Legal

Terms

This page contains EU GPT's Terms of Service and the Data Processing Agreement that apply when using the service. By registering for EU GPT you confirm that you have read and accept these terms. This English text is a translation provided for convenience; in the event of any discrepancy, the Dutch version prevails.

Terms of Service

EU GPT Terms of Service

Last updated: 30 April 2026 · Version 1.0

Article 1 – Definitions

In these terms of service, the following definitions apply:

  • EU GPT / Service Provider: the provider of the service, established in Amsterdam, registered with the Chamber of Commerce under number 97997250.
  • User: any natural or legal person who uses the service.
  • Consumer: a user who is a natural person and acts for purposes outside their trade or profession, within the meaning of Article 6:230g of the Dutch Civil Code.
  • Business User: a user acting in the course of a trade or profession.
  • Service: the sovereign AI platform offered by EU GPT via eugpt.nl and its associated environments, including all current and future functionality.
  • Account: the personal or organisation-bound user profile through which access to the service is obtained.
  • Agreement: the agreement between EU GPT and the user regarding the use of the service.
  • User Data: all input, documents, texts and other materials entered by the user into the service, as well as the output generated by the service.
  • European Infrastructure: servers, networks and storage facilities physically located within the European Union and owned or operated by legal entities subject to European law, without control by non-European entities.
  • Open Source Software: software whose source code is freely available under a licence recognised by the Open Source Initiative.
  • Sub-processor: a third party engaged by EU GPT to (help) deliver the service and which may, in that context, process personal data. An up-to-date overview of sub-processors is available at eugpt.nl.
  • Aggregated Statistics: quantitative data about the use of the service (such as the number of sessions, usage moments and general usage patterns) processed in such a way that it cannot be traced back to individual users. See the privacy statement (Art. 4.3) for further explanation.

Article 2 – Applicability

2.1 These terms of service apply to all use of the service and to all agreements between EU GPT and the user.

2.2 By using the service, the user accepts these terms of service.

2.3 Deviations from these terms are valid only if agreed in writing.

2.4 EU GPT reserves the right to amend these terms. Changes are announced at least 30 days in advance via the service or by email. An overview of previous versions and changes made is available at eugpt.nl.

Article 3 – The service

3.1 EU GPT offers a sovereign European AI platform that allows users to use artificial intelligence in a privacy-safe manner. The service includes, among other things, the real-time processing of input and the storage of chat history within the account environment. The specific functionality of the service may be extended, changed or adjusted by EU GPT.

3.2 EU GPT reserves the right to change, extend or discontinue parts of the service, subject to a reasonable notice period. In the event of a material change to the service that significantly affects the user's use of it, the user has the right to terminate the agreement free of charge within 30 days of notification.

3.3 The service uses open source AI models. EU GPT is not responsible for inherent limitations, inaccuracies or shortcomings of the underlying AI models. EU GPT makes every effort to select and configure models that meet applicable quality and safety standards.

Article 4 – Data sovereignty and privacy

4.1 Data sovereignty is the foundation of the service. EU GPT is architecturally designed to ensure that user data is processed exclusively on European Infrastructure and falls under European law. All infrastructure components are located within the European Union and are managed by European parties. EU GPT uses open source software.

4.2 User content data is stored within the user's account environment on European servers. EU GPT may use Aggregated Statistics (as defined in Article 1) to improve and strengthen the service. EU GPT does not use content input or output for other commercial purposes, except insofar as this is necessary to deliver, secure, maintain and debug the service.

4.3 User data is not used to train AI models.

4.4 EU GPT may use aggregated statistics to improve and strengthen the service, as described in the privacy statement at eugpt.nl. If access to specific user data is necessary to analyse or resolve a problem reported by the user, EU GPT will request the user's explicit prior consent. By granting this consent, the user provides access solely for the purpose of the relevant problem analysis.

