DATA PROCESSING AGREEMENT (DPA)
Last updated: 11 September 2026
This English version is a courtesy translation. In the event of any discrepancy between this text and the Spanish version, the Spanish version is the one that prevails. Read the Spanish version
This Data Processing Agreement (hereinafter, the "DPA" or the "Agreement") governs the conditions under which NURIA LABS SL processes personal data on behalf of the Customer in connection with the provision of the Gescon service, in accordance with the provisions of Article 28 of Regulation (EU) 2016/679 General Data Protection Regulation (hereinafter, the "GDPR") and Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (hereinafter, "LOPDGDD").
This DPA forms an integral part of the Terms and Conditions of Use of the Service and is deemed to be accepted by the Customer upon accepting those Terms or upon activating the Account. In the event of any contradiction between the DPA and the Terms regarding the protection of personal data, this DPA shall prevail.
1. Parties
DATA CONTROLLER: the Customer of the Gescon service, a natural or legal person who has contracted the Service and whose identifying details appear in the sign-up form and/or in the Service account (hereinafter, the "Controller" or the "Customer").
DATA PROCESSOR:
| Item | Detail |
|---|---|
| Corporate name | NURIA LABS SL |
| Tax ID (CIF) | B22853493 |
| Registered address | Carrer Sant Miquel, 36, 1.º A, 07002 Palma, Illes Balears, España |
| Email address | gescon@nurialabs.com |
| Phone | +34 871 55 71 41 |
Hereinafter, "NURIA LABS" or the "Processor".
2. Purpose of the engagement
By means of this DPA, the Controller entrusts the Processor with the processing of the personal data necessary for the provision of the Gescon service in accordance with the applicable Terms and Conditions. The Processor shall process such data on behalf of, and in accordance with the instructions of, the Controller, exclusively for the purposes agreed herein.
3. Details of the processing
In accordance with Article 28.3 of the GDPR, the subject matter, nature and purpose of the processing, as well as the categories of data subjects and personal data covered by the engagement, are specified below:
| Item | Detail |
|---|---|
| Subject matter | Processing of the personal data necessary for the provision of the Gescon service, an AI-based SaaS platform for corporate knowledge management. |
| Nature | Storage, indexing, querying, analysis, reading, transmission, generation of responses by means of AI, retention, deletion and return of the data. |
| Purpose | To provide the Service in accordance with the Terms and Conditions, enabling the Customer and its End Users to centralise and consult the organisation's knowledge through AI assistants. |
| Duration | The duration of the main contract between the parties (Terms and Conditions of Use) and, where applicable, the retention periods set out in Section 11. |
| Categories of data subjects | Employees, collaborators, customers, suppliers, business contacts and any other natural person whose data appears in the documents, sources or queries that the Customer or its End Users upload, connect or process through the Platform. |
| Categories of personal data | Identification and contact data, professional and employment data, financial and billing data, content of communications and documents, associated metadata, as well as any other type of data that the Customer decides to process through the Platform. |
| Special categories of data | Not applicable unless the Customer decides to process specially protected data (Article 9 GDPR) through the Platform. In such case, the Customer warrants that it holds the corresponding legal basis and assumes full responsibility for such processing. |
4. Obligations of the Processor
The Processor and all of its personnel undertake to:
- Process the data on behalf of the Controller: use the personal data subject to processing solely for the provision of the Service and in accordance with the Controller's documented instructions, including those relating to international transfers. The Terms and Conditions, this DPA and the normal use of the Platform constitute documented instructions from the Controller.
- Not process the data for its own purposes: not use the data for purposes other than those agreed, save where required by applicable law, in which case the Processor shall inform the Controller of that requirement in advance, unless the law prohibits this on important grounds of public interest.
- Confidentiality: ensure that the persons authorised to process the data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.
- Security measures: implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including those described in Annex I to this DPA.
- Sub-processors: not engage another processor without the Controller's prior authorisation, in accordance with Section 6 of this DPA.
- Assistance to the Controller: assist the Controller, taking into account the nature of the processing and the information available, so that it can comply with its obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessment and prior consultation).
- Handling of rights: assist the Controller, insofar as this is possible and by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests for the exercise of data subjects' rights (access, rectification, erasure, objection, restriction, portability, automated decisions).
- Return or deletion: at the Controller's choice, delete or return the personal data once the provision of the Service has ended, and delete existing copies, unless retention of the data is required by law.
- Information and audits: make available to the Controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR, and allow for and contribute to audits, in accordance with Section 9 of this DPA.
5. Obligations of the Controller
The Controller undertakes to:
- Hold the appropriate legal basis for the processing of the data that it uploads, connects or processes through the Platform.
- Comply with the duty to inform data subjects about the processing of their data.
