Data Processing Agreement (DPA)
Annex II to the Bedel IA services agreement. Based on the standard clauses of the AEPD, Spain's data protection authority (official model, in Spanish).
Version 2.4 · 31 August 2026.
Currency of this version
Version 2.4 · 31 August 2026. The main agreement incorporates this annex in the version in force on the date of signature; subsequent amendments do not affect what has already been signed unless agreed in writing.
Changes in version 2.4: clause 4 incorporates backup storage (European Union), the destination of the weekly backup, which is stored end-to-end encrypted and without the sub-processor holding the key. This change does not extend the processing: the data is the same data already processed and the purpose is Art. 32 security.
Changes in version 2.3: clause 4 now refers to artificial intelligence model providers in the plural — the Processor may use more than one for the same function — and it is made explicit that substitution between them may occur for continuity of service, with notice as soon as possible. All of them maintain the commitment not to train their models on the Controller's data; the Processor uses no provider, and no service tier of a provider, that does not guarantee it. None of these changes extends the processing: the data that leaves and the purposes are the same.
Changes in version 2.2: in clause 4 the Art. 32 measures are now stated as appropriate to the risk, with the current list given as the state of the art and replaceable by another of equivalent or greater effectiveness; and the code repository and corporate email are added to the list of sub-processors. None of these changes extends the processing.
Changes in version 2.1: clauses 5 bis (health data switched off by default) and 5 ter (reporting channel with no artificial intelligence involved) are added; clause 2 identifies the opt-in features; and clause 6 sets out how the standard contractual clauses are entered into. None of these changes extends the processing: they all narrow it.
The parties
Of the one part, [NAME OF THE CENTRE], with tax ID [CIF] and registered address at [ADDRESS], hereinafter the Controller.
Of the other part, Miguel Gamboa Sánchez (trading as Bedel), with NIF 47402408Y and address at Abegondo (A Coruña), Spain, hereinafter the Processor.
1. Subject matter
The parties govern the processing of personal data on the terms of Art. 28 of Regulation (EU) 2016/679 (GDPR), carried out by the Processor on behalf of the Controller in connection with the provision of the Bedel IA service.
2. Identification of the information processed
The data processed is stored in the Processor's infrastructure and comprises:
This section describes the maximum the service can process. The scope actually active for the Controller is the one set out in Annex I (Order Form); features not contracted process no data at all. Those marked opt-in come switched off by default and are enabled only by the Controller's express and traceable decision.
- Residents: first name and surname, phone, email, room, floor, year, degree course, messages exchanged.
- Health data (allergies, intolerances and medically prescribed diets) — opt-in, switched off by default. See clause 5 bis. Dietary preferences without a medical cause (vegetarian, vegan) are not health data and are not subject to that regime; where a preference reflects religious beliefs, the Controller must treat it with the same care, since it may reveal a different special category.
- Family members — opt-in: first name and surname, phone, email, relationship to the resident, messages exchanged. Only if the Controller contracts and enables the families module.
- The centre's staff: name, phone, email, role, encrypted password (where applicable), 2FA.
- Reporting channel — opt-in: the content of the report, category, priority, and the reporter's details (only if they choose to identify themselves). See clause 5 ter.
3. Duration
This agreement shall last for the term of the main services agreement. Once the processing engagement ends, the Processor shall return to the Controller the personal data and delete any copy in its possession within ninety (90) days of termination, unless a legal provision imposes a longer retention period.
4. Obligations of the Processor
- To process the personal data only in accordance with the Controller's documented instructions, including as regards international transfers.
- To ensure that the persons authorised to process the personal data undertake, expressly and in writing, to respect confidentiality and to comply with the corresponding security measures.
- To adopt the technical and organisational measures appropriate to the risk (Art. 32 GDPR), which as at the date of this agreement include: encryption in transit and at rest, access control, pseudonymisation of sensitive data where possible, encrypted backups and auditable logging. The Processor may replace them with others of equivalent or greater effectiveness as the state of the art evolves.
- Not to engage another processor without the Controller's prior written authorisation, specific or general. The sub-processors authorised on a general basis are listed below by function, location and transfer safeguard.
Sub-processors authorised on a general basis
- Database, authentication and storage (European Union).
- WhatsApp Business Cloud API messaging (Meta Platforms Ireland, EU).
- Application hosting (European Union).
- Artificial intelligence model providers (US), under standard contractual clauses and supplementary measures, all of them with a contractual commitment not to train their models on the Controller's data. The Processor may use more than one provider for this same function and substitute one for another for continuity of service — outage, degradation or discontinuation of the provider — notifying the Controller as soon as possible. Under no circumstances is a provider used, or a service tier of a provider, that does not guarantee the no-training commitment.
- Transactional email (US, under SCCs).
- Code repository and version control (US, under standard contractual clauses).
- Corporate email (European Union).
- Backup storage (European Union). It receives exclusively the end-to-end encrypted dump (AES-256-GCM) with a key that never leaves the Processor's systems: the sub-processor holds a block it cannot open.
The corporate name of each sub-processor is confidential information of the Processor and is provided to the Controller on simple request. The Processor shall give notice of any addition or substitution at least thirty (30) days in advance, stating function, location and safeguard; the Controller may object on reasoned grounds within that period and, if the disagreement persists, terminate without penalty. The Processor imposes on each sub-processor obligations equivalent to those of this agreement (Art. 28(4)).
Remaining obligations of the Processor
- Express instruction of the Controller (Art. 28(3)(a)): the Controller instructs the Processor to (i) anonymise or aggregate the data irreversibly, the resulting information falling outside the scope of the GDPR and belonging to the Processor, and (ii) process the personal data, to the extent strictly necessary, to provide, secure, debug and improve the Service. Under no circumstances does this cover disclosing personal data to third parties or training third-party models on it.