4.5 EU GPT does not share data with third parties, other than: (a) sub-processors necessary to deliver the service (an up-to-date overview is available at eugpt.nl), or (b) insofar as EU GPT is required to do so under a binding legal obligation or a court order. In the latter case, EU GPT informs the user, insofar as legally permitted.

4.6 EU GPT uses European sub-processors to deliver the service. Data processing agreements have been concluded with all sub-processors in accordance with the GDPR.

4.7 In exceptional cases, such as a technical failure or a security incident, it may be necessary for authorised EU GPT staff to obtain limited access to individual user data. This is done solely in accordance with internal procedures and confidentiality arrangements, and is limited to what is strictly necessary.

4.8 For the full description of data processing, retention periods and your rights, we refer to our privacy statement at eugpt.nl. For the cookie policy, we refer to the cookie statement at eugpt.nl.

Article 5 – Ownership of data

5.1 The user is and at all times remains the full owner of all user data. EU GPT claims no rights whatsoever to the user's input or to the output generated by the service.

5.2 The user has full control over their own data within the service at all times. Data deleted by the user is permanently deleted.

5.3 EU GPT does not grant the user a licence to user data, because EU GPT has and claims no rights to that data.

Article 6 – Availability and maintenance

6.1 EU GPT strives for the highest possible availability of the service but cannot guarantee uninterrupted access.

6.2 Planned maintenance is, where reasonably possible, announced at least 48 hours in advance via the service or by email. EU GPT endeavours to carry out planned maintenance outside regular working hours.

6.3 In the event of unforeseen failures or emergency maintenance, EU GPT endeavours to restore the service as quickly as possible and to inform the user.

6.4 EU GPT is not liable for damage resulting from temporary unavailability of the service due to maintenance or failures.

6.5 In the event of prolonged unavailability of the service (more than 7 consecutive calendar days, excluding force majeure), a user with a paid subscription may claim a proportionate extension of the subscription period.

Article 7 – Account and registration

7.1 Registration and the creation of an account are required to use the service.

7.2 The user is responsible for providing accurate and up-to-date information upon registration.

7.3 The user is responsible for keeping login credentials confidential and is liable for all activities that take place through the account.

7.4 EU GPT may suspend or terminate an account in the event of (suspected) misuse or breach of these terms.

Article 8 – Minimum age

8.1 The service is accessible only to persons aged 16 and over. In countries where applicable law prescribes a higher minimum age for processing personal data without parental consent, that higher age applies.

8.2 Users under the age of 16 may use the service only with the demonstrable consent of a parent or legal representative.

8.3 If EU GPT establishes that a user does not meet the required minimum age and no valid consent has been given, EU GPT reserves the right to suspend or terminate the account and delete the associated data.

Article 9 – Permitted use

9.1 The user uses the service solely for lawful purposes and in accordance with these terms.

9.2 The user is prohibited from using the service for:

  • Generating illegal, discriminatory, threatening or otherwise unlawful content
  • Spreading disinformation or misleading content
  • Infringing the intellectual property rights of third parties
  • Circumventing the security measures of the service
  • Systematically and automatically querying the service outside the channels intended for that purpose
  • Intentionally overloading, disrupting or damaging the service or the underlying infrastructure
  • Any use that contravenes applicable laws and regulations, including the EU AI Act

9.3 The user makes reasonable use of the service. EU GPT may set usage limits to safeguard the availability and quality of the service for all users.

9.4 The user is liable for all damage suffered by EU GPT as a result of malicious or unlawful use of the service by the user. EU GPT reserves the right, in the event of malicious use, to suspend the account with immediate effect, terminate the agreement and recover the damage suffered from the user.

9.5 Users can report suspected misuse of the service by other users via info@eugpt.nl.

Article 10 – AI-generated output

10.1 The output generated by the service is produced by artificial intelligence and may contain inaccuracies, incompleteness or outdated information.

