Dated 11 October 2026 · Version 2026-10-11-2
Published version and acceptance
This version was approved by Emplio and published on 11 October 2026. It becomes binding on an individual Customer upon documented acceptance under section 1. Publication does not automatically replace a previously accepted agreement. Appendices B–D describe supplier arrangements, documentation status and conditions for separately instructed AI processing.
The provisions below are the contractual terms offered by Emplio. Descriptions of existing features in the appendices are based on source code and do not certify production operations. The Agreement draws on the Danish Data Protection Agency’s Danish template, version 1.2, with independently drafted and adapted provisions. It is not the Agency’s unchanged standard clauses or a legal approval.
1. Parties, scope and acceptance
This Agreement is between the customer company identified by its legal name, address, Danish CVR number or equivalent identification and customer account in the acceptance records (the Customer/controller), and Emplio ApS, CVR 46460316, Rugmarken 21, 2860 Søborg, Denmark (Emplio/processor). Emplio’s contact is hi@emplio.io. The Customer appoints a contact for instructions, rights requests and personal data breaches. The parties keep their contact details current.
This Agreement covers Emplio’s processing of personal data on the Customer’s behalf in providing the wellbeing application. Appendices A–D form part of the Agreement. In a conflict, this Data Processing Agreement takes precedence over the general terms without limiting statutory rights. Emplio’s own customer administration, billing and marketing purposes are addressed separately in the privacy policy and do not authorise reuse of employees’ responses.
A final version takes effect when both parties’ acceptance of the same version and any customer-specific appendices is documented in writing or electronically. The Customer’s representative must be authorised to conclude the Agreement. Visiting the page, silence or earlier acceptance of general terms does not in itself demonstrate acceptance of this Agreement. The parties must be able to save and retrieve the entire accepted text.
2. Customer responsibilities and documented instructions
The Customer determines the purposes and essential means of processing, ensures a lawful basis and provides data subjects with the required information. Where processing involves special categories of data, the Customer must have both a basis under Article 6 and a relevant exception under Article 9. This Data Processing Agreement does not create those bases.
Emplio processes data only on the Customer’s documented instructions, including for transfers to third countries, unless required otherwise by Union or Member State law applicable to Emplio. In that case, Emplio informs the Customer of the requirement before processing unless the law prohibits this on important grounds of public interest. Instructions comprise this Agreement, its appendices and subsequent documented instructions from authorised persons.
Emplio immediately informs the Customer if, in its opinion, an instruction infringes data protection rules and suspends the affected processing pending clarification. Emplio does not use the Customer’s personal data for its own advertising, sales, model training or other independent purposes. Using an export function does not in itself instruct Emplio to send data to an external AI service.
3. Confidentiality and access
Emplio ensures that persons with access are bound by contractual or statutory confidentiality and process data only to the extent required by their work. This obligation survives the end of access or employment. Emplio must be able to document access authorisation and confidentiality to the Customer.
Emplio states that all its employees can technically open customer data when needed. This is not a promise that access is restricted to a separate support team. Emplio has confirmed that access protection and confidentiality are in place. Access lists and permissions are maintained according to work needs. The Customer assigns appropriate permissions to its own users. Emplio’s support and administrative access may be used only for documented, necessary operations, security or support tasks. Access must be restricted and removed when no longer needed. Technical support access is not general permission to read responses.
4. Security of processing
Emplio implements and maintains appropriate technical and organisational measures under Article 32, taking account of the nature, scope, purposes, context and risks of processing. The assessment covers confidentiality, integrity, availability and resilience, recovery after incidents and regular testing of measures. Encryption and pseudonymisation are used where appropriate to the risk.
Appendix C describes measures supported by the code and operational details to be completed before acceptance. Emplio documents its assessment and assists the Customer with its security assessment. Changes must not reduce the agreed security level; material changes affecting the Customer’s risk assessment are notified to the Customer.
5. Subprocessors
The arrangement is specific written authorisation. Emplio may use only subprocessors that the Customer has authorised in writing for the relevant processing. Before adding or replacing a subprocessor, Emplio requests authorisation and provides its legal identity, task, data types, processing countries, security and any transfer mechanisms. No response does not constitute authorisation. If the Customer objects, the supplier may not be used for the Customer’s data; the parties determine an alternative or terminate the affected service with return and deletion of data.
Before processing begins, Emplio enters into a written agreement imposing the same relevant data protection obligations and sufficient guarantees on the subprocessor as under this Agreement. This also applies to further use of subprocessors. Emplio remains fully liable to the Customer for their performance of those obligations.
