Projects Library - Data Processing Agreement
Version 1.0
Last updated: September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between a customer using Projects Library ("Customer") and EU Systems Ltd ("EU Systems") where EU Systems processes personal data on behalf of the Customer.
1. Parties and Scope
This DPA applies where:
- the Customer uses Projects Library to process personal data;
- the Customer determines the purposes and means of that processing as controller; and
- EU Systems processes that personal data on the Customer's behalf in providing the Service.
For such processing:
- the Customer is the Controller; and
- EU Systems Ltd is the Processor.
Where the Customer acts as a processor on behalf of another controller, the Customer is a processor and EU Systems is its subprocessor for the relevant processing.
This DPA does not govern personal data for which EU Systems independently determines the purposes and means of processing, such as certain account, security, contractual, billing and operational information. For that processing, EU Systems generally acts as a controller as described in our Privacy Policy.
2. Definitions
For this DPA:
"Applicable Data Protection Law" means data-protection and privacy legislation applicable to processing under this DPA, including, where applicable, the UK GDPR, the Data Protection Act 2018 and the EU GDPR.
"Customer Personal Data" means personal data contained within Workspace Content that EU Systems processes on behalf of the Customer in providing Projects Library.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach" and "Processing" have the meanings given to them by Applicable Data Protection Law.
"Service" means Projects Library.
"Subprocessor" means another processor engaged by EU Systems to process Customer Personal Data on EU Systems' behalf in providing the Service.
"Workspace" means the Customer's organisational environment within Projects Library.
"Workspace Content" means information and material entered, uploaded, stored or otherwise processed by Users through a Workspace.
3. Customer Instructions
EU Systems will process Customer Personal Data only:
- on the Customer's documented instructions;
- as necessary to provide, maintain, secure and support the Service;
- as otherwise provided by the agreement between the parties; or
- where required by applicable law.
The Customer's use and configuration of Projects Library, together with the applicable agreement, Terms & Conditions and this DPA, constitute documented processing instructions.
If EU Systems is required by law to process Customer Personal Data other than on the Customer's instructions, EU Systems will inform the Customer of that requirement before processing unless the applicable law prohibits such notification.
If EU Systems reasonably believes an instruction infringes Applicable Data Protection Law, it may inform the Customer and, where appropriate, suspend the relevant processing while the matter is resolved.
4. Details of Processing
The subject matter, nature and purpose of processing are described in Annex A.
In general, processing is undertaken to provide the functionality of Projects Library requested and configured by the Customer.
This may include:
- receiving data;
- storing data;
- organising and displaying data;
- retrieving and searching data;
- transmitting data;
- extracting text from supported documents;
- creating search embeddings;
- performing User-requested Chat Analysis;
- encrypting and decrypting Vault information as required to provide Vault functionality;
- backing up information;
- securing and monitoring the Service;
- enabling authorised sharing; and
- deleting or returning information.
5. Duration
EU Systems will process Customer Personal Data for the duration of the Customer's use of the Service and any applicable post-termination retention period.
Following expiry or termination, the Customer will ordinarily receive the 30-day read-only/export period described in the Terms & Conditions and Refund & Cancellation Policy.
After that period, Customer Personal Data may be scheduled for deletion from active systems.
Copies may remain temporarily within backups or disaster-recovery systems until removed through normal retention and backup-rotation processes.
6. Customer Responsibilities
The Customer is responsible for:
- complying with Applicable Data Protection Law in its use of the Service;
- determining whether it has a lawful basis for processing Customer Personal Data;
- providing required privacy information to Data Subjects;
- ensuring its instructions to EU Systems are lawful;
- deciding what Customer Personal Data is entered into the Service;
- ensuring Users are appropriately authorised;
- managing Workspace membership and permissions;
- determining whether Guest Access is appropriate;
- determining whether information should be submitted to AI processing;
- responding to Data Subjects where the Customer is responsible for doing so; and
- complying with applicable legal, regulatory and contractual requirements relating to its data.
The Customer must not instruct EU Systems to process personal data unlawfully.
