Last updated: 17 August 2026
You are the controller of the data in your workspace; we are your processor. We only act on your instructions, keep it in the EU, use the sub-processors listed below, tell you within 48 hours of a breach, and delete everything when you leave. Full text below.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Admitura – Pieter Beirnaert (“Admisio”, “Processor”) and the Customer (“Controller”). It applies whenever Admisio processes personal data on the Customer's behalf in providing the Service, and is intended to satisfy Article 28 of Regulation (EU) 2016/679 (“GDPR”).
The Customer is the controller of the personal data it and its requesters put into its workspace. Admisio is the processor. For account, billing, and usage data that Admisio collects for its own purposes, Admisio is an independent controller; that processing is described in the Privacy Policy.
Admisio will process personal data only on the Customer's documented instructions — the Terms of Service, this DPA, and the Customer's use of the Service's settings and features constitute those instructions — unless required otherwise by EU or member-state law, in which case Admisio will inform the Customer before processing unless the law prohibits it. Admisio will tell the Customer if it believes an instruction infringes data protection law.
Admisio ensures that every person authorized to process the personal data is bound by confidentiality. Access to production data is limited to the operator of the Service and is used only to run, secure, and support it.
Admisio implements appropriate technical and organizational measures for the risk, including at least:
Admisio may update these measures over time provided the overall level of protection is not reduced.
The Customer gives general authorization for Admisio to use the sub-processors below. Admisio imposes data-protection obligations on each sub-processor equivalent to this DPA and remains responsible for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting, edge network, file (blob) storage, and cookieless usage analytics | EU (Frankfurt) compute; US-headquartered |
| Railway Corp. | Managed PostgreSQL database hosting | EU (europe-west4) region; US-headquartered |
| Resend Inc. | Transactional email delivery (verification codes, notifications) | US-headquartered; EU sending region where available |
| Stripe Payments Europe Ltd. | Subscription billing and payment processing (billing contact and payment data only) | Ireland / US |
| OpenRouter Inc. and its underlying model providers | Optional AI features (draft assessments, form-building assistance). Only used when an organization turns AI features on; only the content of the request being processed is sent | US; model providers vary — no data is used for model training |
Changes. Admisio will give at least 14 days' notice (by email to workspace administrators or by updating this page and notifying in-app) before adding or replacing a sub-processor. If the Customer has reasonable data-protection grounds to object, it may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees; continued use after the notice period is acceptance.
Customer Data is stored and processed in the EU/EEA. Some sub-processors are headquartered in, or may provide support from, the United States or other third countries. Where personal data is transferred outside the EEA, Admisio relies on the European Commission's Standard Contractual Clauses (or the EU–US Data Privacy Framework where the recipient is certified) and appropriate supplementary measures.
Taking into account the nature of the processing, Admisio will assist the Customer, by appropriate technical and organizational measures and insofar as possible, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). The Service already lets administrators view, edit, export, and delete most data directly; for the rest, requests to Admisio are handled within 10 business days.
If Admisio receives a request directly from a data subject about Customer Data, it will redirect the data subject to the Customer and not respond substantively unless the Customer instructs it to or the law requires it.
Admisio will also assist the Customer, on request and at reasonable cost where the effort is significant, with security, breach notification, data protection impact assessments, and prior consultation obligations under Articles 32–36 GDPR.
Admisio will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data, providing the information reasonably available at that time and updating it as the investigation progresses. The Customer is responsible for notifying its supervisory authority and data subjects where required.
During the term the Customer can export its data through the Service; the Customer's right to retrieve its data and switch to another provider is set out in the Terms of Service (“Getting your data out and switching provider”). On termination or on written request, Admisio deletes Customer Data from production systems: a workspace deletion is scheduled with a short grace period (currently 7 days, to allow accidental deletions to be reversed) and then permanently erased; residual copies in encrypted backups are overwritten in the ordinary backup rotation (at most 30 days) and are not restored except to recover the Service as a whole. Admisio may retain data it is legally required to keep (for example invoicing records), subject to continued confidentiality.
Admisio will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR — this DPA, its security description, its sub-processor list, and, on request, summaries of any third-party assessments it holds — and will allow and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates: no more than once a year (unless a supervisory authority or a breach requires more), on at least 30 days' notice, during business hours, under confidentiality, without disrupting the Service, and at the Customer's cost. Written questionnaires are the default audit method.
The limitations and exclusions of liability in the Terms of Service apply to this DPA. Nothing in this DPA limits the parties' obligations or the data subjects' rights under the GDPR. If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA prevails. This DPA is governed by the same law and jurisdiction as the Terms of Service.
Data-protection questions and instructions: privacy@admisio.app. Enterprise customers who need a countersigned copy of this DPA can request one at the same address.