On request, Emplio provides copies of relevant subprocessor agreements and amendments; purely commercial information may be omitted if this does not weaken the Customer’s oversight. Appendix B records documentation status and is not yet an authorised supplier list.
6. Processing outside the EU/EEA
Processing and access from third countries, including remote support, require the Customer’s documented instructions and compliance with GDPR Chapter V. Before a transfer, Emplio documents recipients, countries, transfer mechanisms and necessary supplementary measures, including an assessment of protection when standard contractual clauses are used.
This Agreement is not a transfer mechanism. A supplier name, European billing address, encryption or Zero Data Retention does not in itself establish processing exclusively within the EU/EEA or a lawful third-country transfer. Publication alone gives no general instruction for third-country transfers. Specific instructions and mechanisms must be included in the Customer’s Appendix C and, for AI, in a separate addendum.
7. Rights, impact assessments and authorities
Taking account of the nature of processing, Emplio assists the Customer, insofar as possible, through appropriate technical and organisational measures with compliance with GDPR Chapter III: information, access, rectification, erasure, restriction, notification of recipients, portability, objections and rights concerning automated decisions.
Requests from data subjects are forwarded without undue delay to the Customer’s contact. Emplio does not answer on the Customer’s behalf without instructions, other than referring the person to the Customer. Emplio assists in locating relevant data, implementing the Customer’s decision and explaining technical limitations. Data must not be attributed to a particular employee by guessing or unnecessary re-identification.
Taking account of the nature of processing and available information, Emplio assists with obligations under Articles 32–36, including risk assessments, impact assessments and prior consultation with the Danish Data Protection Agency or another competent supervisory authority. Assistance includes information on data flows, access, suppliers, security, incidents, deletion and planned changes. The Customer decides on legal bases, impact assessments and communications with authorities.
8. Personal data breaches
Emplio notifies the Customer without undue delay after becoming aware of a personal data breach. Emplio does not wait for a complete investigation; missing information is supplied progressively. Any 72-hour deadline applicable to the Customer’s notification to an authority is not a waiting period for Emplio.
Notification is sent to the Customer’s registered security or contractual contact and describes the nature, timing and discovery of the breach, affected data types and approximate numbers of persons and records, likely consequences, remediation and mitigation, and an Emplio contact. Emplio secures relevant documentation and assists with the Customer’s notification to authorities and, where applicable, data subjects. Assistance and follow-up are documented. Material new information is provided without undue delay, and an update schedule is agreed with the Customer. Emplio’s DPO coordinates the matter and customer communications; management remains responsible for ensuring technical remediation and notification. If the DPO is absent, management assigns a responsible person. Emplio has confirmed that its DPO handles these matters; contact channels and handover are maintained as part of operations.
9. Retention, return and deletion
Data is retained only for as long as necessary for the Customer’s documented instructions and agreed purposes. Scores, measurement history and ordinary free-text comments are generally retained during the active relationship without automatic age-based deletion. The purpose is to track developments, compare measurements and evaluate implemented initiatives. The Customer assesses necessity at least annually, including the separate need for raw free text. The Customer may instruct earlier deletion or restriction; specific deletion requirements and loss of necessity take precedence over the maximum periods in Appendix C.
On termination, the Customer chooses deletion or return followed by deletion. For return, Emplio prepares an export in an agreed, commonly used electronic format at planned termination; otherwise without undue delay and no later than 14 calendar days after termination. An aggregated report export does not necessarily constitute complete return of the Customer’s data.
The Customer has a collection window until six months after termination through separate, controlled access. Emplio sends a reminder 30 calendar days before expiry. At expiry, collection access is closed and the export copy is deleted. The window allows the Customer to hand over and check the history and potentially migrate to another solution. The necessary export is kept protected for that purpose; other active data is deleted earlier when no longer needed for winding down. Six months is the Customer’s collection window, not Emplio’s delivery time.
All active copies are deleted no later than six months after termination. All remaining backup copies are deleted or expire no later than 12 months after termination. Both deadlines and the collection window run from the same termination date and are not added together. Earlier necessary deletion, the Customer’s earlier deletion instructions and shorter backup rotation take precedence. The periods do not authorise retaining unnecessary data.
On termination, ordinary use, new measurements, invitations and AI analysis stop. Only necessary, documented wind-down processing on the Customer’s instructions continues, with restricted access and monthly assessment of necessity. Collection availability does not in itself justify retaining the entire production database.
