DPA
Data processing agreement
Pilot notice · last updated 2026-08-20 · not indexed yet
Steinlog processes customer bid/tender content and end-user accounts inside your organisation's tenant as a processor. Your organisation is the controller of that tenant content and those org-user records. Separately, Steinlog / Dago Digital is the controller for the Steinlog B2B customer account (contracting-party / billing identity), account/billing support Steinlog runs for its own commercial relationship, and independent platform telemetry we run for our own purposes — see the Privacy notice. Support roles follow processing purpose: customer-content diagnosis under your organisation's instructions falls under this DPA's processor subject matter; account/billing support for Steinlog's commercial relationship does not. Those controller datasets are otherwise outside this DPA's processor subject matter. A signed DPA is not published on this page and this notice is not an executed contract.
PDF on request
For pilots we provide the current DPA as a PDF on request. Write to privacy@steinlog.com with your company legal name and the contact who will sign. We aim to return the PDF before the first document upload. Voyage and Datalab US inference transfers are disclosed on the Privacy notice; operative Art. 46 safeguards with those providers remain a product/legal open item. A customer DPA PDF is not the Art. 46 transfer mechanism for Voyage or Datalab.
Parties (when signed)
Processor: Dago Digital Michal Walpole-Skwarczynski (Polish JDG), NIP 9570839810, Lecha Kaczyńskiego 10E, 80-373 Gdańsk, Poland. Controller: your organisation, as named in the signed PDF.
Infrastructure vs Steinlog stores
Distinguish the cloud provider from Steinlog-operated components (both appear on Security):
- Provider / infrastructure — Cloudflare (Workers, R2 object storage with EU jurisdiction pins on document/export buckets, Durable Object runtime). Cloudflare is the infrastructure subprocessor; R2 is Cloudflare-hosted object storage Steinlog configures.
- Steinlog-operated stores / components — TenantDb (per-tenant SQLite Durable Object), BidRoom and ClarificationScout — Steinlog application stores running on that infrastructure, not separate third-party SaaS brands.
- Other subprocessors — assistant inference: xAI via Ireland (eu-west-1.api.x.ai). Embeddings / OCR: Voyage and Datalab process in the United States (inference only — not Steinlog document/tenant storage). Analytics: PostHog (EU-hosted, consent-gated; typically controller-side, not DPA subject matter). Processing is mixed: EU-hard storage where pinned, Ireland assistant inference, US embeddings/OCR.
What a pilot DPA typically covers
- Subject matter: hosting and processing tender/bid content and org end-user data inside the customer's tenant (not Steinlog's own B2B contracting/billing identity).
- Instructions: only as needed to provide the service and as you configure in-product (Art. 28).
- Security: isolation per tenant, access logging, and export/delete on request.
- International transfers: destinations disclosed for Voyage and Datalab (may leave the EU); assistant inference pinned to Ireland; storage EU-hard on the named R2 buckets and Steinlog stores above. Operative Art. 46 safeguards with Voyage/Datalab are a product/legal open item — a customer DPA is not those providers' transfer mechanism; this page does not claim SCCs with them are already signed.
- Subprocessor changes: notice before material additions where the signed PDF requires it.
Exact clauses are those in the PDF you sign — not this web summary.
Steinlog