Data Processing Agreement

Last updated: June 25, 2026

This Data Processing Agreement (the "DPA") forms part of, and is incorporated by reference into, the Terms of Service (the "Agreement") between you, the customer (the "Customer," "Controller," or "you"), and Referent Software S.L. ("Referent," "Processor," "we," "us," or "our"), governing your use of the Referent AI-powered enterprise knowledge assistant service (the "Service").

This DPA reflects the parties' agreement on the processing of Personal Data carried out by Referent on the Customer's behalf in connection with the Service. It applies where, and to the extent that, Referent processes Customer Personal Data that is subject to Applicable Data Protection Law, and is designed to satisfy the requirements of Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR.

How this DPA is entered into

This DPA is effective and binding upon your acceptance of the Agreement or your use of the Service, without the need for a separate signature. If your organization requires a countersigned copy, or needs to add the Standard Contractual Clauses as an executed exhibit, contact privacy@referent.app and we will provide one. In case of any conflict between this DPA and the rest of the Agreement, this DPA prevails with respect to the processing of Personal Data.

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement. For the purposes of this DPA:

  • "Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the Spanish Organic Law 3/2018 (LOPDGDD), and, where applicable, other national, state, or regional privacy laws.
  • "Controller," "Processor," "Data Subject," "Personal Data," "Special Categories of Personal Data," "Processing," and "Personal Data Breach" have the meanings given in the GDPR.
  • "Customer Personal Data" means any Personal Data contained within Customer Data (as defined in our Privacy Policy) that Referent processes on the Customer's behalf in the course of providing the Service.
  • "Sub-processor" means any third party engaged by Referent that processes Customer Personal Data in connection with the Service.
  • "Standard Contractual Clauses" (or "SCCs") means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914, and, for transfers subject to UK law, the UK International Data Transfer Addendum issued by the UK Information Commissioner.
  • "Connected Service" means a third-party platform or data source (for example Google Workspace, Microsoft 365, Slack, Notion) that the Customer chooses to connect to the Service via OAuth or an API key.

2. Roles of the Parties and Scope

With respect to Customer Personal Data, the parties acknowledge and agree that the Customer is the Controller and Referent is the Processor. Where the Customer itself acts as a processor on behalf of a third-party controller (for example, the Customer's own clients), Referent acts as a sub-processor; in that case the Customer warrants that it is authorized to engage Referent on those terms and to give the instructions set out in this DPA.

Referent acts as an independent Controller in limited respects that fall outside this DPA — for example, when processing account and billing contact details, security and audit logs, and aggregated or de-identified usage analytics to operate, secure, bill for, and improve the Service. That processing is governed by our Privacy Policy.

Connected Services are not Referent Sub-processors. When you connect a Connected Service, the Service accesses data from it at your direction in order to perform the tasks you request. Those platforms remain under your control and your agreements with them; they are data sources you instruct us to access, not parties we engage to process data on our behalf.

3. Processing of Personal Data

A. Processing on documented instructions

Referent will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law to which Referent is subject (in which case Referent will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest). The Agreement, this DPA, the Privacy Policy, the configuration choices you make in the Service, and your authorized use of the Service together constitute your complete and final documented instructions.

If Referent believes an instruction infringes Applicable Data Protection Law, it will inform the Customer without undue delay.

B. Details of the processing

The subject matter, nature and purpose of the processing, the duration, and the categories of Data Subjects and Personal Data are described in Annex I to this DPA.

C. AI processing and no training on Customer Personal Data

  • To generate responses, reports, and other outputs at your direction, relevant portions of Customer Personal Data (the prompt and context needed for a given task) are processed by AI models operated by the AI sub-processors listed in Annex III, routed through a managed AI gateway.
  • Referent does not use Customer Personal Data to train, fine-tune, or improve its own or any third party's foundation models.
  • We require our AI sub-processors to process Customer Personal Data only to provide the requested output and not to train their general models. AI providers may retain data transiently in accordance with their API retention policies for security and abuse monitoring only.
  • Each request is processed in isolation and is not shared with, or made visible to, other customers.
  • EU data residency option: Customers requiring strict EU-only processing can request the EU data residency configuration, under which all AI inference is routed through the AI gateway to Amazon Bedrock in EU regions, so that Customer Personal Data is not transferred outside the EEA for inference. See Section 8.

