Data Processing Agreement
Acceptance and scope
1.1 This Data Processing Agreement (DPA) forms part of the Obstruo Terms of Service between OBSTRUO prosta spółka akcyjna, ul. Święty Marcin 29 lok. 8, 61-806 Poznań, Poland, KRS 0001254019 ("Obstruo") and the Customer.
1.2 It takes effect when the Customer accepts the Terms. No signature is required. A countersigned copy is available on request to office@obstruo.ai.
1.3 It applies wherever Obstruo processes personal data contained in Customer Data on the Customer's behalf. Capitalised terms not defined here have the meaning given in the Terms.
1.4 "Data Protection Law" means Regulation (EU) 2016/679 (GDPR) and any other data protection law applicable to a party's processing under this DPA.
1.5 If this DPA conflicts with the Terms on personal data, this DPA prevails. If it conflicts with the Standard Contractual Clauses, those Clauses prevail.
Roles
2.1 For personal data contained in Customer Data, the Customer is the controller and Obstruo is the processor. Where the Customer is itself a processor for its own clients, Obstruo is a subprocessor and the Customer warrants that it is authorised to give the instructions it gives.
2.2 Each party is independently responsible for its own compliance with Data Protection Law. This DPA does not transfer to Obstruo any obligation the law places on the Customer as controller, including having a lawful basis, informing data subjects, and assessing proportionality.
2.3 Obstruo is a controller for the personal data it processes to run its business rather than to provide the Service, including account, billing, support and website data. That processing is described in Obstruo's privacy notice and is outside this DPA.
Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I. The Customer determines what personal data enters the Service. Obstruo does not control the content of requests, responses or tool calls and cannot verify what they contain.
Instructions and Customer obligations
4.1 Obstruo processes personal data only on the Customer's documented instructions, unless required otherwise by EU or Member State law, in which case Obstruo informs the Customer beforehand unless the law prohibits it.
4.2 The Terms, this DPA, the Order and the Customer's configuration of the Service together constitute those instructions. Configuration includes the choice of Upstream Providers and routing, redaction recognisers and policies, retention windows, MCP tool permissions, and activation of raw-audit mode.
4.3 Obstruo will inform the Customer if an instruction appears to infringe Data Protection Law, and may decline to act on it pending resolution.
4.4 The Customer warrants that it has a lawful basis for the processing it instructs, has given any required information to data subjects, and that its instructions comply with Data Protection Law.
4.5 The Customer must not submit special categories of personal data under Article 9 GDPR, or data relating to criminal convictions and offences under Article 10 GDPR, without Obstruo's prior written agreement and the additional measures recorded in it.
Confidentiality and personnel
Obstruo ensures that persons authorised to process personal data are bound by confidentiality obligations surviving the end of their engagement, receive role-appropriate data protection instruction, and have access only where needed to provide, operate or secure the Service.
Security
6.1 Obstruo implements and maintains the technical and organisational measures in Annex II, appropriate to the risk under Article 32 GDPR. It may update them provided the level of protection is not reduced.
6.2 The Customer is responsible for the security of its own environment, the safekeeping of its API keys and Upstream Provider credentials, the roles it grants its Users, and its configuration choices.
Subprocessors
7.1 The Customer gives general authorisation for Obstruo to engage the subprocessors listed in Annex III.
7.2 Obstruo gives at least 30 days' notice by e-mail before a new subprocessor begins processing personal data. The Customer may object within that period on reasonable data-protection grounds.
7.3 If the objection cannot be resolved, the Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused period. This is the Customer's sole remedy for an objection.
7.4 Obstruo binds each subprocessor by written contract to obligations no less protective than this DPA, and remains liable to the Customer for their performance.
Upstream Providers, MCP servers and raw-audit mode
8.1 Upstream Providers are not subprocessors of Obstruo. The Customer supplies its own credentials. When the Service routes a request it does so on the Customer's instruction, using the Customer's own account with that provider, under the Customer's own agreement with it. The Customer is responsible for the data-protection and transfer arrangements applicable to that relationship, including any opt-out from the use of submitted data for training. The same applies to MCP servers and models operated by the Customer.
8.2 Redaction happens in memory. Where redaction is enabled and matches, only post-redaction content is written to the audit log and to operational logs. Where reversible tokenization is enabled, the mapping is held in a cache operated without persistence and is lost on restart.
8.3 Obstruo does not therefore expect to hold unredacted personal data at rest. That describes how the Service operates; it is not a warranty that no personal data is ever persisted, because content reaches storage where the Customer has not enabled redaction or has not configured a recogniser for a category of data, where the Customer has enabled raw-audit mode, or where redaction does not match a value, redaction being a statistical process.