7. Confidentiality
EU Systems will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access to Customer Personal Data will be limited to persons who require access for legitimate purposes associated with providing, securing, supporting or maintaining the Service, or where access is otherwise required by law.
8. Security
EU Systems will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Current measures include, where applicable:
- authenticated access;
- Workspace data separation;
- database row-level security;
- role and permission controls;
- private file storage;
- temporary signed file-access links;
- provider-level encryption at rest;
- additional encryption controls for Vault items;
- controlled Vault unlocking;
- security and operational logging; and
- appropriate infrastructure security measures.
Security measures may evolve as technology, risk and the Service change.
EU Systems does not represent that any internet-connected system can eliminate all security risk.
9. Vault Processing
The Vault is designed to provide additional protection for credentials and similar sensitive Workspace Content.
Vault items are encrypted using the Service's current cryptographic architecture. Access is provided to authorised Users through wrapped encryption keys and associated access controls. Workspace Administrators have recovery capabilities that can enable recovery and access to Vault information within their Workspace.
Vault decryption occurs as part of server-side Service processing.
The Vault is therefore not a zero-knowledge or end-to-end encrypted service.
EU Systems does not routinely access Vault contents, and ordinary platform administration does not provide an interface for browsing Customer Workspace Content.
10. Files and Attachments
Customer Personal Data may be contained within files and attachments uploaded to the Service.
Ordinary attachments are stored in private cloud storage protected by application access controls and provider-level encryption at rest. They do not receive the same per-item encryption used by the Vault.
Supported documents may have text extracted and indexed for search.
Under the approved product security model, supported file formats and file sizes are restricted. Uploaded attachments are not currently malware scanned.
11. AI Processing
Where a Customer or authorised User uses Chat Analysis, the submitted content is processed through the Service's AI infrastructure to provide the requested analysis.
The current AI processing path is:
EU Systems / Projects Library -> Lovable AI gateway -> Google Gemini
The current Chat Analysis model is Google Gemini 2.5 Pro.
The Service also uses Google Gemini Embedding 2, through the Lovable AI gateway, to generate embeddings supporting search and retrieval.
Customer Workspace Content processed through these AI services is not used by Projects Library to train AI models.
Based on the applicable service arrangements for the current implementation, submitted Customer Content is not used to train or improve the underlying AI models.
EU Systems maintains available model-training controls in a configuration consistent with this commitment.
Limited retention may nevertheless occur for security, abuse-prevention or service-protection purposes under applicable provider arrangements.
12. Subprocessors
The Customer gives EU Systems general authorisation to engage subprocessors where necessary to provide the Service.
EU Systems currently uses Lovable as a principal subprocessor for the hosting and operation of Projects Library.
Lovable may in turn engage downstream subprocessors to provide components of its platform and infrastructure. These providers currently include services supporting database infrastructure, authentication, storage, edge infrastructure, AI processing, email delivery, search/indexing, logging and monitoring.
Based on Lovable's current published subprocessor information, relevant downstream providers may include Supabase, Cloudflare and Google, together with other providers applicable to the Lovable services used by Projects Library.
The particular providers used may change as Lovable's infrastructure develops. EU Systems therefore does not reproduce Lovable's complete subprocessor register within this DPA. Current information concerning Lovable's subprocessors may be obtained through Lovable's published Trust Center/subprocessor information.
Where Projects Library uses Google Gemini through the Lovable AI gateway, Google processes relevant AI prompts, responses or other information as a downstream provider within Lovable's processing chain.
EU Systems will ensure that subprocessors processing Customer Personal Data are subject to appropriate data-protection obligations as required by Applicable Data Protection Law.
Where required by Applicable Data Protection Law, EU Systems will provide appropriate information concerning material changes to subprocessors and applicable objection rights.
Creem, as Merchant of Record, processes payment and transaction information associated with purchases. Creem may act independently for some of its Merchant of Record responsibilities rather than acting as a Subprocessor of Customer Workspace Content. Creem is therefore not automatically treated as a Workspace Content Subprocessor merely because it provides payment services.
