Data Processing Agreement

Data processing

DPA for Rumbleo customers

Public summary of Rumbleo's DPA for European customers. It is a review base and should be formalized contractually where applicable

Last updated: May 4, 2026

This text is a public DPA base and is not legal advice. The binding DPA must be signed or incorporated into the agreement with the customer organization

Data Processing Agreement

Data Processing Agreement

Document last updated: May 4, 2026

Public summary of Rumbleo's DPA for European customers. It is a review base and should be formalized contractually where applicable

This text is a public DPA base and is not legal advice. The binding DPA must be signed or incorporated into the agreement with the customer organization

01

1. Parties and roles

1.1The customer organization normally acts as controller for personal data it decides to upload, connect, query, or generate through Rumbleo

1.2SALATECH CONSULTING SL normally acts as processor when it processes that data on behalf of the customer organization to provide Rumbleo

1.3When SALATECH processes its own commercial contact, billing, support, corporate security, or contractual relationship data, it may act as an independent controller under the privacy policy

02

2. Subject matter

  1. 2.1Provide a conversational BI platform with specialized agents
  2. 2.2Enable authentication, user management, roles, and permissions
  3. 2.3Process questions, conversational context, agents, semantic model, and analytical results
  4. 2.4Run governed, read-only analytical queries over authorized sources
  5. 2.5Generate answers, tables, charts, documents, or artifacts where the service allows it
  6. 2.6Record audit, usage, errors, and events needed for support, security, and contractual compliance

03

3. Duration

3.1Processing continues during the main agreement and afterwards for periods needed for return, deletion, legal obligations, support, security, claims, or orderly service closure

3.2The customer organization may request additional information about retention by data type where its agreement or risk assessment requires it

04

4. Nature and purpose

  1. 4.1Collection, receipt, storage, structuring, consultation, analysis, generation, logging, retention, disclosure to authorized subprocessors, deletion, and return where applicable
  2. 4.2Main purpose: provide, maintain, protect, audit, and improve Rumbleo according to the customer's documented instructions and applicable agreement
  3. 4.3Personal data is not sold or used for purposes incompatible with service delivery

05

5. Data subjects

  1. 5.1Authorized users of the customer organization
  2. 5.2Organization administrators and authorized internal personnel
  3. 5.3Employees, contractors, customers, suppliers, or other people whose data appears in customer-connected sources
  4. 5.4Commercial or support contacts interacting with SALATECH on behalf of the customer

06

6. Personal data categories

  1. 6.1Identification and contact data: name, professional email, company, position, or role
  2. 6.2Access and security data: identifiers, IP, browser, device, authentication events, and logs
  3. 6.3Usage data: questions, agents, activity, consumption, errors, timings, channel, and conversation metadata
  4. 6.4Business data contained in semantic models, attachments, answers, artifacts, or authorized analytical sources
  5. 6.5Derived analytical data: aggregates, tables, metrics, explanations, comparisons, and service-generated results

07

7. Special categories and sensitive data

7.1Rumbleo is not designed to process special categories of personal data unless the customer expressly indicates it, has a sufficient legal basis, and appropriate controls are agreed

7.2Users should not enter unnecessary personal data, third-party secrets, credentials, health data, biometric data, children's data, or other sensitive information not needed for the contracted professional purpose

08

8. Customer instructions

  1. 8.1SALATECH will process documented personal data according to customer instructions, the main agreement, the DPA, service configuration, and applicable law
  2. 8.2If an instruction appears to infringe data protection law, SALATECH will inform the customer where reasonably possible
  3. 8.3The customer is responsible for the lawfulness, accuracy, minimization, proportionality, and purpose of data it connects or enters into Rumbleo

09

9. Technical and organizational measures

  1. 9.1Organization separation and session-based access control
  2. 9.2Differentiated functional roles and limited administrative privileges
  3. 9.3Read-only analytical queries and validation before execution
  4. 9.4Encryption in transit through HTTPS in deployed environments
  5. 9.5Encryption at rest for artifacts and secrets according to environment
  6. 9.6Analytical credential encryption in cloud deployments
  7. 9.7Logging, usage limits, and traceability for relevant operations
  8. 9.8Internal access restricted to authorized personnel for support, security, quality, or investigation
  9. 9.9Change management through review and testing before deployment

