Data Processing Agreement

Last updated: 2026. 07. 18.
Legal

I. Purpose and Scope of the Agreement

This Data Processing Agreement (“Agreement”) is concluded between the operator of the Smairthub platform, acting as the Data Processor (hereinafter: “Processor”), and the registered customer using the Platform, acting as the Data Controller (hereinafter: “Controller”). The purpose of this Agreement is to regulate the technical processing of datasets and personal data uploaded by the Controller to the Platform, in accordance with Article 28 of the GDPR.

This Agreement covers the Smairthub core framework and its general data processing guarantees. The specific data processing characteristics of each functional component (“Modules”)—including the exact categories of processed data, the technologies used, and the sub‑processors involved—are defined in the respective Module Annexes to this Agreement.

II. Parties

1. Controller

The natural or legal person (registered User of the Platform) who uploads custom data files to the Smairthub interface and independently determines the purposes and means of processing the data contained therein.

2. Processor

  • Company: KirĂĄly Ingrid EV
  • Registered seat: 9030 Győr, Szőlőskert u. 13., Hungary
  • Tax number: 92213159-1-28
  • Registration number: 62565408
  • Contact: legal@smairthub.com or via the internal support ticket system.

III. Nature and General Rules of Processing

The Processor processes the data uploaded by the Controller exclusively for the purpose of executing the technical functions of the Modules selected by the Controller.

Processing may include structuring, cleaning, analysing, or transforming the data, depending on the operational logic of the selected Module. The Processor does not use the data for its own purposes and performs no additional modifications beyond the requested technical operations.

IV. Obligations of the Processor

1. Processing Based on Instructions

The Processor processes data solely based on the Controller’s direct, electronic instructions issued through the Platform (e.g., starting a module, activating a function).

2. Confidentiality

The Processor ensures that all persons involved in operating the Platform and who may technically access the data are bound by strict confidentiality obligations.

3. Technical Security Measures

To guarantee an appropriate level of data security, the Processor implements the following measures:

  • End‑to‑end and network encryption via HTTPS (SSL).
  • Strictly limited, key‑based server‑side access control.
  • Automated, isolated processing environments for module execution.
  • Regular technical security updates.

4. Notification of Data Breaches

The Processor shall notify the Controller without undue delay of any data breach affecting or potentially affecting the Controller’s temporarily processed data.

V. General Sub‑processors (Core Framework)

The Controller authorizes the Processor to use the following permanent sub‑processors for essential technical operation and delivery of system notifications:

  • Resend, Inc. – delivery of system messages and status notifications
  • Intergo Telecom Ltd. – SMS.to – delivery of OTP codes and verification SMS

Additional sub‑processors used by specific software Modules (e.g., AI infrastructure) are defined in the Module Annexes of this Agreement.

VI. Rights and Responsibilities of the Controller

1. The Controller warrants that they possess full processing rights or the necessary data subject consents for all datasets uploaded to the Platform.
2. The Controller is responsible for maintaining backups of original source files, acknowledging the Platform’s temporary storage logic.
3. The Controller may request information regarding the Processor’s technical compliance.

VII. Final Provisions

This Agreement remains valid as long as the Controller’s user account is active. Upon account deletion, the Agreement terminates automatically. This Agreement is governed by Hungarian law and the GDPR. In case of disputes, Hungarian courts with jurisdiction over the Processor’s registered seat shall have exclusive competence.

Annex 1 – Spreadsheet AI Module Specific Terms

Integral part of the Data Processing Agreement

1. Subject and Nature of Processing

The Spreadsheet AI module processes the tabular files (CSV, XLS/XLSX) uploaded by the Controller for the purpose of cleaning, correcting, and formatting their technical structure.

2. Categories of Processed Data

  • Full internal content of the uploaded tabular files (including any personal data or trade secrets).
  • Metadata and technical column structure.

3. Retention and Deletion

The Processor stores uploaded data and temporary database records for a maximum of 12 hours. After this period, all data is automatically, permanently, and irreversibly deleted.

4. Module‑Specific Sub‑processor (AI)

  • OpenAI Ireland Ltd. / Azure OpenAI Enterprise
  • Nature: AI‑based contextual analysis and structure optimization.
  • Data minimization: Only table structure, field types, and a few sample rows are transferred. No long‑term storage, no model training.

Annex 2 – Social Factory AI Video Module Specific Terms

Integral part of the Data Processing Agreement

1. Subject and Nature of Processing

The Social Factory AI module processes scripts, avatar images, and generated audio/video content for the purpose of creating short 9:16 talking‑avatar videos for the Controller.

2. Categories of Processed Data

  • script text provided by the Controller,
  • uploaded or generated avatar image,
  • text used for voice generation,
  • audio file used for lip‑sync,
  • generated videos, subtitles, background music.

3. Retention and Deletion

Generated images, audio, and video content are stored for a maximum of 7 days. After this period, all content is automatically, permanently, and irreversibly deleted.

4. Module‑Specific Sub‑processors (AI)

The Processor uses the following sub‑processors for the module:

  • OpenAI Ireland Ltd. / Azure OpenAI Enterprise
    Service: script processing, text preparation for narration.
    Guarantee: enterprise API, no long‑term storage, no model training.
  • ElevenLabs Inc.
    Service: voice generation.
    Data transferred: text required for voice synthesis.
    Guarantee: no long‑term storage, no model training.
  • fal.ai – Flux/dev and Flux‑pro
    Service: avatar image generation.
    Data transferred: avatar image or description.
    Guarantee: minimal data transfer, no long‑term storage.
  • fal.ai – Kling Standard and Kling Pro
    Service: lip‑sync video generation.
    Data transferred: audio file and avatar image.
    Guarantee: no long‑term storage, no model training.
  • fal.ai – workflow‑utilities / auto‑subtitle
    Service: automatic subtitle generation.
    Data transferred: audio track of the video.
    Guarantee: minimal data transfer, no long‑term storage.
  • Sonilo – v1.1 / video‑to‑video‑music
    Service: background music generation.
    Data transferred: audio or visual characteristics of the video.
    Guarantee: no long‑term storage, no model training.

5. Prohibited Content

The module must not be used to generate unlawful, hateful, violent, sexually explicit content involving minors, deepfake impersonations, or political campaign material.

6. Controller Responsibilities

The Controller must download and store generated content within the 7‑day retention period.

The Controller is responsible for ensuring that provided text, images, and generated videos are lawful and do not infringe third‑party rights.

Data Processing Agreement (DPA) - SmairtHub