Abstractor.io
Legal

Data Processing Agreement

GDPR Article 28 · Version 0.1 (preview) · 2026-05-26

A full signed DPA is required for commercial use. During the private preview, email hello@abstractor.io to request a countersigned agreement tailored to your organisation.

Parties

Data Controller: The customer organisation that uploads data to Abstractor.io.

Data Processor: GINF Systems Kft., Budapest, Hungary — operator of Abstractor.io.

Subject matter

GINF Systems Kft. processes personal data on behalf of the Controller solely to provide the Abstractor.io service as described in the Terms of Service.

Processing obligations

  • Processing only on documented Controller instructions.
  • Confidentiality obligations on all authorised personnel.
  • Appropriate technical and organisational security measures (encryption at rest and in transit, EU-resident infrastructure, Ed25519-attested invocation logs).
  • Assistance with data subject rights requests within 72 hours of notification.
  • Deletion or return of all personal data on termination, at Controller's choice.
  • Provision of audit evidence on reasonable request.

Sub-processors

No personal data is transferred outside the EU. Infrastructure is hosted on EU-resident servers. We will notify Controllers 30 days in advance of any change to sub-processors.

Governing law

This DPA is governed by EU GDPR (Regulation 2016/679) and Hungarian law. Disputes are subject to the courts of Budapest, Hungary.

Request a signed DPA

To receive a countersigned DPA for your organisation, email hello@abstractor.io with subject line "DPA request" and your organisation's legal name and jurisdiction.