Terms of Service Privacy Policy DPA Cookie Policy

Data Processing Agreement

Effective date: 16 September 2026 Version: 1.1a

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service between contenteam OÜ (registry code 16044560, Ahtri tn 12, 10151 Tallinn, Estonia) ("Processor," "we," "us") and the User ("Controller," "you"). It governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the Platform. This DPA is concluded pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR).

1. Definitions

"Controller Personal Data" means personal data that the Controller uploads to, or instructs the Processor to process through, the Platform for the purpose of a task.

"Sub-processor" means any third party engaged by the Processor to process Controller Personal Data.

"Applicable Data Protection Law" means the GDPR and any other data protection laws applicable to the processing.

"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Controller Personal Data.

Terms not defined here have the meaning given in the Terms of Service or in the GDPR.

2. Roles and scope of processing

2.1. The Controller is the data controller of Controller Personal Data. The Processor is the data processor.

2.2. The Processor processes Controller Personal Data only:

  1. on the Controller's documented instructions;
  2. for the purpose of producing and delivering content as described in the Terms of Service;
  3. for no longer than necessary for that purpose.

2.3. The Controller's instructions are set out in:

  1. the Terms of Service and the Help section;
  2. the task brief, editorial policy, and any other instruction submitted through the Platform;
  3. this DPA.

2.4. The Processor will inform the Controller without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law. The Processor may suspend performance of that instruction until it is confirmed or amended by the Controller.

2.5. The duration of processing corresponds to the term of the Terms of Service, unless a shorter period is specified in this DPA or required by law.

3. Categories of data and data subjects

3.1. The categories of Controller Personal Data processed, and the categories of data subjects, are set out in Annex 1.

3.2. The Controller is responsible for ensuring that:

  1. it has a lawful basis for the processing;
  2. its instructions comply with Applicable Data Protection Law;
  3. Controller Personal Data does not include special categories of data (Article 9 GDPR) unless the Controller has obtained a separate written agreement with the Processor and ensured all legal requirements are met.

3.3. The Processor does not process Controller Personal Data for its own purposes, except where required by law.

4. Confidentiality

4.1. The Processor ensures that all personnel authorised to process Controller Personal Data:

  1. are bound by confidentiality obligations, whether contractual or statutory;
  2. receive appropriate training on data protection and security;
  3. only access Controller Personal Data on a strict need-to-know basis.

4.2. Confidentiality obligations survive the termination of the personnel engagement and the term of this DPA.

5. Security measures

5.1. The Processor implements the technical and organisational measures set out in Annex 2. These measures are designed to ensure a level of security appropriate to the risk, taking into account:

  1. the state of the art;
  2. the costs of implementation;
  3. the nature, scope, context, and purposes of processing;
  4. the risk to the rights and freedoms of data subjects.

5.2. The Processor may update the measures in Annex 2 from time to time, provided that the overall level of protection does not decrease.

5.3. The Controller acknowledges that it has evaluated the measures and considers them appropriate for the Controller Personal Data.

6. Sub-processors

6.1. The Controller grants general authorisation for the Processor to engage Sub-processors. A current list is set out in Annex 3.

6.2. The Processor will notify the Controller of any intended addition or replacement of a Sub-processor at least 14 days before the change takes effect. The Controller may object on reasonable data protection grounds. If the Controller objects, the parties will discuss in good faith. If no agreement is reached, the Controller may terminate the affected part of the Terms of Service without penalty.

6.3. The Processor imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA, in accordance with Article 28(4) GDPR.

6.4. The Processor remains liable to the Controller for the performance of each Sub-processor's obligations.

7. International transfers

7.1. Where the Processor transfers Controller Personal Data outside the European Economic Area (EEA), it will ensure that:

  1. the transfer is to a country benefiting from an adequacy decision; or
  2. appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or another lawful transfer mechanism under Chapter V GDPR.

7.2. The Controller may request a copy of the relevant safeguards by contacting legal@contenteam.com.

8. Assistance to the Controller

8.1. The Processor will provide reasonable assistance to the Controller in responding to:

  1. requests from data subjects exercising their rights under Applicable Data Protection Law (access, correction, erasure, restriction, objection, portability);
  2. inquiries or complaints from supervisory authorities or third parties.

8.2. If a request is made directly to the Processor, the Processor will inform the Controller without undue delay, unless prohibited by law.

8.3. The Processor will provide reasonable assistance with:

  1. data protection impact assessments (DPIAs);
  2. prior consultations with supervisory authorities, where required.

8.4. Assistance under this Section is provided at the Controller's cost where it requires substantial resources beyond routine support.

9. Security incidents

9.1. The Processor will notify the Controller of a Security Incident affecting Controller Personal Data without undue delay and in any event within 72 hours of becoming aware of it.

9.2. The notification will include, to the extent available:

  1. a description of the nature of the incident;
  2. the categories and approximate number of data subjects and records affected;
  3. the likely consequences;
  4. the measures taken or proposed to address the incident and mitigate its effects;
  5. contact details for further information.

9.3. The Processor will take reasonable steps to contain, investigate, and remediate the incident and will cooperate with the Controller's reasonable requests.

9.4. Notification does not constitute an admission of fault or liability.

10. Deletion and return of data

10.1. Upon termination of the Terms of Service, or upon the Controller's written request, the Processor will:

  1. delete Controller Personal Data; or
  2. return it to the Controller in a structured, commonly used, machine-readable format;
  3. and delete existing copies, unless retention is required by law.

10.2. The Controller may choose between deletion and return. If the Controller does not specify, the Processor will delete the data within 90 days of termination.

10.3. The Processor may retain Controller Personal Data where required by law, and will in that case limit processing to the purpose required by law and inform the Controller.

