Skip to content
ErmisAI
PricingLyraPartnersAboutContact

Processor terms

Data processing agreement

The terms that govern personal data ErmisAI handles on a customer newsroom's behalf. In force with the Terms; a countersigned copy is available on request.

Last updated August 27, 2026

Agreement

This agreement supplements the Terms and governs processing that Entro314 Labs PC carries out on behalf of a customer organization under Article 28 GDPR. Where ErmisAI decides the purposes itself - the public website, user accounts, billing, and its own commercial communication - it acts as controller and the privacy notice applies instead. The English text is the authoritative version; the other languages are provided for convenience.

Agreement
01

Parties and effect

The customer organization that operates a newsroom workspace is the controller. Entro314 Labs PC is the processor. This agreement takes effect when the customer accepts the Terms and lasts as long as the workspace exists. No separate signature is required for it to bind; a countersigned copy on paper is issued on request.

02

Subject matter, duration, nature and purpose

ErmisAI processes personal data in order to run the newsroom workspace the customer subscribes to: monitoring configured sources, clustering coverage, drafting stories, routing them through editorial review, and delivering approved output to the publishing surfaces the customer connects. Processing lasts for the term of the subscription plus the transition and erasure windows described on the data portability and exit page.

03

Categories of data and data subjects

Data subjects are the customer's editors, administrators and invited members, plus any individual named in the source material a newsroom monitors or in the drafts its editors write. Categories are:

  • identity and account data - name, email address, role, workspace membership,
  • usage data - actions in the workspace, story and draft history, audit records,
  • content data - source articles, clusters, drafts and approved stories, including any personal data they mention,
  • technical data - IP address, device and browser metadata captured in security and error logs.
04

Instructions

ErmisAI processes personal data only on documented instructions from the customer. The Terms, this agreement, the product settings a customer configures, and the actions its editors take in the workspace are those instructions. If ErmisAI is required by EU or member-state law to process beyond them, it informs the customer before doing so unless that law forbids the notice. ErmisAI tells the customer if an instruction appears to infringe data protection law.

05

Confidentiality

Everyone authorised to process customer personal data is bound by confidentiality and has access only to what their work requires. Access to production data is limited to the operator of the service and is logged.

06

Security

ErmisAI maintains technical and organisational measures appropriate to the risk, including encryption in transit, encrypted storage at the hosting providers, role-based access control, tenant isolation on every read and write path, signature verification on inbound webhooks, and rate limiting. The security page describes the measures and states plainly what is not claimed.

07

Sub-processors

The customer gives general authorisation for the sub-processors listed on the sub-processor page, which names every vendor, its role and its processing region. ErmisAI imposes equivalent data protection obligations on each of them and remains fully liable for their performance. New or replaced sub-processors are announced on that page before they start processing, and a customer may object on reasonable data protection grounds; an unresolved objection entitles the customer to terminate the affected service without penalty.

08

Assistance to the controller

Taking into account the nature of the processing, ErmisAI assists the customer with:

  • responding to data subject requests, including access, correction, erasure and portability - most of which the customer can serve itself from the workspace,
  • security of processing, breach notification and data protection impact assessments,
  • prior consultation with a supervisory authority where one is required.
09

Personal data breaches

ErmisAI notifies the customer without undue delay after becoming aware of a personal data breach affecting that customer's data, with the information the customer needs for its own Article 33 notification, and follows up as the investigation develops.

10

Information and audit

ErmisAI makes available the information needed to demonstrate compliance with Article 28 and allows for audits, including inspections, conducted by the customer or an auditor it mandates. Audits are scheduled at reasonable notice, no more than once a year unless an incident or a supervisory authority requires otherwise, and must not compromise the security of other customers.

11

International transfers

Processing is kept in the European Union or European Economic Area where the vendor offers it. Where a sub-processor transfers data outside the EEA, the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses with supplementary measures. The sub-processor page states the region each vendor operates in.

12

Return and deletion

On termination the customer chooses whether personal data is returned or deleted. Data stays readable for the transition period described on the data portability and exit page so exports can be finished, and is then erased, except where EU or member-state law requires retention - billing records being the usual case.

13

Precedence and changes

Where this agreement conflicts with the Terms on the processing of personal data, this agreement prevails. A negotiated agreement signed with a customer prevails over both. Material changes are published on this page with a new effective date and announced to customers with an active subscription.

14 · Contact

Questions about this agreement, requests for a countersigned copy, and sub-processor objections go to privacy@ermisai.com.

privacy@ermisai.com

ErmisAI

ERMIS AI

The AI newsroom for modern publishers. Source intake, same-event clustering, story synthesis, editorial review, and delivery into supported publishing surfaces.

XLinkedIn

Product

  • Lyra
  • Pricing
  • Partners
  • Security
  • Contact

Company

  • About
  • Careers
  • Documentation
  • Journal

Legal

  • Terms
  • Privacy
  • Cookies
  • Legal notice

© 2026 ErmisAI. All rights reserved.

Your multilingual AI newsroom.