DATA PROCESSING AGREEMENT
1.1. This Data Processing Agreement (the “DPA”) is entered into between:
- Golova Europe SL, Tax ID B70717004, EU VAT ESB70717004, with registered office at Calle l’Hospital, 95, Planta 1, Puerta 2, 08001 Barcelona, Spain (the “Processor”, “Golova”); and
- the Customer registered for the Services (the “Controller”) — together, the “Parties”.
1.2. This DPA forms an integral part of the User Agreement between the Parties. The Controller accepts this DPA by accepting the User Agreement.
1.3. This DPA gives effect to Article 28 of Regulation (EU) 2016/679 (GDPR) and to the equivalent provisions of Spanish Organic Law 3/2018 (LOPDGDD), and governs the processing by Golova of personal data on behalf of the Controller in the context of the provision of the Services.
1.4. In case of conflict between this DPA and the User Agreement, this DPA prevails with respect to the processing of personal data by Golova as Processor.
1.5. Capitalised terms used and not defined in this DPA have the meaning attributed to them by the GDPR or the User Agreement.
2.1. Subject matter. The Processor processes personal data of End Users on behalf of the Controller to the extent necessary to provide the Services defined in the User Agreement.
2.2. Duration. This DPA applies for the duration of the User Agreement and survives its termination to the extent necessary for the return or deletion of personal data (section 11).
2.3. Nature of processing. The processing comprises the collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure to authorised subprocessors, restriction, erasure or destruction of personal data.
2.4. Purpose. The processing is carried out for the sole purpose of providing the Services to the Controller in accordance with the User Agreement and the documented instructions of the Controller.
2.5. Categories of data subjects. End Users of the Controller — typically customers, personnel, self-employed professionals engaged by the Controller, contacts and counterparties.
2.6. Categories of personal data. Typically: identification data (name, position), contact data (email, telephone), professional data (function, company), content of communications, internal notes, project assignments, rider documents (which may include dietary, accessibility or health-related preferences). The exact categories depend on what the Controller uploads into the Services.
3.1. The Processor processes personal data only in accordance with the Controller’s documented instructions — including with regard to international transfers of personal data — unless required to do otherwise by Union or Member State law to which the Processor is subject; in that case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2. The User Agreement, the Service Plan, the configuration of the Account by the Controller, the actions performed by the Controller’s authorised users within the Services and any specific instructions sent in writing to legal@golova.ai constitute, together, the Controller’s documented instructions.
3.3. If the Processor considers that an instruction infringes the GDPR or other applicable data protection legislation, it shall communicate its concerns to the Controller and may refuse to follow the instruction until clarification.
4.1. The Processor ensures that any person authorised to process personal data under this DPA — personnel, consultants, authorised subprocessors — is subject to appropriate contractual or statutory confidentiality obligations.
4.2. Access to personal data within the Processor’s organisation is granted on a “need-to-know” basis, with role-based access controls and audit logging.
5.1. The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32 GDPR), taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of data subjects.
5.2. The technical and organisational measures in force are described in Annex II to this DPA. The Processor may update such measures over time, provided that the level of security is not reduced.
6.1. The Controller grants the Processor a general written authorisation to engage subprocessors for the provision of the Services, subject to the safeguards set out in this section.
6.2. The Processor maintains a list of authorised subprocessors in Annex I and publishes it at https://golova.ai/lt/subprocessors. The list identifies the name, legal entity, purpose, data location and applicable transfer safeguard.
6.3. Before engaging a new subprocessor or replacing an existing one, the Processor will notify the Controller by email or through the Services at least thirty (30) days in advance. The Controller may object to the proposed change on reasonable and demonstrable grounds relating to data protection. The Parties will seek a solution in good faith; if none is found, the Controller may terminate the affected Services by written notice, with a pro-rata refund of the unused prepaid period.
6.4. The Processor enters into a written contract with each subprocessor imposing on it the same data protection obligations set out in this DPA, in particular sufficient guarantees that the subprocessor will implement appropriate technical and organisational measures (Article 28(4) GDPR).
6.5. The Processor remains fully liable to the Controller for the subprocessor’s performance of the obligations of the corresponding subprocessing contract.
7.1. Personal data are processed primarily within the European Economic Area (EEA). Where the Processor or a subprocessor must transfer personal data to a third country, the Processor ensures that one of the following safeguards under Chapter V of the GDPR applies:
- An adequacy decision of the European Commission (Article 45 GDPR), in particular the EU-US Data Privacy Framework for certified US recipients and the adequacy decision for the United Kingdom (of 19 December 2025);
- Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Decision 2021/914 — Module 3 (processor to subprocessor) where the Processor transfers data to a subprocessor outside the EEA, or Module 2 (controller to processor) where the Processor transfers data on behalf of the Controller;
- Other safeguards provided for in Articles 46 to 49 GDPR, where appropriate.