10.2 EU GPT does not guarantee the accuracy, completeness or suitability of the output for a specific purpose.

10.3 The user is responsible for checking and validating the output before using it for decision-making, publication or any other purpose. Human review of the output is always recommended.

10.4 The generated output does not constitute professional advice of any kind (legal, medical, financial or otherwise).

10.5 The user is interacting with an AI system and not with a human.

Article 11 – Intellectual property

11.1 All intellectual property rights to the service, the software and the underlying technology rest with EU GPT or its licensors.

11.2 The user retains all rights to the data they enter into the service. EU GPT acquires no rights to it.

11.3 EU GPT claims no rights to the output generated by the service. The user may use the output freely. Whether and to what extent the generated output qualifies for copyright protection depends on applicable law and the degree of human creative input. EU GPT cannot provide any guarantees in this respect.

Article 12 – Prices and payment

12.1 Use of the service may be offered free of charge or for payment, depending on the chosen subscription.

12.2 All quoted prices are in euros and include VAT, unless stated otherwise.

12.3 Payment is made via the payment methods offered on the website.

12.4 In the event of late payment, EU GPT may suspend access to the service after a reasonable notice of default.

12.5 EU GPT reserves the right to change prices and subscription types. Price changes are announced at least 30 days in advance and do not apply to the current billing period.

Article 13 – Subscriptions and renewal

13.1 Paid subscriptions are entered into for the period indicated when the subscription is taken out (monthly or annually).

13.2 Subscriptions are automatically renewed at the end of the chosen period, unless the user cancels the subscription before the end of the current period via the functionality available for this purpose in the service.

13.3 For consumers, after the initial subscription period the subscription is cancellable monthly with a notice period of no more than one month, regardless of the originally chosen subscription period (in accordance with Article 6:236 sub p and q of the Dutch Civil Code).

13.4 EU GPT informs the user in good time before an automatic renewal, stating the option to cancel and how to do so.

Article 14 – Trial period

14.1 EU GPT may offer a free trial period allowing the user to try the service for a limited time.

14.2 At the end of the trial period, access to the service is terminated unless the user takes out a subscription. The way to take out a subscription is indicated via the service.

14.3 EU GPT reserves the right to change the duration, conditions and availability of the trial period or to end the trial period.

14.4 During the trial period, certain functionality or usage limits may differ from paid subscriptions.

Article 15 – Right of withdrawal

15.1 Consumers have the right to withdraw from a distance contract within 14 days of its conclusion without giving reasons (Article 6:230o of the Dutch Civil Code).

15.2 To exercise the right of withdrawal, the consumer may send an unequivocal statement by email to info@eugpt.nl.

15.3 The right of withdrawal lapses once the service has been fully performed with the user's express prior consent, whereby the user has declared that they waive the right of withdrawal.

15.4 In the event of withdrawal, any amounts paid are refunded within 14 days of receipt of the withdrawal via the same payment method. After withdrawal, the account is terminated and the user data is permanently deleted within 90 days.

Article 16 – Data breaches

16.1 Despite all security measures taken, a security incident can never be entirely ruled out.

16.2 In the event of a data breach likely to result in a high risk to the rights and freedoms of the user, EU GPT informs the affected user(s) without undue delay and in clear language about the nature, scope and possible consequences of the incident, as well as the measures taken or proposed.

16.3 EU GPT reports data breaches that pose a risk to data subjects to the Dutch Data Protection Authority within 72 hours, in accordance with Article 33 GDPR.

16.4 In the event of a data breach, EU GPT immediately takes measures to limit the consequences and prevent recurrence.

Article 17 – Liability

17.1 As described in Article 10, the user is responsible for assessing, validating and applying the output generated by the service. EU GPT is not liable for damage arising from the use of the output, except for damage resulting from intent or deliberate recklessness on the part of EU GPT and except for liability that cannot be excluded under mandatory (consumer) law.

