Data Processing Agreement (DPA)
Version: privacy-v1 · Effective: 18 July 2026
Controlling language: German. This text is an informational translation.
This DPA forms part of the agreement between the business customer (“Customer”) and Mykola Orlenko, Einzelunternehmer, trading as SonikaAI, Trierer Str. 700, 52078 Aachen, Germany (“SonikaAI”), where SonikaAI processes personal data for the Customer. The controller-processor clauses in Commission Decision (EU) 2021/915 are incorporated by reference and prevail in case of conflict.
1. Roles and instructions
The Customer is controller or processor; SonikaAI is processor or subprocessor. SonikaAI processes data only to provide, maintain, and secure the ordered services under documented instructions, and does not use Customer content for advertising or model training.
The Customer is responsible for lawful data and instructions. Self-service use excludes full card data, payment authentication data, passwords, keys, other secrets, biometric templates, and HIPAA PHI. Predominant processing of children's data, government IDs, criminal-conviction data, or GDPR Articles 9/10 data requires a written manual B2B order and risk review.
2. Processing and EU PII Masking
Processing may include receipt, transfer, analysis, temporary storage, translation, output generation, and deletion. When EU PII Masking is enabled, Microsoft Azure AI Language in an EU region first receives the unmasked language probe and each translation package to detect PII. Downstream language-detection and translation providers receive masked text; restoration occurs within SonikaAI.
Masking is best-effort pseudonymisation, not complete anonymisation or medical-grade de-identification. Without masking, relevant providers may receive unmasked content.
3. Confidentiality, security, and retention
SonikaAI restricts access to authorised persons and applies transport encryption, logical separation, least-privilege access, incident procedures, and controlled deletion. The workflow vault is encrypted, isolated per workflow, deleted at terminal status, and in every case automatically purged within 24 hours.
- Visible files and results: until Customer deletion or contract termination.
- Completed-workflow technical copies: usually up to 3 days; other hidden technical copies: no more than 30 days.
- Application logs in daily mode: up to 14 days; local operational backups: up to 7 days.
4. Subprocessors and transfers
The Customer grants general written authorisation for subprocessors. The current Subprocessor Register forms part of this DPA. SonikaAI gives at least 30 calendar days' email notice of additions or replacements. Transfers outside the EEA use an adequacy decision, SCC 2021/914, or another lawful mechanism.
5. Assistance, incidents, and audit
SonikaAI notifies the Customer without undue delay of a known Customer Data breach and provides reasonable assistance with data-subject requests, DPIAs, and regulatory obligations. The Customer may request compliance information and, if insufficient, one audit per year with advance notice, confidentiality, and no unreasonable disruption.
6. Termination, law, and acceptance
After the services end, SonikaAI returns or deletes Customer Data at the Customer's choice, except where law requires retention. German law applies; for merchants and qualifying public-law B2B customers, where legally permitted, Aachen is the exclusive venue.
The DPA is accepted electronically at checkout or incorporated into an order form or main agreement. The accepting person confirms authority to bind the Customer. SonikaAI stores the version, timestamp, and technical evidence of acceptance.
7. Processing details and TOMs
Subject and duration: document processing and ordered output generation for the service term plus the technical deletion period. Purpose and frequency: executing Customer workflows whenever the Customer uses the services.
Data subjects: users, employees, contractors, customers, counterparties, and others named in content. Data: identification, contact, professional, contractual information, and document content. Special categories are permitted only under section 1.
Core TOMs include TLS in transit; encrypted workflow vault; tenant/workflow separation; least-privilege and authentication controls; restricted admin access; content-safe logging; vulnerability, backup, and incident procedures; confidentiality duties; retention review and controlled deletion.
SonikaAI's independent-controller processing for accounts, billing, security, and legal records is governed by the Privacy Policy. Contact: legal@sonikaai.com.