4. Customer Obligations

As Controller, the Customer is responsible for:

  • Ensuring it has a valid legal basis (and, where required, has obtained consent) for the collection and processing of Customer Personal Data and for instructing Referent to process it, including data originating from Connected Services and from end users on messaging channels (web chat, Telegram, Discord, Slack, WhatsApp).
  • Providing all notices and information required under Applicable Data Protection Law to its Data Subjects.
  • The accuracy, quality, and legality of Customer Personal Data and of the instructions it gives Referent.
  • Configuring the Service appropriately, including channel and workspace access, integration scopes, automation rules, approval policies, and administrator permissions, and for keeping those configurations up to date.
  • Not submitting Special Categories of Personal Data except as contemplated in Annex I, and not using the Service in a manner that would require Referent to comply with sector-specific regimes (such as PCI-DSS for cardholder data) unless separately agreed in writing.

5. Confidentiality

Referent treats Customer Personal Data as confidential. Referent ensures that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory) and are granted access on a need-to-know basis, limited to what each person requires to perform their role.

6. Security of Processing

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects, Referent implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. A description of these measures is set out in Annex II.

Referent may update its security measures from time to time provided that the updates do not materially reduce the overall level of protection of Customer Personal Data. The Customer is responsible for security measures within its own control, including managing user access, integration permissions, and channel membership.

7. Sub-processors

The Customer provides a general authorization for Referent to engage Sub-processors to process Customer Personal Data, subject to this Section. A current list of Sub-processors is set out in Annex III.

  • Flow-down obligations: Referent imposes on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures.
  • Liability: Referent remains fully liable to the Customer for the performance of each Sub-processor's obligations.
  • Notice of changes and right to object: Referent will notify the Customer of any intended addition or replacement of a Sub-processor (for example, by updating Annex III and, where the Customer has subscribed to notifications, by email) with reasonable advance notice, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Customer objects and the parties cannot reach a resolution, the Customer may, as its sole remedy, terminate the affected portion of the Service.

8. International Data Transfers

Referent stores tenant content (such as conversations, uploaded documents, workspace files, and encrypted integration credentials) in object storage configured for European Union data residency. Other components of the underlying infrastructure run on a global cloud network, and AI inference may be performed outside the European Economic Area (for example, in the United States).

Where Referent transfers Customer Personal Data to a country outside the EEA or the UK that is not subject to an adequacy decision, such transfers are made under an appropriate transfer mechanism, principally the Standard Contractual Clauses (together with the UK Addendum where relevant), supplemented by additional technical and organizational measures such as encryption in transit and at rest.

To the extent the SCCs apply, they are incorporated into this DPA by reference: Module Two (Controller-to-Processor) applies where the Customer is a Controller, and Module Three (Processor-to-Processor) applies where the Customer acts as a processor. The optional docking clause applies; the option for general sub-processor authorization applies; and the governing law and forum are those of Spain. Annex I, II, and III to this DPA populate the corresponding annexes of the SCCs.

EU data residency option

For customers that require strict EU-only processing, Referent offers, on request, an EU data residency configuration under which: (i) tenant content is stored in EU-located object storage; (ii) the underlying Cloudflare infrastructure serving the tenant operates on EU-based servers; (iii) all large language model inference is routed through the AI gateway to Amazon Bedrock in EU regions, so that Customer Personal Data is processed for inference within the European Economic Area and is not transferred to the United States for that purpose; and (iv) product and website analytics are processed on Referent's self-hosted infrastructure located in the EU rather than by any third-party analytics provider. Contact privacy@referent.app to enable this configuration.

9. Assistance with Data Subject Requests

Taking into account the nature of the processing, Referent assists the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, and objection). The Service provides self-service functionality enabling the Customer to access, correct, export, and delete much of its Customer Personal Data directly.

If Referent receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond to the request itself (except to confirm that the request relates to the Customer) and will, without undue delay, forward the request to the Customer or direct the Data Subject to the Customer.

10. Personal Data Breach Notification

Referent will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known and reasonably available at the time:

  • the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and mitigate its adverse effects; and
  • a contact point for further information.

Referent will provide reasonable cooperation and assistance to support the Customer's own breach-notification and documentation obligations. Notification of a breach is not, and will not be construed as, an acknowledgment by Referent of any fault or liability.

11. Data Protection Impact Assessments

Taking into account the nature of the processing and the information available to Referent, Referent provides reasonable assistance to the Customer with any data protection impact assessments and prior consultations with supervisory authorities that the Customer reasonably considers to be required under Articles 35 and 36 of the GDPR, in each case solely in relation to the processing of Customer Personal Data by Referent.

12. Deletion and Return of Personal Data

Upon termination or expiry of the Agreement, or upon the Customer's earlier written request, Referent will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless EU or Member State law requires continued storage.

