{-- Shared page body for /legal/dpa and its localized URLs. The copy is English-only for now -- translating legal text needs counsel, not a content pass -- but each locale serves it from its own URL so the nav, footer and language switcher stay in the visitor's language instead of the whole site flipping to English. Same shape as the blog, whose localized pages render English posts in the localized layout. --}
Last updated: 28 June 2026
This page summarizes Akumi's Data Processing Agreement (DPA) in plain language so you can see how we handle personal data. It is not the agreement itself. The signed DPA, including its annexes, is the binding document, and you can request it to execute alongside your contract. Where this summary and the signed DPA differ, the signed DPA governs.
For personal data contained in the content you send through the platform, you are the controller and Akumi is the processor, processing that data on your behalf. Terms such as personal data, processing, controller, processor, and personal data breach have the meanings given in the GDPR.
The DPA covers the processing carried out to provide the Service. The specifics are set out in Annex A and include:
We process personal data only on your documented instructions, which include your use of the platform and its settings, unless required to act otherwise by EU or member-state law (in which case we will inform you, unless the law prohibits it). We will tell you if, in our opinion, an instruction infringes data protection law.
We ensure that personnel authorized to process personal data are bound by an appropriate duty of confidentiality and process the data only as needed to provide the Service.
We implement appropriate technical and organizational measures under Article 32, taking into account the state of the art, the costs, and the risks. These are described in Annex B and on our Security and Trust page, and include:
You give general authorization for us to engage sub-processors to provide the Service. We:
Taking into account the nature of the processing, we assist you with appropriate technical and organizational measures to respond to data subject requests under Articles 12 to 23. The platform helps directly: personal data is pseudonymized before egress, and an erasure API removes an end-user's stored data on demand.
We assist you, taking into account the nature of processing and the information available to us, in meeting your obligations under Articles 32 to 36, including security of processing, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
We maintain measures to detect and respond to personal data breaches, and will notify you without undue delay after becoming aware of a breach affecting your data, with the information you reasonably need to meet your own notification obligations.
Processing is EU-resident. We do not transfer personal data outside the EU to provide the Service. Where you instruct routing to an external or non-EU model, that transfer occurs only through the egress guard and under an appropriate transfer mechanism, such as the Standard Contractual Clauses, and remains your decision as controller.
On termination, and at your choice, we delete or return the personal data we process on your behalf and delete existing copies, unless EU or member-state law requires storage. Deletions you trigger during the term run in the background and are bounded by the retention you configured.
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To minimize disruption, we may satisfy audit rights through up-to-date documentation and third-party audit reports where available, subject to reasonable notice and confidentiality.
The DPA forms part of your agreement with us. In the event of a conflict between the DPA and other terms regarding the processing of personal data, the DPA prevails. Liability is governed by your agreement with us.
The signed DPA includes: Annex A, details of processing; Annex B, technical and organizational security measures; and Annex C, the list of authorized sub-processors, which mirrors the current list published at akumi.cloud/legal/sub-processors. These are provided with the DPA on request.
To put the DPA in place, contact legal@akumi.cloud or your account contact. We will share the current document, annexes, and sub-processor list.
We use privacy-friendly, EU-hosted analytics to understand how Akumi is used. Accept analytics cookies, or continue without them. See our cookie policy.