Data Processing Agreement (DPA)
§1 Subject, duration and purpose
This Data Processing Agreement (DPA) governs, under GDPR Art. 28, the processing of personal data that UAB NVGroup ("Processor") carries out on the instructions of the client ("Controller") using the demurrit.eu service (the "Service").
Purpose of processing — provision of the Service: extraction of data from cargo and customs documents, invoice/declaration auditing, and preparation of related reports/claims for the benefit of the Controller.
Duration of processing — this DPA remains in effect for as long as the underlying Service Agreement between the Controller and the Processor is in effect. Upon termination of the underlying agreement, §7 (Return and deletion of data upon termination) applies.
Categories of data subjects — the Controller's employees and customer portal users (name, email, role within the organization); and third parties whose data appears in the content of documents uploaded by the Controller (e.g. drivers, contact persons, consignees).
Categories of personal data — contact data (name, email, phone), data related to cargo/customs documents (vehicle registration number, driver's name, addresses, signatures on documents), and account usage data (login times, activity log).
§2 Location of processing
All primary processing and storage for the Service takes place exclusively within the EU/EEA: the application server and database – at netcup GmbH's data center in Nuremberg, Germany; document storage – at Hetzner Online GmbH's data center, also in Nuremberg; backups – at Akenes SA (Exoscale)'s data center in Vienna, Austria.
Data is transferred outside the EEA in two cases: (1) for automated data extraction from documents that cannot be processed deterministically on EU infrastructure (see Section 6.1 of the Privacy Policy – tiered processing, most documents NEVER leave the EU), content is transferred to Anthropic PBC, registered in the USA; (2) for sending emails (invoices, login links, reminders), via Proton AG, registered in Switzerland.
The USA has no general adequacy decision; the transfer to Anthropic PBC is based on the EU Standard Contractual Clauses (GDPR Art. 46), which form part of Anthropic's data processing terms. Switzerland is covered by the European Commission's adequacy decision (GDPR Art. 45) — no additional safeguards are required for the transfer to Proton AG.
§3 List of subprocessors (approved processors)
| Subprocessor | Location | Purpose |
|---|---|---|
| netcup GmbH | Registered: Karlsruhe, DE<br>Data center: Nuremberg, DE | Server hosting, application + database |
| Hetzner Online GmbH | Nuremberg, DE | Document storage (S3-compatible) |
| Akenes SA (Exoscale) | Registered: Switzerland<br>Data center: Vienna, AT (GDPR Art. 45 adequacy decision for Switzerland) | Encrypted backups |
| Anthropic PBC | San Francisco, USA (GDPR Art. 46 Standard Contractual Clauses) | AI-based data extraction from documents that cannot be processed deterministically |
| Proton AG | Switzerland (GDPR Art. 45 adequacy decision) | Sending emails (invoices, login links, reminders) |
By this DPA, the Controller grants the Processor general authorisation to engage the subprocessors listed above. The Processor undertakes to inform the Controller of any planned change involving the engagement or replacement of a subprocessor no later than 30 calendar days in advance (see Section 7 of the Privacy Policy), so that the Controller has the opportunity to raise a reasoned objection within 15 days. If such an objection is raised and the parties cannot agree on an alternative within a reasonable time, either party has the right to terminate the underlying agreement with respect to the part of the Service that requires the objected-to subprocessor.
§4 Processor's obligations
The Processor undertakes to:
- process personal data only on the Controller's documented instructions (including instructions relating to transfers of personal data to a third country), unless required to do so by EU or Member State law — in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
- ensure that persons authorised to process personal data have committed themselves in writing to confidentiality or are under an appropriate statutory obligation of confidentiality;
- take the technical and organisational measures set out in §6, pursuant to GDPR Art. 32;
- comply with the conditions set out in §3 for engaging subprocessors;
- taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures for the fulfilment of the Controller's obligation to respond to requests for exercising data subjects' rights (GDPR Chapter III);
- assist the Controller in ensuring compliance with the obligations under GDPR Art. 32–36 (security of processing, breach notification, data protection impact assessment, prior consultation), taking into account the nature of processing and the information available to the Processor;
- at the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of processing-related services, and delete existing copies, unless EU or Member State law requires storage of the personal data (see §7);
- make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Art. 28, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (see §5).