  • Export: Where legally permitted, the Customer may request an export of its Customer Personal Data prior to deletion, in addition to the self-service export available in the Service.
  • Active systems: Following account closure or a validated deletion request, Customer Personal Data is deleted from active production systems typically within approximately 30 days.
  • Backups: Residual copies in encrypted backups are removed as backups age out on their normal rotation (currently approximately 35 days), after which they are overwritten or purged.
  • Derived data: Derived representations (such as search indexes and embeddings) are deleted or disassociated when the underlying Customer Personal Data is deleted, subject to backup rotation.

13. Audits and Inspections

Referent makes available to the Customer all information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

To the extent reasonably possible, the Customer's audit rights are satisfied first by Referent making available relevant documentation, security summaries, and any third-party certifications or reports it holds. Where that is insufficient to address a specific, documented concern, the parties will agree in advance on the reasonable timing, scope, duration, and cost of any further audit; audits take place during business hours, no more than once per twelve-month period (except where required by a supervisory authority or following a Personal Data Breach), and must not unreasonably interfere with Referent's operations or compromise the confidentiality or security of other customers' data.

14. Liability, Term, and Governing Law

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA takes effect on the effective date of the Agreement and remains in force for as long as Referent processes Customer Personal Data, after which the obligations in Section 12 (Deletion and Return) and any other provisions that by their nature should survive will continue to apply.

This DPA is governed by the laws of Spain, and any disputes are subject to the exclusive jurisdiction of the courts of Soria, Spain, except where Applicable Data Protection Law (including the SCCs) requires otherwise.

15. Contact

For any matter relating to this DPA, data protection, or to request a countersigned copy or the executed SCCs, contact:

Referent Software S.L.

Email: privacy@referent.app

Address: Carretera de matanza Nº6, San Esteban de Gormaz 42330, Soria, España

Annex I — Description of the Processing

A. Parties

Data exporter / Controller: the Customer, as identified in the Agreement and its account, which determines the purposes and means of the processing of Customer Personal Data.
Data importer / Processor: Referent Software S.L., Carretera de matanza Nº6, San Esteban de Gormaz 42330, Soria, España, providing the Service.

B. Categories of Data Subjects

  • The Customer's administrators and authorized users of the Service.
  • The Customer's employees, contractors, and other personnel.
  • The Customer's own customers, contacts, counterparties, and other individuals whose Personal Data appears in connected data sources, documents, messages, or conversations that the Customer instructs the Service to process.
  • Individuals who communicate with the Customer's assistant through web chat or messaging channels (Telegram, Discord, Slack, WhatsApp).

C. Categories of Personal Data

  • Identity and contact data: names, email addresses, usernames, user and workspace/organization identifiers, display names, roles.
  • Authentication and credential data: one-time login codes, session tokens, and OAuth access/refresh tokens for Connected Services (stored encrypted).
  • Content data: chat messages and conversation history; prompts and AI-generated outputs; uploaded and generated documents and files; workspace and memory files; and the contents of emails, files, messages, and records retrieved from Connected Services at the Customer's direction.
  • Usage, billing, and log data: token-usage metrics, feature-usage events, approval decisions, scheduled-task and automation configurations, audit and security logs, and billing-related identifiers (for example, payment-processor customer and subscription identifiers).
  • Any other Personal Data the Customer chooses to submit to, or connect with, the Service.

D. Special Categories of Personal Data

The Service is not designed or intended for the processing of Special Categories of Personal Data. The Customer should not submit such data unless it has implemented appropriate safeguards and has a valid legal basis to do so. To the extent the Customer's content nonetheless contains such data, it is processed as Content data under the same technical and organizational measures.

E. Nature and purpose of the processing

Hosting, storage, retrieval, organization, structuring, and AI-assisted analysis and generation of outputs in order to provide the Service: operating an AI assistant that answers questions, drafts and analyzes documents, conducts research, runs scheduled tasks and automations, and executes approved actions across Connected Services on the Customer's behalf, together with related security, support, and billing operations.

F. Frequency and duration

Processing is continuous for the duration of the Agreement and until Customer Personal Data is deleted or returned in accordance with Section 12 of this DPA.

G. Competent supervisory authority

Where the SCCs apply with Spain as the EU point of reference, the competent supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD). Otherwise, the competent supervisory authority is determined by the Customer's place of establishment under Applicable Data Protection Law.

Annex II — Technical and Organizational Measures

Referent implements and maintains the following technical and organizational measures. Specific measures may evolve as the Service develops, provided the overall level of protection is not materially reduced.

