SRI Group
HomeContact

Data Processing Agreement

Between SRI Group BV ("Processor") and Client ("Controller")

1. Roles

For purposes of GDPR: Client = Data Controller; SRI Group BV = Data Processor. Processor acts only on documented instructions of the Controller.

2. Scope of Processing

Processing activities may include: AI systems architecture, workflow automation, knowledge infrastructure, data analysis, and AI integration.

3. Categories of Data

As determined by Controller. May include customer data, employee data, business contact data, and operational records.

4. Processor Obligations

Processor shall:

  • Process data only on documented instructions
  • Ensure confidentiality
  • Implement appropriate security measures
  • Assist with GDPR compliance
  • Notify Controller of data breaches without undue delay
  • Delete or return data upon termination

5. Subprocessors

Processor may engage subprocessors (e.g., cloud providers). Processor ensures equivalent data protection obligations via contractual agreements.

6. Security

Security measures include role-based access control, encryption where applicable, secure hosting infrastructure, and internal access policies.

7. AI Training Restriction

Client data shall not be used to train general-purpose AI models or shared across clients unless explicitly agreed in writing.

8. Data Deletion

Upon termination, Processor shall return data or securely delete data, as instructed by Controller.

9. Governing Law

This DPA is governed by Belgian law.

© 2026 SRI Group BV Terms of Service Privacy Policy DPA Korte Gasthuisstraat 18/301 · 2000 Antwerp sri-group.eu