7.2. For transfers carried out under SCCs, the Processor has conducted a Transfer Impact Assessment (TIA) and implemented appropriate supplementary measures (in particular encryption in transit and at rest, pseudonymisation where feasible, contractual safeguards against unlawful access).
7.3. By accepting this DPA, the Controller authorises the Processor to enter into SCCs with subprocessors on behalf of the Controller, in the name of the Processor and on the Processor’s own behalf, to the extent necessary to provide the Services.
8.1. Where the Processor receives a request from a data subject to exercise their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection), and the request relates to personal data processed on behalf of the Controller, the Processor:
- shall not respond to the request itself, unless required by law;
- shall forward the request to the Controller without undue delay and, in any event, within five (5) business days;
- shall provide the Controller with reasonable assistance, taking into account the nature of the processing, to enable the Controller to comply with its obligations under Article 12(3) GDPR.
8.2. The Services provide self-service tools enabling the Controller to fulfil data subject rights — including export of data of a specific End User (portability) and deletion of data (right to be forgotten). Where the Controller requests the Processor to carry out such actions on its behalf, the Processor may charge reasonable fees for work that exceeds the standard tools of the Service Plan.
9.1. Taking into account the nature of the processing and the information available, the Processor shall assist the Controller in complying with its obligations under:
- Article 32 (Security): by maintaining the technical and organisational measures in Annex II and providing the documentation described in section 10;
- Articles 33-34 (Breach notification): in accordance with section 10;
- Articles 35-36 (Impact assessment and prior consultation): by providing information about the Services reasonably necessary for the Controller’s impact assessment and making available the documentation that the Processor usually provides for that purpose.
9.2. The Processor’s assistance under this section is provided at no additional cost to the extent that it relates to the standard documentation made available. Where the Controller requests assistance beyond that documentation, the Processor may charge reasonable fees, notified in advance.
10.1. Upon becoming aware of a personal data breach affecting personal data processed under this DPA, the Processor shall notify the Controller without undue delay and, in any event, within 72 hours of such awareness, unless it reasonably considers that the breach does not involve a risk to the rights and freedoms of natural persons.
10.2. The notification shall contain, at a minimum, to the extent the information is available at that time:
- the nature of the breach, including, where possible, the categories and approximate number of data subjects and records affected;
- the contact details of the Processor’s point of contact for further information;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and to mitigate its possible adverse effects.
10.3. Where not all information is available within 72 hours, the Processor shall provide initial information and update the Controller on a phased basis. The Processor cooperates with the Controller and provides reasonable assistance in the Controller’s notifications to supervisory authorities (Article 33 GDPR) and to data subjects (Article 34 GDPR).
10.4. The Processor maintains a record of personal data breaches in accordance with Article 33(5) GDPR.
11.1. Upon termination of the User Agreement, and at the Controller’s choice, the Processor shall return or delete all personal data processed on behalf of the Controller, unless Union or Member State law requires the retention of the personal data.
11.2. The default approach is that the Processor: (a) makes Customer Data available for export for thirty (30) days after termination; (b) deletes Customer Data from active production systems within thirty (30) days after that export period; (c) purges Customer Data from backups according to the standard rotation cycle (within ninety (90) days after deletion from active systems).
11.3. The Processor provides written confirmation of deletion upon the Controller’s written request.
12.1. The Processor makes available to the Controller all information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by it (Article 28(3)(h) GDPR).
12.2. Audits are subject to the following conditions, which the Parties consider proportionate:
- the Controller gives the Processor at least thirty (30) days’ prior written notice, unless a competent supervisory authority requires a shorter period or in case of a confirmed personal data breach;
- the audit is conducted during business hours and without unreasonably interfering with the Processor’s operations;
- the auditor is bound by confidentiality and is not a competitor of the Processor;
- each Party bears its own costs, except where the audit reveals material non-compliance by the Processor — in which case the Processor reimburses the Controller’s reasonable costs.
12.3. As an alternative to an on-site audit, the Controller may accept third-party audit reports (such as SOC 2, ISO 27001) and questionnaires provided by the Processor. Where the Processor’s infrastructure subprocessors hold applicable certifications (such as Hetzner Online GmbH, with a current ISO/IEC 27001 certification for its data centres), it is presumed that this satisfies the audit obligation with respect to the matters covered by those certifications, unless the Controller has a specific and reasonable concern not covered by them. The Processor is currently working towards obtaining its own ISO/IEC 27001 certification for the processes under its direct control.
13.1. Liability under this DPA is governed by the liability section of the User Agreement, save that the User Agreement’s limitations of liability for indirect damages do not exclude or limit damages for which the Processor is liable to the Controller under Article 82 GDPR.
