1. What this is and how it fits together
1.1 This Data Processing Agreement (the "DPA") governs our processing of personal data contained in Customer Data, as defined in the Terms of Service (the "Terms"). It forms part of the Terms and applies automatically from the moment you use the Service, with no separate signature needed. We will sign a counterpart on request.
1.2 The parties are you, the customer identified in your account or order form (the "Customer"), and Songbird AI BV, Rue Emile Wittmann 50, 1030 Schaerbeek, Belgium, enterprise number BE 1033.450.866 ("Songbird AI", "we", "us").
1.3 Terms defined in the Terms have the same meaning here. "GDPR" means Regulation (EU) 2016/679. "Personal Data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data contained in Customer Data.
1.4 If this DPA and the Terms conflict on a data protection question, this DPA wins. If this DPA and a set of standard contractual clauses entered into between us conflict, the clauses win.
2. Roles
2.1 The Customer is the controller of Customer Personal Data, and Songbird AI is the processor. Where the Customer is itself a processor for a third party, the Customer is the processor and Songbird AI is the sub-processor, and this DPA is read accordingly.
2.2 Songbird AI is a controller in its own right for account, authentication, support and billing data about the Customer's users, and for the security logs it keeps about access to the Service. The Privacy Policy governs that processing. This DPA does not.
2.3 Each party is responsible for its own compliance with the GDPR in the role it holds. The Customer is responsible for having a lawful basis for the processing it instructs, and for the accuracy and lawfulness of the Customer Data it sends.
3. Our instructions
3.1 We process Customer Personal Data only on the Customer's documented instructions, including as regards transfers, unless EU or Member State law requires otherwise. Where such a law requires it, we will tell the Customer before processing, unless that law forbids the notification on important grounds of public interest.
3.2 The Terms, this DPA including its annexes, and the configuration choices and requests the Customer makes through the Service are the Customer's complete documented instructions. Additional instructions need to be agreed in writing, and may be chargeable where they require work outside the Service.
3.3 We will tell the Customer if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection law, and we may suspend that instruction until it is withdrawn or amended.
3.4 The Customer must not send us special categories of personal data as defined in Article 9 GDPR, nor personal data relating to criminal convictions and offences under Article 10, unless we have agreed in writing in advance how it will be handled. The Service is built for procurement, activity and spend data, and it is neither designed nor assessed for special category data.
4. Subject matter, duration, nature and purpose
4.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex I.
4.2 The processing lasts for as long as the Customer's subscription lasts, plus the period described in clause 11.
5. Confidentiality
5.1 We ensure that every person authorised to process Customer Personal Data is bound by an obligation of confidentiality, whether by contract or by statute, and that the obligation survives the end of their engagement.
5.2 Access is granted on a need to know basis and withdrawn when the need ends.
6. Security
6.1 We implement the technical and organisational measures set out in Annex II, which take account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32 GDPR.
6.2 We may update those measures as the Service evolves, provided the level of protection does not fall. The current version is always the one published at https://open-climate.ai/legal/dpa/.
6.3 Access for support and engineering. Our staff access Customer Personal Data only to operate the Service, to answer a support request, to investigate a fault or a security incident, or for the evaluation work described in clause 7, and only from within the EU or the EEA. Where an extract is used for evaluation it is de-identified first, in the sense clause 7.4 defines, it is held under the same measures as the production Service, and clause 7.2 limits what may be done with it. Every tool our engineers use that is given Customer Personal Data is a sub-processor and is listed in Annex III.
7. Using Customer Personal Data to improve the Service
7.1 The Customer instructs us, as part of the Service, to process Customer Personal Data for the purposes described in article 7.4 of the Terms: evaluating and improving retrieval, search ranking, classification, unit conversion, the harmonised factor model, quality checks and the accuracy measurement we run against them.
7.2 That instruction is subject to all of the following, and each is a limit on our authority rather than a statement of intent:
a. we use the minimum data the purpose requires, and we remove or pseudonymise direct identifiers wherever the purpose does not require them; b. the outputs are statistics, evaluation metrics, rules, vocabulary entries and test cases. We may retain de-identified extracts of Customer Data as evaluation fixtures for as long as the fixture remains useful to test the Service. Once an output or a fixture is genuinely anonymous it is no longer personal data, and the GDPR no longer applies to it; c. no output identifies the Customer, its suppliers or its volumes to any other customer or to the public; d. we do not use Customer Personal Data to train, fine tune or otherwise adapt large language models, ours or anyone else's; e. we do not publish, sell or license the underlying Customer Personal Data.
7.3 The Customer may withdraw this instruction at any time by writing to hello@open-climate.ai, with effect for the future. Withdrawal does not require us to unpick aggregate outputs already produced, which no longer identify anyone.
