Legal · Compliance landing page
Data Processing Agreement
Last updated: April 29, 2026
This Data Processing Agreement (“DPA”) forms part of the contract between Rebelframes Kft. (the “Processor”) operating AIWorkFluency, and the Customer (the “Controller”). It governs the processing of personal data carried out by the Processor on behalf of the Controller in the course of providing the AIWorkFluency service. It is drafted to satisfy Article 28 of the EU General Data Protection Regulation 2016/679 (“GDPR”).
A counter-signed PDF copy is provided automatically as part of the customer contract package. To request a standalone signed copy before contracting, email privacy@aiworkfluency.com with subject line “DPA request”.
1. Subject matter and duration
The Processor processes personal data solely to provide the AIWorkFluency service to the Controller, for the duration of the customer contract plus the post-cancellation export window of 3 months.
2. Nature and purpose of processing
- Delivering weekly role-tailored AI-literacy lessons to staff.
- Recording responses, scores, and timestamps.
- Generating and maintaining the Article 4 Compliance Folder as audit-ready evidence of the literacy programme.
- Operating the customer admin dashboard and account management.
- Service security, fraud prevention, and troubleshooting.
3. Categories of personal data
- Identification and contact data: full name, work email, role/job title.
- Service-generated data: lesson responses, scores, completion timestamps, assigned track.
- Technical data: IP, browser type, session identifiers (for security only).
No special-category data (GDPR Art. 9) is intentionally collected. The Controller will not enter special-category data into free-text fields.
4. Categories of data subjects
- The Controller’s employees enrolled in training.
- The Controller’s administrators of the service.
- Other persons working under the Controller’s direction whom the Controller chooses to enroll (contractors, interns).
5. Controller obligations
- The Controller is responsible for the lawful basis of providing staff data to the Processor (typically Art. 6(1)(c) — compliance with the Article 4 obligation — and Art. 6(1)(f) where applicable).
- The Controller must inform staff that their participation is logged in line with this DPA and the Privacy Policy.
- The Controller is responsible for the accuracy of the staff list it provides.
6. Processor obligations
The Processor will:
- Process personal data only on documented instructions from the Controller, including those set out in this DPA and the customer contract.
- Ensure persons authorised to process the personal data have committed themselves to confidentiality.
- Implement and maintain the technical and organisational measures described in our Security overview.
- Assist the Controller in responding to data-subject requests under GDPR Articles 15–22.
- Assist the Controller in fulfilling its obligations under Articles 32–36 (security, breach notification, DPIA where applicable).
- At the Controller’s choice, return or delete all personal data at the end of the export window, and delete existing copies unless retention is required by Union or Member State law.
7. Sub-processors
The Controller authorises the Processor to engage the sub-processors listed in the Security overview. Each sub-processor is bound by data protection obligations equivalent to those in this DPA. The Processor will give the Controller at least 30 days’ prior written notice of any intended addition or replacement of sub-processors. The Controller may object on reasonable data-protection grounds within that period.
8. International transfers
Where personal data is transferred outside the European Economic Area, the transfer is covered by Standard Contractual Clauses (Commission Decision 2021/914) plus any supplementary measures required after a transfer-impact assessment.
9. Personal data breach notification
The Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach. The notification will include the information required under GDPR Article 33(3).
10. Audit rights
The Processor will make available to the Controller all information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Controller will give reasonable notice and audits will be conducted during normal business hours, no more frequently than once per year unless required by a supervisory authority.
11. Data return and deletion
The Compliance Folder remains exportable by the Controller for 3 months after contract termination. After that window, all personal data is deleted from active systems within 30 days and from backups within the standard 90-day backup-retention cycle, except where retention is required by law (for example billing records under Hungarian Act C of 2000).
12. Liability and term
This DPA is effective for the term of the customer contract and survives termination for as long as the Processor holds personal data on behalf of the Controller. Liability under this DPA is governed by the limitation clauses of the customer contract and the governing law thereof.