Sluis
ProductPricingEnterpriseDocsCompliance
ConsoleGet a key
Legal

Data Processing Agreement

The GDPR Art. 28 processing agreement every Sluis organisation concludes, with its sub-processor annex.

Version 2, effective 2026-08-06. The English text below is the binding version.

Data Processing Agreement

Version 2 — effective 6 August 2026.

This Data Processing Agreement (the "DPA") forms part of the Agreement between the customer organisation that accepts it in the Sluis Console (the "Controller") and 7Lab B.V., Danzigerbocht 39 G, 1013 AM Amsterdam, The Netherlands, Chamber of Commerce 84815515 (the "Processor"), for the provision of the Sluis platform (the "Service"). It reflects the parties' agreement on the processing of personal data under Regulation (EU) 2016/679 ("GDPR").

Conclusion. This DPA is concluded electronically (Art. 28(9) GDPR) when a user with the owner or admin role of the Controller's organisation accepts it in the Console. The Service records the accepting user, timestamp, IP address, document version, the SHA-256 hash of this text, and a snapshot of the organisation's sub-processor annex (Annex B) at the moment of acceptance. Each organisation, including a client organisation created by an agency, concludes this DPA for itself.

1. Roles and scope

1.1 The Controller determines the purposes and means of processing personal data submitted to the Service. The Processor processes that personal data only on the documented instructions of the Controller, including with regard to transfers, unless required to do otherwise by EU or Member State law, in which case the Processor informs the Controller before processing unless that law prohibits it on important grounds of public interest.

1.2 The Service is an OpenAI-compatible gateway that routes the Controller's requests to upstream model providers (the "Sub-processors", Annex B), applying the Controller's residency and data-protection policies. The Service itself is hosted in the EU.

1.3 The Controller's documented instructions consist of: this DPA, the Controller's Service configuration (residency policy, DLP mode, content retention and caching opt-ins, provider selections), and the International Transfer Terms acknowledgments described in §8.

2. Subject matter, duration, nature and purpose

ItemDetail
Subject matterProxying, screening (DLP, reversible pseudonymization, document anonymization), residency enforcement, optional caching, and tamper-evident audit logging of AI API requests.
DurationThe term of the Agreement, plus the retention periods in §7.
Nature and purposeRouting requests to the model providers permitted by the Controller's policy; recording an auditable, tamper-evident trail; enforcing the Controller's residency and DLP policies; metering usage.
Type of personal dataWhatever the Controller's users include in prompts, documents and responses; plus request metadata (model, provider, region, tokens, cost) and tenant/key identifiers. See Annex A.
Categories of data subjectsThe Controller's users and any individuals referenced in submitted content.

3. Processor obligations

The Processor shall:

3.1 Process on instructions only (Art. 28(3)(a)) — process personal data solely per the documented instructions in §1.3, and immediately inform the Controller if, in its opinion, an instruction infringes the GDPR.

3.2 Confidentiality (Art. 28(3)(b)) — ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.3 Security (Art. 28(3)(c), Art. 32) — implement the technical and organisational measures in Annex C.

3.4 Sub-processors (Art. 28(3)(d)) — engage Sub-processors only per §6 and Annex B.

3.5 Assist the Controller (Art. 28(3)(e)-(f)) — taking into account the nature of the processing, assist with: responding to data-subject requests (Chapter III GDPR); security of processing; personal-data breach notification; data protection impact assessments and prior consultation (Arts. 32-36). The Service's self-service tooling (erasure, export, sub-processor disclosure, retention purge; Annex A §A.3) is the primary means of this assistance.

3.6 Deletion and return (Art. 28(3)(g)) — at the Controller's choice, delete or return all personal data at the end of the provision of the Service, and delete existing copies unless EU or Member State law requires storage. The append-only audit metadata trail is retained as described in §5.3 and §7.

3.7 Demonstrate compliance (Art. 28(3)(h)) — make available to the Controller all information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, at reasonable intervals and on reasonable prior notice.

4. Controller obligations

4.1 The Controller warrants that it has a lawful basis for the processing and for including personal data in submitted content, and that its instructions comply with applicable law.

4.2 The Controller configures the Service (residency policy, DLP mode, content retention, caching, provider selections) consistent with its own obligations. The default configuration is EU-only routing with reversible pseudonymization enabled and content retention enabled at tokenized fidelity (the retained audit copy holds placeholders, not raw identifiers); the Controller may disable content retention for metadata-only audit.

