Version: 1.0Effective from: 2026-09-13

Data Processing Agreement (DPA)


§1 Subject, duration and purpose

This Data Processing Agreement (DPA) governs, under GDPR Art. 28, the processing of personal data that UAB NVGroup ("Processor") carries out on the instructions of the client ("Controller") using the demurrit.eu service (the "Service").

Purpose of processing — provision of the Service: extraction of data from cargo and customs documents, invoice/declaration auditing, and preparation of related reports/claims for the benefit of the Controller.

Duration of processing — this DPA remains in effect for as long as the underlying Service Agreement between the Controller and the Processor is in effect. Upon termination of the underlying agreement, §7 (Return and deletion of data upon termination) applies.

Categories of data subjects — the Controller's employees and customer portal users (name, email, role within the organization); and third parties whose data appears in the content of documents uploaded by the Controller (e.g. drivers, contact persons, consignees).

Categories of personal data — contact data (name, email, phone), data related to cargo/customs documents (vehicle registration number, driver's name, addresses, signatures on documents), and account usage data (login times, activity log).

§2 Location of processing

All primary processing and storage for the Service takes place exclusively within the EU/EEA: the application server and database – at netcup GmbH's data center in Nuremberg, Germany; document storage – at Hetzner Online GmbH's data center, also in Nuremberg; backups – at Akenes SA (Exoscale)'s data center in Vienna, Austria.

Data is transferred outside the EEA in two cases: (1) for automated data extraction from documents that cannot be processed deterministically on EU infrastructure (see Section 6.1 of the Privacy Policy – tiered processing, most documents NEVER leave the EU), content is transferred to Anthropic PBC, registered in the USA; (2) for sending emails (invoices, login links, reminders), via Proton AG, registered in Switzerland.

The USA has no general adequacy decision; the transfer to Anthropic PBC is based on the EU Standard Contractual Clauses (GDPR Art. 46), which form part of Anthropic's data processing terms. Switzerland is covered by the European Commission's adequacy decision (GDPR Art. 45) — no additional safeguards are required for the transfer to Proton AG.

§3 List of subprocessors (approved processors)

SubprocessorLocationPurpose
netcup GmbHRegistered: Karlsruhe, DE<br>Data center: Nuremberg, DEServer hosting, application + database
Hetzner Online GmbHNuremberg, DEDocument storage (S3-compatible)
Akenes SA (Exoscale)Registered: Switzerland<br>Data center: Vienna, AT (GDPR Art. 45 adequacy decision for Switzerland)Encrypted backups
Anthropic PBCSan Francisco, USA (GDPR Art. 46 Standard Contractual Clauses)AI-based data extraction from documents that cannot be processed deterministically
Proton AGSwitzerland (GDPR Art. 45 adequacy decision)Sending emails (invoices, login links, reminders)

By this DPA, the Controller grants the Processor general authorisation to engage the subprocessors listed above. The Processor undertakes to inform the Controller of any planned change involving the engagement or replacement of a subprocessor no later than 30 calendar days in advance (see Section 7 of the Privacy Policy), so that the Controller has the opportunity to raise a reasoned objection within 15 days. If such an objection is raised and the parties cannot agree on an alternative within a reasonable time, either party has the right to terminate the underlying agreement with respect to the part of the Service that requires the objected-to subprocessor.

§4 Processor's obligations

The Processor undertakes to:

§5 Right to audit

The Controller has the right, upon written notice of at least 20 business days, no more than once per calendar year (except where the audit is conducted due to a reasonable suspicion of a breach — in which case the advance notice period does not apply), to request that the Processor provide documents confirming compliance with this DPA and GDPR Art. 28. The audit shall be conducted during normal business hours, without unreasonably disrupting the Processor's operations, and the reasonable costs associated with a specific audit shall be borne by the Controller, except where the audit reveals an actual breach of the GDPR or this DPA.

§6 Technical and organisational measures (TOM)

These measures are actually implemented and verified as of the date this document was prepared (2026-09-06) — an honest list, not a marketing form:

A detailed description of technical and organisational measures, including their current limits, is available to the buyer's security team or data protection officer on request: privacy@demurrit.eu.

§7 Retention, deletion and return of data upon termination

Periods for ongoing processing are set out in Section 9 of the Privacy Policy (24 months for document originals, 40 months for customs documents, etc.) — this DPA does not duplicate them, but points to the same source, so the two documents cannot drift apart over time.

Regardless of the periods above, upon termination of the underlying Service Agreement between the Controller and the Processor, the Processor shall, within 30 days of the Controller's request, delete or (if requested by the Controller) return all remaining personal data and delete existing copies — except for data which EU or Member State law (e.g. accounting legislation, the CMR Convention, or the Union Customs Code) requires to be retained longer; in that case, the data shall be retained only for as long as required by that legal basis, and shall not be processed for any other purpose.

§8 Notification of personal data breaches

Upon becoming aware of a personal data breach concerning data processed under this DPA, the Processor shall notify the Controller without undue delay and no later than within 48 hours of becoming aware, by email to the address the Controller provided in its account or the underlying agreement. The notification shall describe, as far as possible, the nature of the breach, its likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects. This timeframe is set so that the Controller has a real opportunity to meet its own 72-hour notification obligation to the supervisory authority under GDPR Art. 33.

§9 Liability

Each party is liable for damage caused by its own breach of the GDPR or this DPA, in accordance with GDPR Art. 82 and applicable national law. Any limitations of liability agreed between the parties (if set out in the underlying Service Agreement) also apply to this DPA, except where such limitations are prohibited by mandatory provisions of the GDPR.

§10 Governing law and dispute resolution

This DPA is governed by the law of the Republic of Lithuania. Disputes arising out of or in connection with this DPA shall be resolved through negotiation, and failing agreement, before the competent court of the Republic of Lithuania having jurisdiction over the Processor's registered office.

§11 Contacts

For questions about this DPA, individual arrangements, or your data protection officer's questions: privacy@demurrit.eu. UAB NVGroup, Lithuania (details — see Section 1 of the Privacy Policy).