Sykik
SecurityPricing
Request early access
Back to sykik.ai

Data Processing Agreement

Version 1 August 2026Effective 1 August 202617 sectionssykik.ai/dpa

This Data Processing Agreement ("DPA") is entered into between the Customer ("Controller") and Sykik [FlexCo i.G.] ("Processor") and forms part of the Sykik Terms of Service or separate written agreement between the parties (the "Main Agreement"). This DPA applies where and to the extent the Processor processes Personal Data on behalf of the Controller under the Main Agreement.

One agreement, four documents — plus the Imprint
Terms of ServicePrivacy PolicyData Processing AgreementSecurity · TOMsImprint

The Terms of Service incorporate the Privacy Policy and the DPA by reference. The measures published on the Security page are Annex III of the DPA. The Imprint is the disclosure required by § 5 ECG and is not part of the agreement.

Sections
  1. 1Definitions
  2. 2Subject matter and duration
  3. 3Processor obligations
  4. 4Controller obligations
  5. 5Personal data breach notification
  6. 6Sub-processors
  7. 7International data transfers
  8. 8Audit rights
  9. 9Liability
  10. 10Termination and data deletion
  11. 11Governing law
  12. 12Order of precedence
  13. The parties
  14. IAnnex I — Details of processing
  15. IIAnnex II — Sub-processors
  16. IIIAnnex III — Measures
  17. IVAnnex IV — SCC cross-reference
SECTION 1

Definitions

"Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Personal Data Breach," and "Supervisory Authority" shall have the meanings given in Article 4 of the GDPR.

"Sub-Processor" means any processor engaged by the Processor to process Personal Data on behalf of the Controller under this DPA, as listed in Annex II or subsequently approved in accordance with Section 6.

"Standard Contractual Clauses" ("SCCs") means the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (Commission Implementing Decision (EU) 2021/914 of 4 June 2021).

SECTION 2

Subject Matter, Nature, Purpose, and Duration

The subject matter, nature, and purpose of the Processing, the types of Personal Data, and categories of Data Subjects are set out in Annex I.

The Processing shall continue for the term of the Main Agreement or until the Controller instructs the Processor to cease processing and delete all Personal Data.

SECTION 3

Processor Obligations

The Processor shall:

  • process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
  • ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • take all measures required pursuant to Article 32 GDPR (Security of Processing), and as further described in Annex III (Technical and Organisational Measures);
  • respect the conditions referred to in paragraphs 2 and 4 of Article 28 for engaging another processor (see Section 6 of this DPA);
  • taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR;
  • assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR (security, data breach notification, data protection impact assessment, and prior consultation with the Supervisory Authority), taking into account the nature of processing and the information available to the Processor;
  • at the choice of the Controller, delete or return all the Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data;
  • make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

SECTION 4

Controller Obligations

The Controller shall:

  • ensure that it has a lawful basis for the Processing of Personal Data under Article 6 GDPR and, where applicable, Article 9 GDPR (special categories of data), and that the Controller's instructions to the Processor comply with all applicable data protection laws;
  • ensure that Data Subjects have been provided with all information required under Articles 13 and 14 GDPR, including the identity of the Processor and any Sub-Processors;
  • provide the Processor with documented instructions as required under this DPA, and notify the Processor promptly of any changes that affect the Processing.
SECTION 5

Personal Data Breach Notification

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA. The notification shall:

  • describe the nature of the Personal Data Breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
  • communicate the name and contact details of the Data Protection Officer or other contact point where more information can be obtained;
  • describe the likely consequences of the Personal Data Breach;
  • describe the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach. Where feasible, this notification shall be made within 72 hours of becoming aware.