Deletion must cover relevant operational data, invitations, responses, files, export copies, report history and subprocessor copies, as well as backups under the documented procedure. Until deleted, backups must be protected against ordinary use; previous deletion instructions must be reapplied on restoration. Emplio confirms completion in writing and identifies any remaining copies and their final deletion date.
After necessary winding down is completed, and no later than the relevant maximum deadlines, data may be retained only where Union or Member State law requires it. Emplio informs the Customer of the specific requirement, data, duration and limited purpose unless prohibited by law. Emplio’s own accounting obligations do not generally permit retaining employee responses. The Agreement’s protections remain in effect until all covered data is deleted.
10. Documentation, audits and duration
Emplio makes available all information necessary to demonstrate compliance with Article 28 and this Agreement and allows for and contributes to audits and inspections by the Customer or its authorised auditor. Lawful access by supervisory authorities is not restricted.
The Customer may first request written documentation and then remote or on-site inspection where necessary. The parties agree practical access arrangements and protection of other customers’ data. Reasonable notice is sought for routine audits but must not prevent urgent audits following breaches, justified suspicion or authority requirements. There is no agreed limit of one annual audit or requirement to accept certification as the sole evidence.
Emplio carries out risk-based oversight of subprocessors and makes documentation and follow-up on findings available. The Customer may request additional information or participation in relevant inspections if documentation is insufficient. This Agreement does not imply that Emplio or its suppliers already hold any particular certification or audit report.
The Agreement may be renegotiated following changes in law or processing. It cannot end while Emplio continues to process the Customer’s data unless replaced by another agreement providing coverage. New versions do not automatically replace an accepted version; amendments and the Customer’s acceptance are documented.
Appendix A — Details of processing
A.1 Purpose and subject matter: Providing the Customer’s employee and wellbeing measurements, invitations and reminders, team and access administration, and calculation, display and export of results for ordinary workplace wellbeing and management follow-up. AI processing under Appendix D generates management, HR and employee reports. The purpose does not include collecting or analysing special categories of personal data under GDPR Article 9 or handling sensitive individual cases. Support and necessary operations take place within this purpose. AI processing requires the separate instructions in Appendix D.
A.2 Nature: Creating and importing employees, recording team membership, sending system emails, collecting and storing responses, calculating scores and group statistics, filtering by measurement round and team, displaying results to authorised users and exporting to JSON and PDF. Rectification, restriction, return and deletion follow the Customer’s instructions. For AI processing, this includes automated processing of the entire dataset for the instructed report, including free text, without prior manual review of responses, as set out in C.5 and Appendix D.
A.3 Personal data: First and last name, work email, team and manager relationship, active status, employment date, date of birth, gender, employment type and customer-added metadata insofar as the Customer uses those fields. Also user accounts and permissions, invitation identifiers/tokens and timestamps for sending, viewing, reminders and completion; questionnaire, measurement round, questions, scores, free-text answers, team, demographic categories and response/submission metadata. Technical operational and access data is processed insofar as necessary for the service; production log fields and retention must be documented in Appendix C. AI input may therefore also contain unintentionally entered data as described in A.4; such data is handled under C.5–C.5.2.
A.4 Data subjects and unintended data categories: The Customer’s current and former employees, managers and administrators, and persons mentioned in free text. Emplio does not request health data or other special categories under GDPR Article 9. However, free text may unintentionally contain such data, data relating to criminal offences under Article 10, or identifying details of individual cases. Such data may be included in raw data and automated AI input even though the model is instructed to omit it from the report. This does not expand the agreed purpose or itself provide a legal basis. The Customer must guide respondents as set out in C.5. Intentional collection or analysis of special categories or criminal offence data is outside the standard instructions and requires separate clarification of necessity, legal basis and security.
A.5 Planned WHO-5: The source code contains WHO-5 questions and calculation of wellbeing status. Emplio states that the feature is not really used currently but is intended for use. This planned measurement of mental wellbeing may involve health data and is outside the standard instructions. Before use, a separate addendum must define the purpose, questions and derived assessments, data subjects, access, retention and security. The Customer must document the relevant bases under Articles 6 and 9, employee information and assessment of the need for a data protection impact assessment. This is planned processing, not merely unintended free text.
A.6 Duration and access: Processing runs from valid acceptance through service delivery until return and final deletion. Customer administrators and report users have access according to their permissions and team scope; authorised Emplio personnel may have technical administrative access. Absence of names in a report does not guarantee anonymity: combinations of team, demographics, timestamps and free text may identify individuals.
