Data Processing Agreement

    Last updated: 2 August 2026 · Version 1.0

    This agreement governs the processing of personal data that Orakis carries out on your behalf under Art. 28 GDPR. Its structure follows the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/915.

    It forms part of the Terms of Service and takes effect automatically when you use Orakis as a business customer.

    Where this agreement and the Terms of Service conflict on data protection, this agreement prevails.


    1. The parties

    The controller is you, the customer identified in the Orakis account. The processor is Abdullah Emin Koç, trading as Orakis, Schneideräckerstraße 8, 70378 Stuttgart, Germany.

    For data protection matters, write to info@orakis.com.


    2. Subject matter and duration

    We process personal data on your behalf solely to provide the services described in the Terms of Service.

    This agreement runs for as long as your contract runs. Our obligations regarding deletion and confidentiality survive its end.


    3. Your instructions

    We process personal data only on your documented instructions. Your use of the service is itself an instruction: connecting a mailbox instructs us to retrieve and process that mailbox. Instructions that go beyond ordinary use of the service must be given in text form to info@orakis.com.

    We will tell you immediately if we consider an instruction to breach the GDPR or other data protection law, and we may suspend that instruction until you confirm it.

    We do not process your data for our own purposes. We do not sell it, we do not use your content for advertising, and we do not use your content to train AI models, which we require of our AI providers as well.

    For a limited set of data we are the controller rather than your processor: account and billing data, and aggregated usage statistics that contain no content and permit no inference about individuals. Our Privacy Policy covers that.


    4. What we process

    The categories of data subjects and of personal data, the nature and purpose of the processing, and how long it lasts are set out in Annex I.


    5. Confidentiality

    Everyone we authorise to process your data is bound to confidentiality and has been instructed on data protection. That obligation continues after they stop working for us.

    Access is granted only where it is necessary. Access to production data for support purposes requires a specific reason and is logged.


    6. Security

    We implement appropriate technical and organisational measures under Art. 32 GDPR. These are described in Annex II.

    We may change these measures. We will not lower the overall level of protection.


    7. Sub-processors

    You give us general authorisation to engage sub-processors, and Annex III below explains how to obtain the current list. Before adding or replacing one, we will announce it at least 30 days in advance, and you can subscribe to those notifications by writing to info@orakis.com.

    You may object on reasonable data protection grounds within 30 days. If we cannot resolve your objection, you may terminate the affected services with effect from the date the change takes effect, and we will refund fees paid in advance for services not yet provided.

    We impose the same data protection obligations on every sub-processor as apply to us under this agreement, and we remain fully liable to you for their performance.

    Orakis also lets you connect your workspace to an external AI client of your own choosing. If you enable that, the recipient is not our sub-processor. You select that provider, you agree its terms, and the transfer happens on your instruction, so we are not responsible for what happens to your data once it arrives there. The connection is only ever established after you explicitly confirm it in the application, and you can revoke it at any time.


    8. Transfers outside the EU

    Some sub-processors are located in the United States. The list described in Annex III states for each one where it processes data and on what legal basis any transfer rests.

    Where a transfer is not covered by an adequacy decision, it is based on the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by additional safeguards where our assessment shows they are needed.

    We will make transfer impact assessments available on request.


    9. Helping you meet your obligations

    If a data subject contacts us directly, we will not respond on the merits, but forward the request to you without undue delay. The application gives you the tools to access, correct, export and delete data yourself, and where you still need our help we will provide it. Reasonable assistance is free of charge. Where your requests go substantially beyond that, we may charge for the time at our standard rates, after telling you in advance.

    We will also support your data protection impact assessments and any prior consultation with a supervisory authority under Arts. 35 and 36 GDPR, with the information available to us.


    10. Personal data breaches

    If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and early enough for you to meet your own reporting deadline under Art. 33 GDPR.

    The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

    Where we cannot provide all of it at once, we will provide it in phases without further undue delay.

    Notifying the supervisory authority under Art. 33 GDPR and the data subjects under Art. 34 GDPR is your responsibility, since you are the controller. We will support you with everything we have.


    11. Audits

    We will make available all information necessary to demonstrate compliance with Art. 28 GDPR.

    You may audit us, including by inspection, once per calendar year, with 30 days' notice, during business hours, and without unreasonable disruption to our operations. You may appoint an independent auditor, who must not be our competitor and must be bound to confidentiality.

    If a supervisory authority has grounds, an audit may take place more often and at shorter notice.

    We may satisfy audit obligations by providing current certifications or audit reports from our sub-processors, where these cover the subject matter of your audit.


