Data Processing Agreement
1. Scope and roles
This Data Processing Agreement ("DPA") applies whenever you use Scraiber on behalf of an organisation, institution or other legal entity (the "Customer") and personal data of the Customer's members is processed in the Services. It forms part of, and is incorporated into, our Terms of Use. No signature is required: it takes effect when the Customer accepts the Terms of Use. If the Customer requires a countersigned copy for its procurement process, write to [email protected].
For the personal data processed on the Customer's instructions, the Customer is the controller and Scraiber GmbH is the processor within the meaning of Article 4 GDPR. For data we process for our own purposes — billing, security, and operating and improving the Services — we act as an independent controller and our Privacy Notice applies.
2. Subject matter, duration, nature and purpose
We process the personal data for the sole purpose of providing the Services described in the Terms of Use: hosting documents, running the editor and library, enabling real-time collaboration, executing the AI features the user triggers, and providing support. Processing lasts for as long as the Customer's account exists and ends with its deletion.
3. Categories of data subjects and personal data
Data subjects: the Customer's members who use the Services (typically researchers, students and administrative staff). Personal data: account data (name, email address, job title, institution, profile picture), authentication data, usage and log data, and any personal data the Customer's members themselves place in documents, uploads or prompts.
4. Instructions
We process the personal data only on the Customer's documented instructions. The Terms of Use, this DPA, and the configuration the Customer chooses in the admin area constitute those instructions. If we believe an instruction infringes data protection law, we will inform the Customer and may suspend the affected processing. Where we are required by EU or Member State law to process beyond the Customer's instructions, we will inform the Customer before processing unless that law prohibits it.
5. Confidentiality
Every person authorised to process the personal data is bound by a written confidentiality obligation or an appropriate statutory duty of confidentiality, and that obligation survives the end of their engagement.
6. Security of processing
We implement technical and organisational measures appropriate to the risk under Article 32 GDPR. These include encryption in transit and at rest, role-based access control with least privilege, separated production and development environments, multi-factor authentication for administrative access, logging and monitoring with credentials and email addresses scrubbed from telemetry, automated backups with restore testing, and regular dependency and configuration scanning. A current description of the measures is available on request.
7. Sub-processors
The Customer grants general authorisation for the sub-processors listed below. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain fully liable for their performance. We will announce any intended addition or replacement at least 30 days in advance by email to the Customer's administrators. The Customer may object on reasonable data protection grounds within that period; if we cannot accommodate the objection, the Customer may terminate the affected Services without penalty.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Amazon Web Services EMEA SARL | Application hosting, databases, file storage, backups, authentication, email delivery and machine-learning endpoints | United States, United Kingdom, Singapore |
| Cloudflare, Inc. | DNS, content delivery, bot protection and DDoS mitigation | Global edge network |
| Vercel Inc. | Hosting of the web front ends | United States |
| Stripe Payments Europe, Ltd. | Payment processing, invoicing and subscription management | Ireland, United States |
| OpenAI, L.L.C. | AI models for writing assistance, when the user selects an OpenAI model | United States |
| Anthropic, PBC | AI models for writing assistance, when the user selects a Claude model | United States |
| Google LLC | Gemini API for writing assistance, and Google Sign-In where the user chooses it | United States |
| Fireworks AI, Inc. | Serving of open-weight AI models, when the user selects one | United States |
| Mathpix, Inc. | Conversion of uploaded images and formulas into LaTeX | United States |
| Slack Technologies, LLC | Internal operational notifications about sign-ups and payments | United States |
| Termly, Inc. | Consent management and hosting of the legal documents | United States |
8. International transfers
Personal data is processed in the United States, the United Kingdom and Singapore. Transfers outside the EEA are covered by the European Commission's Standard Contractual Clauses, together with supplementary measures where required. The Customer authorises us to conclude the Standard Contractual Clauses with sub-processors on its behalf.
9. Assistance with data subject rights
The Services let administrators access, correct, export and delete the data of their members directly. Where that is not sufficient, we will assist the Customer with appropriate technical and organisational measures in responding to requests under Chapter III GDPR. If a data subject contacts us directly, we will refer them to the Customer.
10. Breach notification and assistance
We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, and will provide the information the Customer needs for its own notification duties. We will also assist the Customer with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR.
11. Return and deletion
On termination the Customer may export its data from the Services. We delete the personal data within 30 days of the end of the contract, except where EU or Member State law requires longer retention. Backups are overwritten on their normal rotation and are isolated from further processing until then.
12. Audits
On request we provide the information necessary to demonstrate compliance with Article 28 GDPR. The Customer may audit us, or mandate an independent auditor bound by confidentiality, at most once per year and on 30 days' notice, at reasonable times and without disrupting our operations. The Customer bears the cost unless the audit reveals a material breach.
13. Contact
For any matter arising under this DPA, including requests for a countersigned copy, the description of security measures or notice of sub-processor changes, write to [email protected].