SECTION 6

Sub-Processors

The Controller authorises the Processor to engage the Sub-Processors listed in Annex II. The Processor shall:

  • inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors at least 14 days in advance by email to the address registered with the Controller's Sykik account, thereby giving the Controller the opportunity to object to such changes;
  • impose data protection obligations on the Sub-Processor that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the GDPR;
  • where the Sub-Processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-Processor's obligations.
SECTION 7

International Data Transfers

The Controller acknowledges that certain Sub-Processors listed in Annex II process data outside the European Economic Area (EEA). Transfers are governed by:

  • an adequacy decision of the European Commission pursuant to Article 45(3) GDPR (including the EU-US Data Privacy Framework for certified recipients);
  • the Standard Contractual Clauses (Module 2: Controller to Processor and Module 3: Processor to Processor) adopted under Article 46(2)(c) GDPR; or
  • binding corporate rules approved under Article 47 GDPR.

The SCCs are incorporated by reference into this DPA. Where the SCCs apply, the Controller is the "data exporter" and the Processor is the "data importer" (or sub-exporter/sub-importer, as appropriate under the onward transfer chain). A Transfer Impact Assessment has been documented and is available on request.

SECTION 8

Audit Rights

The Controller may audit the Processor's compliance with this DPA. Audits shall be:

  • upon reasonable written notice (minimum 30 days);
  • during normal business hours;
  • conducted no more than once per calendar year, unless an audit is required by a Supervisory Authority or follows a confirmed Personal Data Breach;
  • at the Controller's own cost, including the Processor's reasonable time and expenses in supporting the audit.

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance. The Controller may appoint an independent auditor, provided the auditor enters into a confidentiality agreement with the Processor.

SECTION 9

Liability

Each party's liability arising out of or related to this DPA shall be subject to the limitations and exclusions of liability set out in the Main Agreement. Nothing in this DPA limits either party's liability to a Data Subject or to the extent prohibited by applicable law.

SECTION 10

Termination and Data Deletion

This DPA terminates automatically upon termination or expiry of the Main Agreement. Upon termination, the Processor shall, at the Controller's choice:

  • delete all Personal Data, except to the extent that EU or Member State law requires ongoing storage; or
  • return all Personal Data to the Controller in a common, machine-readable format.

Deletion shall be completed within 30 days of the termination date. Residual copies held in encrypted backups shall be automatically overwritten in accordance with the backup rotation schedule (currently ~35 days). The Processor shall confirm deletion in writing upon the Controller's request.

SECTION 11

Governing Law and Jurisdiction

This DPA shall be governed by the law governing the Main Agreement. Any disputes arising from this DPA shall be subject to the jurisdiction of the courts specified in the Main Agreement. Nothing in this DPA affects the rights of Data Subjects to bring claims under the GDPR.

SECTION 12

Order of Precedence

In the event of any conflict between this DPA, the Standard Contractual Clauses (where applicable), and the Main Agreement, the following order of precedence applies:

  • Standard Contractual Clauses
  • This Data Processing Agreement
  • The Main Agreement
PREAMBLE

The Parties

This DPA is entered into by the duly authorised representatives of the parties. It forms part of the Terms of Service, which Customer accepts electronically on creating an account; a countersigned execution copy is available on request.

Controller
The Customer, as identified in the Main Agreement. Company, signatory, title, date and [Registered Address] completed on execution.
Processor
Sykik [FlexCo i.G.] · Signatory: Niklas Retzl, CEO · Wollzeile 6-8, 46, 1010 Vienna, Austria · FN: [INSERT AFTER INCORPORATION] · DPO: Hermann Wagner, sykik-privacy@sykik.ai
ANNEX I

Annex I — Details of Processing

A. List of Parties

Data Exporter (Controller): As identified in the Main Agreement and the Parties section above.

Data Importer (Processor): Sykik [FlexCo i.G.], [Registered Address], [FN Number].

