Navigation menu

Data Processing Agreement

Article 28 GDPR terms for organisation and institution customers

1. Scope and roles

This Data Processing Agreement ("DPA") applies whenever you use Scraiber on behalf of an organisation, institution or other legal entity (the "Customer") and personal data of the Customer's members is processed in the Services. It forms part of, and is incorporated into, our Terms of Use. No signature is required: it takes effect when the Customer accepts the Terms of Use. If the Customer requires a countersigned copy for its procurement process, write to [email protected].

For the personal data processed on the Customer's instructions, the Customer is the controller and Scraiber GmbH is the processor within the meaning of Article 4 GDPR. For data we process for our own purposes — billing, security, and operating and improving the Services — we act as an independent controller and our Privacy Notice applies.

2. Subject matter, duration, nature and purpose

We process the personal data for the sole purpose of providing the Services described in the Terms of Use: hosting documents, running the editor and library, enabling real-time collaboration, executing the AI features the user triggers, and providing support. Processing lasts for as long as the Customer's account exists and ends with its deletion.

3. Categories of data subjects and personal data

Data subjects: the Customer's members who use the Services (typically researchers, students and administrative staff). Personal data: account data (name, email address, job title, institution, profile picture), authentication data, usage and log data, and any personal data the Customer's members themselves place in documents, uploads or prompts.

4. Instructions

We process the personal data only on the Customer's documented instructions. The Terms of Use, this DPA, and the configuration the Customer chooses in the admin area constitute those instructions. If we believe an instruction infringes data protection law, we will inform the Customer and may suspend the affected processing. Where we are required by EU or Member State law to process beyond the Customer's instructions, we will inform the Customer before processing unless that law prohibits it.

5. Confidentiality

Every person authorised to process the personal data is bound by a written confidentiality obligation or an appropriate statutory duty of confidentiality, and that obligation survives the end of their engagement.

6. Security of processing

We implement technical and organisational measures appropriate to the risk under Article 32 GDPR. These include encryption in transit and at rest, role-based access control with least privilege, separated production and development environments, multi-factor authentication for administrative access, logging and monitoring with credentials and email addresses scrubbed from telemetry, automated backups with restore testing, and regular dependency and configuration scanning. A current description of the measures is available on request.

7. Sub-processors

The Customer grants general authorisation for the sub-processors listed below. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain fully liable for their performance. We will announce any intended addition or replacement at least 30 days in advance by email to the Customer's administrators. The Customer may object on reasonable data protection grounds within that period; if we cannot accommodate the objection, the Customer may terminate the affected Services without penalty.

Sub-processorPurposeProcessing location
Amazon Web Services EMEA SARLApplication hosting, databases, file storage, backups, authentication, email delivery and machine-learning endpointsUnited States, United Kingdom, Singapore
Cloudflare, Inc.DNS, content delivery, bot protection and DDoS mitigationGlobal edge network
Vercel Inc.Hosting of the web front endsUnited States
Stripe Payments Europe, Ltd.Payment processing, invoicing and subscription managementIreland, United States
OpenAI, L.L.C.AI models for writing assistance, when the user selects an OpenAI modelUnited States
Anthropic, PBCAI models for writing assistance, when the user selects a Claude modelUnited States
Google LLCGemini API for writing assistance, and Google Sign-In where the user chooses itUnited States
Fireworks AI, Inc.Serving of open-weight AI models, when the user selects oneUnited States
Mathpix, Inc.Conversion of uploaded images and formulas into LaTeXUnited States
Slack Technologies, LLCInternal operational notifications about sign-ups and paymentsUnited States
Termly, Inc.Consent management and hosting of the legal documentsUnited States

8. International transfers

Personal data is processed in the United States, the United Kingdom and Singapore. Transfers outside the EEA are covered by the European Commission's Standard Contractual Clauses, together with supplementary measures where required. The Customer authorises us to conclude the Standard Contractual Clauses with sub-processors on its behalf.

9. Assistance with data subject rights

The Services let administrators access, correct, export and delete the data of their members directly. Where that is not sufficient, we will assist the Customer with appropriate technical and organisational measures in responding to requests under Chapter III GDPR. If a data subject contacts us directly, we will refer them to the Customer.

10. Breach notification and assistance

We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, and will provide the information the Customer needs for its own notification duties. We will also assist the Customer with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR.

11. Return and deletion

On termination the Customer may export its data from the Services. We delete the personal data within 30 days of the end of the contract, except where EU or Member State law requires longer retention. Backups are overwritten on their normal rotation and are isolated from further processing until then.

12. Audits

On request we provide the information necessary to demonstrate compliance with Article 28 GDPR. The Customer may audit us, or mandate an independent auditor bound by confidentiality, at most once per year and on 30 days' notice, at reasonable times and without disrupting our operations. The Customer bears the cost unless the audit reveals a material breach.

13. Contact

For any matter arising under this DPA, including requests for a countersigned copy, the description of security measures or notice of sub-processor changes, write to [email protected].