Article 28 GDPR terms for Customer Personal Data · Last updated 1 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement governing the Customer’s use of the Okyra Service (the “Main Agreement”). It applies where ENIN BV processes Customer Personal Data on behalf of the Customer.
| Role | Party details |
|---|---|
| Controller / Customer | The customer identified in the Main Agreement or Order Form (“Customer”). |
| Processor | ENIN BV, trading as Okyra, Meersstraat 43, 9000 Gent, Belgium; company/VAT number BE0808506381 (“Okyra”). |
If the Customer is itself a processor, references to “Controller” include the relevant controller and the Customer appoints Okyra as a subprocessor. The Customer confirms that it is authorised to give the instructions and enter into this DPA for the relevant processing.
Capitalised terms not defined here have the meaning given in the Main Agreement. “Applicable Data Protection Law” means the GDPR, the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, and other data-protection law applicable to the processing. “Customer Personal Data” means Personal Data processed by Okyra on behalf of the Customer under the Main Agreement. “GDPR” means Regulation (EU) 2016/679. “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings in Applicable Data Protection Law.
The schedules form part of this DPA. References to Articles are to the GDPR unless stated otherwise. If this DPA conflicts with the Main Agreement on processing of Customer Personal Data, this DPA prevails. If applicable Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail.
Okyra will process Customer Personal Data to provide the AI-assisted research Service described in the Main Agreement, including project administration, participant invitations, voice-based interviews, transient audio processing, transcription, generation of research summaries and insights, storage, support, security and deletion. The processing details are set out in Schedule 1.
This DPA takes effect when the Main Agreement is accepted and continues for as long as Okyra processes Customer Personal Data. Termination of the Main Agreement ends routine processing, subject to deletion, return, backup and legal-retention obligations in this DPA.
The Customer is the Controller and Okyra is the Processor for Customer Personal Data. The Customer determines the purposes and essential means of its research. The Main Agreement, this DPA, the Customer’s configuration and documented use of Service functionality constitute the Customer’s instructions.
Okyra will process Customer Personal Data only on documented instructions, including transfers, unless Union or Member State law requires otherwise. In that case, Okyra will inform the Customer before processing unless the law prohibits notice for important public-interest reasons. Okyra will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing until the parties resolve the issue. Okyra is not required to provide legal advice or perform an instruction that is technically infeasible or outside the Service without a separate agreement.
The Customer is responsible for the lawfulness, fairness and transparency of its research and instructions. The Customer will:
Okyra will ensure that persons authorised to process Customer Personal Data are subject to confidentiality obligations and receive access only as necessary for their functions. Okyra will apply appropriate access-management and least-privilege practices.
Taking account of the state of the art, implementation costs, and the nature, scope, context and purposes of processing as well as risks to Data Subjects, Okyra will maintain appropriate technical and organisational measures meeting Article 32. The current measures are described in Schedule 3. Okyra may update them provided the overall level of protection is not materially reduced.
Okyra will make available information reasonably necessary to demonstrate compliance with Article 28 and this DPA, subject to confidentiality, security, privilege and third-party restrictions.
Okyra will not use Customer Personal Data, Participant responses, interview transcripts or AI-generated research outputs to train general-purpose artificial-intelligence models. Customer Personal Data is processed to provide, secure and support the Service and as otherwise instructed by the Customer.
The Customer gives Okyra general written authorisation to appoint subprocessors. The subprocessors authorised on the effective date are listed in Schedule 2. Okyra will impose data-protection obligations that provide substantially the same protection required by this DPA, to the extent applicable to the subprocessor’s services, and remains responsible for performance of those obligations as required by Article 28(4).
Okyra will provide advance notice through email, the Service or another agreed channel before adding or replacing a subprocessor that will process Customer Personal Data. The Customer may object within 14 days on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, Okyra may refrain from using the new subprocessor for that Customer or either party may terminate the materially affected Service; Okyra will refund prepaid fees for the unused terminated period. An objection does not relieve the Customer from paying for unaffected Service.
Okyra seeks to use EU/EEA deployment locations for core Service infrastructure where stated in Schedule 2. A provider’s corporate location, remote support or onward processing may nevertheless involve a transfer outside the EEA. Okyra will ensure that each Restricted Transfer is covered by a valid mechanism under Chapter V GDPR, including an adequacy decision, the European Commission’s Standard Contractual Clauses (“SCCs”), or another lawful mechanism, together with supplementary measures where appropriate.
