← RavenBI

Data Processing Agreement

Annex to the RavenBI Terms of Service · Last updated: 1 October 2026

This agreement (hereinafter the “DPA”) supplements the RavenBI Terms of Service and governs the processing of personal data carried out by RavenBI on behalf of the Customer within the meaning of Article 28 of Regulation (EU) 2016/679 (“GDPR”).

The controller is the Customer. The processor is RavenBI. The identification details of the parties follow from the main contract and from the Imprint.

This DPA is concluded together with the main contract and does not require a separate signature. On request, RavenBI will make available a signature-ready version.

1. Subject-matter and duration of the processing

1.1 The subject-matter of the processing is the provision of the RavenBI service as described in the main contract: user accounts, access to the platform, reports, alerts and support.

1.2 The processing lasts for as long as the main contract is in force. Upon its termination, Section 9 below applies.

2. Nature and purpose of the processing

RavenBI processes personal data exclusively for:

RavenBI does not use this data for its own marketing purposes and does not sell it.

3. Type of data and categories of data subjects

Categories of data: first and last name, business e-mail address, role within the organisation, chosen language and market, time and IP address of logins, actions on the platform (searches, brands and ingredients followed, reports generated), notification preferences.

Categories of data subjects: the employees, contractors and representatives of the Customer to whom the Customer grants access to the platform.

⚠️ Personal data appearing in publicly observed advertising materials (for example, identifiable persons in creatives) is not covered by this DPA: in respect of such data RavenBI acts as a controller in its own right, and the legal basis and the retention periods are described in the Privacy Policy.

4. Obligations of the controller

4.1 The Customer determines the purposes and means of the processing and is responsible for the lawfulness of the transfer of the data to RavenBI.

4.2 Instructions are given in writing or in text form. Using the platform functions in the manner provided for in the documentation constitutes a documented instruction.

4.3 The Customer informs RavenBI without delay if it discovers errors or irregularities in the processing.

5. Obligations of RavenBI (Article 28(3)(a)–(h) GDPR)

5.1 Instructions (point (a)). RavenBI processes the data exclusively on the basis of the Customer's documented instructions, including with regard to transfers to third countries, unless a legal obligation requires otherwise; in that case RavenBI informs the Customer before the processing, unless the law prohibits that information.

5.2 Confidentiality (point (b)). The persons who process the data are bound by contract to confidentiality and are trained at regular intervals.

5.3 Security (point (c)). RavenBI implements the technical and organisational measures set out in Section 7.

5.4 Sub-processors (point (d)). Section 6 applies.

5.5 Rights of data subjects (point (e)). RavenBI assists the Customer, through appropriate technical and organisational measures, in handling requests for access, rectification, erasure, restriction, portability and objection. If a data subject contacts RavenBI directly, the request is forwarded to the Customer without undue delay.

5.6 Assistance (point (f)). RavenBI assists the Customer in complying with the obligations under Articles 32–36 GDPR, including the data protection impact assessment, within the limits of the information available to it.

5.7 Erasure or return (point (g)). Section 9 applies.

5.8 Demonstrating compliance (point (h)). Section 10 applies.

5.9 Personal data breaches. RavenBI notifies the Customer without undue delay and within 48 hours at the latest of becoming aware of a security breach affecting the Customer's data, describing the nature of the incident, the categories and approximate number of data subjects concerned, the likely consequences and the measures taken.

6. Sub-processors

6.1 The Customer grants RavenBI a general authorisation to engage sub-processors within the meaning of Article 28(2) GDPR.

6.2 The list of sub-processors in force, stating the name, the country, the service provided and the storage location, is available on request and is communicated through the contractual channels.

6.3 RavenBI informs the Customer at least 30 days before engaging a new sub-processor or replacing an existing one. The Customer may raise a reasoned objection, on data protection grounds, within 14 days of being informed. In the absence of an objection within that period, the change is deemed approved.

6.4 If the objection is well founded and cannot be resolved within a reasonable period, the Customer may terminate the main contract with effect from the planned date of the change, without additional cost and with a proportionate refund of amounts paid in advance.

6.5 RavenBI imposes on each sub-processor, by contract, data protection obligations at least equivalent to those set out in this DPA, and is liable for compliance with them.

7. Technical and organisational measures

RavenBI implements at least the following measures, which it may adapt to the state of the art without reducing the level of protection:

8. Transfers outside the European Economic Area

8.1 The principal infrastructure (hosting, database, backups) is located in the European Union.

8.2 For certain functions, data may be transferred to sub-processors in third countries — in particular providers of artificial intelligence models used to classify public content and providers of transactional communications.

8.3 For such transfers, in the absence of an adequacy decision, the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, Module 3 (processor to processor), apply and are incorporated into this DPA by reference. The full text is made available on request.

8.4 Before each transfer of this kind, RavenBI assesses whether the law of the third country affects the effectiveness of the safeguards and applies supplementary measures where necessary (minimisation of the data transferred, pseudonymisation, restriction of access).

9. Erasure and return of the data

9.1 Upon termination of the main contract, the Customer may choose, within 30 days, between the return of the data in a structured, commonly used format and its erasure. In the absence of an express choice, the data is erased.

9.2 Erasure is carried out within 30 days at most of the expiry of the period referred to above.

9.3 An exception applies to copies held in backup archives, which are overwritten in the normal rotation cycle, and to data which RavenBI is under a legal obligation to retain (in particular invoicing records). Until erasure, such data remains subject to the obligations set out in this DPA.

9.4 What remains and why, line by line, is described in the Privacy Policy.

10. Demonstrating compliance and audits

10.1 RavenBI makes available to the Customer, on request, the information necessary to demonstrate compliance with the obligations under Article 28 GDPR.

10.2 The Customer may verify compliance with those obligations by means of: (i) a written questionnaire, which RavenBI answers within 30 days; (ii) the documentation of the technical and organisational measures; (iii) audit or security testing reports, where available.

10.3 An on-site audit is possible if the verifications above are not sufficient, subject to 30 days' notice, at most once per calendar year, during business hours, without disrupting operations and respecting confidentiality towards other customers. Each party bears its own costs; effort exceeding one working day may be invoiced by RavenBI at its usual rates.

11. Liability

The liability of the parties is as set out in the main contract, without prejudice to Article 82 GDPR.

12. Final provisions

12.1 In the event of a conflict between this DPA and the main contract, this DPA prevails as regards data protection.

12.2 The applicable law and the competent court are those set out in the main contract.

12.3 If any provision is invalid, the remainder stays in force.


Data protection enquiries: Corrections and reports · Privacy Policy · Terms of Service