11. AI and automated processing

11.1. In AI-assisted working modes, Controller Personal Data may be transmitted to Sub-processors listed in Annex 3 for the sole purpose of providing services to the Controller.

11.2. The Processor does not train, fine-tune, or otherwise develop any AI model on Controller Personal Data, does not process that data for any purpose other than providing the services, and does not knowingly transfer it to anyone for training, model development, or similar use. Where an AI Sub-processor offers a setting or a mode that excludes submitted data from training or shortens its retention, the Processor makes reasonable efforts to use it.

11.2.1. The Controller acknowledges that the set of AI Sub-processors changes over time, that their own terms differ, and that the processing carried out by an AI Sub-processor within its own systems — its purposes, onward transfers, retention periods, the marking of outputs, and any use for that Sub-processor's own model development — cannot be verified by the Processor. The Processor uses reasonable efforts to prevent such use but does not warrant the outcome. For the avoidance of doubt, this acknowledgement does not affect the Processor's liability under Sections 6.4 and 12.2, which applies as required by Article 28(4) GDPR.

11.2.2. Where the Controller does not wish Controller Personal Data to be transmitted to AI Sub-processors, the Controller selects the Fully manual working mode for the relevant task.

11.3. The Processor does not make decisions about data subjects based solely on automated processing that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR.

12. Liability

12.1. Each party is liable for damages caused by processing that infringes Applicable Data Protection Law, in accordance with Article 82 GDPR.

12.2. The Processor is liable for the acts and omissions of its Sub-processors to the same extent as if it had performed the processing itself.

12.3. Nothing in this DPA limits or excludes liability for:

  1. intentional misconduct;
  2. gross negligence;
  3. any liability that cannot be limited or excluded under applicable law.

12.4. The limitation of liability in the Terms of Service applies to claims under this DPA, except where such limitation is prohibited by mandatory law.

13. Term

13.1. This DPA takes effect on the date the Controller accepts the Terms of Service and continues until:

  1. the termination of the Terms of Service; or
  2. the Processor ceases to process Controller Personal Data; whichever is later.

13.2. Provisions that by their nature should survive termination (confidentiality, liability, deletion and return) survive.

14. Governing law

14.1. This DPA is governed by the law of the Republic of Estonia.

14.2. Disputes are resolved in accordance with Section 17 of the Terms of Service.

Annex 1 — Categories of personal data and data subjects

Categories of personal data:

  1. identification data (name, email address, username);
  2. contact data (company name, address, phone number) where provided;
  3. task-related data (briefs, queries, editorial policies, reference materials);
  4. communication data (messages, comments, support requests);
  5. payment-related data (payment details, transaction identifiers);
  6. technical data (IP address, log data, device information).

Categories of data subjects:

  1. the Controller's personnel and representatives;
  2. the Controller's clients and end customers, where their data appears in briefs or task materials;
  3. authors, editors, and proofreaders engaged by the Processor.

Annex 2 — Technical and organisational measures

Encryption

  • Data in transit: TLS 1.2 or higher.
  • Data at rest: AES-256 on production systems.

Access control

  • Role-based access with least-privilege principle.
  • Multi-factor authentication for administrative access.
  • Logging and monitoring of access to production systems.

Personnel

  • Confidentiality obligations for all personnel.
  • Data protection and security training.
  • Background checks where legally permissible.

Incident response

  • Documented incident response procedures.
  • Notification to Controller within 72 hours of becoming aware of a Security Incident.

Data minimisation

  • Access to Controller Personal Data limited to personnel who need it to perform the task.
  • No use of production data in non-production environments.

Physical security

  • Production systems hosted in data centres with physical access controls.

Annex 3 — Sub-processors

The table below lists the categories of Sub-processors and the providers engaged within each category. A provider is engaged only where the corresponding function is used for the Controller's task: in the Fully manual working mode no AI provider receives Controller Personal Data at all, and a check or a model that is not selected for the task receives nothing. Listing a provider here therefore means that it may be engaged, not that every task passes through it.

Category and purpose Providers
Hosting, cloud infrastructure, database and file storage Hetzner (data centre in Switzerland)
AI text generation and editing (AI-assisted modes only; a given model is engaged only where it is selected for the task) Anthropic, OpenAI, xAI, Moonshot AI
Machine translation DeepL
Plagiarism and AI-detection checks of the produced text (each engaged only where that check is selected for the task) Copyscape, Copyleaks, Originality.AI, Winston AI, Pangram, ZeroGPT, Duplichecker, Text.ru, Smodin, Grammarly
Text humanisation (where selected for the task) GPTHuman, HumanizeAI Pro, WriteHuman, Smodin
Research and market data for the brief (search results, competitor and keyword data, page retrieval) Apify, DataForSEO, Ahrefs
Email delivery Google (Workspace SMTP relay)
Delivery of the finished text as a Google Doc (only where the Controller requests it) Google (Docs, Drive)
Payment processing for balance top-ups OxaPay
Messaging and notifications (only where the Controller connects the channel) Telegram
Web analytics and tag management Google (Tag Manager)

Controller Personal Data is stored on infrastructure located in Switzerland, a country recognised by the European Commission as providing an adequate level of data protection.

Some of the other Sub-processors listed above are established outside the European Economic Area. Where Controller Personal Data is transferred to them, the transfer relies on a mechanism set out in Section 7 of this DPA. The Controller may request the current list of Sub-processors, together with their place of establishment and the transfer mechanism applied to each, at any time by contacting legal@contenteam.com.

iGamingTextLab.com Terms of Service Privacy Policy DPA Cookie Policy Cookie settings
We use cookies for analytics. Cookies · Details