- To assist the Controller in responding to the exercise of the rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to automated decisions (known in Spain by the acronym ARSULIPO).
- To assist the Controller in carrying out impact assessments (DPIAs) and in prior consultations with the AEPD where appropriate.
- To notify the Controller of personal data security breaches it detects without undue delay and, in any event, with sufficient time for the Controller to meet its own 72-hour deadline before the authority (Art. 33(1)), with the information required by Art. 33(3) GDPR.
- To make available to the Controller all information necessary to demonstrate compliance with its obligations, and to allow for and contribute to audits by the Controller or another auditor authorised by it, on reasonable notice.
- To maintain a record of processing activities (Art. 30 GDPR), accessible to the Controller on request.
5. Obligations of the Controller
- To provide the Processor with the data necessary to deliver the service.
- To carry out prior consultation with the AEPD where applicable, and a DPIA where the activity requires it.
- To ensure the Processor complies with the GDPR and to supervise the processing.
- To inform the data subjects (residents, family members, staff) of the processing of their data within the centre's activity.
- To obtain and retain explicit consent where special category data (Art. 9) is processed, such as allergies or diets for medical reasons, and to provide only the minimum information necessary. See clause 5 bis.
- Where the users include minors, to guarantee the age and consent requirements of Art. 7 of Organic Act 3/2018 (valid consent from the age of fourteen).
5 bis. Health data: switched off by default
The service is delivered with the processing of health data — allergies, intolerances and medically prescribed diets — switched off. Until it is enabled, the system does not collect it, does not store it, does not display it and does not send it to any sub-processor, including the artificial intelligence model provider. This guarantee is not a promise about configuration: it is implemented as a constraint in the database itself, which rejects any record of this nature whatever the route of entry (dashboard, file import, WhatsApp conversation or maintenance).
Enabling it is an express decision of the Controller and requires a person with authority to bind the centre to declare, with their identity, the date and the accepted text recorded, that the centre:
- will obtain the explicit consent (Art. 9(2)(a) GDPR) of each data subject, individually, before entering any health data concerning them;
- will retain proof of each consent and be able to evidence it;
- will inform them of the possibility of withdrawing it and will communicate any withdrawal so that the data is deleted;
- will enter only the minimum information necessary, with no diagnoses or medical reports.
The Processor, which has no direct relationship with the data subjects, cannot obtain that consent on the Controller's behalf. On disabling the processing, the centre's health data is deleted: once processing has ceased, retaining it has no legal basis. Dietary preferences without a medical cause are unaffected.
5 ter. Reporting channel: no artificial intelligence involved
The reporting channel is an optional feature enabled only if the Controller contracts it. When active, it is accessed solely through the channel's own web address, publicised by the Controller by means of the QR-code poster the system generates. The conversational assistant gives no access to the channel: faced with a sensitive query, it directs the person to the centre's reception or management.
At no stage of the channel is an artificial intelligence model involved: not in receiving the report, nor in classifying it, nor in storing it, nor in handling it. The report travels from the reporting person's browser to the channel's form, is encrypted with AES-256-GCM before being stored, and is not sent to any sub-processor located outside the European Economic Area. Notices that a new communication exists are limited to the essentials: the one that arrives by messaging to the centre's management contains the category and the priority, never the report or the identity of the person reporting; the one that arrives by email — the only medium involving a sub-processor outside the EEA — contains no data at all, only an indication that there is something pending review in the dashboard.
The decrypted content is accessible only to those people at the centre with express permission over that section, and every access is logged (who, when, from which IP address) in a record the centre itself cannot alter. The Controller assumes the obligations that Act 2/2023 imposes on the owner of the internal information system, among them the designation of the person responsible for the system and the approval of its policy; the Processor provides technical support, not ownership of the channel.
6. International transfers
The Controller authorises the Processor to use the AI model provider, based in the US, for the artificial intelligence model processing. This transfer relies on the standard contractual clauses (European Commission Decision (EU) 2021/914), which that provider incorporates into its data processing agreement and which the Processor has entered into by accepting its commercial terms, together with supplementary measures post-Schrems II: encryption, a contractual policy of not training the model on client data, and minimisation of the payload sent.
The transactional email provider, used for operational alerts, and the code repository and version control are likewise based in the US and their transfers rely on the same standard contractual clauses. There are no other transfers outside the European Economic Area: the remaining sub-processors operate in the European Union.
7. Confidentiality
The Processor and all its personnel shall maintain professional secrecy in respect of the data processed, including after the agreement ends. This obligation is indefinite.
8. Liability
Each party's liability towards data subjects and the authorities is governed by Art. 82 GDPR. As between the parties, the Processor's liability for damages — including those arising from a security breach — is contractually limited to the amount actually paid by the Controller in the three (3) months preceding the triggering event, provided the Processor had adopted the appropriate security measures of Art. 32, save for wilful misconduct or gross negligence, in which cases the limitation shall not apply. This limit is the same as that provided for in the main agreement and constitutes a single, combined cap for both documents: it does not accumulate.
9. Governing law and jurisdiction
This annex is governed by the law and jurisdiction agreed in the main agreement of which it forms part, and follows them if they are amended. In the absence of a main agreement, it is governed by Spanish law and the parties submit to the Courts and Tribunals of A Coruña, waiving any other jurisdiction.
10. Signature
In __________________________, on ___ __________________ 20___.
| For the Controller | For the Processor |
|---|---|
| Name: _____________________ | Name: _____________________ |
| Position: __________________ | Position: __________________ |
| Signature: | Signature: |