🔒 Official APIs only. Your session is never automated, your feed never scraped.
● Legal

Data Processing Agreement.

The Art. 28 GDPR terms under which Nextarp B.V. processes your workspace's data. Plain, short, and published — not available-on-request.

Data Processing Agreement

This DPA forms part of the Avatorial Terms of Service for business customers and applies where Nextarp B.V. processes personal data on your behalf under Art. 28 GDPR. Version 1.0 — 27 July 2026.

1 · Roles

You (the customer workspace) are the controller of the personal data in your workspace — your team’s writing corpus, drafts, connected-account identifiers and imported connection names. Nextarp B.V. (Wilhelminaplein 1, 3072 DE Rotterdam, the Netherlands, “Avatorial”) is the processor.

2 · Subject matter, duration, nature and purpose

Processing is limited to providing the Avatorial service as described in the Terms: learning each user’s writing style from content they provide, generating drafts, holding them for explicit human approval, and publishing approved content to platforms the user connected — for the duration of the subscription plus the deletion window below.

3 · Instructions

Avatorial processes personal data only on documented instructions from the controller — the configuration and actions taken in the product are those instructions. Avatorial never publishes content without an explicit per-post approval by an authorised user; this is enforced in the application’s database schema and code, not policy.

4 · Confidentiality and security (Art. 32)

Measures include: EU-region hosting (Google Cloud europe-west1); platform tokens stored exclusively in Google Secret Manager, never in the database; TLS in transit and encryption at rest; tenant isolation enforced by a database access layer that scopes every query to the workspace; role-based access with no role that grants control over another person’s personal account; audit logging of approvals, publishes, role changes and connections; staff access on a need-to-know basis only.

5 · Sub-processors

The controller grants general authorisation for the sub-processors listed at avatorial.com/subprocessors. Avatorial gives at least 30 days’ notice of additions or replacements, during which the controller may object on reasonable data-protection grounds.

6 · Data subject rights

Avatorial assists the controller with access, rectification, erasure and portability requests. Workspace owners can self-serve full erasure (Billing → Delete workspace), which permanently removes all content, voice profiles, member records and destroys stored platform tokens; residual backups expire within 30 days.

7 · Personal data breach

Avatorial notifies the controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting their workspace, with the information required by Art. 33(3) GDPR as it becomes available.

8 · International transfers

Primary processing stays in the EU. Where a sub-processor processes data outside the EEA (see the register), transfers rely on the European Commission’s Standard Contractual Clauses and supplementary measures.

9 · AI processing

Draft generation and embeddings run on Google Vertex AI in the EU region under Google Cloud’s DPA. Customer content is not used by Avatorial or its sub-processors to train foundation models. Each user’s voice profile is built only from content that user provided; Avatorial does not offer imitation of third parties.

10 · Deletion and return

On termination, workspace data is deleted within 30 days. During the subscription, the controller can export their content at any time and delete the workspace at any time.

11 · Audit

Avatorial makes available the information reasonably necessary to demonstrate compliance with Art. 28, and allows for audits — normally satisfied by documentation and third-party attestations of its infrastructure providers.

To execute this DPA counter-signed for your organisation, or to ask questions about it, contact privacy@avatorial.com.