§5 Right to audit
The Controller has the right, upon written notice of at least 20 business days, no more than once per calendar year (except where the audit is conducted due to a reasonable suspicion of a breach — in which case the advance notice period does not apply), to request that the Processor provide documents confirming compliance with this DPA and GDPR Art. 28. The audit shall be conducted during normal business hours, without unreasonably disrupting the Processor's operations, and the reasonable costs associated with a specific audit shall be borne by the Controller, except where the audit reveals an actual breach of the GDPR or this DPA.
§6 Technical and organisational measures (TOM)
These measures are actually implemented and verified as of the date this document was prepared (2026-09-06) — an honest list, not a marketing form:
- Encryption in transit: all traffic over TLS (Let's Encrypt, automatically renewed certificate).
- Database isolation: organization separation at the database level (row-level security with FORCE), applied to EVERY table holding organization data – verified by automated tests.
- Server access control: SSH key authentication only (password login disabled), root login disabled, firewall (ufw) allows only necessary ports (22/80/443), automatic security updates.
- Document storage protection: uploaded original documents are stored with versioning and Object Lock (Governance mode) – confirmed by a real test that even an admin key cannot permanently delete a stored version without additional permission.
- Backups: daily, automated, stored with a different provider than the production infrastructure, using keys without delete permission. A real restore procedure to an independent server has been verified.
- Access log: an append-only log of every document's status changes (write and read only for the application).
A detailed description of technical and organisational measures, including their current limits, is available to the buyer's security team or data protection officer on request: privacy@demurrit.eu.
§7 Retention, deletion and return of data upon termination
Periods for ongoing processing are set out in Section 9 of the Privacy Policy (24 months for document originals, 40 months for customs documents, etc.) — this DPA does not duplicate them, but points to the same source, so the two documents cannot drift apart over time.
Regardless of the periods above, upon termination of the underlying Service Agreement between the Controller and the Processor, the Processor shall, within 30 days of the Controller's request, delete or (if requested by the Controller) return all remaining personal data and delete existing copies — except for data which EU or Member State law (e.g. accounting legislation, the CMR Convention, or the Union Customs Code) requires to be retained longer; in that case, the data shall be retained only for as long as required by that legal basis, and shall not be processed for any other purpose.
§8 Notification of personal data breaches
Upon becoming aware of a personal data breach concerning data processed under this DPA, the Processor shall notify the Controller without undue delay and no later than within 48 hours of becoming aware, by email to the address the Controller provided in its account or the underlying agreement. The notification shall describe, as far as possible, the nature of the breach, its likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects. This timeframe is set so that the Controller has a real opportunity to meet its own 72-hour notification obligation to the supervisory authority under GDPR Art. 33.
§9 Liability
Each party is liable for damage caused by its own breach of the GDPR or this DPA, in accordance with GDPR Art. 82 and applicable national law. Any limitations of liability agreed between the parties (if set out in the underlying Service Agreement) also apply to this DPA, except where such limitations are prohibited by mandatory provisions of the GDPR.
§10 Governing law and dispute resolution
This DPA is governed by the law of the Republic of Lithuania. Disputes arising out of or in connection with this DPA shall be resolved through negotiation, and failing agreement, before the competent court of the Republic of Lithuania having jurisdiction over the Processor's registered office.
§11 Contacts
For questions about this DPA, individual arrangements, or your data protection officer's questions: privacy@demurrit.eu. UAB NVGroup, Lithuania (details — see Section 1 of the Privacy Policy).