5. Data-subject rights

5.1 The Processor shall, to the extent the Controller cannot do so itself through the Service, assist with requests to exercise data-subject rights. Requests received directly by the Processor are forwarded to the Controller without undue delay.

5.2 The Service provides self-service mechanisms (Annex A §A.3): erasure of an organisation's content, cache and credentials; export of the audit trail; the per-organisation sub-processor disclosure; and retention/TTL purge.

5.3 Erasure preserves the tamper-evident audit metadata chain. Erasure deletes personal data (prompt/response content, cache entries, stored credentials) but retains the append-only metadata chain (model, provider, region, tokens, cost, routing decision; no prompt/response content), which is necessary for the integrity of the audit trail and the Processor's own compliance evidence (Arts. 17(3) and 5(1)(b)-(c) GDPR).

6. Sub-processors

6.1 The Controller grants general written authorisation for the Processor to engage the Sub-processors in Annex B: the platform Sub-processors (infrastructure) and the model providers reachable under the Controller's own configuration at any given time.

6.2 The Processor shall inform the Controller of any intended addition or replacement of platform Sub-processors or of the model-provider catalogue, by notice in the Console and by updating the published sub-processor list, giving the Controller the opportunity to object within 30 days. If the Controller objects on reasonable data-protection grounds and no solution is found, the Controller may terminate the affected part of the Service without penalty.

6.3 A model provider becomes reachable for the Controller's organisation only through the Controller's own configuration (its residency policy, provider allow-list, or its own connected keys). Enabling a provider or jurisdiction in the policy is the Controller's instruction; for non-EU providers §8 applies additionally. No notice period applies to changes the Controller makes itself.

6.4 The Processor imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains fully liable to the Controller for the performance of the Sub-processor's obligations.

6.5 The Controller can view its current, organisation-specific Sub-processor list at any time in the Console (and download it with the DPA document), reflecting exactly the providers its configuration can route to.

7. Retention

DataDefault retentionMechanism
Prompt/response contentEnabled by default at tokenized fidelity; 30-day TTL; the Controller can disable retentionAEAD-encrypted at rest; TTL purge
Cache entries (exact + semantic)Until TTL; caching is opt-inencrypted; TTL purge / erasure
Audit metadataThe term of the Agreement plus the applicable limitation period (append-only; needed for billing integrity and as compliance evidence, Arts. 5(1)(e), 17(3)(b) and (e))hash-chained; preserved through erasure
Chat conversations, attachments and org knowledgeUntil deleted by the Controller or erased on requestAEAD-encrypted at rest; erasure tooling
Provider credentialsUntil removed by the Controllerenvelope-encrypted; deleted on erasure

8. International transfers

8.1 The Service is hosted in the EU and routes by default only to EU-jurisdiction model providers. Where the Controller's policy permits a US-owned, EU-region provider, the Controller acknowledges the associated CLOUD-Act exposure, which the Service surfaces in the sub-processor disclosure.

8.2 Enabling a non-EU jurisdiction or provider in the policy is the Controller's documented transfer instruction. For changes made through the Console, the Console presents the International Transfer Terms before the change takes effect and records the Controller's acknowledgment, including which jurisdictions or providers were added. A change the Controller makes through its own API tokens or command-line tooling is itself the documented instruction, subject to the same Transfer Terms. Transfers are subject to an appropriate Chapter V mechanism as described in the International Transfer Terms (Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework), incorporated by reference.

9. Personal-data breach

The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's personal data, providing the information reasonably available to assist the Controller's obligations under Arts. 33 and 34 GDPR, and shall document the breach and remediation.

10. Liability, precedence, law

Liability follows the limitations in the Terms of Service. This DPA prevails over the Terms on data-protection matters. This DPA is governed by the same law and venue as the Terms of Service (the Netherlands; Amsterdam).


Annex A — Processing description and tooling

A.1 Categories of data

  • Prompt/response content (retention per the Controller's setting): free-text and documents that may contain personal data entered by the Controller's users.
  • Request metadata (always): tenant id, hashed virtual-key id, model, provider, region, jurisdiction, token counts, cost, routing decision, cache-hit class, use-case label. No prompt/response content.
  • Credentials: the Controller's own upstream API keys (envelope-encrypted).
  • Sluis Chat data (when the Controller enables the chat workbench): conversations and attachments, uploaded organisation knowledge, and durable work records (Passages, Gates, Seals), stored encrypted until deleted by the Controller or erased on request; chat storage is independent of the content-retention setting above. When the optional web-search tool is enabled, search queries derived from chat content are sent to the deployment's search service, which fans them out to external search engines.

