Legal

Data Processing Agreement

Last updated: October 2026

Parties & scope

This Data Processing Agreement ("DPA") is entered into between the Customer ("Controller") and Atela Capital S.L. (NIF B22564249), trading as Drel ("Processor"), a company registered in Madrid, Spain.

This DPA supplements the Terms of Service and forms part of the agreement between Controller and Processor. It applies whenever Drel processes personal data on behalf of the Customer in connection with the Drel AI security review platform.

In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters. Where the Controller and the Processor have signed an order form or master agreement, its terms and this DPA prevail over any description of the Service on Drel's website.

Definitions

Personal Data means any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.

Processing means any operation or set of operations performed on personal data, whether or not by automated means, as defined in Article 4(2) GDPR.

Controller means the Customer, who determines the purposes and means of processing personal data.

Processor means Atela Capital S.L. (trading as Drel), who processes personal data on behalf of the Controller.

Sub-processor means any third party engaged by the Processor to process personal data on behalf of the Controller.

Sub-processor List means the list of Sub-processors, with the purpose, location and transfer mechanism of each, that the Processor provides to the Controller under the Sub-processors section of this DPA.

Data Subject means the identified or identifiable natural person to whom the personal data relates.

GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).

Standard Contractual Clauses (SCCs) means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission (Commission Implementing Decision (EU) 2021/914).

Data processing details

Subject matter. The processing concerns the provision of AI security review generation services through the Drel platform.

Duration. Processing continues for the term of the agreement between Controller and Processor, plus the period required for deletion of personal data in accordance with this DPA.

Nature of processing. Storage, and automated analysis by large language models (LLMs) running on Amazon Web Services infrastructure in the European Union. Neither the Processor nor its AI provider uses customer inputs or outputs to train, fine-tune or improve any model, and the AI provider does not retain them after processing.

Purpose. Generating AI Security Reviews — including threat analysis, control recommendations, attack path derivation, and disposition recommendations — based on system architecture descriptions provided by the Controller.

Categories of data subjects. Customer's employees, contractors, and users whose roles or activities are described in the system architectures submitted for assessment.

Types of personal data. Names, email addresses, role descriptions, organizational titles, and system access patterns as described in assessment inputs submitted by the Controller.

Processor obligations

The Processor shall:

Process on instructions only. Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by EU or Member State law (in which case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).

Confidentiality. Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Security measures. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including: encryption at rest (AES-256), encryption in transit (TLS 1.2+), logical access controls, multi-factor authentication for all production access, and regular security assessments.

Sub-processors. Engage sub-processors only with prior written consent of the Controller. The Controller provides general authorization for the Processor to engage the sub-processors on the Sub-processor List, subject to the Processor notifying the Controller of any intended changes (additions or replacements) at least 15 days in advance.

Data subject requests. Assist the Controller in responding to requests from data subjects exercising their rights under GDPR. The Processor shall notify the Controller of any data subject request within 5 business days and provide reasonable assistance to respond within 10 business days of receiving the request.

Data protection impact assessments. Provide reasonable assistance to the Controller in conducting data protection impact assessments and prior consultations with supervisory authorities, where required.

Deletion or return. At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies within 30 days unless EU or Member State law requires storage of the personal data.

Audit rights. Make available to the Controller all information necessary to demonstrate compliance with obligations under Article 28 GDPR, and allow for and contribute to audits conducted by the Controller or a mandated auditor. Audits shall be limited to once per year, require 30 days' advance written notice, take place during normal business hours, and the auditor shall be bound by a non-disclosure agreement.

Sub-processors

The Processor maintains a Sub-processor List identifying each sub-processor, the processing it performs, the categories of personal data it can access, its processing location and the transfer mechanism that applies.

Provision. The Processor provides the current Sub-processor List to the Controller on execution of this DPA, and at any time on request to hello@drel.ai or security@drel.ai.

Location of processing. Content submitted for assessment is stored and analysed only in the European Union. Sub-processors that provide identity, transactional email and payment services may process account and billing data in the United States under the Standard Contractual Clauses.

Changes. The Processor shall notify the Controller by email of any intended addition or replacement of a sub-processor at least 15 days before it takes effect.

The Controller has 15 calendar days from receipt of notification to object to a new sub-processor. Objections must be reasonable and based on data protection grounds. If the Processor and Controller cannot resolve the objection within 15 days of the Processor receiving it, the Controller may terminate the affected services by providing written notice.

The Processor shall impose on each sub-processor, by way of contract, data protection obligations no less protective than those set out in this DPA.

International transfers

Content submitted for assessment is stored and analysed only in the European Union.

Where a transfer of personal data outside the European Economic Area is required (for example, account and billing data processed by sub-processors located in the United States), such transfer shall be governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 3: Processor to Processor, entered into between the Processor and the relevant sub-processor.

Supplementary measures. In addition to the SCCs, the following supplementary measures apply to all international transfers: encryption of personal data in transit and at rest, strict logical access controls limiting access to authorized personnel, contractual commitments from sub-processors to notify the Processor of any government access requests, and the Processor's commitment to challenge any request for mass or disproportionate access to personal data.

Security measures

Technical measures: • Encryption at rest using AES-256 • Encryption in transit using TLS 1.2+ • Network segmentation and firewall rules • Automated vulnerability scanning • DDoS protection via CDN and WAF • Automated daily backups, stored in the EU • Encryption keys managed by our infrastructure providers' key-management services

Organizational measures: • Role-based access control with least privilege principle • Multi-factor authentication for all production system access • Security awareness training for all personnel with access to personal data • Documented incident response procedures • Regular internal security assessments • Vendor security review for all sub-processors

Data breach notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Controller's personal data.

The notification shall include:

• The nature of the personal data breach, including where possible the categories and approximate number of data subjects concerned • The categories and approximate number of personal data records concerned • The likely consequences of the personal data breach • The measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects

Where it is not possible to provide all information at the same time, the information may be provided in phases without undue further delay. The Processor shall document all personal data breaches and make the documentation available to the Controller on request.

Term & termination

This DPA is effective from the date the Controller accepts the Terms of Service and shall remain in effect for the duration of the Terms.

This DPA automatically terminates when the Terms of Service terminate, subject to the Processor's obligation to delete or return personal data as specified in Section 4.

On termination: The Processor shall delete all Controller personal data within 30 days of termination, except where EU or Member State law requires continued storage. Upon request, the Processor shall provide written confirmation of deletion.

Survival. The confidentiality obligations, audit rights, and indemnification provisions of this DPA shall survive termination.

Governing law

This DPA shall be governed by and construed in accordance with the laws of Spain.

Any dispute arising out of or in connection with this DPA shall be submitted to the exclusive jurisdiction of the courts of Madrid, Spain.

This is without prejudice to the rights of data subjects under GDPR, including the right to lodge complaints with supervisory authorities and to seek judicial remedy in the Member State of their habitual residence.

How to execute

This DPA is incorporated into and forms part of the Terms of Service. By creating a Drel account and using the platform, the Customer accepts this DPA on behalf of themselves and (where applicable) their organization.

No separate signature is required for the DPA to be binding.

Enterprise customers requiring a countersigned copy of this DPA or needing to incorporate it into a master services agreement: contact hello@drel.ai and we will provide a version suitable for individual execution within 5 business days.

Need a countersigned copy?

Enterprise customers requiring individual execution of this DPA — contact our legal team.

hello@drel.ai →