← Home

Data Processing Agreement

This agreement applies when Creduna processes personal data on behalf of a client while providing its services. The client is the controller and Krzysztof Kwiatkowski K2, Zecerska 23/1, 51-180 Wrocław, Poland, tax ID (NIP) 6912440973, a sole proprietorship entered in the Polish Central Register and Information on Economic Activity (CEIDG) is the processor. It forms part of the Terms of Service and takes effect when the client starts using a service that involves such processing.

1. Subject matter and duration

The processor processes personal data only to provide the services described in the Terms of Service: analysing cost and usage data, preparing reports and recommendations, and preparing draft credit applications. Processing lasts for as long as the services are provided.

2. Nature of processing, data and data subjects

  • Nature: reading, analysing, storing reports, and deleting.
  • Types of data: identifiers of IAM users and roles that appear in billing and usage data; names and business contact details of the client’s staff; any personal data contained in material the client chooses to provide, such as request samples.
  • Data subjects: the client’s employees and contractors, and other persons whose data the client includes in the material it provides.

The services are not designed to process special categories of data, and the client does not provide such data.

3. Obligations of the processor

  • Processes personal data only on the documented instructions of the controller, including these terms, unless required to do otherwise by law.
  • Ensures that persons authorised to process the data are bound by confidentiality.
  • Applies the technical and organisational measures listed in section 7.
  • Assists the controller, as far as possible, in responding to requests from data subjects and in meeting its obligations under Articles 32 to 36 GDPR.
  • Informs the controller if, in its opinion, an instruction infringes data protection law.

4. Sub-processors

The controller gives general authorisation to use sub-processors. The current sub-processors are:

  • Hetzner Online GmbH (Germany), servers in Helsinki, Finland: hosting of the application and database.
  • Amazon Web Services: running Claude models through Amazon Bedrock.
  • Anthropic: running Claude models through its API.
  • Google: spreadsheet copy of application data, where enabled.

The processor informs the controller of intended changes at least 14 days in advance, and the controller may object on reasonable grounds. The processor imposes equivalent data protection obligations on each sub-processor and remains responsible for their performance.

5. Transfers outside the European Economic Area

Where a sub-processor processes data outside the European Economic Area, the transfer relies on an adequacy decision or on the standard contractual clauses adopted by the European Commission.

6. Personal data breaches

The processor notifies the controller of a personal data breach without undue delay and no later than 48 hours after becoming aware of it, with the information available about its nature, likely consequences and the measures taken.

7. Security measures

  • Access to the client’s AWS account only through a read-only role with a unique external identifier, which the client can delete at any time.
  • No access to prompts, model outputs or application data in the client’s account.
  • Encrypted connections to the website and internal panel.
  • Database reachable only from the application’s internal network; internal panel protected by authentication.
  • Request content pasted into analysis tools is processed in memory and not stored.
  • Access to data limited to persons who need it to provide the service.

8. Audits

The processor makes available the information needed to demonstrate compliance with this agreement and allows audits by the controller or an auditor it appoints, on at least 14 days’ notice, during business hours, no more than once a year unless a breach has occurred, and subject to confidentiality.

9. End of processing

After the services end, the processor deletes the personal data within 30 days, or returns it if the controller asks, unless the law requires it to be kept longer. The client can also end access at any time by deleting the access role.

10. Liability and final provisions

The limits of liability in the Terms of Service apply to this agreement to the extent permitted by law. In case of conflict in matters of data protection, this agreement prevails over the Terms of Service. It is governed by Polish law.