Legal

Data Processing Addendum

Standard data-processing terms for business customers when archevis processes customer personal data on their behalf.

Version

2026-05-17

Effective date

May 17, 2026

Jurisdiction

European Union

This Data Processing Addendum ("DPA") applies when a business customer uses archevis and MONOLITHIQ Single-Member Private Company (IKE) ("Monolithiq") processes Customer Personal Data on that customer's behalf.

This DPA forms part of the archevis Terms of Service for business customers whenever Monolithiq acts as a processor for Customer Personal Data.

1. Parties and roles

  • Customer means the business customer using archevis.
  • Customer Personal Data means personal data that the Customer or its authorized users submit to archevis for processing on the Customer's behalf.

For Customer Personal Data processed under this DPA:

  • the Customer acts as controller or processor, as applicable to the Customer's own relationship with the data subjects; and
  • Monolithiq acts as processor.

Monolithiq remains an independent controller for its own account, billing, support, security, compliance, and aggregate analytics processing described in the archevis Privacy Policy.

2. Subject matter, duration, and purpose

This DPA applies for as long as Monolithiq processes Customer Personal Data in connection with the Customer's use of archevis.

The subject matter of the processing is the provision of the archevis service, including:

  • account access and workspace administration;
  • storage, retrieval, transformation, and export of customer-submitted files and project materials;
  • generation workflows requested by the Customer's authorized users;
  • support, troubleshooting, security, and incident response related to the service.

3. Categories of data and data subjects

Customer Personal Data may include, depending on the Customer's use of the service:

  • project files, sketches, reference images, and generated outputs;
  • project metadata, prompts, settings, user-entered notes, and workspace identifiers;
  • limited support and troubleshooting context supplied by the Customer;
  • personal data contained in uploaded materials or project records.

Potential data-subject categories may include the Customer's staff, contractors, clients, consultants, and other individuals whose personal data the Customer decides to submit to archevis.

4. Customer instructions

Monolithiq will process Customer Personal Data only:

  • on the Customer's documented instructions, including the Customer's use of the service features;
  • as necessary to provide, secure, and maintain archevis; or
  • where required by applicable law, in which case Monolithiq will inform the Customer unless the law prohibits doing so.

The Customer is responsible for:

  • having a valid legal basis for the Customer Personal Data it submits to archevis;
  • giving any notices required to data subjects; and
  • ensuring that its instructions to Monolithiq are lawful.

5. Confidentiality and access controls

Monolithiq will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

Access to Customer Personal Data is limited to personnel and contracted service providers who need that access to provide, secure, support, or maintain the service.

6. Security measures

Monolithiq will maintain technical and organizational measures appropriate to the risk of the processing, taking into account the nature of archevis and the Customer Personal Data processed through it.

These measures include, at a high level:

  • authenticated access controls;
  • encrypted transport and protected storage access;
  • role-based data-access restrictions;
  • logging, monitoring, and incident-traceability controls; and
  • provider due diligence and contractual controls for hosted service providers.

This DPA does not publish sensitive implementation detail such as storage structure, security topology, workflow internals, or operational secrets.

7. Service providers and subprocessors

Customer authorizes Monolithiq to use the service providers listed on the Service Providers and Transfers page to support archevis.

That page identifies Monolithiq's current hosted service providers and links to their public legal materials where available. Monolithiq may update those providers from time to time, provided that any replacement remains suitable for the relevant processing activity and subject to appropriate contractual controls.

8. International transfers

Where Customer Personal Data is transferred outside the EEA or otherwise processed in a third country, Monolithiq will rely on an applicable lawful transfer mechanism, such as an adequacy decision, standard contractual clauses, or another valid safeguard under applicable law.

Customers may request additional information about Monolithiq's current transfer posture by contacting info@monolithiq.co.

9. Assistance with rights requests and compliance

Taking into account the nature of the processing, Monolithiq will provide reasonable assistance to the Customer for:

  • data-subject requests;
  • security incident response;
  • data-protection impact assessments; and
  • consultations with supervisory authorities where applicable,

to the extent required by applicable data-protection law and to the extent the relevant information is available to Monolithiq.

10. Security incidents

If Monolithiq becomes aware of a confirmed personal-data breach affecting Customer Personal Data, Monolithiq will notify the Customer without undue delay and provide the information reasonably available to help the Customer meet its own legal obligations.

11. Return, deletion, and retention

During the term, the Customer may use archevis's live features to access, export, or delete Customer Personal Data that the service makes available through normal product workflows.

After termination or upon valid deletion instructions, Monolithiq will delete or return Customer Personal Data in accordance with the archevis service functionality, the Privacy Policy, and Monolithiq's legal retention obligations.

Some data may be retained where required by law, needed for security or abuse prevention, necessary to evidence legal compliance, or subject to legal hold.

12. Audits and information

Monolithiq will make available information reasonably necessary to demonstrate compliance with this DPA, taking into account the need to protect other customers, security-sensitive information, and Monolithiq's confidential information.

Monolithiq may satisfy this obligation through public documentation, security/compliance materials, written responses, or other appropriate evidence.

13. Contact

Questions about this DPA may be sent to:

  • MONOLITHIQ Single-Member Private Company (IKE)
  • Sidiras Merarchias 8, 42100 Trikala, Greece
  • info@monolithiq.co