17.2 EU GPT's total liability towards business users is limited to the amount the user paid to EU GPT in the 12 months preceding the event causing the damage.

17.3 For free use of the service, EU GPT's liability is limited to the licence fees paid for the preceding 12 months, insofar as legally permitted.

17.4 Towards business users, EU GPT is not liable for indirect damage, consequential damage, lost profits or missed savings. This exclusion does not apply to consumers insofar as it is not legally permitted to exclude such damage by contract.

17.5 The limitations in this article do not apply to damage caused by intent or deliberate recklessness on the part of EU GPT, nor to liability that cannot be limited under mandatory law.

17.6 The liability limitations in this article do not affect the statutory rights of consumers. Nothing in these terms limits or excludes EU GPT's liability for damage that cannot be contractually excluded or limited under mandatory (consumer) law, including damage from death or personal injury, intent, deliberate recklessness, or damage for which exclusion is deemed unreasonably onerous under Articles 6:236 and 6:237 of the Dutch Civil Code. In the event of doubt about the interpretation of a liability provision towards a consumer, the interpretation most favourable to the consumer prevails.

Article 18 – Indemnification

18.1 The business user indemnifies EU GPT, its directors, employees and processors against all third-party claims arising from or related to the business user's use of the service, insofar as such claims are attributable to the business user, including but not limited to:

  • Claims resulting from content generated or distributed by the user
  • Claims for infringement by the user of third-party intellectual property rights
  • Claims resulting from use of the service in breach of these terms or applicable laws and regulations

18.2 The business user reimburses EU GPT for all reasonable costs, damage and expenses (including legal costs) incurred by EU GPT as a result of such attributable third-party claims.

18.3 A consumer is liable towards EU GPT only for damage resulting from a shortcoming attributable to the consumer and can be held to compensate damage only insofar as this is reasonable and legally permissible under Book 6 of the Dutch Civil Code. The broad indemnification obligation in 18.1 does not apply to consumers.

Article 19 – Processing of personal data in business use

19.1 If the user is an organisation that deploys EU GPT for its employees or customers, and personal data of third parties is thereby entered into the service, EU GPT acts as a processor within the meaning of Article 28 GDPR.

19.2 In that case, EU GPT's data processing agreement applies, which is available at eugpt.nl. This data processing agreement forms an integral part of the agreement between EU GPT and the user. By using the service for business purposes, the business user accepts the data processing agreement.

Article 20 – Security

20.1 EU GPT takes appropriate technical and organisational measures to secure the service and the data processed. The European Infrastructure on which EU GPT runs meets the highest European security standards.

20.2 EU GPT cannot guarantee that the service is entirely free of vulnerabilities at all times. Should a security incident occur, EU GPT acts in accordance with applicable laws and regulations.

Article 21 – Regulatory compliance

21.1 EU GPT strives to comply with the requirements of applicable European regulations, including the General Data Protection Regulation (GDPR) and the European AI Regulation (EU AI Act).

21.2 EU GPT informs users that they are interacting with an AI system. Human review of the output is always recommended.

21.3 The service is designed to enable organisations to deploy AI in accordance with European privacy and safety requirements.

21.4 As the deployer of the service, the user is responsible for using the AI output in accordance with applicable laws and regulations, including the EU AI Act. This includes the responsibility not to use AI output for automated decision-making that significantly affects data subjects without appropriate human intervention.

21.5 The service does not qualify as a high-risk AI system within the meaning of the EU AI Act. EU GPT maintains a transparency overview at eugpt.nl with information about the AI models used, their origin and how the service is configured.

Article 22 – Force majeure

22.1 EU GPT is not obliged to perform any obligation in the event of force majeure.

22.2 Force majeure is understood to mean: infrastructure failures, power outages, cyberattacks, government measures, pandemics and other circumstances beyond EU GPT's reasonable control.