Data Protection Officer: Hermann Wagner, sykik-privacy@sykik.ai

B. Description of Processing

Subject matter
Provision of the Sykik AI productivity service: AI-assisted email drafting, analysis, summarisation, calendar management, chat responses, document processing, and proactive work suggestions integrated with the Controller's Google Workspace or Microsoft 365 environment.
Duration
For the term of the Main Agreement.
Nature and purpose
Analysis, drafting, summarisation, scheduling, and suggestion generation using AI models routed by the Processor on behalf of the Controller for the purpose of increasing workplace productivity. The Processor does not make autonomous decisions without human review.
Type of Personal Data
Email content and metadata (from/to/cc/bcc, subject, body, attachments); chat messages; calendar event data (title, participants, time, location, description); document content; workspace user identifiers (user ID, display name, email); OAuth tokens; conversation history and AI-generated outputs; service logs (timestamps, error logs, request metadata); voice/audio data (where enabled, with explicit consent).
Categories of Data Subjects
Employees, contractors, and authorised users of the Controller who use the Sykik Service; individuals who communicate with those users via email, chat, or calendar invitations.
Sensitive Data
None intentionally processed. The Controller shall not route special categories of data under Art. 9 GDPR through the Service.

C. Competent Supervisory Authority

Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria. dsb.gv.at

ANNEX II

Annex II — Authorised Sub-Processors

The Controller authorises the following Sub-Processors. The Processor will notify the Controller at least 14 days in advance of any addition or replacement in accordance with Section 6 of this DPA.

Sub-processor
Service
Processing location
Adequacy / transfer safeguard
Google Cloud Platform
Service
Cloud infrastructure, hosting, compute
Processing location
EU (europe-west)
Adequacy / transfer safeguard
Adequacy (Art. 45)
OpenRouter, Inc.
Service
AI model inference gateway
Processing location
USA
Adequacy / transfer safeguard
SCCs (Module 3) + EU-US DPF
Anthropic / OpenAI / Google / Mistral / model providers
Service
Underlying LLM inference (via OpenRouter)
Processing location
Depends on Provider
Adequacy / transfer safeguard
SCCs (Module 3) via OpenRouter chain
Clerk
Service
Authentication and SSO
Processing location
USA
Adequacy / transfer safeguard
DPF certified
Stripe
Service
Payment processing
Processing location
USA
Adequacy / transfer safeguard
SCCs
Brevo
Service
Transactional and marketing email
Processing location
France (EU)
Adequacy / transfer safeguard
Adequacy (Art. 45)
PostHog
Service
Product analytics
Processing location
EU (EU Cloud)
Adequacy / transfer safeguard
Adequacy (Art. 45)
Cloudflare
Service
CDN, DDoS protection, DNS
Processing location
Global (EU preference)
Adequacy / transfer safeguard
SCCs + DPF
Slack
Service
Messaging integration (if enabled)
Processing location
USA
Adequacy / transfer safeguard
SCCs
HubSpot
Service
CRM integration (if enabled)
Processing location
USA / EU
Adequacy / transfer safeguard
SCCs
Meta Ads
Service
Ads integration (if enabled)
Processing location
USA
Adequacy / transfer safeguard
SCCs
Google Ads
Service
Ads integration (if enabled)
Processing location
USA / EU
Adequacy / transfer safeguard
SCCs
QuickBooks
Service
Finance/accounting integration (if enabled)
Processing location
USA
Adequacy / transfer safeguard
SCCs
Shopify
Service
E-commerce integration (if enabled)
Processing location
USA / Canada
Adequacy / transfer safeguard
SCCs
Notion
Service
Workspace integration (if enabled)
Processing location
USA
Adequacy / transfer safeguard
SCCs
Moz
Service
SEO integration (if enabled)
Processing location
USA
Adequacy / transfer safeguard
SCCs
Pipedream
Service
Integration connectivity platform (if enabled)
Processing location
USA
Adequacy / transfer safeguard
SCCs
Composio
Service
Integration connectivity platform (if enabled)
Processing location
USA
Adequacy / transfer safeguard
SCCs
Zapier
Service
Integration connectivity platform (if enabled)
Processing location
USA
Adequacy / transfer safeguard
SCCs
Google Workspace APIs
Service
Source integration — Gmail, Calendar, Drive, Chat
Processing location
EU (customer-tenant region)
Adequacy / transfer safeguard
Adequacy (Art. 45) / SCCs depending on tenant region
Microsoft Graph API
Service
Source integration — Outlook, OneDrive, Teams (if enabled)
Processing location
EU (customer-tenant region)
Adequacy / transfer safeguard
SCCs
ANNEX III

