Version 1.0 — 2 September 2026. This agreement forms an integral part of the service agreement (terms and conditions) and is accepted in-app when the account is activated. A signed copy is provided on request.
1. Parties and roles
- Controller: the customer company that contracts the platform.
- Processor: AIRON TEAM SL, registered office at Plaza Mayor 23, 1.º A, 47001 Valladolid, España, tax ID En trámite de asignación (sociedad de reciente constitución), email privacidad@airon.team.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the AIRON platform, which entails automated processing of the personal data held in the systems the Customer connects (email, invoicing, CRM, marketing accounts, document storage and messaging channels) and in its interactions with the platform. Duration: for as long as the main agreement is in force, plus the transition period in clause 12 and the applicable retention periods. Nature: collection, recording, organisation, storage, consultation, retrieval, comparison, interconnection, transmission to sub-processors, generation of derived content through language models, and erasure. Purpose: solely to provide the contracted service and the features the Customer activates.
3. Categories of data and data subjects
Identification and contact data, commercial and billing data, email content and attachments, CRM data, aggregated marketing data, voice audio and transcripts, and usage metadata, relating to the Customer’s staff, customers, suppliers and contacts. The service is not intended for the processing of special categories of data (Art. 9 GDPR), although these may appear incidentally within synchronised email content: a circumstance the Controller must weigh in its own risk assessment.
4. Documented instructions — Art. 28.3(a)
The Processor processes the data solely on documented instructions from the Controller. The following constitute documented instructions: this agreement, the main agreement, the configuration the Customer sets in the platform (connectors enabled, agents allowed, approval policies, document scope per department) and written instructions sent to privacidad@airon.team. If an instruction appears to infringe applicable law, the Processor will say so without delay and may suspend its execution.
5. Confidentiality — Art. 28.3(b)
Persons authorised to process the data are bound to confidentiality, contractually or by statute, and that duty survives the end of the relationship.
6. Security measures — Art. 28.3(c) and Art. 32
The technical and organisational measures described in security measures apply; that page explicitly separates what is verified today from what is planned. The measures are reviewed at least annually and after any material incident.
7. Sub-processors — Art. 28.3(d) and 28.2
The Controller grants general authorisation. The current list is published at sub-processor list. Every addition or replacement is notified 30 calendar days in advance; the Controller may object with reasons within that period and, if the objection is well founded and no reasonable alternative exists, terminate the affected service without penalty. The Processor contractually imposes the same obligations on each sub-processor and remains liable for their performance.
8. Assistance with data subject rights — Art. 28.3(e) and (f)
- If a data subject approaches the Processor directly, the Processor will not answer on the merits and will forward the request to the Controller within a maximum of 3 working days.
- The Processor answers the Controller’s assistance requests within a maximum of 10 working days, which leaves the Controller room to meet the one-month deadline of Art. 12.3 GDPR.
- The Processor also assists the Controller with Arts. 32 to 36 GDPR: security, breach notification, impact assessment and prior consultation.
9. Personal data breaches — Art. 33
The Processor notifies the Controller without undue delay, aiming not to exceed 48 hours from becoming aware, stating the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken and a point of contact. Where the information is not fully available it is provided in phases. The Processor does not notify the supervisory authority on the Controller’s behalf unless so instructed in writing.
10. International transfers and processing location — Chapter V
The main processing takes place in Frankfurt am Main (Germany, EU). Transfers to third countries rely on the EU-US Data Privacy Framework where the importer is certified and active, or on the Standard Contractual Clauses of Decision (EU) 2021/914, Module 3, with a transfer impact assessment and supplementary measures. The per-provider detail is at sub-processor list. Where this agreement conflicts with the standard clauses, the latter prevail.
11. Processing by means of artificial intelligence
- The platform invokes third-party language models to generate replies, drafts and classifications.
- No training on Customer data, whether for our own or third-party models; the exclusion from training is contracted with the inference provider.
- Human review of outbound messages: no outbound communication to a third party is sent automatically. This is a contractual guarantee, not merely a product feature.
- No decisions within the meaning of Art. 22 GDPR are taken.
- Regulation (EU) 2024/1689: AIRON is the provider of the AI system and maintains a record of transparency notices and the marking of generated content (Art. 50). The Customer, as deployer, assumes the obligations the Regulation places on it, including the AI literacy duty of Art. 4.
- Generative models can produce inaccurate content: human verification remains necessary.
12. Switching providers — Regulation (EU) 2023/2854 (Data Act)
- Termination notice: a maximum of 2 months.
- Transition period: 30 calendar days with the service fully operational, extendable once with written justification.
- Format: open, structured, commonly used and machine-readable; the register of exportable data is published at portability and switching providers.
- Fees: AIRON charges no switching fee at all, ahead of the prohibition that applies from 12 January 2027.
- Third-country authority access (Art. 32): we check the legal basis, inform the Customer unless legally prohibited, provide only the permitted minimum, and record the request and the response.
13. Deletion or return at the end — Art. 28.3(g)
At the Controller’s choice, communicated in writing before the end of the transition period, the Processor deletes or returns the data and deletes existing copies. Deletion is executed in a coordinated way across the relational database, the vector store and the cache. Encrypted backups are retained for 30 days: deleted data disappears from the backups by rotation within that period, without selective deletion inside a backup. A certificate of destruction is issued on request within 15 days of execution.
14. Information and audits — Art. 28.3(h)
The Processor makes available the information needed to demonstrate compliance and allows audits and inspections, with a minimum of 30 days’ notice (5 working days after a breach affecting the Controller), one ordinary audit per 12-month period, a confidentiality undertaking from the auditor and no access to other customers’ data. AIRON holds no ISO 27001 or SOC 2 certification: the route is a direct audit.
15. Liability, governing law and versions
Each party is liable for damage caused by processing that infringes applicable law, under Art. 82 GDPR. This agreement is governed by Spanish law and by the law of the European Union. For Colombian customers, the Personal Data Processing Policy (Colombia) and the corresponding international transmission contract apply in parallel.
Every amendment to this agreement is numbered and notified to the Customer 30 days in advance. Operational context is in the platform privacy policy. To request a signed copy: privacidad@airon.team or info@airon.team.