Article 23 – Termination

23.1 The user may terminate the account, and thereby use of the service, at any time. For paid subscriptions, termination takes effect at the end of the current billing period. No refund is made of subscription fees already paid, unless termination results from an attributable shortcoming on the part of EU GPT.

23.2 EU GPT may terminate the agreement with immediate effect in the event of a breach of these terms by the user.

23.3 Prior to termination, the user may export their user data via the functionality available for this purpose in the service. Data is provided in a structured, commonly used and machine-readable format (in accordance with Article 20 GDPR).

23.4 After termination, the user has 60 days to export remaining data. After this period, all content user data is automatically and permanently erased no later than 90 days after termination. Account data is deleted no later than 12 months after termination for the purpose of administrative settlement and the possibility of handling any legal claims. Billing data is retained for 7 years in accordance with the statutory tax retention obligation. EU GPT does not retain any content user data after the aforementioned periods, unless retention is required under applicable law.

Article 24 – Complaints procedure

24.1 Complaints about the service or about the performance of the agreement can be submitted via info@eugpt.nl.

24.2 EU GPT aims to substantively address complaints within 30 days of receipt. If a longer handling period is required, the user is informed of this within 30 days, stating the expected timeframe.

Article 25 – Governing law and disputes

25.1 These terms of service and all agreements between EU GPT and the user are governed by Dutch law.

25.2 Disputes between EU GPT and business users are submitted exclusively to the competent court in Amsterdam.

25.3 Consumers may submit a dispute to the court that has jurisdiction by law, including the court of their place of residence.

25.4 Consumers may also submit a dispute to the European Online Dispute Resolution (ODR) platform: https://ec.europa.eu/consumers/odr.

Article 26 – Other provisions

26.1 If any provision of these terms proves to be void or voidable, this does not affect the validity of the remaining provisions.

26.2 EU GPT's failure to exercise any right does not constitute a waiver of that right.

26.3 EU GPT may transfer rights and obligations under the agreement to third parties, provided this does not disadvantage the user.

Article 27 – Contact details

EU GPT
Science Park 608 - A10
1098 XH Amsterdam
The Netherlands
Email: info@eugpt.nl
Privacy: info@eugpt.nl
Abuse: misbruik@eugpt.nl
Chamber of Commerce no.: 97997250
VAT no.: NL868318097B01
Website: https://eugpt.nl

Data Processing Agreement

Data Processing Agreement — in accordance with Article 28 GDPR

Last updated: 30 April 2026 · Version 1.0

Article 1 – Parties and definitions

1A. Parties

The undersigned:

1. [Organisation name], established in [place of establishment], registered with the Chamber of Commerce under number [number], hereinafter referred to as: “the Controller”;

and

2. EU GPT, established in Amsterdam, registered with the Chamber of Commerce under number 97997250, lawfully represented by Harmenjan Sijtsma, hereinafter referred to as: “the Processor”;

This data processing agreement may be entered into by (a) physical or digital signature, or (b) acceptance via the EU GPT platform when taking out a business subscription. In case (b), the business user is deemed the Controller and this agreement enters into force at the moment of acceptance.

1B. Definitions

In this data processing agreement, the following definitions apply:

  • GDPR: the General Data Protection Regulation (EU) 2016/679.
  • Personal Data: all information about an identified or identifiable natural person, within the meaning of Article 4(1) GDPR.
  • Processing: any operation on personal data within the meaning of Article 4(2) GDPR.
  • Sub-processor: a third party engaged by the Processor to carry out part of the processing.
  • Service: the EU GPT platform as described in the Terms of Service.
  • Terms of Service (ToS): EU GPT's terms of service, available at eugpt.nl.

Article 2 – Background and purpose

2.1 The Controller uses the EU GPT service, a sovereign European AI platform.

2.2 When using the service, personal data may be processed on the instructions of the Controller. The Processor processes this solely for the benefit of the Controller.