- Ensure that the data provided to the Processor is accurate, adequate, relevant and limited to what is necessary for the purposes of the processing.
- Handle requests for the exercise of data subjects' rights addressed to it, with the assistance of the Processor.
- Carry out, where appropriate, a data protection impact assessment (DPIA) under the terms of Article 35 GDPR.
- Comply with the obligations incumbent upon it as Controller under the GDPR and the LOPDGDD.
- Notify the Processor, without undue delay, of any relevant incident relating to the processing of the data.
- Not upload or process through the Platform data for which it does not hold an appropriate legal basis or which infringes the rights of third parties.
6. Sub-processors
6.1 General authorisation
The Controller expressly authorises the Processor to engage third-party sub-processors necessary for the provision of the Service, in accordance with the initial list set out in Annex II to this DPA.
6.2 Changes to sub-processors
The Processor shall inform the Controller of any intended addition or replacement of sub-processors with at least 30 calendar days' notice, except where such notice period is not possible for justified reasons of urgency. Notification may be given by publication on the Service website, by email, or through other usual channels of communication with the Customer.
The Controller may object, with reasons, to the addition of a new sub-processor within 30 calendar days of the notification. In that case, the parties shall negotiate an alternative solution in good faith. If no agreement is reached within a reasonable period, either party may terminate the contract without penalty, with the Customer retaining the right to a refund of amounts paid for periods not consumed.
6.3 Obligations of sub-processors
The Processor shall ensure that sub-processors are bound by data protection obligations equivalent to those agreed in this DPA by means of the corresponding contracts. The Processor shall be liable to the Controller for the sub-processors' compliance with those obligations.
7. Processing by means of Artificial Intelligence
Gescon's internal chat uses the API of OpenAI Ireland Ltd. ("OpenAI"). In Open chat, the End User can select OpenAI, Anthropic, Perplexity, xAI or Google AI Studio. The following 30-day retention terms apply to OpenAI; other providers are governed by their own terms and the contracted configuration. The parties acknowledge that:
- Temporary retention mode: the Processor uses the OpenAI API under the mode that ensures data is retained by OpenAI for 30 days for abuse monitoring and audit purposes, in accordance with the contractual agreement signed with that provider.
- No training: the personal data of the Controller and of the End Users will not be used to train, retrain, fine-tune or improve OpenAI's models or those of any other provider.
- Retention: data sent to OpenAI is processed to answer the query and is not kept on its systems after the 30 days stated in the first point. NURIA LABS retains queries and answers in the Customer's account to provide the Service and ensure security and traceability, under the Controller's instructions and the retention periods in the Privacy Policy.
- AI limitations: the Controller acknowledges that responses generated by AI may contain errors and undertakes to review them before making decisions based on them, in particular where those decisions have legal, financial or similar effects.
8. International data transfers
Personal data is stored primarily in the Microsoft Azure Spain region (Madrid). However, certain sub-processors (in particular, OpenAI and electronic communications providers) may be located, or may carry out processing, in countries outside the European Economic Area, principally the United States.
Where international transfers are carried out, the Processor shall ensure that such transfers are made with the appropriate safeguards provided for in Articles 44 et seq. of the GDPR, by means of one of the following mechanisms:
- An adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework for certified providers.
- Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914.
- Additional technical and organisational measures where necessary following the corresponding impact assessment.
The Controller authorises the Processor to carry out the international transfers necessary for the provision of the Service, subject to the safeguards indicated. The Processor shall make available to the Controller, upon reasonable request, the supporting documentation for the safeguards applied.
9. Audits
The Controller has the right to verify the Processor's compliance with the obligations arising from this DPA by means of:
- Requesting reasonable information from the Processor about the technical and organisational measures applied.
- Accepting certifications, external audit reports or data protection schemes to which the Processor has adhered.
- An on-site audit, upon prior written notice of at least 30 calendar days, during business hours and in a manner that does not interfere with the Processor's normal operations.
On-site audits shall be limited to once a year, except in the event of a confirmed security incident or a request from a competent authority. The costs of the audit shall be borne by the Controller, unless the audit reveals material non-compliance by the Processor, in which case the Processor shall bear the reasonable costs.
The auditor appointed by the Controller must be independent and must sign a confidentiality agreement with the Processor before carrying out the audit. The auditor may not be a competitor of the Processor.
10. Notification of security breaches
The Processor shall notify the Controller, without undue delay and, in any event, within a maximum period of 72 hours of becoming aware of it, of any breach of the security of personal data (breach) affecting the data covered by this DPA. The notification shall include, insofar as possible:
- The nature of the breach, including, where possible, the categories and approximate number of data subjects affected, as well as the categories and approximate number of data records affected.
- The Processor's contact details for obtaining further information.
