Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") supplements and forms part of the Terms of Service between Headframe sp. z o.o. ("Provider", "Traken") and the Customer ("Controller") (together the "Agreement"). It follows the Common Paper DPA structure: this document sets out the key terms; where restricted transfers occur, the EU Standard Contractual Clauses are incorporated by reference. In the event of conflict on data-protection matters, this DPA controls over the Terms of Service.
1. Definitions
"Applicable Data Protection Law" means the GDPR (Regulation (EU) 2016/679), the Polish Act of 10 May 2018 on the Protection of Personal Data, and, where applicable, the UK GDPR and the Swiss FADP. "Customer Personal Data" means personal data Provider processes on the Controller's behalf under the Agreement. "SCCs" means the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914. "Subprocessor" means a third party engaged by Provider to process Customer Personal Data. Terms such as "controller", "processor", "processing", "personal data", and "data subject" have the meanings in the GDPR.
2. Roles and scope
The Controller is the controller and the Provider is the processor of Customer Personal Data. Provider processes Customer Personal Data only to provide the Service and only on the Controller's documented instructions (including as set out in the Agreement and this DPA), unless required by EU or Member State law, in which case Provider will inform the Controller unless legally prohibited. Given Traken's Zero-Data architecture, the personal data processed is minimal and does not include the content of AI prompts or responses.
3. Details of processing (Annex I)
- Subject matter: provision of the Traken FinOps reconciliation Service.
- Duration: for the term of the Agreement and until deletion/return under Section 9.
- Nature and purpose: ingestion, storage, computation, reconciliation, and reporting on token/usage/cost data and business metadata.
- Types of personal data: limited and incidental โ e.g., business-contact identifiers of authorised users; any personal data incidentally present in metadata labels, provider invoices, or GL data supplied by the Controller. The Controller must not submit special categories of personal data.
- Categories of data subjects: the Controller's personnel/authorised users and any individuals incidentally referenced in supplied metadata or invoices.
4. Provider obligations
Provider will: (a) process only on documented instructions; (b) ensure persons authorised to process are bound by confidentiality; (c) implement appropriate technical and organisational measures under Art. 32 GDPR (Annex II); (d) assist the Controller, taking into account the nature of processing, with data-subject requests and with obligations under Arts. 32โ36 GDPR; (e) notify the Controller without undue delay after becoming aware of a personal-data breach; and (f) make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates (subject to reasonable confidentiality and frequency limits).
5. Security measures (Annex II)
Provider maintains: encryption of Customer Personal Data in transit (TLS) and at rest; role-based access control and least-privilege; authentication controls; logging and monitoring; segregation on EU-based infrastructure; backup and restoration procedures; and vendor/subprocessor security review. Provider itself does not currently hold SOC 2 or ISO 27001 certification; its infrastructure providers hold certifications as described in the Trust & Security page and their respective documentation.
6. Subprocessors
The Controller provides general authorisation for Provider to engage the Subprocessors listed at traken.ai/subprocessors, incorporated into this DPA by reference. Provider imposes data-protection obligations on each Subprocessor that are, in substance, no less protective than those in this DPA, and remains liable for its Subprocessors' performance. Provider will give at least thirty (30) days' notice before adding or replacing a Subprocessor (by updating the list and, on request, by email notification), during which the Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected part of the Service.
7. International transfers
Where processing of Customer Personal Data involves a restricted transfer outside the EEA, the parties agree that the SCCs (Module Two, controller-to-processor, and Module Three where onward transfer to a Subprocessor occurs) are incorporated into this DPA by reference and completed as follows: the Controller is the data exporter and Provider the data importer; the optional docking clause applies; the governing law is the law of Poland; the competent supervisory authority is the Polish UODO; and Annexes I and II of the SCCs are populated by Sections 3 and 5 of this DPA and by the Subprocessors page. For US Subprocessors that are DPF-certified (e.g., Cloudflare), transfers may rely on the EU-U.S. Data Privacy Framework; for US Subprocessors that are not DPF-certified (e.g., Anthropic), transfers rely on the SCCs with supplementary measures. The UK Addendum and Swiss amendments apply where UK or Swiss data is involved.
8. Data-subject requests
Provider will, taking into account the nature of processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests. If Provider receives a request directly, it will refer the data subject to the Controller and notify the Controller.
9. Return and deletion
Upon termination or expiry of the Agreement, Provider will, at the Controller's choice, delete or return Customer Personal Data and delete existing copies within 30 days, unless retention is required by EU or Member State law.
10. Liability and duration
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. This DPA remains in effect for as long as Provider processes Customer Personal Data, notwithstanding termination of the Agreement.