7.4 What de-identified means here. Before an extract of Customer Data is kept as an evaluation fixture, the personal data is removed from it. That means the names of individuals, whoever they are on the line: a supplier's contact, a requester, an approver, an employee named on a travel or expense row. It means their email addresses, telephone numbers and postal addresses, their personnel, user and account identifiers, their signatures, and any free text that identifies or describes a person.
What stays is the business information that makes a fixture worth keeping: item and service descriptions, quantities, units, spend, currencies, dates, cost centres, and the names of the companies involved. The name of a company is not personal data and is not removed. The exception is the one-person business whose registered name is the person's own name, and there the name goes with the rest.
8. Sub-processors
8.1 The Customer gives general written authorisation for us to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex III.
8.2 Before we add or replace a sub-processor we will update Annex III and notify the Customer at least 30 days in advance, by email to the account contact and by a notice on the page that hosts this DPA.
8.3 The Customer may object to a new sub-processor on reasonable data protection grounds within that period. We will work with the Customer in good faith to find a solution. If none is found, the Customer may terminate the affected part of the Service on notice, and that is the Customer's sole remedy.
8.4 We impose on every sub-processor, by contract, data protection obligations that are at least as protective as those in this DPA, and we remain fully liable to the Customer for a sub-processor's performance.
9. International transfers
9.1 We process Customer Personal Data inside the European Union, on the infrastructure identified in Annex III. We do not transfer it outside the European Economic Area, and we do not permit a sub-processor to.
9.2 If that ever has to change, we will tell the Customer in advance under clause 8.2, and the transfer will take place only under an adequacy decision or under the European Commission's standard contractual clauses, which are incorporated here by reference and take effect automatically on the transfer, with the annexes to this DPA populating the annexes to those clauses. We will carry out a transfer impact assessment first and make it available on request.
9.3 Neither remote access from a third country by us or by a sub-processor, nor storage of a backup outside the EEA, is permitted under clause 9.1.
10. Assistance to the Customer
10.1 Data subject requests. Taking into account the nature of the processing, we assist the Customer with appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise rights under Chapter III GDPR. If a data subject contacts us directly about Customer Personal Data, we will not respond substantively, and will refer them to the Customer and tell the Customer without undue delay.
10.2 Security, breach and impact assessments. We assist the Customer in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to us. That includes providing the information a data protection impact assessment needs about the Service.
10.3 Personal data breach. We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in time for the Customer to meet its own deadline under Article 33 GDPR. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point. We provide further information as the investigation progresses. We do not notify the supervisory authority or data subjects on the Customer's behalf unless the Customer asks us to in writing.
10.4 Assistance under this clause is included in the fees, except where a request is manifestly unfounded, excessive, or requires engineering work outside the Service, in which case we may charge our reasonable costs, agreed in advance.
11. Return and deletion
11.1 On the end of the provision of services, at the Customer's choice, we delete or return all Customer Personal Data and delete existing copies, unless Union or Member State law requires us to keep it.
11.2 In practice, following article 7.6 of the Terms: we keep Customer Data and Results for as long as the account is open and delete nothing on a timer while it is. The Customer has 30 days from termination to export, and we delete Customer Data and Results within 90 days of the account closing. At any time before that, a request to delete a file, a job or the whole account is actioned within 30 days. Backups containing Customer Personal Data expire on their own cycle of at most 90 days and are not selectively edited.
11.3 The aggregate and anonymous outputs described in clause 7.2(b) are not deleted, because they are no longer personal data and cannot be traced to the Customer or to any data subject.
11.4 We certify deletion in writing on request.
12. Audit
12.1 We make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
12.2 In the first instance we satisfy this by providing our documentation, including Annex II, our sub-processor list, and any third-party assessment reports we hold.
12.3 Where that is not sufficient, the Customer may audit us once in any twelve month period, on 30 days' written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality obligations. An auditor who competes with us is not acceptable. The Customer bears its own costs and ours, unless the audit reveals a material breach of this DPA, in which case we bear ours.
12.4 An audit does not extend to data about other customers, to our commercially sensitive information, or to anything covered by article 11.7 of the Terms except to the extent strictly necessary to verify compliance with this DPA.
13. Liability
Liability under this DPA is subject to the limitations and exclusions in article 14 of the Terms. Nothing in this DPA limits a data subject's rights, or either party's liability under Article 82 GDPR.
14. Term, changes and law
14.1 This DPA takes effect with the Terms and lasts as long as we process Customer Personal Data.
14.2 We may amend this DPA where a change in law, a supervisory authority decision, or a change to the Service requires it. We give 30 days' notice of a material amendment, and article 16 of the Terms applies to it.
14.3 This DPA is governed by Belgian law, and clause 18 of the Terms governs jurisdiction.
14.4 This DPA is drafted in English. Where we publish a translation and the versions differ, the English version prevails.
Annex I. Description of the processing
A. Parties
Controller / exporter: the Customer identified in the account or order form, acting for the purposes described in its own privacy notice.