Annex III — Technical and Organisational Measures

The Processor maintains the following Technical and Organisational Measures (TOMs) pursuant to Article 32 GDPR, corresponding to those published in the Processor's Privacy Policy (Section 14). These TOMs are also published as a standalone document at sykik.ai/security for transparency during security reviews.

Pseudonymisation and encryption of personal data
Encryption in transit: TLS 1.3. Encryption at rest: AES-256 via GCP-managed keys (Customer-Managed Encryption Keys under evaluation). Secrets (API keys, OAuth tokens) stored in GCP Secret Manager.
Confidentiality
All personnel with access to Personal Data are bound by confidentiality obligations. RBAC (Role-Based Access Control) enforced with least-privilege policies. Multi-factor authentication required for all administrative access.
Integrity
Immutable audit logging enabled on all production systems. Change management processes for production deployments. Code review requirements for all changes affecting data processing.
Availability and resilience
GCP infrastructure with automatic failover, redundancy across availability zones. Daily encrypted backups with ~35-day rotation. Incident response runbook with escalation paths. Target RTO: 4 hours, RPO: 24 hours.
Ability to restore availability and access
Backup restoration tested quarterly. Disaster recovery plan documented and reviewed annually.
Process for regularly testing, assessing, and evaluating effectiveness
Annual penetration testing and vulnerability scanning. SOC 2 Type 2 audit planned. Continuous monitoring via service logs and alerting.
Data minimisation
OAuth scoped per integration and per user — only explicitly authorised data categories accessible. ZDR (Zero Data Retention) enabled on AI inference endpoints where available. Data retention periods enforced per the Privacy Policy (Section 12).
Physical security
Data centres operated by GCP with ISO 27001, SOC 2, SOC 3 certifications. Physical access controlled by the cloud provider; Sykik personnel do not have physical access to data centre facilities.
Organisational measures
Data Protection Officer appointed. Privacy-by-design and default approach. Staff training on data protection at onboarding and annually. Sub-processor management process including due diligence and DPA requirements.
ANNEX IV

Annex IV — Standard Contractual Clauses (Cross-Reference)

Where transfers are subject to the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the parties agree that:

  • Clause 7 (Docking Clause): The optional clause is included.
  • Clause 9 (Use of sub-processors): Option 2 (General Written Authorisation) with 14 days' prior notice applies, as set out in Section 6 of this DPA.
  • Clause 11 (Redress): The optional language is not included; Data Subjects shall be entitled to redress from the Data Importer or its representatives.
  • Clause 17 (Governing Law): The law of Austria shall govern.
  • Clause 18 (Choice of Forum and Jurisdiction): Any dispute arising from the SCCs shall be resolved by the competent courts of Vienna, Austria.
  • Annexes I-III of this DPA serve as Annexes I, II, and III of the SCCs.
  • The competent Supervisory Authority is the Österreichische Datenschutzbehörde.
The rest of the legal section
Terms of ServiceThe agreement that governs access to and use of Sykik.Privacy PolicyHow Sykik handles your data, and the rights you have over it.Technical and Organisational MeasuresThe Article 32 controls behind the Service — where a security review starts.Impressum — Legal DisclosureWho operates sykik.ai, and who is answerable for it.
Sykik

AI agents that do the work — on the model you choose.

Product
  • What Sykik delivers
  • Chatbot vs. Sykik
  • How it works
  • Control & security
  • FAQ
Resources
  • Blog
  • Pricing
  • Security
Company
  • Contact
  • Imprint
Legal
  • Privacy
  • Terms
  • DPA
© 2026 Sykik. All rights reserved.Logos provided by Logo.dev