A.2 Processing operations

Receipt of API requests; DLP scanning and, per policy, blocking, masking or reversible pseudonymization; document anonymization and OCR; residency evaluation and routing; dispatch to the selected Sub-processor; optional response caching; usage metering; tamper-evident audit logging.

A.3 Self-service compliance tooling

Right / taskMechanism
Erasure (Art. 17)organisation-scoped erasure of content, caches and credentials
Retention / TTL purgeautomatic purge of expired retained content
Sub-processor disclosureper-organisation list in the Console and in the DPA download
Audit export (access/portability)JSON Lines export of the audit trail
Audit integrity checkhash-chain verification that fails loudly on any mutation

Annex B — Sub-processors

B.1 Platform Sub-processors (infrastructure; engaged for every organisation): the then-current list published on the Sluis legal pages, comprising at the version date: Scaleway SAS (cloud hosting, EU/France), Mollie B.V. (payment processing, EU/Netherlands; billing data only), and the EU transactional-email provider named on the published sub-processor list (verification, security and invoice email; [to be named before launch]).

B.2 Model providers. The model providers the Controller's configuration can route to. The organisation-specific list, with each provider's region, jurisdiction and ownership exposure, is shown in the Console at acceptance and at any later time, and a snapshot is stored with each acceptance of this DPA. Providers outside the EU become reachable only through the Controller's own opt-in (§6.3, §8).

Annex C — Technical and organisational measures (Art. 32)

  • Encryption at rest: provider credentials envelope-encrypted (per-tenant data key wrapped by a master key); retained content and cache entries AEAD-encrypted with a dedicated content key; virtual keys stored as hashes, never plaintext.
  • Encryption in transit: TLS for client and upstream connections.
  • Tenant isolation: every store is scoped by tenant id; caches cannot cross tenant boundaries.
  • Data minimisation: reversible pseudonymization substitutes typed placeholders for detected personal data before egress, restoring them only at the Controller's own boundary; the retained audit copy defaults to the same tokenized fidelity (placeholders, not raw identifiers), and content retention can be disabled entirely for metadata-only audit.
  • Tamper evidence: append-only, per-tenant hash-chained audit log with chain verification that fails loudly on any mutation; operator actions are separately audited.
  • Access control: role-based Console access with per-request membership re-verification; optional organisation-wide two-factor authentication; residency and DLP gates enforced before any dispatch.
  • Hosting: EU jurisdiction, EU-owned infrastructure.

Annex D — AI Act responsibility allocation

For AI systems the Controller builds or operates using the Service, the Controller acts as provider and/or deployer under Regulation (EU) 2024/1689. The Processor's role is limited to routing and applying the Controller's policies; the Processor does not develop or place on the market the underlying models. The Controller remains responsible for its transparency duties (Art. 50), human oversight, and lawful use; the Service's audit and gate records are made available as supporting evidence.

Platform sub-processors

  • Scaleway SAS (Cloud hosting, EU (France)). Hosting of the Sluis gateway, PostgreSQL database and Redis (EU-owned infrastructure).
  • Mollie B.V. (Payment processing, EU (Netherlands)). Card, SEPA Direct Debit and bank-transfer payment processing for paid plans (billing contact and payment data only; never prompt or response content).
  • Transactional email provider (SMTP) (Email delivery, EU). Delivery of verification, security and invoice emails (recipient address and message content only).

Signed-in organisations see their organisation-specific sub-processor annex in the console and can download the agreement, with the annex snapshot that was accepted, as a PDF.

Sluis is a product of 7Lab B.V., Amsterdam, the Netherlands (KVK 84815515).

Sluis

The lock between your engineers and whoever audits them. One API for every AI model that strips personal data before it leaves, restores it in the answer, and seals every passage in an audit ledger. Compliant by default, EU-sovereign until you decide otherwise. Built below sea level, in Amsterdam.

ProductHow it worksPricingPerformanceSecurity & complianceEnterpriseConsole
DevelopersQuickstartAPI referenceOpen the console
CompanyAboutTrust centreContactCareers
LegalTerms of ServicePrivacy PolicyDPA
© 2026 7Lab B.V. · Amsterdam, NL · Sluis is a product of 7Lab B.V. (KVK 84815515)Built below sea level · AmsterdamISO 27001 certified