EU Project Manager
Data processing agreement
Effective 26 September 2026
1. Parties and roles
This Agreement is between the Customer (an organisation using EU Project Manager — “the Platform”; the controller) and SIA "Plenty Group", registration number 40203061230, Latvia (the processor, “we”). It forms part of the Terms of Service and is accepted with them. For the personal data in Annex A, the Customer is the controller and we are its processor. Where several partners in one consortium use the Platform, each organisation is the controller of its own data and is bound by this Agreement separately; we do not assume joint controllership between partners.
Our contact for anything under this Agreement — sub-processor notices and objections, audits and data-protection questions: security@theplentygroup.eu.
2. Subject matter, duration, nature and purpose
We process personal data only to provide the Platform: helping the Customer manage its EU-funded projects and keep the records those grants require. Details are in Annex A. This Agreement lasts as long as we process personal data for the Customer.
3. Our obligations as processor (Art 28(3))
We will:
- Process only on the Customer’s documented instructions, including on international transfers; the Terms of Service, this Agreement and normal use of the Platform’s features are those instructions — unless EU or Member State law requires otherwise, in which case we will tell the Customer of that requirement first, unless that law forbids it. We will tell the Customer if we believe an instruction breaks the law.
- Ensure people authorised to process the data are under a duty of confidentiality.
- Take the security measures required by Art 32 (summarised in Annex B).
- Respect the conditions on engaging sub-processors (section 4).
- Assist the Customer to answer data subjects exercising their rights (Chapter III).
- Assist the Customer with its obligations under Art 32–36 (security, breach notification, impact assessments, prior consultation), taking into account the information available to us.
- On the end of the services, delete or return the personal data at the Customer’s choice, and delete existing copies unless the law requires storage (section 8).
- Make available the information needed to show compliance with Art 28 and allow and contribute to audits (section 7).
4. Sub-processors
- The Customer gives general authorisation for us to use the sub-processors listed in Annex C.
- We impose equivalent data-protection obligations on each and remain liable for their performance.
- We will tell the Customer’s account holders by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds; if the objection cannot be resolved, the Customer may stop using the affected service.
5. International transfers
The Platform runs in the EU/EEA. Where a sub-processor in Annex C involves a transfer outside the EU/EEA, it is covered by the safeguard listed there: an adequacy decision (the EU-US Data Privacy Framework, for certified providers) or Standard Contractual Clauses.
6. Data subject requests
If a data subject contacts us directly about data we process for the Customer, we will not respond ourselves (beyond acknowledging) but will pass the request to the Customer without undue delay and help it answer.
7. Audits, information and personal-data breaches
- We will make available the information reasonably needed to demonstrate compliance, and allow audits or inspections by the Customer or an auditor it mandates, on reasonable notice and without compromising the security or data of other customers.
- We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting its data, with the information it needs to meet its own Art 33/34 duties.
8. Return or deletion on termination
On the end of the services, we will, at the Customer’s choice, return or delete the personal data we hold for it and delete remaining copies, except data we must keep by law, or that the Customer must retain for EU-grant audit (as a rule until 5 years after the EU’s final payment, 3 years if the grant is at most EUR 60 000). Retained data stays governed by this Agreement and is kept only for that purpose.
9. Order of precedence and liability
On the processing of personal data this Agreement prevails over the rest of the Terms of Service. Liability is as set out in the Terms of Service.
10. The Customer’s obligations
The Customer is responsible for having a lawful basis for the processing; for giving its staff and other data subjects the information the GDPR requires; for its instructions being lawful; for deciding whom it invites and at what level of access; and for any AI provider key that it or its users connect. The Customer’s rights under this Agreement are set out in sections 3, 4, 7 and 8.
Annex A — Details of the processing
| Subject matter | Managing the Customer’s EU-funded projects in the Platform |
|---|---|
| Duration | For the term of the Terms of Service, plus any legally required retention (section 8) |
| Nature and purpose | Recording, displaying and storing project, consortium, working-time and personnel-cost data, and keeping the records EU grants require |
| Data subjects | The Customer’s staff whose time is charged to projects, and their supervisors; the Customer’s project and finance users; contact persons at partner organisations |
| Personal data | Name, email, role and organisation; personnel type; working time and absences; personnel-cost data used to compute grant costs; signatures and signing dates; uploaded documents; meeting attendance; and the record of who did what (identity, IP address, time, reason) |
| Special categories (Art 9) | May arise where an absence is recorded as sick leave (health data). The Customer is responsible for the Art 9 condition (typically employment law, Art 9(2)(b)). |
Annex B — Security measures (Art 32), summary
The Platform applies measures appropriate to the risk, covering: access control on a least-privilege basis with multi-factor authentication; logical separation of each customer’s data; encryption of data in transit; protection of the integrity of records that serve as audit evidence, with tamper-evident logging; and regular backups. Further detail is available to a Customer under confidentiality on request.
Annex C — Authorised sub-processors
| Sub-processor | Purpose | Transfer safeguard |
|---|---|---|
| DigitalOcean, LLC | Hosting of the Platform and its database, in the EU/EEA | Provider established in the US; EU-US Data Privacy Framework |
| Resend | Sending transactional email | US; EU-US Data Privacy Framework and Standard Contractual Clauses |
| Anthropic, PBC | Reading an uploaded document to set up a project: the imports the Processor covers (a user’s first; on a paid plan, three per credit) run on the Processor’s own account, under the Processor’s data processing agreement with Anthropic. Every other AI use (summaries on request, further imports) only when the Customer or its user supplies its own AI key, under the Customer’s own agreement with Anthropic | US; Standard Contractual Clauses |