Legal

Data Processing Agreement

Last updated: August 2026

Parties & scope

This Data Processing Agreement ("DPA") is entered into between the Customer ("Controller") and Atela Capital S.L., trading as Drel ("Processor"), a company registered in Madrid, Spain.

This DPA supplements the Terms of Service and forms part of the agreement between Controller and Processor. It applies whenever Drel processes personal data on behalf of the Customer in connection with the Drel AI security review platform.

In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.

Definitions

Personal Data means any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.

Processing means any operation or set of operations performed on personal data, whether or not by automated means, as defined in Article 4(2) GDPR.

Controller means the Customer, who determines the purposes and means of processing personal data.

Processor means Atela Capital S.L. (trading as Drel), who processes personal data on behalf of the Controller.

Sub-processor means any third party engaged by the Processor to process personal data on behalf of the Controller.

Data Subject means the identified or identifiable natural person to whom the personal data relates.

GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).

Standard Contractual Clauses (SCCs) means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission (Commission Implementing Decision (EU) 2021/914).

Data processing details

Subject matter. The processing concerns the provision of AI security review generation services through the Drel platform.

Duration. Processing continues for the term of the agreement between Controller and Processor, plus the period required for deletion of personal data in accordance with this DPA.

Nature of processing. Automated processing via large language models (LLMs) hosted on AWS Bedrock. AWS Bedrock does not use customer inputs or outputs to train its foundation models and does not retain them after processing.

Purpose. Generating AI Security Reviews — including threat analysis, control recommendations, attack path derivation, and disposition recommendations — based on system architecture descriptions provided by the Controller.

Categories of data subjects. Customer's employees, contractors, and users whose roles or activities are described in the system architectures submitted for assessment.

Types of personal data. Names, email addresses, role descriptions, organizational titles, and system access patterns as described in assessment inputs submitted by the Controller.

Processor obligations

The Processor shall:

Process on instructions only. Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by EU or Member State law (in which case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).

Confidentiality. Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Security measures. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including: encryption at rest (AES-256), encryption in transit (TLS 1.2+), logical access controls, multi-factor authentication for all production access, and regular security assessments.

Sub-processors. Engage sub-processors only with prior written consent of the Controller. The Controller provides general authorization for the Processor to engage sub-processors listed in this DPA, subject to the Processor notifying the Controller of any intended changes (additions or replacements) at least 15 days in advance.

Data subject requests. Assist the Controller in responding to requests from data subjects exercising their rights under GDPR. The Processor shall notify the Controller of any data subject request within 5 business days and provide reasonable assistance to respond within 10 business days of receiving the request.

Data protection impact assessments. Provide reasonable assistance to the Controller in conducting data protection impact assessments and prior consultations with supervisory authorities, where required.

Deletion or return. At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies within 30 days unless EU or Member State law requires storage of the personal data.

Audit rights. Make available to the Controller all information necessary to demonstrate compliance with obligations under Article 28 GDPR, and allow for and contribute to audits conducted by the Controller or a mandated auditor. Audits shall be limited to once per year, require 30 days' advance written notice, take place during normal business hours, and the auditor shall be bound by a non-disclosure agreement.

Sub-processors

The Processor currently engages the following sub-processors:

Amazon Web Services (AWS) — Infrastructure and AI model hosting. Processing location: EU (eu-central-1, eu-west-1). AWS Bedrock does not train on customer data.

Vercel — Application hosting and edge delivery. Processing location: EU/US. Transfers governed by Standard Contractual Clauses.

Stripe — Payment processing and billing. Processing location: US. Transfers governed by Standard Contractual Clauses.

Clerk — Authentication and identity management. Processing location: US. Transfers governed by Standard Contractual Clauses.

Amplitude — Product analytics. Processing location: US. Transfers governed by Standard Contractual Clauses.

The Controller has 15 calendar days from receipt of notification to object to a new sub-processor. Objections must be reasonable and based on data protection grounds. If the Processor and Controller cannot resolve the objection within 15 days of the Processor receiving it, the Controller may terminate the affected services by providing written notice.

The Processor shall impose on each sub-processor, by way of contract, data protection obligations no less protective than those set out in this DPA.

International transfers

Primary processing takes place in the European Union (AWS eu-central-1 and eu-west-1 regions).

Where a transfer of personal data outside the European Economic Area is required (for example, to sub-processors located in the United States), such transfer shall be governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2: Controller to Processor.

Supplementary measures. In addition to the SCCs, the following supplementary measures apply to all international transfers: encryption of personal data in transit and at rest, strict logical access controls limiting access to authorized personnel, contractual commitments from sub-processors to notify the Processor of any government access requests, and the Processor's commitment to challenge any request for mass or disproportionate access to personal data.

Security measures

Technical measures: • Encryption at rest using AES-256 • Encryption in transit using TLS 1.2+ • Network segmentation and firewall rules • Automated vulnerability scanning • DDoS protection via CDN and WAF • Automated backups with point-in-time recovery • Secure key management via AWS KMS

Organizational measures: • Role-based access control with least privilege principle • Multi-factor authentication for all production system access • Security awareness training for all personnel with access to personal data • Documented incident response procedures • Regular internal security assessments • Vendor security review for all sub-processors

Data breach notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Controller's personal data.

The notification shall include:

• The nature of the personal data breach, including where possible the categories and approximate number of data subjects concerned • The categories and approximate number of personal data records concerned • The likely consequences of the personal data breach • The measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects

Where it is not possible to provide all information at the same time, the information may be provided in phases without undue further delay. The Processor shall document all personal data breaches and make the documentation available to the Controller on request.

Term & termination

This DPA is effective from the date the Controller accepts the Terms of Service and shall remain in effect for the duration of the Terms.

This DPA automatically terminates when the Terms of Service terminate, subject to the Processor's obligation to delete or return personal data as specified in Section 4.

On termination: The Processor shall delete all Controller personal data within 30 days of termination, except where EU or Member State law requires continued storage. Upon request, the Processor shall provide written confirmation of deletion.

Survival. The confidentiality obligations, audit rights, and indemnification provisions of this DPA shall survive termination.

Governing law

This DPA shall be governed by and construed in accordance with the laws of Spain.

Any dispute arising out of or in connection with this DPA shall be submitted to the exclusive jurisdiction of the courts of Madrid, Spain.

This is without prejudice to the rights of data subjects under GDPR, including the right to lodge complaints with supervisory authorities and to seek judicial remedy in the Member State of their habitual residence.

How to execute

This DPA is incorporated into and forms part of the Terms of Service. By creating a Drel account and using the platform, the Customer accepts this DPA on behalf of themselves and (where applicable) their organization.

No separate signature is required for the DPA to be binding.

Enterprise customers requiring a countersigned copy of this DPA or needing to incorporate it into a master services agreement: contact hello@drel.ai and we will provide a version suitable for individual execution within 5 business days.

Need a countersigned copy?

Enterprise customers requiring individual execution of this DPA — contact our legal team.

hello@drel.ai →