Data processing agreement (DPA)
Last updated: 1 May 2026
This Data Processing Agreement (DPA) supplements the Terms of Service and applies whenever Umbiko B.V. ("processor") processes personal data on behalf of a Customer ("controller") in connection with the Umbiko procurement platform. It implements Article 28 of the EU General Data Protection Regulation (GDPR).
1. Roles
Customer is the data controller for personal data uploaded into or generated within the platform.
Umbiko B.V. is the processor and processes personal data only on documented instructions from Customer.
2. Subject and duration
Subject: processing personal data to provide the Umbiko procurement platform (extraction, comparison, search, AI assistance, support).
Duration: for as long as the underlying subscription is active, plus the retention period stated in the Privacy Policy.
3. Categories of data and data subjects
Data subjects: Customer's employees and authorised users; persons referenced in tender, quotation and supplier documents uploaded by Customer.
Categories: name, business contact information, role, login data; document content as uploaded by Customer.
4. Sub-processors
Customer authorises Umbiko to engage the following sub-processors: Microsoft Azure (hosting + AI services, EU West region), Microsoft Communication Services (transactional email).
Umbiko notifies Customer at least 30 days in advance of any new sub-processor. Customer may object on reasonable grounds, in which case the parties will discuss alternatives in good faith.
5. Security measures
Encryption in transit (TLS 1.2+) and at rest (AES-256). Per-tenant data isolation in dedicated Cosmos containers, blob paths and search indexes.
Role-based access control with least-privilege principles. Audit logging of authentication, status changes and admin overrides. Automated patching and dependency scanning in CI.
6. International transfers
Personal data is stored and processed in Microsoft Azure data centres in the European Union. Data does not leave the EU.
If a transfer to a third country becomes necessary, Umbiko will use the EU Standard Contractual Clauses or another transfer mechanism recognised under GDPR.
7. Data subject requests and breach notification
Umbiko assists Customer with data-subject requests (access, rectification, erasure, portability) within reasonable timeframes.
Umbiko reports a personal-data breach to Customer without undue delay, in any event within 72 hours of becoming aware, with the information required to enable Customer's own GDPR Art. 33/34 obligations.
8. Audit rights
Once per year, Customer may request a written summary of Umbiko's security controls and the latest available third-party audit reports (e.g. SOC 2 once obtained).
On-site audits are limited to reasonable advance notice and confidentiality obligations, and are charged at cost above one audit per twelve months unless triggered by a substantiated security incident.
9. Return and deletion
On termination of the underlying subscription, Customer Content is made available for export for 30 days.
After that period, all Customer Content and personal data are permanently deleted, except where retention is required by mandatory law.
10. Contact
For DPA execution or questions: email hello@umbiko.ai. We provide a counter-signed copy on request, no charge.