13. Changes to Subprocessors
EU Systems may add, replace or change Subprocessors where reasonably necessary to operate and develop the Service.
Where required by Applicable Data Protection Law, EU Systems will provide appropriate notice of intended material changes to Subprocessors that process Customer Personal Data.
If the Customer has a reasonable data-protection objection to a new Subprocessor, the Customer should contact EU Systems promptly.
The parties will seek in good faith to identify a reasonable solution.
Where no reasonable solution is available, the Customer may discontinue the affected Service in accordance with the applicable contractual arrangements and mandatory legal rights.
14. Subprocessor Obligations
Where EU Systems engages a Subprocessor to process Customer Personal Data on its behalf, EU Systems will impose data-protection obligations appropriate to the relevant processing and required by Applicable Data Protection Law.
Such obligations will require appropriate protection of Customer Personal Data.
15. Data Location and International Transfers
The primary database and storage environment currently used for Projects Library is hosted in the European Union. The current project environment is hosted in the AWS eu-west-1 (Ireland) region.
Some processing may nevertheless occur outside the European Economic Area or United Kingdom. For example, AI processing using Google Gemini currently involves processing in the United States, and global edge, email, monitoring or other infrastructure may involve processing in other locations.
EU Systems and its subprocessors will use appropriate safeguards for restricted international transfers where required by Applicable Data Protection Law.
Depending on the applicable processing relationship, these safeguards may include adequacy decisions, the EU Standard Contractual Clauses, the UK Addendum to those clauses, the UK International Data Transfer Agreement or another legally recognised transfer mechanism.
16. Data Subject Requests
Where EU Systems receives a request from a Data Subject relating to Customer Personal Data for which the Customer is Controller, EU Systems may direct the Data Subject to the Customer unless prohibited from doing so.
Taking into account the nature of the processing, EU Systems will provide reasonable assistance to the Customer in responding to requests to exercise applicable Data Subject rights where required by Applicable Data Protection Law.
The Customer remains responsible for determining how to respond to the request.
17. Assistance With Compliance
Taking into account the nature of the processing and information available to EU Systems, EU Systems will provide reasonable assistance where required by Applicable Data Protection Law concerning:
- security of processing;
- Personal Data Breach obligations;
- data-protection impact assessments; and
- prior consultation with supervisory authorities.
The extent and method of assistance may depend on the circumstances and the information reasonably available to EU Systems.
18. Personal Data Breaches
If EU Systems becomes aware of a Personal Data Breach affecting Customer Personal Data, it will notify the Customer without undue delay, as required by Applicable Data Protection Law.
The notification will provide information reasonably available to EU Systems concerning the nature and circumstances of the breach and measures taken or proposed in response.
Where all information is not immediately available, information may be provided in stages.
EU Systems' notification of an incident does not constitute an admission of fault or liability.
The Customer remains responsible for determining whether notification to a supervisory authority or affected Data Subjects is required where the Customer is Controller.
19. Deletion and Return of Data
During active use of the Service, Customers may use available product functionality to access, export or delete information.
Following expiry or termination, Customers will ordinarily receive the agreed 30-day read-only/export period.
After that period, EU Systems may delete Customer Personal Data from active systems unless applicable law requires continued retention.
Customer Personal Data may remain temporarily in backups until removed through normal backup-rotation processes.
Where information must be retained by law, EU Systems will continue to protect it and limit further processing to the purpose requiring retention.
20. Audits and Information
EU Systems will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable to it under Applicable Data Protection Law.
Where required by law, EU Systems will allow and contribute to reasonable audits or inspections concerning processing under this DPA.
The parties should first seek to satisfy audit requirements using available documentation, security information, questionnaires, certifications or other proportionate evidence.
Any additional audit should:
- be subject to reasonable advance notice;
- occur during normal business hours;
- avoid unnecessary disruption;
- protect the confidentiality and security of other Customers;
- be limited to relevant systems and processing; and
- comply with reasonable security requirements.
Where an audit creates substantial additional work beyond EU Systems' ordinary compliance obligations, the parties may agree reasonable costs where legally permitted.
