Data processing agreement (DPA)
Updated 29 September 2026
Draft pending legal review. Items marked [COMPLETAR: …] must be filled in before publication.
This is a translation. In case of discrepancy, the Spanish version prevails.
1. Parties
1.1. Controller: the customer who accepts the Constaia Terms of service or signs an Enterprise contract ("Controller").
1.2. Processor: Add On Dev Solutions S.L., tax ID B22654610, with registered office at Calle Espronceda, nº 2, planta 1, puerta C, 21001 Huelva (Huelva), Spain, registered in the Commercial Registry of Huelva (Registro Mercantil de Huelva), sheet H-00029947, electronic folio (IRUS) 1000453930356, which provides the Constaia service ("Processor").
1.3. This agreement forms part of the Terms of service and is accepted together with them. If the Controller needs a signed version, it may request one at contacto@addon-sport.com.
2. Subject matter
The Processor processes personal data on behalf of the Controller to provide the Constaia service: receiving documents, recognising their text (OCR), classifying them, extracting fields, applying checks, issuing a verdict and, if the Controller so requests, generating exports and sending webhook notifications to the URLs configured by the Controller.
3. Duration
For as long as the Controller uses the service. Section 13 applies on termination.
4. Nature and purpose
4.1. Nature: receipt, temporary or persistent storage according to instructions, text recognition, analysis with AI models, extraction, validation, consultation, export, disclosure to the Controller and erasure.
4.2. Purpose: the one determined by the Controller (for example, checking the documentation for a registration or a sports licence). The Processor does not process the data for its own purposes.
5. Types of data and categories of data subjects
5.1. Types of data, depending on the documents sent by the Controller:
- Identification and contact data: first name, surnames, document number, date and place of birth, sex, nationality, address, signature, photograph printed on the document.
- Identity and residence documents (Spanish DNI, NIE/TIE, passports, EU identity cards, driving licences).
- Financial data: IBAN, amounts, payment references, invoices.
- Academic and professional data: qualifications, sports licences, registration number of the signing doctor.
- Special categories (Art. 9 GDPR): health data contained in medical or disability certificates.
- Data relating to criminal convictions and offences (Art. 10 GDPR): sexual offences certificates and criminal record certificates.
5.2. The Controller must send only the necessary documents and, where possible, request only the essential fields (for example, fitness, date and doctor's registration number on a medical certificate, without diagnoses).
5.3. Categories of data subjects: the people whose data appear in the documents (for example, athletes, members, students, employees, customers, suppliers, minors represented by their guardians, doctors or signatories).
6. Documented instructions
6.1. The Processor processes data only on documented instructions from the Controller. The Controller's instructions include:
- the options of each API request:
storage(none,temporaryorpersistent),ttl_hours,keep_results,extract,checks,exportandmetadata; - deletion requests (
DELETE /v1/analyses/{id}); - account settings (default retention, webhooks, members).
6.2. Effect of the retention options:
storage: "none"(default): the file is deleted as soon as the analysis ends.storage: "temporary": the file is deleted afterttl_hourshours (1 to 720; 24 by default).storage: "persistent": the file is kept until the Controller deletes it.keep_results: false: extracted fields are not stored either; only the data needed for billing is kept.
6.3. If the Processor considers that an instruction infringes data protection law, it will inform the Controller immediately.
6.4. If EU or Member State law requires the Processor to process the data otherwise, it will inform the Controller before processing, unless the law prohibits it.
7. Confidentiality
The Processor ensures that persons authorised to process the data have committed to confidentiality or are under a statutory obligation of confidentiality, and that they access the data only when necessary to provide the service, give support at the Controller's request or resolve incidents.
8. Security measures (Art. 32 GDPR)
- Hosting and processing in the European Union.
- Encryption in transit with TLS.
- Application-level encryption of files at rest with AES-256-GCM and a separate key per account.
- API keys and passwords stored only as hashes; API keys can be revoked.
- Role-based access control in the dashboard and need-to-know internal access.
- Audit log of actions (who, IP, action and changes).
- Automatic deletion of files according to the
storageoption. - Signed, expiring export URLs.
