Our DPA, in plain language
Every InVerba client signs a Data Processing Agreement before any document is uploaded - including pilots. This page summarises what the standard DPA contains, so your legal and compliance teams can review the substance before a sales call. The signed DPA is the binding document; request the full text at office@inverba.app.
Roles and legal basis
You (the client) are the data controller; Inverba d.o.o. is the data processor. The DPA is drafted to satisfy Article 28 of the GDPR and the Serbian Law on Personal Data Protection (ZZPL), and it applies to all personal data contained in the documents you upload.
We process your documents solely to provide the contracted service - indexing, retrieval, and answering your team's queries. No other purpose, and never for training AI models.
Where your data lives
- All customer data is stored and processed in AWS eu-central-1 (Frankfurt, Germany)
- Each client's documents and vector index are stored in isolated, per-client storage
- Encryption at rest uses AES-256 with a dedicated AWS KMS key per client; TLS protects data in transit
- Enterprise clients may instead run InVerba entirely inside their own AWS account
Subprocessors
The standard DPA lists our subprocessors and commits us to notifying you before adding or replacing one, with a right to object:
- Amazon Web Services EMEA SARL - cloud infrastructure hosting and AI model inference, region eu-central-1 (Frankfurt). Model inference runs within AWS in-region; your documents are not sent to third-party AI providers outside this infrastructure.
Technical and organisational measures
- AES-256 encryption at rest, TLS 1.2+ in transit, per-client KMS keys
- Role-based access control - you decide which team members can query which document collections
- Full audit trail of every query: user, question, retrieved documents, timestamp - exportable for your compliance reviews
- Inverba staff do not access document content except under an explicit, written support authorisation from you
Incidents, rights, and deletion
- Breach notification: we notify you without undue delay, and at the latest within 72 hours of becoming aware of a personal data breach affecting your data
- Data subject rights: we assist you in fulfilling access, rectification, and erasure requests, including erasure of individual documents from the index
- End of contract: your data is available for export for 30 days after termination, then permanently deleted - consistent with our Terms of Service
- Audit: you may request documentation demonstrating compliance, and audits as provided by Article 28(3)(h) GDPR
Want the full text?
We share the complete DPA with prospective clients before any commitment - your DPO or outside counsel can review it first.