Data Processing Agreement (GDPR Art. 28)

Last updated: June 6, 2026

Parties & Roles

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer and Patentopia and governs the processing of personal data under Article 28 of the EU General Data Protection Regulation (GDPR).

Patentopia.AI ApS acts as the data controller for the personal data processed through the platform. Seven Consult ApS, operating the Patentopia platform, acts as the data processor and processes personal data solely on the documented instructions of the controller.

Subject-Matter

The subject-matter of the processing is the provision of AI-powered patent intelligence services — prior art searches, patentability assessments, and the generation of analysis reports — through the Patentopia platform.

Duration

The processor processes personal data for the duration of the agreement between the parties. Upon termination, personal data is deleted or returned in accordance with the Data Deletion section below, unless storage is required by Union or Member State law.

Nature & Purpose of Processing

Personal data is processed for the sole purpose of operating and improving the Patentopia service: authenticating users, running patent claims through AI models and external prior art sources, generating assessment reports, processing payments, and delivering transactional communications. The processor does not use personal data for any purpose other than performing its obligations under the agreement.

Types of Personal Data

  • Account information— email addresses used for authentication and communication.
  • Submitted content— patent claims and analysis inputs, which may incidentally contain personal data (e.g. inventor names).
  • Billing data— payment metadata processed through our payment provider.
  • Usage & audit data— interaction analytics and audit-log records of privileged actions.

The categories of data subjects are the customer’s authorized users and any individuals referenced within submitted content.

Controller Obligations

The controller is responsible for ensuring it has a lawful basis for the processing, that its instructions to the processor comply with GDPR, and that data subjects have been provided with appropriate notice. The controller warrants that it is entitled to transfer personal data to the processor for processing as described in this DPA.

Processor Obligations

The processor shall: process personal data only on the documented instructions of the controller; ensure persons authorized to process the data are bound by confidentiality; implement appropriate technical and organizational security measures; assist the controller in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations; make available the information necessary to demonstrate compliance; and notify the controller without undue delay of any personal-data breach.

Sub-Processors

The controller authorizes the processor to engage the following sub-processors, each bound by data-protection obligations no less protective than those in this DPA:

  • Supabase — authentication and database hosting.
  • Stripe — payment processing.
  • OpenRouter — AI model inference for patent analysis.
  • Resend — transactional email delivery.
  • Brightdata — proxied prior art search retrieval.

The processor will inform the controller of any intended changes concerning the addition or replacement of sub-processors, giving the controller the opportunity to object.

Security Measures

Taking into account the state of the art and the nature of the processing, the processor implements appropriate technical and organizational measures, including:

  • Encryption — data encrypted in transit (TLS) and at rest (Supabase / PostgreSQL).
  • Access control — row-level security (RLS) policies and session-scoped tokens restrict each user to their own records.
  • Audit logging — privileged actions, such as assessment approvals and amendments, are recorded in an append-only audit log.
  • Session-scoped deletion / TTL — anonymous case data is automatically deleted after 24 hours.

Data Deletion

Anonymous case data submitted without an account is automatically deleted after 24 hours. Upon termination of the agreement, or at the controller’s written request, the processor will delete or return all personal data and delete existing copies, unless retention is required by Union or Member State law. Data subjects may exercise their rights of access, correction, and erasure as described in our Privacy Policy.

Contact

Questions about this DPA or our data-processing practices? Reach us at info@patentopia.ai.