[COMPLETAR: backups (encryption, location and rotation period), vulnerability management, continuity plan]
Constaia does not use documents or results to train models.
9. Sub-processors
9.1. The Controller gives the Processor general authorisation to engage sub-processors. The current ones are:
| Sub-processor | Service | Data location | Data processed |
|---|---|---|---|
| Hetzner Online GmbH | Infrastructure, databases and object storage | Germany (EU) | Documents, results and account data |
| Mistral AI | Text recognition (OCR) | France (EU) | Documents |
| Amazon Web Services EMEA SARL | AI models for classification and extraction (Amazon Bedrock, eu-central-1 region, Frankfurt, no cross-region inference) | Germany (EU) | Document images and text |
| Stripe Payments Europe Ltd. | Payments | Ireland (EU) | Only the Controller's billing data; receives no documents |
[COMPLETAR: confirm with Mistral AI the contracted plan and its data retention terms (zero retention)]
9.2. The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those in this agreement and remains liable to the Controller for their compliance.
9.3. Changes. The Processor will give at least 30 days' notice of any addition or replacement of sub-processors, by email to the account address and on this page. The Controller may object on reasonable data protection grounds within that period. If no solution is reached, the Controller may stop using the service and close its account before the change takes effect. [COMPLETAR: confirm financial consequences of objection (e.g. pro rata refund of unused credits)]
10. International transfers
Documents and results are processed in the EU. The Processor will not transfer that data outside the European Economic Area without the Controller's instruction and without the safeguards of Chapter V GDPR.
11. Assistance to the Controller
11.1. Data subject rights. The Processor will help the Controller respond to requests for access, rectification, erasure, objection, restriction and portability. The API allows analyses to be retrieved (GET /v1/analyses/{id}) and deleted (DELETE /v1/analyses/{id}). If a data subject contacts the Processor directly, it will forward the request to the Controller without delay and will not answer it on its own.
11.2. Impact assessments and prior consultations. The Processor will provide the available information on the processing and security measures so that the Controller can carry out impact assessments (Art. 35 GDPR) and, where applicable, prior consultations with the supervisory authority (Art. 36 GDPR).
12. Personal data breaches
12.1. The Processor will notify the Controller, without undue delay and within 48 hours at the latest of becoming aware of it, of any security breach affecting its data. [COMPLETAR: confirm deadline]
12.2. The notification will include, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed and a contact point. Information not yet available will be provided in phases.
12.3. It is for the Controller to notify, where applicable, the supervisory authority and data subjects.
13. End of processing
On termination of the service, the Processor will delete the Controller's documents and results within [COMPLETAR: 30 days], unless the Controller first requests their return (for example, through the API exports) or a legal provision requires them to be kept. Backups will be removed in their ordinary rotation cycle [COMPLETAR: period]. Only the billing data needed to meet legal obligations will be kept, blocked.
14. Audits
The Processor will make available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR and will allow audits, including inspections, by the Controller or an auditor mandated by it and bound by confidentiality, with reasonable notice of [COMPLETAR: 30 days], during business hours and without harming other customers. [COMPLETAR: allocation of audit costs and maximum frequency]
15. Artificial intelligence
15.1. Constaia does not perform biometric identification or verification, does not compare faces and does not process the document photograph for biometric purposes.
15.2. Results are automated indications. The Controller is responsible for ensuring human oversight where required by law (in particular Art. 22 GDPR) and for meeting its obligations as a deployer of an AI system.
16. Controller's obligations
The Controller warrants that it has a legal basis for the processing (and, for data under Arts. 9 and 10 GDPR, the corresponding authorisation), that it has informed data subjects and that its instructions comply with the law.
17. Governing law
This agreement is governed by Spanish law and the GDPR. The jurisdiction agreed in the Terms of service applies to disputes.
18. Signature
For the signed version of this agreement:
| Controller | Processor | |
|---|---|---|
| Entity | [COMPLETAR: customer company name] | Add On Dev Solutions S.L. |
| Tax ID | [COMPLETAR: customer tax ID] | B22654610 |
| Signatory and position | [COMPLETAR] | [COMPLETAR: representative's name and position] |
| Date | [COMPLETAR] | [COMPLETAR] |