A. Encryption

  • Encryption in transit using TLS 1.2 or higher for all connections to and from the Service.
  • Encryption at rest of stored data using AES-256 (or equivalent) managed by the underlying cloud platform.
  • Application-layer encryption of sensitive secrets — in particular Connected Service credentials and OAuth tokens — using authenticated AES-GCM encryption with a dedicated master key held as a platform secret, separate from the data store.

B. Tenant isolation and confidentiality

  • Multi-tenant logical isolation: each tenant's data is partitioned by tenant-scoped storage keys, tenant-scoped session keys, and per-tenant isolated runtime state, with tenant-identity checks enforced on internal service endpoints.
  • AI requests are processed per request in isolation and are not shared with, or visible to, other tenants.
  • Personnel are bound by confidentiality obligations and access is granted on a least-privilege, need-to-know basis.

C. Access control and authentication

  • Passwordless end-user authentication via email one-time codes and federated OAuth (Google, Microsoft); first-party, Secure, same-site session cookies and bearer tokens.
  • Role-based access control within the Customer's organization (owner / administrator / member) with membership-status enforcement.
  • "Bring your own key" model for AI providers: provider API keys are held in a managed AI gateway rather than in application code, and gateway access is separately authenticated.

D. Isolation of code execution and network egress

  • Code generated or executed on the Customer's behalf runs inside sandboxed, ephemeral runtime isolates and containers.
  • Outbound network requests from those isolates are forced through an egress-filtering proxy that only forwards traffic to allowlisted origins; per-isolate CPU and sub-request limits are enforced.
  • Server-side request forgery (SSRF) protections are applied to URL-fetching tools.

E. Logging, monitoring, and integrity

  • Audit logging of security-relevant events and platform-level observability and metrics.
  • Approval mechanisms for higher-risk actions, so that actions which modify external systems can require explicit human approval before execution.

F. Availability, resilience, and recovery

  • The Service runs on a globally distributed, resilient cloud platform.
  • Managed, encrypted backups are maintained for business continuity, with the ability to restore availability and access to Personal Data in a timely manner following an incident.

G. Secure development and vendor management

  • Secure software development practices including static type-checking, automated testing, code review, and security review of changes.
  • Sub-processors are engaged under written contracts with data-protection terms no less protective than this DPA, and, where relevant, the Standard Contractual Clauses.
  • Data-minimization and documented retention and deletion timelines, as described in Section 12 and the Privacy Policy.

Annex III — Sub-processors

Referent engages the following Sub-processors to process Customer Personal Data in connection with the Service. Each is engaged under a written agreement including data-protection terms and, where applicable, the Standard Contractual Clauses.

Sub-processorPurposePrimary locationTransfer safeguard
Cloudflare, Inc.Core cloud infrastructure: compute, primary database, object storage, queues, vector search and embedding/reranking inference, browser rendering, sandbox containers, the managed AI gateway, and transactional email.Global network; EU-based servers and EU object-storage residency available.SCCs / EU residency option
Amazon Web Services EMEA SARL (Amazon Bedrock)Large language model inference (including Claude models) via Amazon Bedrock, hosted in EU regions. Used for the EU data residency option so that AI inference stays within the EEA. No training on Customer Personal Data.EU regionsWithin EEA (no transfer)
Anthropic PBCLarge language model (Claude) inference for AI-generated outputs via the managed AI gateway (standard configuration). No training on Customer Personal Data.USASCCs
Google LLCLarge language model (Gemini) inference for AI-generated outputs via the managed AI gateway (standard configuration). No training on Customer Personal Data.USASCCs
Stripe, Inc.Payment processing and subscription billing. Processes billing contact and transaction data; Referent does not store full payment-card numbers.USA / EUSCCs

AI inference path. Under the standard configuration, large language model inference is routed via the AI gateway to Anthropic and Google (United States) under SCCs. Under the EU data residency option (Section 8), all inference is instead routed to Amazon Bedrock in EU regions and remains within the EEA. Product and website analytics are processed on Referent's self-hosted infrastructure located in the EU, not by a third-party analytics provider.

This list may be updated as described in Section 7. To receive notice of changes to this list, or to obtain the current version, contact privacy@referent.app.

Note: Connected Services that you choose to link to the Service (such as Google Workspace, Microsoft 365, Slack, Notion, and other integrations) are data sources you instruct the Service to access on your behalf. They are governed by your own agreements with those providers and are not Referent Sub-processors.

Be the first to hear about Referent news.

By signing up, you agree to receive marketing emails from Referent. See our Privacy Policy.