2.3 The Controller warrants that the personal data entered into the service was lawfully obtained and that the Controller has a valid legal basis for processing it. The Controller indemnifies the Processor against third-party claims arising from the absence of a lawful basis.

2.4 This data processing agreement is concluded in implementation of Article 28 GDPR and forms an integral part of EU GPT's Terms of Service.

Article 3 – Order of precedence

3.1 In the event of a conflict between this data processing agreement and the Terms of Service, this data processing agreement prevails insofar as it concerns the processing of personal data.

Article 4 – Subject of the processing

4.1 The processing relates to:

  • Input data: texts, prompts and documents entered into the service, insofar as they contain personal data;
  • Output data: the output generated by the service, insofar as it contains personal data;
  • Account data: email addresses and names of employees who use the service.

4.2 The categories of data subjects are: employees of the Controller, and persons whose data they enter into the service (such as customers, contacts and other third parties).

4.3 The purpose of the processing is the real-time processing of input by means of artificial intelligence to generate output, as well as the storage of input and output within the account environment. Content data is not reused for commercial purposes outside the delivery of the service, except for the operational processing purposes described in Article 5.2.

4.4 The processing takes place during the term of the agreement.

Article 5 – Obligations of the Processor

5.1 The Processor processes personal data solely on the basis of the Controller's written instructions, unless otherwise legally required. Use of the service in accordance with the Terms of Service and the product documentation constitutes the Controller's written instruction. Additional instructions are agreed in writing.

5.2 The Processor does not process personal data for its own commercial purposes. In particular, user data is not used for (a) training or fine-tuning AI models, (b) profiling users, or (c) resale or marketing. The Processor may process personal data solely for the following own purposes related to the delivery of the service: (i) securing, monitoring and maintaining the service, (ii) detecting and resolving technical failures and security incidents, (iii) complying with legal obligations, and (iv) generating Aggregated Statistics (as further described in the Terms of Service and privacy statement) that cannot be traced back to individual data subjects. If access to specific data is necessary to resolve a problem reported by the Controller or its employees, the Processor requests explicit prior consent for this.

5.3 The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality.

5.4 The Processor takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These include, among other things:

  • Encryption of data in transit and at rest
  • Strict access controls based on the need-to-know principle
  • Separated customer environments
  • Logging and monitoring of access actions
  • Regular security testing and vulnerability analysis
  • Backup and recovery policy
  • Incident response procedures

A further description of the security measures is available in the security annex at eugpt.nl.

5.5 The Processor processes all personal data exclusively within the European Union and the European Economic Area (EEA). If transfer outside the EEA were to become unavoidable (for example due to acquisition or bankruptcy of a sub-processor), the Processor informs the Controller immediately and appropriate safeguards are put in place in accordance with Chapter V GDPR (including SCCs). In that case, the Controller has the right to terminate the agreement with 30 days' notice. During this period, the Processor endeavours to reverse the transfer outside the EEA or to offer an alternative European solution.

Article 6 – Sub-processors

6.1 The Controller hereby grants general authorisation for engaging sub-processors, under the conditions of this article.

6.2 The Processor informs the Controller at least 30 days in advance when adding or replacing sub-processors. The Controller may object within this period. If the Parties do not reach agreement, the Controller may terminate the agreement with 30 days' notice.

6.3 The Processor imposes the same obligations on sub-processors as in this agreement and remains fully liable for their actions.

6.4 An up-to-date overview of the engaged sub-processors, including the nature of the processing and the location, is available at eugpt.nl.

Article 7 – Rights of data subjects

7.1 The Processor provides assistance in responding to requests from data subjects (Articles 15 to 22 GDPR).

7.2 If the Processor receives a request directly from a data subject, the Processor notifies the Controller without delay.

7.3 The Controller can view, correct, export and delete personal data via the service.

Article 8 – Data breaches

8.1 The Processor reports a data breach without delay, and in any event within 48 hours after the Processor has reasonably become aware of the data breach, to the Controller.