8.4 Raw-audit mode is off by default and can be enabled only by the Customer, through an explicit confirmation step in the Panel. In that mode redaction may be skipped and requests and responses are stored as submitted. Enabling it is the Customer's documented instruction, activation is logged with the User and the time, and the Customer remains responsible as controller for the lawfulness of the resulting processing.
8.5 Obstruo does not use Customer Data to train, fine-tune or evaluate any model. Obstruo uses only aggregated operational metadata, such as counts of redactions by type, latency, routing outcomes and error rates, to operate, secure and improve the Service.
International transfers
9.1 Obstruo processes personal data contained in Customer Data within the EEA. The subprocessors in Annex III process within the EEA.
9.2 Transmission to an Upstream Provider outside the EEA is made on the Customer's instruction under §8.1 and is a transfer by the Customer, not by Obstruo. The Service records the destination in the audit log so the Customer can evidence it.
9.3 Where the Customer is established outside the EEA, or where Obstruo later engages a subprocessor outside the EEA, the parties will apply the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with Annexes I to III of this DPA incorporated by reference. The UK International Data Transfer Addendum and the Swiss adaptations are available on request to office@obstruo.ai.
Assistance
10.1 Data-subject rights. The Panel provides self-service tools to search, export and delete audit records. Where a request cannot be met through the Panel, Obstruo responds to the Customer's written request within 5 business days. Obstruo does not respond to the substance of a request received directly from a data subject about Customer Data; it refers the individual to the Customer and informs the Customer without undue delay.
10.2 Articles 32 to 36. Taking into account the nature of the processing and the information available to it, Obstruo assists the Customer with security, breach notification, data protection impact assessments and prior consultation. The audit log, the redaction configuration and Annex II are intended to supply what an impact assessment needs.
10.3 Obstruo maintains a record of processing carried out on the Customer's behalf under Article 30(2) GDPR and makes it available to the Customer or a supervisory authority on request.
Personal data breach
11.1 Obstruo notifies the Customer of a personal data breach affecting personal data contained in Customer Data without undue delay after becoming aware of it, and in any event in time for the Customer to meet its own obligation under Article 33 GDPR. Obstruo aims to notify within 48 hours of becoming aware and states in the notification when it became aware.
11.2 The notification describes, so far as known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information not available at once follows in phases without further undue delay.
11.3 Obstruo assists the Customer with Articles 33 and 34, and does not notify a supervisory authority or any data subject on the Customer's behalf unless instructed or required by law. Notification is not an admission of fault.
Audits and information
12.1 Obstruo makes available the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, Annex II, and any assurance report or certification it holds from time to time.
12.2 The Customer may audit compliance once in any twelve-month period, on at least 30 days' written notice, during business hours, without unreasonable disruption, under confidentiality, and without access to other customers' data or systems. An additional audit may take place where a supervisory authority requires it or following a breach affecting the Customer.
12.3 An audit proceeds first by review of documentation and written questionnaire. On-site inspection is available where the Customer shows that the documentation is insufficient, or where a supervisory authority requires it.
12.4 The Customer bears its own and Obstruo's reasonable costs, except where the audit reveals a material breach of this DPA by Obstruo, in which case Obstruo bears its own. Where the Customer's auditor is a competitor of Obstruo, Obstruo may require an independent third-party auditor instead.
12.5 Obstruo holds no certification or attestation against ISO 27001, ISO 42001, SOC 2 or any comparable framework and does not represent otherwise. Certifications held by Obstruo's hosting provider cover that provider's infrastructure within the scope of its own certificate.
Retention, return and deletion
13.1 Audit records are retained for the window applicable to the Customer's plan and are deleted at the end of it.
13.2 On termination, Customer Data remains available for export for 30 days, as CSV from the Panel and, on plans that include it, through the audit log API.
13.3 After that window Obstruo deletes Customer Data, unless retention is required by law, in which case it isolates the data, restricts processing to what the law requires, and informs the Customer.
13.4 Residual copies may persist in encrypted backups for up to 30 days until overwritten in the ordinary backup cycle, and remain subject to this DPA.
13.5 Obstruo confirms deletion in writing on request.
Liability, term and governing law
14.1 Liability under this DPA is subject to the limitations in Section 11 of the Terms.
14.2 Nothing in this DPA limits either party's liability to a data subject or a supervisory authority under Data Protection Law, or alters the allocation Article 82 GDPR makes between controllers and processors.
14.3 This DPA takes effect with the Terms and continues until Obstruo has deleted or returned all personal data processed on the Customer's behalf.