Where Okyra transfers Customer Personal Data to a subprocessor in a third country and the transfer is not covered by adequacy, Okyra will enter into the applicable SCC module with that subprocessor. Where the Customer’s transfer to Okyra requires SCCs, Schedule 4 applies and incorporates the then-current SCCs approved by the European Commission, with the Customer as data exporter and Okyra as data importer. Nothing in this DPA varies the SCCs in a manner that conflicts with them.
Taking account of the nature of processing, Okyra will assist the Customer through appropriate technical and organisational measures, insofar as possible, to fulfil requests under Articles 12-23. If Okyra receives a request relating to Customer Personal Data, it will not respond substantively except on the Customer’s instructions or where required by law. Okyra will, where possible, direct the requester to the Customer and promptly notify the Customer. Assistance beyond standard Service functionality may be charged at reasonable rates if permitted by law and agreed in advance.
Okyra will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will include information reasonably available to Okyra concerning the nature of the breach, categories and approximate numbers of Data Subjects and records, likely consequences, mitigation measures and a contact point. Information may be provided in phases. Notification is not an admission of fault or liability.
Okyra will take reasonable steps to contain, investigate and mitigate the breach, document it as required by Article 33(5), and reasonably assist the Customer with its obligations under Articles 33 and 34. The Customer is responsible for notifications to Supervisory Authorities and Data Subjects unless law assigns that obligation to Okyra.
Taking account of the nature of processing and information available to Okyra, Okyra will reasonably assist the Customer with data-protection impact assessments under Article 35 and prior consultation under Article 36. Standard information is included in this DPA and Service documentation. Additional bespoke assistance may be subject to mutually agreed fees where permitted by law.
Okyra will provide available security documentation, questionnaires, summaries of relevant assessments and other appropriate evidence to demonstrate compliance. The Customer will first review that information before requesting an audit.
If reasonably necessary to demonstrate Article 28 compliance, the Customer may conduct one audit in any 12-month period, and additional audits following a confirmed material Personal Data Breach or where required by a Supervisory Authority. Audits require at least 30 days’ notice unless an urgent legal reason prevents it, must occur during normal business hours, minimise disruption, avoid access to other customers’ data, and be performed by an independent qualified auditor bound by confidentiality and not an Okyra competitor.
The Customer bears its audit costs and Okyra may charge reasonable assistance costs, except where an audit identifies a material breach by Okyra. Okyra may redact information protected by privilege, third-party confidentiality, security requirements or trade-secret law, provided it supplies sufficient alternative evidence where reasonably possible.
During the term, the Customer may use available Service controls to export or delete Customer Personal Data. On termination or written instruction, Okyra will delete or return Customer Personal Data, at the Customer’s choice and to the extent technically available, unless Union or Member State law requires retention. Interview audio is processed transiently and is not permanently stored by Okyra. Project data, transcripts and generated outputs follow the Customer’s configured retention and deletion settings.
Deleted data may remain in protected backups until overwritten in the ordinary backup cycle. During that period it will remain protected, will not be restored except for disaster recovery or legal necessity, and will be deleted again when the relevant backup is restored. Okyra may retain evidence of compliance and business records that do not contain Customer Content, or limited Personal Data required by law.
Routine DPA compliance is included in Service fees. If the Customer requests assistance, audits, exports, bespoke security reviews or instructions beyond standard functionality, the parties may agree reasonable fees based on the work required. Okyra will not charge for assistance required because of its own breach of this DPA.
Liability arising from this DPA is subject to the limitations and exclusions in the Main Agreement to the extent permitted by Applicable Data Protection Law. Nothing limits a Data Subject’s rights or either party’s liability to a Supervisory Authority where such rights or liability cannot lawfully be limited. The allocation of responsibility between the parties does not prejudice Article 82 GDPR.