21. Customer Audits Do Not Permit Access to Other Customers
Nothing in this DPA requires EU Systems to:
- disclose another Customer's information;
- compromise the security of another Customer;
- provide unrestricted access to production systems;
- disclose information that would itself create a security vulnerability; or
- breach another legal or contractual obligation.
EU Systems may provide alternative evidence where direct disclosure would create such a risk.
22. Processing Instructions on Termination
Termination of the Service ends the Customer's continuing instruction for EU Systems to provide normal active processing, subject to:
- the agreed post-termination access/export period;
- deletion and backup processes;
- security requirements;
- legal retention requirements; and
- other processing required by law.
23. Liability
Liability arising under this DPA is subject to the applicable liability provisions of the agreement governing the Customer's use of Projects Library, except where Applicable Data Protection Law requires otherwise.
Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited.
24. Order of Precedence
If there is a conflict concerning the processing of Customer Personal Data between this DPA and the general Terms & Conditions, this DPA will take precedence to the extent of that conflict.
Mandatory provisions of Applicable Data Protection Law take precedence where applicable.
25. Governing Law
Unless Applicable Data Protection Law requires otherwise, this DPA is governed by the laws of England and Wales.
26. Contact
Data-protection enquiries relating to this DPA should be sent to:
EU Systems Ltd
Suite RA01, 195-197 Wood Street
London, E17 3NU
United Kingdom
Company number: 06956313
VAT number: GB 528 1369 81
Annex A - Details of Processing
A1. Subject Matter
Provision of the Projects Library SaaS platform and functionality selected by the Customer.
A2. Duration
For the period during which the Customer uses the Service, together with the applicable post-termination/export, deletion, backup and legally required retention periods.
A3. Nature and Purpose
Processing necessary to provide Projects Library, potentially including:
- collection;
- recording;
- organisation;
- storage;
- retrieval;
- consultation;
- display;
- search and indexing;
- text extraction from supported documents;
- AI embedding generation;
- User-requested Chat Analysis;
- encryption and controlled decryption;
- sharing with authorised Users and guests;
- transmission;
- backup;
- security;
- support;
- export; and
- deletion.
A4. Categories of Data Subjects
Depending on what the Customer chooses to store, Data Subjects may include:
- Customer personnel;
- Workspace Users;
- employees;
- contractors;
- clients and customers;
- suppliers;
- professional contacts;
- project participants;
- family members and personal contacts;
- people recorded as Resources;
- people mentioned in uploaded documents or conversations;
- guests; and
- other individuals whose information the Customer lawfully processes.
The Customer determines which Data Subjects are represented in its Workspace Content.
A5. Categories of Personal Data
Depending on Customer use, Customer Personal Data may include:
- names;
- contact details;
- professional and organisational information;
- project information;
- communications;
- meeting or conversation transcripts;
- tasks and decisions;
- notes;
- documents and attachments;
- photographs and other media;
- Resource/contact records;
- subscription information;
- website credentials;
- API credentials;
- other Vault information;
- information contained within shared Collections; and
- other personal data the Customer chooses to store.
A6. Special Category and Highly Sensitive Data
Projects Library is not specifically designed as a specialist repository for special-category personal data or information subject to specialised regulatory storage requirements.
Because the Service allows Customers to upload project information and documents, Customer Workspace Content could nevertheless contain special-category or otherwise sensitive personal data if the Customer chooses to place it there.
The Customer is responsible for determining whether such processing is lawful and whether Projects Library provides appropriate safeguards for its particular requirements.
The Service must not be used to store the prohibited financial authentication information identified in the Acceptable Use & Security Policy.
A7. Processing Frequency
Processing may occur continuously or intermittently as necessary to provide the Service and in response to Customer and User activity.
A8. Customer Instructions
The Customer's instructions are established through:
- its use and configuration of the Service;
- its Workspace settings;
- actions of authorised Users and Administrators;
- the Terms & Conditions;
- this DPA; and
- other written instructions accepted by EU Systems.