    12. Deletion and return

    On termination we delete your personal data, or return it, at your choice.

    The application lets you export your data at any time in a machine-readable format. After termination your data stays available for 30 days so you can export it. We then delete it, and it is removed from backups within a further 30 days.

    We may retain data where EU or member state law requires it. In that case we restrict processing to what that law requires.

    We will confirm deletion in writing on request.


    Annex I: Description of the processing

    Categories of data subjects

    • Your employees and other users you invite
    • Senders and recipients of emails in connected mailboxes
    • Participants in calendar entries
    • Persons named in documents, notes or messages you bring into Orakis
    • Your contacts, customers and suppliers, where they appear in that content

    Note that the second and third categories are typically the largest. Anyone who has written to your employees appears in Orakis without ever having had a relationship with us.

    Categories of personal data

    CategoryExamples
    Account dataName, email address, password hash, profile picture, time zone
    Usage dataLast activity, AI usage volume
    Communication contentEmail bodies, subject lines, senders, recipients, attachments
    Calendar dataAppointments, participants, descriptions, locations
    Document contentUploaded files and text extracted from them
    User contentNotes, knowledge entries, goals, tasks, messages, comments
    AI contextConversation history and derived summaries, which may contain extracts of all of the above

    Special categories of data

    Orakis is not designed for special categories of personal data under Art. 9 GDPR.

    We cannot prevent such data appearing in an email or a document. Where it does, it falls under this agreement and the measures in Annex II. If you know that you will process special categories systematically, tell us before you begin and we will then agree additional measures with you.

    Nature and purpose of the processing

    Storage, retrieval, organisation, structuring, analysis and deletion, for the purpose of providing a workspace with AI-assisted summarisation, prioritisation and search.

    How mailbox and calendar content is handled

    This point matters for your own record of processing activities:

    We do not store your mailbox. Emails and calendar entries are retrieved live from the connected account when you view them, and are not copied into our database.

    One exception. When the AI assistant processes an email or an appointment because you asked it to, extracts become part of the conversation history and of the assistant's memory, and are stored there until you delete the conversation.

    Duration

    For the duration of the contract, plus the grace period described in section 12.


    Annex II: Technical and organisational measures

    This annex describes the measures in place at the version date shown at the top of this document. We may change them, and we will not lower the overall level of protection.

    Confidentiality

    Access control (physical). All systems run in the data centres of our providers (see Annex III). Physical security is theirs; we select providers that hold recognised certifications.

    Access control (system). Access to the application requires an individual account with a password, or single sign-on via an external identity provider. Passwords are stored as salted hashes. Administrative access to our providers is limited to the business owner and protected by individual credentials.

    Access control (data). The application enforces a workspace model: users see only data in workspaces they belong to. Documents additionally carry visibility settings (private / workspace) and an AI access flag.

    Separation. Customer data is logically separated by workspace identifier. Every database query is scoped to the authenticated user's workspace.

    Integrity

    Transmission. All connections use TLS 1.2 or higher. There is no unencrypted transport of personal data.

    Storage. Data is held in the managed database of our backend provider, whose platform-level protections apply. Credentials for connected apps are stored with restricted field-level access so that they are never returned through the API.

    Input control. Changes to content are attributed to a user identity and timestamped.

    Availability

    Backups. Our backend provider operates regular backups of the database as part of its managed platform.

    Resilience. The infrastructure is operated by providers with redundant systems.

    Procedures for regular review

    Incident response. Suspected breaches are investigated immediately. Notification to affected customers follows section 10 of this agreement.

    Order control. Sub-processors are engaged only under a data processing agreement. Annex III describes them.

    Data protection by design and by default. New features are assessed for the personal data they require. The mailbox architecture is an applied example: content is retrieved live rather than copied, so that we hold as little as possible.

    Deletion. Users can delete content in the application. Deletion propagates to backups within the cycle stated in section 12.


    Annex III: Sub-processors

    We engage a small number of providers to run Orakis. One holds the database and the files you upload, one hosts the website and the application, one supplies the AI models, one handles payments, and one sends transactional email such as account verification and notifications. Content you bring into Orakis reaches the first three of these; the other two see only your account and billing details.

    The database and the files are held in Germany. The remaining providers process data in the United States or in Ireland, and those transfers rest on the Standard Contractual Clauses, as described in section 8. Each provider is engaged under its standard data processing terms, which we accepted when opening the account.

    The current list naming every provider, with its purpose, its location and the basis for any transfer, is available to customers on request. Write to info@orakis.com. The same address subscribes you to advance notice of new sub-processors under section 7.

    Version history

    VersionDateChange
    1.02 August 2026Initial version