This DPA terminates when Okyra no longer processes Customer Personal Data, except for provisions that must survive to protect retained data. Belgian law governs this DPA. The courts of Ghent, Belgium, have exclusive jurisdiction, subject to mandatory law and any competent Supervisory Authority. The dispute, notice, assignment, severability and electronic-acceptance provisions of the Main Agreement also apply.
| Element | Description |
|---|---|
| Subject matter | Provision of the Okyra AI-assisted qualitative research platform and related hosting, authentication, support, security and communications. |
| Duration | For the term of the Main Agreement and thereafter only for deletion, return, backup cycling or legal retention. |
| Nature and operations | Collection and organisation of project data; participant invitation; transient capture and streaming of interview audio; speech-to-text transcription; AI inference; generation of summaries, themes, sentiment indicators and research insights; storage, retrieval, export, deletion, security monitoring and support. |
| Purposes | To conduct Customer-configured research interviews, create transcripts and research outputs, manage projects and authorised access, communicate with Participants and users, secure and support the Service, and comply with documented instructions. |
| Data Subjects | Participants and prospective Participants; Customer employees, contractors, researchers, administrators and other Authorised Users; persons mentioned in interview responses. |
| Personal Data | Names and contact details; account and authentication data; research project information; interview questions and responses; transcripts; AI-generated summaries, themes, sentiment indicators and insights; identifiers, timestamps, device/connection data, audit and security logs; support communications. |
| Special categories | Not required by default. May arise if a Customer asks about or a Participant discloses health, ethnicity, political opinions, religion, trade-union membership, sex life or sexual orientation, biometric identifiers, or other sensitive information. The Customer must establish an Article 9 condition and apply appropriate safeguards. |
| Criminal-offence data | Not required by default and should not be collected unless lawful, necessary and specifically safeguarded by the Customer under Article 10. |
| Frequency | Continuous or intermittent, depending on Customer use during the term. |
| Retention | Customer-configured retention and deletion for project data; transient audio is not permanently stored; limited logs and backups retained for risk-based operational periods; legal records retained as required. |
Locations below describe the intended primary deployment or service region where agreed. Corporate location, remote support and onward subprocessors may differ and are handled under section 7.
| Provider | Service / data involved | Primary location or safeguards |
|---|---|---|
| Vercel | Frontend hosting, content delivery and platform operation; limited account, connection and service data. | EU deployment where configured; transfer safeguards applied where required. |
| Supabase and Supabase Auth | Database, storage, authentication and account management; account, project, transcript, output and authentication data. | EU region. |
| Render | Application and backend hosting; project, service and technical data. | EU region. |
| Hetzner | Infrastructure and hosting; project, service and technical data. | EU/EEA. |
| Mistral AI | AI model processing supporting interview, transcription and research-output functions; transient interview content, transcripts, prompts and generated output as applicable. | EU/EEA processing where contracted; transfer safeguards applied where required. |
| Brevo | Transactional and operational emails, including account or participant invitations; names, email addresses and message metadata/content. | EU/EEA processing where contracted; transfer safeguards applied where required. |
TWIPLA is used for Okyra website/product analytics and Stripe for billing and payment processing. To the extent they process Okyra’s own controller data rather than Customer Personal Data on the Customer’s behalf, they are not subprocessors under this DPA. If their role changes so that they process Customer Personal Data as subprocessors, Okyra will update this list under section 6.
If a transfer from the Customer to Okyra is a Restricted Transfer not covered by an adequacy decision, the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 are incorporated by reference as follows: Module Two applies where the Customer is a Controller and Okyra a Processor; Module Three applies where the Customer is a Processor and Okyra a Subprocessor. Clause 7 (docking) applies. For Clause 9, Option 2 applies with the notice period in section 6. For Clause 11, the optional language does not apply. For Clause 17, Option 1 applies and Belgian law governs. For Clause 18(b), the courts of Belgium are selected.
Annex I to the SCCs is completed by the party details and Schedule 1 of this DPA. The competent Supervisory Authority is determined under Clause 13. Annex II is completed by Schedule 3. Annex III is completed by Schedule 2. The parties’ acceptance of the Main Agreement and this DPA constitutes signature of the SCCs where permitted. The parties will complete additional information reasonably required for a valid transfer.
This DPA may be accepted electronically and is effective without handwritten signature when the Customer accepts the Main Agreement, signs an Order Form incorporating it, or uses the Service after being presented with it. A signed counterpart may be requested for procurement or compliance purposes.
ENIN BV (trading as Okyra)
Meersstraat 43, 9000 Gent, Belgium
Company / VAT number: BE0808506381
Privacy contact: privacy@okyra.io