14.4 Obstruo may update this DPA on 30 days' notice where required by a change in law, in the Service, or in its subprocessors, provided the level of protection is not reduced. Section 13.3 of the Terms applies where a change materially reduces the Customer's rights.
14.5 Governed by Polish law. Section 18.2 of the Terms applies to disputes. Data protection contact: office@obstruo.ai.
Annex I: Description of the processing
Parties. Data exporter: the Customer, acting as controller or as processor for its own clients. Data importer: Obstruo, acting as processor or subprocessor.
Subject matter. Provision of the Obstruo control plane: routing of requests to Upstream Providers and MCP servers selected by the Customer, redaction in transit, guardrail evaluation, tool-permission enforcement, audit logging, and the Panel.
Duration. The term of the Order, plus the retention window configured within the Customer's plan, plus the export and deletion periods in §13.
Nature. Receipt, transmission, transformation by redaction and tokenization, classification, storage of audit records, retrieval and deletion. Processing is automated. Obstruo takes no decision producing legal or similarly significant effects.
Purpose. To provide the Service as configured by the Customer, and for no other purpose.
Types of personal data. Determined by the Customer. Ordinarily: identifiers and contact details of the Customer's Users, being name, business e-mail address and role, for access to the Panel; and any personal data contained in requests, responses and tool calls submitted by the Customer's applications, agents and end users. Where redaction is enabled and matches, such data is replaced with tokens before an audit record is written.
Categories of data subjects. The Customer's Users; the Customer's own customers and end users; any individual whose personal data appears in submitted content.
Special categories. Not permitted without prior written agreement under §4.5.
Frequency. Continuous for the duration of the Order.
Competent supervisory authority. Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland, where the Standard Contractual Clauses apply and Obstruo is the exporter.
Annex II: Technical and organisational measures
Encryption. In transit using TLS 1.2 or higher, with mutual TLS between internal services. At rest at both the storage volume layer and the application layer. Application-layer keys held in a dedicated secrets manager, so that direct access to a data store yields ciphertext only. Key retrieval is audit-logged.
Data minimisation in processing. Redaction applied in memory in the request path. Only post-redaction content written to audit and operational logs where redaction is enabled and matches. Token mapping cache operated without persistence and lost on restart. Limits described in §8.3.
Pseudonymisation. Detected values replaced with type-tagged tokens before transmission to an Upstream Provider. Where reversible tokenization is enabled by the Customer, resolution is possible only within the lifetime of the in-memory cache.
Access control. Role-based access control over production systems. Multi-factor authentication enforced for Obstruo personnel on all systems that support it. Access to production data stores restricted to a strictly limited number of named administrator identities. Panel accounts support multi-factor authentication, which the Customer may enforce organisation-wide or a User may enable individually.
Separation. Logical separation of Customer environments at the gateway and storage layers, and of production from non-production environments.
Logging and accountability. Actions taken in the Panel logged and retained for the same period as the Customer's audit log under its plan. Activation of raw-audit mode logged with the User and the time.
Availability and resilience. Weekly full backups with daily incremental backups, retained for 30 days and then overwritten, held on encrypted storage within the EEA.
Physical security. Hosting on OVHcloud Public Cloud in France. Physical and environmental security provided by OVH SAS under its own certified information security management system.
Governance. Confidentiality obligations for personnel. Role-appropriate data protection instruction. Controls designed with reference to the control objectives of ISO 27001 and ISO 42001. Obstruo holds no certification against those standards at the date of this DPA.
Subprocessors. Bound by written contract to obligations no less protective than this DPA, and processing within the EEA.
Annex III: Subprocessors
- OVH SAS, hosting infrastructure (OVHcloud Public Cloud), France.
- Scaleway SAS, delivery of transactional e-mail sent by the Service, France.
- Microsoft (Ireland), business e-mail receiving support correspondence, tenant in the EU, Ireland.
All subprocessors process personal data within the EEA.
Upstream Providers configured by the Customer under its own credentials, MCP servers registered by the Customer, and models operated on the Customer's own infrastructure are not subprocessors of Obstruo. See §8.1.
Customers should avoid sending Customer Data to Obstruo by e-mail where it is not necessary. E-mail is processed outside the gateway and outside the redaction path.
Annex IV: Standard Contractual Clauses
The Standard Contractual Clauses are not engaged where Obstruo and every subprocessor in Annex III process within the EEA. Where §9.3 applies, the Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply with Annexes I to III of this DPA incorporated by reference, using Module Three where the Customer is a processor and Module Four where Obstruo transfers to a controller established outside the EEA.