Data Processing Agreement

Version 1.0, 22 August 2026

This agreement applies where you are a controller of personal data under the GDPR (or the UK GDPR) and we process that data on your behalf in providing ServeX Guard Cloud. It forms part of the Terms of Service. If you need it as a signed document, email mahdielaimani@gmail.com and we will countersign the same text.

1. Parties and roles

Controller ("you"): the customer entity that has an account with us.
Processor ("we", "us"): El Mahdi El Aimani, an individual trading as ServeX Guard, Rabat, Morocco.

You determine the purposes and means of the processing. We process only on your documented instructions, which are: to provide the Service as described in the Terms, and nothing else.

2. What is processed, and why

ItemDetail
Subject matterQuality monitoring of your AI systems
DurationThe term of your account, plus the retention windows in §7
Nature and purposeStoring already-computed CI results; converting production samples to vectors; comparing vector distributions to produce a drift score; sending alerts
Categories of data subjectsYour authorised users; and the end users whose interactions your SDK samples
Types of personal dataAccount: email address, authentication credentials, billing identifiers, API key metadata. Production samples: a numeric vector only (see §3). Technical: IP address and request logs.
Special category dataNot requested and not required. Do not send it.

3. The processing design, stated precisely

This section is technical rather than legal, because it determines what the rest of this agreement has to cover.

4. Our obligations

  1. Documented instructions. We process only on your instructions, including for transfers, unless required by law; in that case we inform you first, unless that law forbids it.
  2. Confidentiality. Anyone authorised to process your data is bound by confidentiality.
  3. Security. We implement the measures in Annex II (Article 32).
  4. Sub-processors. §5.
  5. Data subject rights. We assist you in responding to access, rectification, erasure, restriction, portability and objection requests, taking into account the nature of the processing. Where a request reaches us directly, we refer the individual to you rather than answering for you.
  6. Articles 32–36. We assist you with security, breach notification, impact assessments and prior consultation, to the extent the information is available to us.
  7. Breach notification. We notify you without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting your data, with the information we hold at that time.
  8. Deletion or return. On termination, or on your written request, we delete your data. Deleting your account removes your projects, runs, samples and API keys. We keep only what tax or accounting law requires.
  9. Audit. We make available the information needed to demonstrate compliance with Article 28, and allow audits by you or an auditor you mandate, once per twelve months on reasonable notice, or after a breach. In the first instance we will answer a security questionnaire and provide this agreement's annexes, which is usually sufficient.
  10. Instructions that appear unlawful. We will tell you if we consider an instruction infringes the GDPR or other data protection law.

5. Sub-processors

You give general written authorisation for the sub-processors listed in Annex III. We will give you at least 30 days' notice before adding or replacing one, by email to your account address. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the affected part of the Service and receive a pro-rata refund of any prepaid fees.

Each sub-processor is bound by written terms offering protection equivalent to this agreement, and we remain fully liable to you for their performance.

6. International transfers

Application data is stored in the European Union (Ireland).

We are established in Morocco, which is not currently the subject of a European Commission adequacy decision. Our access to your data from Morocco is therefore a transfer to a third country, and it is covered by the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated into this agreement by reference and which we will execute as a separate signed document on request.

Where a sub-processor in Annex III is established outside the EEA, transfers to it rely on Standard Contractual Clauses or another Article 46 safeguard. For the purposes of the SCCs: the supervisory authority is that of your establishment; the governing law and forum are those of your EU member state; Annexes I, II and III of this agreement serve as the corresponding SCC annexes.

7. Retention

DataRetained
CI runs, Free plan7 days
CI runs, Pro plan180 days (six months)
Production sample vectors30 days
Daily drift scoresYour plan's retention window
Account and billing recordsTerm of the account, then as tax law requires

Retention is enforced by a scheduled job that deletes expired rows nightly, not by hiding them in the interface.

8. Liability and precedence

Liability under this agreement is subject to the limitations in the Terms of Service, except where the GDPR does not permit that. Where this agreement conflicts with the Terms on the processing of personal data, this agreement prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.


Annex I: Processing details

Parties, categories of data subject, types of personal data, purposes, duration and retention are set out in §1, §2 and §7 above, which together constitute Annex I for the purposes of the Standard Contractual Clauses.

Annex II: Technical and organisational measures

These are implemented, not aspirational. Each has been verified against the running system.

AreaMeasure
Data minimisationProduction sample text is discarded after embedding and never written to the database. Only a numeric vector is stored.
Tenant isolationRow Level Security is enabled on every table, so one customer's query cannot return another's rows even if application code were wrong. Verified across multiple tenants.
Encryption in transitTLS on all endpoints, with HSTS (max-age=31536000; includeSubDomains).
Encryption at restProvided by the managed database platform.
Credential storageAPI keys are stored only as SHA-256 hashes; the plaintext is shown once at creation and cannot be recovered by us. Passwords are hashed by the authentication provider.
Access controlUser sessions use asymmetric (ES256) JWT verification against the issuer's published keys. Ingest uses separate, revocable API keys with rotation.
Integrity of billing eventsPayment webhooks are rejected unless their cryptographic signature verifies, and replayed requests are rejected on timestamp.
Availability and abuse controlPer-key and per-IP rate limiting; request bodies capped at 512 KB and rejected before being read; stored reports capped at 256 KB; JSON nesting depth limited.
HardeningX-Content-Type-Options, X-Frame-Options: DENY, Referrer-Policy: no-referrer on every response. Output escaped before rendering.
DeletionNightly purge deletes data past its retention window. Deleting a user cascades to their projects, runs and samples.
Segregation of dutiesDetection runs on your infrastructure. We hold results, not the systems that produce them.
LoggingStandard request logs are retained by the hosting provider for security and debugging.

Not yet in place, stated plainly: we hold no SOC 2 or ISO 27001 certification, and there is no formal 24/7 on-call rotation. If either is a requirement for you, tell us before contracting rather than after.

Annex III: Sub-processors

Sub-processorPurposeDataLocation
SupabaseDatabase and authenticationAll stored application dataEU (Ireland)
VercelAPI and dashboard hostingRequest traffic and logsEU region (Dublin)
Hugging FaceEmbedding generationSampled text, at the moment of embedding only; not retained by usUS (serverless). EU region available on request (see note below)
ResendTransactional and alert emailAccount email address, message contentUS
PaddleMerchant of record, payments and taxBilling details entered at checkoutUK / EU

On the embedding step. By default the sample is embedded through Hugging Face's serverless endpoint, which is US-hosted; Hugging Face relies on the European Commission's 2021 Standard Contractual Clauses for such transfers, maintains an EU establishment (Hugging Face SAS, Paris, supervised by the CNIL), and is SOC 2 Type 2 certified. Where you require inference to stay inside the EEA, we will deploy a dedicated Inference Endpoint in an EU region for your account, after which no data leaves the EEA at any point. Ask before contracting and it is configured before your first sample.

Supabase and Vercel are US-incorporated companies operating the infrastructure in the EU regions stated. We disclose this rather than describe the deployment as sovereign. If EU-owned infrastructure is a requirement for you, raise it: the database and application are portable to a European provider without redesign.

Contact

El Mahdi El Aimani, trading as ServeX Guard
Rabat, Morocco
mahdielaimani@gmail.com