13.2. Each Party is liable in accordance with Article 82 GDPR. Where both Parties are responsible for damage caused by an infringement of the GDPR, they shall be jointly and severally liable to the data subject in accordance with Article 82(4) GDPR; the apportionment of liability between the Parties follows Article 82(5) GDPR.
14.1. This DPA is governed by Spanish law and any dispute shall be submitted to the exclusive jurisdiction of the courts and tribunals of Barcelona, Spain. Mandatory consumer protection rules under Brussels Ia and Rome I (where applicable) are unaffected.
14.2. The Parties may agree on modifications to this DPA, in particular to reflect changes in applicable law or in guidance issued by competent supervisory authorities. The Processor shall propose such modifications in writing; if the Controller does not object within thirty (30) days, the modification shall take effect.
14.3. This DPA is published in English as the master version. Translations are provided for convenience. Given that this DPA forms part of a strictly B2B relationship between business entities, in the event of any discrepancy between language versions, the English version prevails.
The current list of subprocessors is also available at https://golova.ai/lt/subprocessors and is kept up to date. TBC = To Be Confirmed.
| Subprocessor | Legal entity | Purpose | Data location | Transfer safeguard |
|---|---|---|---|---|
| Hetzner Online GmbH | Hetzner Online GmbH (Gunzenhausen, Germany) | Hosting and cloud infrastructure | EU (Helsinki, Finland) | EEA — no transfer |
| Cloudflare | Cloudflare Inc. (USA) | CDN, DDoS protection, WAF | Global edge (incl. USA) | SCCs + EU-US DPF (where certified) |
| Stripe | Stripe Payments Europe Ltd (Ireland) | Payment processing | EU (Ireland) with US subsidiaries | SCCs + DPF |
| Sentry | Functional Software Inc. | Error monitoring | EU region | EEA — no transfer (EU region) |
| Apple Push Notification Service | Apple Distribution International Ltd (Ireland) | iOS push notifications | EU and USA | SCCs + DPF |
| Firebase Cloud Messaging | Google Ireland Ltd | Android push notifications | EU and USA | SCCs + DPF |
| Anthropic (Claude) | Anthropic PBC (USA) | AI assistant for support & help chat (processes submitted text) | USA | SCCs + DPF |
| Email provider — TBC | TBC | Transactional and marketing email | TBC | TBC |
| Analytics provider — TBC | TBC | Web analytics | TBC | TBC |
| Support tool — TBC | TBC | Customer support | TBC | TBC |
The Processor implements, as a minimum, the following measures:
A. Access control
- Unique identifiers for each employee with access to systems processing personal data;
- Role-based access control following the principle of least privilege;
- Multi-factor authentication for administrative access;
- Strong password policy in accordance with NIST SP 800-63B;
- Periodic review of access rights, at least every six (6) months;
- Revocation of access within 24 hours of an employee’s departure or role change.
B. Encryption
- Encryption of personal data in transit using TLS 1.2 or higher;
- Encryption of personal data at rest using AES-256 or equivalent;
- Encrypted backups, stored separately from production data;
- Secure storage of cryptographic keys (key management service).
C. Confidentiality and integrity
- Confidentiality commitments imposed on all personnel with access to personal data;
- Network segmentation and firewalls between environments;
- Anti-malware and intrusion detection systems;
- Application-level protections (input validation, CSRF, XSS, SQL injection protection);
- Vulnerability management programme with periodic scans and timely patching.
D. Availability and resilience
- Personal data backups at least every 48 hours;
- Backups retained according to the standard rotation cycle and stored in a location physically separated from production;
- Disaster recovery procedures and periodic testing;
- Monitoring of availability, performance and security events of systems;
- Incident response procedures with defined roles, escalation paths and external notification procedures.
E. Pseudonymisation and minimisation
- Pseudonymisation of personal data where compatible with the purpose of processing;
- Minimisation of the data collected to what is necessary for the purpose;
- Deletion or anonymisation of personal data on expiry of the applicable retention period.
F. Governance
- Information security management framework aligned with ISO/IEC 27001;
- Designated person responsible for data protection (privacy@golova.ai);
- Periodic data protection training for personnel;
- Vendor risk management programme for subprocessors;
- Record of processing activities maintained in accordance with Article 30 GDPR;
- Personal data breach register maintained in accordance with Article 33(5) GDPR.
G. Physical security
- Physical security of the production environment is ensured through certified data centres of our hosting subprocessors (Hetzner Online GmbH, with a current ISO/IEC 27001 certification; Cloudflare), which apply industry-standard controls (access logging, video surveillance, two-factor entry, environmental controls);
- Office workstations of Golova personnel are encrypted, kept up to date, with mandatory automatic screen lock and no local processing of production data beyond what is strictly necessary.