10

10. Processor obligations

  1. 10.1Process personal data only according to the customer's documented instructions and applicable agreement
  2. 10.2Ensure that people authorized to process personal data are subject to appropriate confidentiality obligations
  3. 10.3Apply reasonable technical and organizational measures considering the state of the art, risks, data nature, and service scope
  4. 10.4Not sell personal data or use it to train models or for purposes incompatible with providing Rumbleo
  5. 10.5Inform the customer where an instruction appears to infringe data protection law, where reasonably possible

11

11. Customer obligations

  1. 11.1Determine the purpose and legal basis for data the customer connects, uploads, or generates through Rumbleo
  2. 11.2Ensure data is adequate, relevant, accurate, and proportionate for the intended use
  3. 11.3Avoid entering special categories, children's data, credentials, secrets, or sensitive information not needed for the contracted purpose
  4. 11.4Configure users, roles, and access according to internal policies and remove access when no longer needed
  5. 11.5Review answers and insights before making relevant decisions about people, operations, finance, or strategy

12

12. Confidentiality and authorized personnel

  1. 12.1SALATECH will limit internal access to customer data to authorized personnel who need it for support, security, quality, operations, or contractual compliance
  2. 12.2Internal access to full records is reserved for authorized personnel
  3. 12.3Authorized personnel must treat non-public customer information as confidential
  4. 12.4Confidentiality obligations survive while information remains non-public or as required by the applicable agreement

13

13. Subprocessors

13.1SALATECH may use subprocessors for infrastructure, authentication, storage, communications, AI models, security, technical analytics, deployment, and operational support

13.2The public subprocessors list is maintained on its dedicated page. The customer generally authorizes subprocessors needed to provide the service unless the agreement requires specific authorization or objection rights

13.3SALATECH will require subprocessors to apply substantially equivalent data protection obligations for processing they perform on behalf of Rumbleo

14

14. International transfers

14.1Some providers may process data outside the European Economic Area. Where this occurs, SALATECH will apply recognized mechanisms under applicable law, such as adequacy decisions, standard contractual clauses, or other valid safeguards

14.2The specific location may depend on cloud region, provider, and customer configuration. The subprocessors list indicates the known location or reference for each provider

15

15. Customer assistance

  1. 15.1Reasonable assistance responding to data subject rights requests where SALATECH acts as processor
  2. 15.2Reasonable information for DPIAs, risk assessments, or security questions related to Rumbleo
  3. 15.3Support investigating errors, incidents, misuse, or unauthorized exposure
  4. 15.4Reasonable cooperation with breach notification obligations where applicable

16

16. Security incidents

16.1SALATECH will notify the customer without undue delay after becoming aware of a personal data breach affecting data processed on behalf of the customer, according to the agreement and applicable law

16.2The notice will include reasonably available information: nature of the incident, affected data or systems, measures taken, recommended measures, and point of contact

17

17. Deletion, return, and termination

17.1At service termination, SALATECH will return or delete personal data processed on behalf of the customer according to contractual instructions, except where retention is required by law, security, claims defense, or technical backup subject to scheduled deletion

17.2Specific export, deletion, log retention, artifact, and backup periods should be defined in the agreement or operational annex where the customer needs them for audit

18

18. Audits and evidence

18.1SALATECH will provide reasonable information to demonstrate DPA compliance, prioritizing documentation, questionnaires, control evidence, and review meetings

18.2Any direct audit must be agreed in advance, limited to the necessary scope, protect confidentiality, avoid compromising other customers' security, and avoid disproportionate service interruption

19

19. Retention, backups, and technical deletion

  1. 19.1Ordinary retention is governed by the agreement, service configuration, and applicable legal obligations
  2. 19.2Technical backups may retain data for limited retention cycles and remain subject to scheduled deletion
  3. 19.3Deletion from production does not imply immediate deletion from every backup copy where backups are not accessible in ordinary operations
  4. 19.4Where the customer requires specific periods by data category, these should be documented in the agreement, operational annex, or service level agreement

20

20. Document hierarchy

  1. 20.1This public DPA is a review basis and does not replace a signed agreement where one exists
  2. 20.2The main agreement, data processing annex, security annex, service order, or customer-specific agreement prevails over this public text if there is a conflict
  3. 20.3Certifications, residency commitments, SLAs, or additional controls apply only where expressly stated in the relevant agreement

Need this for a security review?

Contact info@salatechconsulting.com for vendor questionnaires, additional evidence, or contract annexes

Request a demo