Appendix B — Suppliers and documentation status
e-studio ApS, CVR 37074640, Højgårdsvej 25, 8620 Kjellerup, is listed in Emplio’s privacy policy as the application hosting and system email supplier. Hosting may encompass the entire application dataset; email includes recipient details and message content. The supplier’s public processor template mentions a Global Connect data centre in Skanderborg. Hosting terms describe product-dependent backups retained for up to 31 days; some server products require a separate purchase. Emplio states that the application runs on e-studio’s Large VPS, maintained by e-studio, with purchased/included backup. The product choice is therefore confirmed by Emplio. Public information still does not establish the concluded agreement, specific VPS backup rotation, full email/backup chain or support countries. The standard hosting terms and public processor template have been retrieved as source material. Section 13.1 of the template requires both parties’ signatures; downloading alone therefore does not demonstrate conclusion. Coverage of Emplio’s role as a processor must follow from the agreement actually concluded.
Vercel hosts the marketing website and forwards registration data to Laravel. Marketing, cookie and advertising services do not thereby become subprocessors of employee responses. No flow sending wellbeing responses to them has been found in emplio_sales. If a supplier also processes the Customer’s application data on its behalf, the relevant processing must be documented and included in the supplier list.
Google Cloud/Vertex AI is selected as a subprocessor for the separately instructed AI processing in Appendix D. Its task is automated processing of the entire dataset for the instructed report, including wellbeing figures, free-text responses and relevant, scoped report history, to generate management, HR and employee reports. Free text may contain unintended data as described in A.4 and C.5; no manual prescreening takes place before data is processed by the AI service. Model processing takes place in the EU under D.2. The chain is Customer → Emplio → Google. OpenRouter is not part of this chain.
Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland, is the standard contracting entity for Google Cloud Platform with a Danish billing address according to Google’s public entity list. This is the contractual basis used here, assuming Danish billing and no separate agreement. The standard Google Cloud Terms of Service, Cloud Data Processing Addendum and Service Specific Terms have been retrieved as source material. A public source copy is not an account acceptance receipt. Before AI processing under this Agreement, identity, contractual coverage, Google’s relevant subprocessors, processing countries and any transfer mechanisms must be documented and authorised under sections 5–6. An EU endpoint for AI requests does not by itself establish the location of support, logs and other processing.
Appendix C — Instructions, security and operational matters
C.1 Instructions: Emplio may carry out the activities in Appendix A for the Customer’s selected measurements and users. Data must be limited to what is necessary. Exports may be accessed only by the Customer’s authorised recipients or processed by Emplio on documented instructions. External AI processing and local report history for AI processing require Appendix D’s addendum.
C.2 Measures supported by code: The application is configured with customer-specific databases and customer scoping of caches, files and queues. Access to reports and exports is controlled through user permissions and team access. Employee email has an encrypted database field; passwords are hashed. This does not demonstrate encryption of all fields, backups or the overall production infrastructure.
AI export suppresses groups below a minimum threshold of at least five and may include comments following a separate selection. A text filter attempts to remove known employee names. These controls reduce risk but do not prove anonymity, absence of health data or a lawful basis. No prior manual review of free text takes place. AI processing uses the system instructions in C.5; on becoming aware of specific data outside the instructions, C.5.2 applies.
C.3 Operational documentation before a final version: Emplio must document actual processing locations for operations, email, backups and support; access allocation and review, confidentiality, any multi-factor authentication, logging, updates, incident management and regular security review. Specific backup, recovery and deletion procedures must be documented and capable of meeting the deadlines below. Emplio has appointed its DPO to coordinate personal data breaches. Emplio has confirmed that deletion can be performed, that breaches are handled by the DPO and that access protection and confidentiality are in place. These are statements by the operator, not an independent technical audit.
C.4 Retention during the relationship: Scores, measurement history and ordinary free-text comments follow section 9 without a fixed age limit for as long as the Customer’s documented purposes require retention. This includes relevant reports and, under separate AI instructions, necessary local AI history. An employee leaving does not permit continued retention of unnecessary identity links.
Employee profiles and direct identity links are deleted no later than 30 calendar days after the Customer records departure or instructs permanent removal; invitations stop immediately. User accounts are closed immediately on revocation and deleted no later than 30 calendar days afterwards. Invitations, tokens and identifiable participation status are deleted no later than 90 calendar days after the measurement round ends, or earlier upon employee deletion. Invitation access is invalidated at the end of the round.