Processor / importer: Songbird AI BV, Rue Emile Wittmann 50, 1030 Schaerbeek, Belgium. Contact: hello@open-climate.ai.
B. Description
Subject matter. Provision of the open-climate.ai emission factor search and mapping Service.
Duration. The Subscription Term, plus the periods in clause 11.
Nature and purpose of the processing. Receiving and parsing files and line items submitted by the Customer; classifying and matching them against emission factors; calculating emissions; returning and storing Results; retaining job records so a Result can be explained or re-run; securing and monitoring the Service; and the improvement processing described in clause 7.
Categories of data subjects.
- Individuals who use the Service on behalf of the Customer.
- Individuals whose details incidentally appear in the Customer's procurement, spend or activity data, such as a named contact at a supplier, an employee named on a travel or expense line, or a requester or approver carried over from the Customer's source system.
Types of personal data.
- Business contact details: name, work email, job title, employer.
- Account and usage data: user identifier, API key identifier, timestamps, IP address, actions taken.
- Whatever personal data the Customer chooses to include in an uploaded file or an API request, which is typically limited to names appearing in free text description, supplier and requester fields.
Special categories. None. Clause 3.4 prohibits sending them.
Frequency. Continuous for the duration of the subscription, driven by the Customer's own use.
Retention. As set out in clause 11 and in article 7.6 of the Terms.
C. Competent supervisory authority
The Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, as the authority of the processor's place of establishment. Where standard contractual clauses apply, the competent authority is determined under those clauses.
Annex II. Technical and organisational measures
Encryption. TLS for all traffic in transit, terminated at our reverse proxy. Encryption at rest for the database, for object storage and for backups.
Access control. Authentication through an OpenID Connect provider we host ourselves on our own infrastructure. Role based authorisation, granted on need, with administrative interfaces served to administrator roles only. API keys are scoped and individually revocable. File downloads are proxied through the API and re-checked against a capability token on every request, so no public or signed object storage URL is ever exposed to a browser. Time-based one-time password is available as a second factor on every account, and is required on administrative accounts: enrolment is set on the account when the administrative grant is made, and the sign-in flow demands the second factor at every login afterwards.
Segregation. Separate development and production environments on separate machines. Development data is a sanitised clone, never a live copy of customer content. Per-schema database roles and per-environment credentials.
Secrets. Application secrets are stored encrypted and never committed in clear text. Access to production secrets is limited to those who operate the Service.
Logging and monitoring. An access log covering job execution and file access. Error and performance monitoring on an EU-hosted service, configured not to attach personal data to reports. Scheduled jobs that protect the data report their own failure to an alert handler rather than failing silently.
Resilience and backup. Continuous database backup with write-ahead log archiving to EU object storage: a full backup weekly, a differential backup daily, and a retention policy that holds a point-in-time recovery window of at least 28 days. Backup integrity is verified by an automated weekly job, and a heartbeat check alerts when a backup or a verification does not run.
Pseudonymisation and minimisation. The improvement processing under clause 7 operates on the minimum fields required, with direct identifiers removed or pseudonymised where the purpose does not need them, and produces aggregate outputs.
Software security. Code review before merge, automated type and lint gates, dependency updates, and a quality gate that runs across the codebase before release.
People. Confidentiality obligations for everyone with access, and access granted per person rather than through shared accounts.
Incident response. A single named owner for security incidents, reachable at hello@open-climate.ai, and the monitoring above as the detection path, so the notification clause 10.3 requires can be produced in time for the Customer's own Article 33 deadline.
Sub-processor management. Contractual flow-down of these obligations, and the register at Annex III.
Annex III. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| OVHcloud (OVH SAS, France) | Hosting, database, object storage, backups | France |
| Functional Software Inc. trading as Sentry, EU region | Error and performance monitoring, configured without personal data | Germany |
| Sinch Email trading as Mailgun, EU region | Transactional and support email | European Union |
| OpenAI Ireland Limited, EU data residency | Language model processing of Customer Data during a job | European Union |
| Anthropic | Engineering assistance during development and evaluation, on de-identified fixtures only. No access to the production Service | United States |
Notes that belong with this table and are part of it:
- Our authentication service runs on software we operate ourselves, on the infrastructure in row one. It is not a separate sub-processor.
- The model provider in row four is engaged under terms that prohibit it from using the content of our requests to train or improve its models, and under a data residency arrangement that keeps the processing of our requests in the European Union.
- Row five is listed for transparency rather than because it has to be. The provider in that row assists our engineers during development and evaluation and is given only the fixtures described in clause 7.2(b), de-identified as clause 7.4 requires. It is never given Customer Personal Data, it has no access to the production Service, and clause 9.1 is therefore unaffected by its location. It is engaged under terms that prohibit training on the content of our requests.
- No other model provider processes Customer Data.