and organizational measures to respond to data subject requests under Articles 12 to 23. The platform helps directly: personal data is pseudonymized before egress, and an erasure API removes an end-user's stored data on demand.

Assisting with your obligations

We assist you, taking into account the nature of processing and the information available to us, in meeting your obligations under Articles 32 to 36, including security of processing, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.

Personal data breaches

We maintain measures to detect and respond to personal data breaches, and will notify you without undue delay after becoming aware of a breach affecting your data, with the information you reasonably need to meet your own notification obligations.

International transfers

Processing is EU-resident. We do not transfer personal data outside the EU to provide the Service. Where you instruct routing to an external or non-EU model, that transfer occurs only through the egress guard and under an appropriate transfer mechanism, such as the Standard Contractual Clauses, and remains your decision as controller.

Return and deletion

On termination, and at your choice, we delete or return the personal data we process on your behalf and delete existing copies, unless EU or member-state law requires storage. Deletions you trigger during the term run in the background and are bounded by the retention you configured.

Audits and inspections

We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To minimize disruption, we may satisfy audit rights through up-to-date documentation and third-party audit reports where available, subject to reasonable notice and confidentiality.

Liability and precedence

The DPA forms part of your agreement with us. In the event of a conflict between the DPA and other terms regarding the processing of personal data, the DPA prevails. Liability is governed by your agreement with us.

Annexes

The signed DPA includes: Annex A, details of processing; Annex B, technical and organizational security measures; and Annex C, the list of authorized sub-processors, which mirrors the current list published at akumi.cloud/legal/sub-processors. These are provided with the DPA on request.

Executing the DPA

To put the DPA in place, contact legal@akumi.cloud or your account contact. We will share the current document, annexes, and sub-processor list.