Data Processing Terms

Back to DomintAI
Version
1.1
Effective from
2026-08-01
Content hash (SHA-256)
c45d178ccc069f56f485db70079174374df5b38b5b5113452219171c0a4ce79e

DomintAI — Data Processing Terms (database upload)

Version: 1.1 Effective from: 2026-08-01 Processor: DomintAI Oy, Business ID 3618399-6, c/o Bing Li, Uitontie 2 C, 79810 Karvion kanava, Finland ("DomintAI", "we", "us") Controller: the organisation that uploads the database ("Customer", "you") Contact: info@domintai.com

You accept these terms when you upload a Domino database, or authorise us to work on one. They govern what we may do with the content of that database. They are also the data processing agreement required by Article 28(3) GDPR, so that no separate document has to be negotiated.

Personal data about *you as a platform user* is a different matter, and we are the controller for it — see the Privacy Policy.


1. What we need, and what we do not need

1.1 To modernize a form we need the database's design: the form design, its fields, layout, formulas and resources.

1.2 We do not need the personal data your database may contain. Nothing in the Service requires it.

1.3 You are responsible for removing or anonymising personal data before you upload. Upload a design-only copy, or a copy whose documents have been emptied or anonymised, wherever your process allows it.

1.4 You authorise us to process the business content that remains in the database you upload — records, values and attachments — to the extent needed to analyse the design, generate and validate an interface, and build the package you asked for.

1.5 You confirm that you have the right to upload the database and to allow us to process its content, and that doing so does not breach an obligation you owe to anyone else.

2. Roles

2.1 For everything inside the uploaded database, you are the controller and we are the processor. We process it only on your instructions — an upload, and the modernization steps you then run, are those instructions.

2.2 If personal data reaches us despite clause 1.3, we process it as your processor under these terms. That keeps the processing lawful on our side; it does not transfer your responsibility as controller to us, and it does not make us liable for a lawfulness or minimisation failure that happened before the upload.

2.3 We never use the content of your database for our own purposes, to build a product, or to train models.

3. Article 28(3) particulars

  • Subject matter: hosting and processing the uploaded Domino database in order to provide the modernization Service.
  • Duration: from upload until deletion under clause 7.
  • Nature and purpose: storing a copy of the database; reading and rendering its form design; generating, validating and packaging a modern interface; deploying a modernized copy for your testing.
  • Types of data: business records held in the database. Personal data only where you did not remove it — typically identifiers, contact details and request records of your employees or contacts.
  • Categories of data subjects: your employees, contractors, customers or other people whose records your database happens to contain.
  • Controller obligations: yours are set out in clauses 1.3–1.5 and 2.2.

4. Our obligations as processor

4.1 Instructions only. We process the content only as needed to provide the Service, or where EU or Member State law requires otherwise — in which case we tell you first, unless the law forbids it.

4.2 Confidentiality. Access is limited to people who need it to do the work, each under a confidentiality obligation that survives the end of their engagement.

4.3 Security. We apply measures appropriate to the risk: access control, encrypted transport, encryption at rest for uploaded databases and verification documents, integrity-checked signed packages, and audit logging of the operations performed. A per-package change-audit report records exactly what we changed in your database and what we did not.

4.4 Sub-processors. We use only the categories of sub-processors set out in the published Sub-processor List. Each provider is bound by data-protection terms no less protective than these, and no model provider may use your content to train or improve its models. We tell you before a provider change that affects personal data; if you reasonably object on data-protection grounds, you may stop using the affected feature or terminate the upload relationship and have the database deleted.

4.5 What is sent to AI providers. Form design and the derived rendering of that design are sent to a model provider to generate an interface. We do not send your document data as such. Because a rendered form can reflect values present in the database, clause 1.3 is the control that keeps personal data out of that path.

4.6 Assistance. We help you respond to data-subject requests and to supervisory authorities, at your cost where the effort is more than trivial. Where a data subject contacts us directly about content in your database, we refer them to you.

4.7 Breach notification. If we become aware of a personal data breach affecting the content you uploaded, we notify you without undue delay and give you what you need for your own Article 33 notification.

4.8 Audit information. On reasonable request, and no more than once a year unless a supervisory authority requires otherwise, we make available the information needed to demonstrate compliance with this clause 4.

5. Where the database lives

5.1 The database you upload is stored as a persistent copy on a Domino server operated by us. It is not a temporary artefact: the modernization steps read and write that same copy, and so does the build that produces your package.

5.2 It stays there until you ask us to delete it, or until deletion under clause 7. We keep it so you can re-run and extend the work without uploading again.

5.3 A package we build for you is cut from that copy. What the package contains, and what we changed to produce it, is listed in the change-audit report shipped with it.

6. International transfers

We aim to keep processing within the EEA. Where a sub-processor processes outside the EEA, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses with an assessment of the destination country. Ask us at info@domintai.com for the mechanism that applies to your account.

7. Deletion and return

7.1 You may ask us at any time to delete an uploaded database. We delete it, and any working copies, within thirty (30) days, and confirm when it is done.

7.2 On termination of your account we delete uploaded databases within thirty (30) days unless you ask for them back first — in which case we make a copy available to you before deleting.

7.3 We may keep the change-audit records and licence lineage for an issued package after deletion. Those describe what we did; they do not contain the content of your database.

7.4 Backups roll over on their own cycle; a deleted database disappears from backups within ninety (90) days.

8. Relationship to the Enterprise Evaluation License Agreement

8.1 These terms apply from your first upload, before any evaluation agreement exists. If your organisation later accepts the Enterprise Evaluation License Agreement, its Schedule 1 (Data Processing Agreement) becomes the processor contract for your organisation from that moment: it supersedes these terms for you and ratifies the processing already performed. That schedule is accepted by an authorised signatory on behalf of the organisation, which is why it takes precedence over an acceptance recorded for an individual user here.

8.2 Until that happens, these terms are the processor contract, and nothing in them is weakened by the absence of the evaluation agreement.

9. Liability and precedence

9.1 Liability under these terms is subject to the limitations in the Terms of Service, except where the GDPR or other mandatory law provides otherwise — in particular Article 82 GDPR, which these terms do not and cannot restrict.

9.2 Where these terms conflict with the Terms of Service on the handling of uploaded content, these terms prevail.

9.3 These terms are governed by the laws of Finland, with the District Court of Helsinki having exclusive jurisdiction, save for mandatory rules on the competence of supervisory authorities and courts under the GDPR.


© 2026 DomintAI Oy. All rights reserved.