Technical application, web and email delivery logs are deleted no later than 30 calendar days after recording. Separate security and access logs are deleted no later than 180 calendar days after the action. Temporary export and support copies are deleted when the task is resolved and no later than seven calendar days after creation. The special termination export follows the collection window in section 9; download links expire no later than seven calendar days after issue and may be reissued after recipient verification within that window.
C.4.1 Termination: Collection remains possible until six months after termination; active operational data, files, caches, queues, local reports, AI history and suppliers’ active copies are deleted by that same six-month deadline. Backup copies are finally deleted no later than 12 months after termination. Example: termination on 1 November 2026 means collection and active deletion by 1 May 2027 and final backup deletion by 1 November 2027.
C.4.2 Execution: Emplio appoints a deletion lead and substitute, verifies the instruction’s sender and customer scope and maps all relevant copies. Deletion instructions during ongoing operations are implemented without undue delay and no later than 14 calendar days after receipt unless a shorter deadline applies. Deletion means actual removal or documented irreversible anonymisation; soft deletion alone is insufficient. Emplio checks the result and records the executor, scope, date and remaining copies. The Customer receives confirmation of active and final deletion.
C.4.3 Backup: Backups are not used for ordinary reporting. On restoration, the system remains isolated and previous deletion instructions are reapplied before normal access is restored. Copying or restoration does not extend the final deadlines. Existing shorter rotation is not extended to 12 months. Maximum remaining backup lifetime after specific deletions during an active relationship: to be determined from documented supplier rotation in the Customer’s instructions; a future termination date must not permit unlimited retention.
C.4.4 Documentation: Minimal deletion evidence and closed incident records are retained for at most three years after closure, with annual necessity review and without raw responses. Raw technical incident evidence is deleted no later than 90 calendar days after closure, or earlier when no longer needed. Specifically necessary retention for a dispute or authority investigation is limited in scope and reviewed every 30 days.
Operational status: The periods in section 9 and Appendix C are contractual obligations upon acceptance, not evidence of existing automation. Emplio has confirmed its ability to delete data and approved the wind-down purpose. Actual supplier periods must still match the Agreement. A specific test exercise is a recommended check, not a separate statutory requirement or proof of existing automation.
C.5 Processing of free text and unintended data: Processing includes free-text fields for ordinary workplace wellbeing and management follow-up. The purpose does not include collecting or analysing special categories of personal data (GDPR Article 9). The Processor does not carry out prior manual review of submitted responses. For AI processing under Appendix D, the entire dataset for the instructed report, including free text, is processed automatically through the Processor’s connected AI service, Google Cloud/Vertex AI in the EU. Processing follows predefined system instructions requiring the model to summarise only overarching work-related themes and to omit sensitive data, individual cases and identifying information from the final report. As controller, the Customer must, before responses are submitted, instruct respondents not to enter health data or other sensitive data in free-text fields and to omit names and other identifying details about themselves or others.
C.5.1 Scope and legal basis: The entire dataset means the data covered by the Customer’s instructions for the specific report, not all Customer data or the entire report archive. The system instructions concern report output and are neither prescreening nor a guarantee of complete exclusion or anonymisation. Unintended sensitive data may therefore be processed in raw data and AI input even if absent from the final report. Omission from output does not delete raw data or supplier copies. Neither the Customer’s guidance nor the model’s system instructions itself provides a legal basis or an exception under Article 9. Section 2 on lawful bases and unlawful instructions also applies to such data.
C.5.2 Handling on becoming aware: Emplio does not, as a general practice, routinely delete or edit the content of employee comments. This does not affect the Customer’s right to instruct rectification, restriction or deletion, or the obligation to handle data outside the agreed instructions. On becoming aware of such data, further use, including export and AI, is restricted and the DPO coordinates clarification with the Customer without undue delay. The Customer must give documented instructions on handling and any basis for continued processing. No response does not permit unlimited retention; Emplio follows up and escalates to the Customer’s responsible person. Necessary deletion or editing is carried out under the Customer’s lawful instructions and applicable requirements. There is no promise of automatic monitoring or a fixed seven-day deadline for all comments.
The Customer’s decision, affected copies and implementation are documented with as little personal data as possible. Reports already distributed, export files and any supplier copies are included in follow-up. If the incident also constitutes a personal data breach, section 8 applies. The procedure requires a responsible contact and practical ability to restrict and delete data before operation; there is no claim of automatic detection of all sensitive data.