8.2 The notification includes at least: the nature of the data breach, the categories of data subjects and data, the estimated number of data subjects, the likely consequences, and the measures taken or proposed.

8.3 The Processor provides full cooperation in the investigation, the notification to the Dutch Data Protection Authority and any notification to data subjects.

Article 9 – Assistance with DPIA and prior consultation

9.1 The Processor provides the Controller with reasonable assistance in carrying out a data protection impact assessment (DPIA) as referred to in Article 35 GDPR, insofar as the processing via the service gives cause for one.

9.2 The Processor also provides assistance with any prior consultation of the supervisory authority as referred to in Article 36 GDPR.

9.3 The assistance includes providing information about the nature of the processing, the security measures taken and the risks to data subjects, insofar as this information is available to the Processor. If the assistance requires more than a reasonable effort, the Processor may charge a fee for this based on the then-current rates.

Article 10 – Audit

10.1 The Processor makes available all information necessary to demonstrate compliance with Article 28 GDPR.

10.2 The Processor may satisfy the audit right by making available a current independent audit report or certification (such as ISO 27001 or SOC 2).

10.3 If the Controller substantiates in writing and with reasons that the available report is insufficient, the Processor enables an on-site audit after a notice period of at least 30 days.

Article 11 – Confidentiality

11.1 The Processor treats all personal data as strictly confidential.

11.2 All employees with access to personal data have signed a confidentiality agreement.

Article 12 – Return and deletion

12.1 Upon termination, the Controller can export all personal data via the service in a structured, commonly used and machine-readable format.

12.2 After termination, all personal data is permanently erased no later than 90 days, unless retention is legally required. The Processor confirms the deletion in writing on request.

Article 13 – Liability

13.1 The Processor's liability towards the Controller in connection with this data processing agreement is limited in accordance with Article 17 of EU GPT's Terms of Service. This limitation concerns solely the mutual relationship between the Parties.

13.2 This limitation does not apply to damage caused by intent or deliberate recklessness, nor to liability that cannot be contractually limited under the GDPR, including liability towards data subjects under Article 82 GDPR.

13.3 The rights of data subjects under the GDPR are not limited by this agreement.

Article 14 – Term

14.1 This data processing agreement applies for the duration of the agreement relating to the service.

14.2 Provisions that by their nature are intended to continue after termination (confidentiality, deletion, liability) remain in force.

Article 15 – Amendment

15.1 The Processor may amend this data processing agreement if this is necessary due to changes in laws and regulations, guidelines from supervisory authorities, or the technical design of the service.

15.2 Changes are announced at least 30 days in advance. If the Controller objects to a change, it may terminate the agreement with 30 days' notice.

Article 16 – Contact person

16.1 The point of contact at the Processor for questions about data protection can be reached via info@eugpt.nl.

16.2 EU GPT has not currently appointed a Data Protection Officer (DPO). EU GPT continuously monitors the need to appoint a DPO.

Article 17 – Governing law

17.1 This data processing agreement is governed by Dutch law.

17.2 Disputes are submitted to the competent court in Amsterdam.

Annex A – Processing overview

Purpose
Processing input through AI to generate output; storage within the account environment
Nature
Real-time processing (inference), storage, transmission, deletion
Categories of personal data
Contact details (name, email), content data insofar as it contains personal data (texts, documents, prompts, output), technical data (IP address)
Categories of data subjects
Employees of the Controller; customers, contacts and other third parties whose data is entered
Processing location
European Union (specifically: Scaleway, Paris, France)
Retention period
For the duration of the account; permanent deletion no later than 90 days after termination
Security measures
See security annex at eugpt.nl; includes encryption (transit + at rest), access controls, separated customer environments, logging, pentests, backup/recovery, incident response
Sub-processors
See up-to-date overview at eugpt.nl

Questions about these terms? Contact us at info@eugpt.nl.

Contact us