- The likely consequences of the breach.
- The measures taken or proposed to remedy the breach and, where applicable, mitigate its possible adverse effects.
The Processor shall assist the Controller in complying with its obligations to notify the supervisory authority and data subjects, where applicable, in accordance with Articles 33 and 34 GDPR.
11. Return and deletion of data
Once the provision of the Service has ended, the Processor shall, at the Controller's choice:
- Return to the Controller the personal data subject to processing, in a structured, commonly used format, by export through the Platform or by any means agreed.
- Delete the personal data and any existing copies from its active systems.
The Controller shall have a period of 30 calendar days from the end of the Service to download or export its data. Once that period has elapsed without the Controller having taken action, the Processor shall proceed to delete the personal data from its active systems.
Notwithstanding the foregoing, the Processor may retain copies of the data for the legally applicable periods (in particular, rotating backup copies and data required by tax or commercial regulations), ensuring that such copies remain blocked and are processed only for the strictly legal purposes that justify their retention.
12. Liability
Each party shall be liable to data subjects for damages caused as a result of a breach of its respective obligations under the GDPR.
In the relationship between the parties, the Processor's liability for breaches of this DPA shall be subject to the limitations set out in the Terms and Conditions of the Service, except in those cases where data protection legislation imposes greater liability by mandatory provision.
Notwithstanding the foregoing, the Processor shall not be liable for damages arising from the Controller's breach of its obligations, in particular where the Controller has provided the Processor with data without an appropriate legal basis or has given instructions contrary to data protection legislation.
13. Term
This DPA shall enter into force upon acceptance of the Terms and Conditions of the Service or, where applicable, upon signature of the DPA by the parties, and shall remain in force for the entire duration of the processing of data by the Processor on behalf of the Controller.
The obligations of confidentiality, return or deletion of data, and any others that by their nature must survive, shall remain in force after the end of the Service.
14. Applicable law and jurisdiction
This DPA is governed by Spanish law and by European data protection legislation. For the resolution of any dispute arising from it, the parties submit to the Courts and Tribunals of Palma (Illes Balears, España), unless data protection or consumer protection legislation establishes a different mandatory jurisdiction.
ANNEX I — Technical and organisational security measures
The Processor applies the following technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR:
1. Access control measures
- Authentication of End Users by username and password, with complexity and expiry policies.
- Support for multi-factor authentication (MFA) where available.
- Role-based access control (RBAC) system to limit access to information according to the user's profile.
- Logging and auditing of access to the Platform.
2. Encryption
- Encryption of communications in transit using TLS 1.2 or higher.
- Encryption of data at rest using AES-256 or equivalent.
- Secure management of cryptographic keys through the Microsoft Azure infrastructure.
3. Confidentiality and integrity
- Confidentiality undertaking by all personnel with access to the data.
- Logical segregation of data between the different Customers (secure multitenancy).
- Integrity control mechanisms for the information stored.
4. Availability and resilience
- Hosting on Microsoft Azure infrastructure with high availability and redundancy.
- Periodic backup copies with defined retention policies.
- Documented disaster recovery procedures.
5. Verification, assessment and continuous improvement
- Periodic reviews of the security configuration and internal policies.
- Vulnerability analysis of the Platform.
- Incident management processes with defined response and notification timeframes.
6. Organisational measures
- Internal data protection and information security policy.
- Periodic staff training on data protection and cybersecurity.
- Confidentiality agreements with all suppliers and sub-processors.
- Documented procedure for managing staff onboarding, offboarding and changes.
ANNEX II — Authorised sub-processors
As of the date of the last update of this DPA, the authorised sub-processors are as follows:
| Sub-processor | Purpose | Location of processing | International transfer safeguards |
|---|---|---|---|
| Microsoft Ireland Operations Ltd. (Microsoft Azure) | Hosting of the Platform and storage of the Customer's data | Spain (Azure Spain Central region) | Processing within the EU. For global support: Standard Contractual Clauses and Data Privacy Framework. |
| OpenAI Ireland Ltd. | Processing of queries by means of AI models (retention of interactions for 30 days) | European Union / United States | Standard Contractual Clauses and, where applicable, Data Privacy Framework. Specific agreement on temporary retention and no training. |
| Stripe Payments Europe Ltd. | Payment processing and billing management | Ireland / United States | Standard Contractual Clauses and Data Privacy Framework. |
| Providers of transactional email delivery | Sending of transactional emails and Service notifications | European Union / United States | Standard Contractual Clauses and, where applicable, Data Privacy Framework. |
Anthropic, Perplexity, xAI and Google AI Studio also take part in Open chat when selected by the End User. A detailed, current list of sub-processors, their retention periods, locations and specific international transfer safeguards is available on request at gescon@nurialabs.com.