C.6 Assistance and oversight: Enquiries to hi@emplio.io are assigned to a responsible person and handled under sections 7–10. Emplio provides relevant extracts, processing information and evidence of implemented instructions through a suitably secure channel. The production procedure must specify responsibility, escalation and the Customer’s contact. Authorised processing countries and any specific third-country instructions must be added on a documented basis; they cannot be inferred from a supplier’s name.
Appendix D — AI processing and separate instructions
D.1 Purpose and separate instructions: AI processing generates suggested management, HR and employee reports for ordinary workplace wellbeing and management follow-up. The entire dataset for the instructed report, including free text, is processed automatically without manual prescreening under C.5–C.5.2. The model is instructed to summarise only overarching work-related themes and omit sensitive data, individual cases and identifying information from the report. The Customer must separately instruct on data, measurement rounds, teams, recipients, history, retention and suppliers. Aggregates and free text are treated as personal data unless a specific assessment establishes genuine anonymisation. AI outputs are suggestions for human assessment and must not be used for automated decisions producing legal or similarly significant effects on employees.
D.2 Supplier and routing: Customer → Emplio → Google Cloud/Vertex AI. Requests go directly to the configured EU endpoint without OpenRouter as intermediary. There must be no fallback to another provider or unauthorised region. The stated technical configuration was tested in a separate setup session; endpoint, model, regional restrictions and change control must form part of operational documentation. This does not in itself guarantee that all support and log processing takes place in the EU.
D.3 Supplier terms: Google must be covered by Emplio’s direct Google Cloud agreement and Cloud Data Processing Addendum with Emplio as processor and Google as subprocessor. The Customer’s authorisation must cover the relevant further processing chain. The precise legal contracting entity, covered services and accepted agreement version must be documented before activation.
Checks in the separate chats and report tool’s operational documentation on 11 October 2026 show project emplio-511210, EU endpoint aiplatform.eu.rep.googleapis.com and model google/gemini-3.8-flash without global fallback. Project caching and model request-response and OTel logging are disabled, evidenced by confirmed configuration changes and subsequent reads. According to Emplio, the account uses standard online terms; an exemption from Google’s separate abuse monitoring logging is not documented. Follow-up on abuse logging is deferred by Emplio’s decision. This potential content retention must be included in the assessment and must not be described as disabled; deferral does not itself provide additional processing instructions. Emplio documents the specific Google Cloud terms and settings for input/output use, training, logging, caching, abuse monitoring, support access and deletion. Previous OpenRouter settings are not evidence for Google Cloud. No undocumented Zero Data Retention promise is made.
Google’s relevant deletion processes must be mapped for the services actually used and accommodated within section 9 and Appendix C. Emplio must initiate supplier deletion early enough to meet the Customer’s deadlines; sending instructions only at expiry is insufficient. A general supplier deadline does not establish that all AI inputs are actually retained throughout that period.
D.4 Local processing: The report tool’s operational log contains only permitted technical metadata, such as timestamps, request IDs, status, duration and token usage, not prompts, comments, AI responses or credentials. Logs have seven-day retention and automatic cleanup; on powered-off or sleeping equipment, cleanup runs when the task can next execute. This does not apply to report history or supplier logs. The report tool can import JSON, prepare selected data and send it to AI. Uploads remain in process memory with a one-hour expiry and periodic cleanup. Generated reports, however, are stored in local SQLite with source data, analysis and HTML. The reviewed report history has no automatic expiry or deletion function. Downloaded JSON/PDF files, local copies and device backups are not covered by upload expiry.
Comparison history is scoped by company ID, report type, team scope and an earlier dated measurement. Only the selected comparison and relevant earlier analysis are added to model input; the entire archive is not sent automatically. The server listens locally on 127.0.0.1 and the SQLite file is created with restricted file permissions. This is not multi-user access control, disk encryption or evidence of secure device backups.
D.5 Conditions before activation: Separate Customer instructions, supplier agreements covering roles and data types, verified provider routing without unauthorised fallback, processing countries and lawful transfer mechanisms with necessary assessments must be in place. The Customer must have clarified the legal basis, employee information and need for an impact assessment. Emplio must document and maintain the system instructions in C.5 and check their intended effect on report output; this does not entail manual prescreening of raw data. Emplio must establish access and deletion procedures for local copies, and documentation of supplier settings and handling of breaches and rights. Until then, AI processing must not begin using the Customer’s personal data on the basis of this Agreement. The ordinary Agreement may be finalised while AI processing remains outside the instructions.
Sources
Official sources checked on 11 October 2026. Suppliers’ public standard terms do not themselves document Emplio’s specific contractual coverage.