Skip to content
Ajenzo
ProductHow it worksSourcesPrivacyPricing
Launching November 1Log inGet started
ProductHow it worksSourcesPrivacyPricingLog in
Get startedLaunching November 1
Home/Data processing agreement

Data processing agreement

Last updated 9 October 2026

This data processing agreement ("DPA") applies when an organisation uses Ajenzo and forms part of our terms of service. It meets the requirements of article 28 of the GDPR. It is accepted by creating an account for the organisation or buying a plan; a signed copy is available on request.

1. Parties and roles

The customer ("Controller") is the organisation that uses Ajenzo. The processor ("Processor") is: Ajenzo is a trade name of matan works, registered with the Dutch Chamber of Commerce (KvK) under number 98277952, VAT number NL005321442B69, Nassaulaan 6, 1182 BA Amstelveen, the Netherlands. Email: info@ajenzo.com.

The Controller determines the purposes and means of processing personal data in its content. The Processor processes that data only to provide Ajenzo to the Controller and its users.

2. Subject, nature and purpose

Transcribing, storing, searching and analysing conversations, documents and connected sources chosen by the Controller's users, to show relevant answers and suggestions during and after conversations, and related hosting, support and security.

3. Types of personal data and data subjects

  • Data subjects: the Controller's users; participants in conversations transcribed by users, such as customers, prospects, candidates and colleagues; people mentioned in uploaded documents or connected sources.
  • Personal data: names, contact details, job titles and organisations, statements made in conversations, content of documents, emails, calendar items and records in connected sources, and metadata such as timestamps.
  • Special categories: not intended. The Controller does not use Ajenzo for special categories of personal data or criminal data unless it has a legal basis and has agreed additional measures with the Processor in writing.

4. Duration

This DPA applies for as long as the Processor processes personal data for the Controller, and ends automatically when the agreement on the Service ends and the data has been deleted.

5. Instructions

The Processor processes personal data only on documented instructions of the Controller. The terms, this DPA and the use and settings of the Service by the Controller's users are the Controller's instructions. The Processor informs the Controller if it believes an instruction infringes the GDPR. If the law requires other processing, the Processor informs the Controller first, unless the law prohibits this.

6. Confidentiality

The Processor ensures that persons authorised to process the personal data are bound by confidentiality and have access only where needed.

7. Security

The Processor takes appropriate technical and organisational measures, including at least:

  • hosting of the application and database in the EU;
  • encryption in transit (TLS) and encryption of stored access tokens and credentials (AES-256-GCM);
  • password hashing (Argon2id), hashed session tokens, CSRF protection and rate limiting;
  • logical separation of customer data and strict access control on the Processor's side;
  • speech recognition on the user's own device, so that audio is not sent to the cloud;
  • regular software updates and monitoring of the Service.

The Processor may improve these measures, provided the level of protection does not decrease.

8. Sub-processors

The Controller gives general authorisation for the sub-processors on our sub-processors page. The Processor informs the Controller by email at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected part of the Service and receives a refund of prepaid fees for the remaining period. The Processor imposes data protection obligations on sub-processors that are no less protective than this DPA and remains responsible for them.

9. International transfers

Transfers to countries outside the European Economic Area take place only with appropriate safeguards under chapter V of the GDPR, such as an adequacy decision including the EU-U.S. Data Privacy Framework, or standard contractual clauses.

10. Assistance

The Processor assists the Controller, taking into account the nature of the processing, with responding to requests from data subjects, with data protection impact assessments and prior consultation, and with security obligations. Users can delete documents, memory items, connections and accounts themselves; other requests can be sent to info@ajenzo.com. The Processor forwards requests it receives directly from data subjects to the Controller without delay.

11. Personal data breaches

The Processor notifies the Controller without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting the Controller's data, with the information available at that time, and keeps the Controller informed. The Processor takes reasonable measures to limit the consequences. The Controller decides on notification to the supervisory authority and data subjects.

12. Deletion and return

At the end of the Service, or earlier at the Controller's request, the Processor deletes the personal data, unless the law requires storage. On request made before deletion, the Processor provides an export of the Controller's content in a common format. Any backups are overwritten in their normal cycle.

13. Audits

The Processor makes available the information necessary to demonstrate compliance with this DPA. The Controller may have an audit performed by an independent auditor bound by confidentiality, at most once a year, with at least 30 days' notice and at the Controller's expense, unless the audit reveals a material breach by the Processor.

14. Liability

The limitations of liability in the terms of service apply to this DPA, to the extent permitted by law.

15. Precedence

In case of conflict on the processing of personal data, this DPA prevails over the terms of service. Dutch law applies; disputes are submitted to the competent court in Amsterdam.

Ajenzo

Your knowledge. In the conversation.

ExploreProductHow it worksSourcesPrivacyPricing
AccountCreate an accountLog inTeam pilot
LegalTerms of servicePrivacy policyData processingSub-processors
© 2026 Ajenzo · a trade name of matan works · KvK 98277952 · VAT NL005321442B69The right answer, right when you need it.