Data processing (DPA)
Data processing agreement
If you use AICLOUD Bulgaria (“AICLOUD”) to process personal data of your own customers or staff, this is the document that governs our relationship under Article 28 GDPR. It supplements the Terms of use and prevails over them on matters of personal data.
Last revised: 6 August 2026
1. When this document applies
It applies when you use the platform to process personal data of third parties — your customers, employees, applicants, patients, partners. You then decide why and how they are processed, and we process them on your instruction. If you use the platform only for yourself and upload no third-party personal data, this document does not concern you; your own data is covered by the Privacy policy.
2. Who is who
- You are the controller. You decide what data to upload, what it is used for and how long it is kept.
- We — 3D Code EOOD — are the processor. We process it only in order to provide you the service.
- The infrastructure provider, the language model providers and the others listed below are our sub-processors.
- If you are yourself a processor for a client of yours, we are a sub-processor and everything here applies in the same way.
3. On whose instructions we process
We process personal data only on your documented instructions. Your instructions are: the Terms of use, this document, and the way you have configured and use the platform. We do not process your data for our own purposes — not for model training, not for advertising, not for profiling. If we consider an instruction to infringe data protection law, we will tell you before carrying it out.
4. What exactly is processed
- Subject matter — processing of personal data in order to provide you the platform and the services on it.
- Duration — for the term of the agreement, plus the export period after it ends.
- Nature and purpose — storage, retrieval, transmission and processing, including sending text to a language model provider in order to obtain a response.
- Categories of data subjects — determined by you. May include your staff, customers, applicants, counterparties.
- Categories of data — determined by you. May include names, contact details, identifiers, document and correspondence content.
5. Data we do not accept without an explicit agreement
Do not upload health information, biometric data, children's data, criminal record data or payment card data unless we have agreed to it in writing in advance. The reason is not formal: those categories require measures the platform does not offer today, and an agreement with every sub-processor down the chain.
6. Security measures
The measures in force are described by name and verifiably on the Data security page — encryption in transit, passwords stored only as an irreversible digest, role-separated access, logical isolation between customers and a log of administrative actions. That page forms part of this document. The measures may change, but not fall below what is described there.
7. Sub-processors
By accepting this document you give us general authorisation to engage sub-processors. The categories are:
- AI infrastructure and hosting provider — storage and processing, with data at rest in the European Union.
- Language model providers — OpenAI, Anthropic, Google. Only the text submitted for processing goes to them.
- Stripe — payment card processing.
- Email service provider — notifications, confirmations and correspondence.
- The full current list with names is provided on request by email.
8. Changing a sub-processor, and objection
We notify you at least 14 days before a new sub-processor begins processing personal data. If you have a reasonable objection, raise it in writing within that period — we will look for a solution, and if none is found you may terminate the affected service. We are answerable for the acts of our sub-processors as for our own.
9. Data subject rights
We assist you in answering a request for access, rectification, erasure, restriction, portability or objection — through the export and deletion facilities available in the platform. If a data subject approaches us directly, we will not answer in your place: we redirect them to you, unless the law requires otherwise.
10. Security incidents
We notify you without undue delay and no later than 72 hours after we become aware of an incident. The notice states what happened, the categories of data and approximate number of subjects affected, the likely consequences and the measures taken, together with a contact point. We assist you in notifying the supervisory authority and the data subjects. For an incident in a sub-processor's systems, our deadline runs from the moment they notify us.
11. International transfers
Data at rest is stored in the European Union. Language model processing may take place outside the European Economic Area. Such transfers rest on the European Commission's standard contractual clauses (Decision (EU) 2021/914, controller-to- processor module), which are deemed incorporated into this document.
12. Audits and inspections
On request we provide the information necessary for you to demonstrate compliance with Article 28 GDPR, and we complete your questionnaire. An on-site inspection is subject to the usual limits: 30 days' written notice, no more than once a year except after an incident or at a supervisory authority's request, during business hours, at your cost and with the auditor bound by confidentiality. One thing we say plainly: we cannot give you access to our sub-processor's data centre. Instead we provide their audit reports and certifications, to the extent we are entitled to share them.
13. Deletion and return of data
After termination you have 15 days to export your data in a machine-readable format using the platform's facilities. After that period we may delete all personal data from our systems and those of our sub-processors. On request we issue written confirmation of deletion. We retain data only to the extent the law obliges us to — accounting records for payments, for example.
14. Assistance with compliance
Within reason and given the information available to us, we assist you with data protection impact assessments, with prior consultation of the supervisory authority and in answering its enquiries relating to the processing under this document.
15. Liability and precedence
Liability under this document is subject to the limitations in the Terms of use, to the extent the law permits. On matters of personal data processing this document prevails over the Terms of use. Bulgarian law applies, without prejudice to the mandatory provisions of applicable data protection law.
16. How it is signed
For a signed copy write to the official email on the Company page, with your company name and registration number. We will send the document for signature. If you are a regulated entity with your own template, send it — we will review yours rather than impose ours.