# Retorik — Data processing agreement

Version 3 · 8 September 2026

Part of the terms of service for every institution that uses Retorik, and for every solo executive who uses it for their business or profession ("you" below means either). A solo executive who uses Retorik as a private person is covered by the privacy notice instead, with the same promises. It covers the content the institution puts in, the people whose data is in it, and the connected accounts. Nothing needs signing: it applies from the first upload. An institution that needs a signed copy for its files asks at info@retorik.pro.

Canonical: https://www.retorik.pro/legal/dpa/

## In short

- **You decide, we carry out.** For the executive's writing, the drafts, the record and the connected accounts, you are the controller and we are the processor. We do only what is needed to run Retorik for you, on your instructions, never for our own purposes.
- **Two companies help us**, listed in annex C: Scaleway in the EU runs the service; Anthropic in the United States runs the AI model, under EU standard contractual clauses. We tell you 30 days before adding or changing one, and you can object.
- **We keep it safe** with the measures in annex B, keep it confidential, and tell you within 48 hours if a breach affects your data.
- **We help you meet your own duties**: answering people's requests about their data, dealing with a breach, and showing what we do.
- **When you leave, it goes.** Export first; then we erase everything within the periods in the terms.

## i. What this covers (annex A has the detail)


**Subject and purpose.** Storing the executive's writing and building a profile of their voice from it; drafting, refining and checking text with an AI model; keeping drafts, versions, review notes, references and the record of who did what; publishing approved posts to the accounts the executive connected; exporting; backing up and restoring. **Duration:** as long as the institution uses Retorik, plus the erasure period. **Nature:** storage, analysis, generation, transmission, backup. **Data and people concerned:** annex A.


## ii. Your side


You are responsible for the content you put in: that you may lawfully use the executive's writing and what it says about other people, that the people concerned know Retorik is used, and that you put in no more than you need. You instruct us by using the service: uploading, drafting, approving, publishing, exporting and deleting are all instructions. An instruction the service cannot carry out goes to info@retorik.pro; we say whether we can, and what it costs if it is not part of the plan.


## iii. Our side


1. **Only on your instructions.** We process the content only to run Retorik as these documents describe, and as the law requires of us. If we believe an instruction breaks the law, we tell you before acting on it.
2. **Confidentiality.** The only person with access to your content is the one who runs Retorik, bound to confidentiality. We do not open your content to look at it, except to fix a fault or to answer your support request; where a fix touches a draft the change appears in that draft's history.
3. **Security.** We take the measures in annex B and keep them current.
4. **Sub-processors.** We use the companies in annex C, and you agree to them. We add or replace one only after telling your administrators by email at least 30 days ahead. If you object and we cannot find another way, you can end the agreement and export; that is the remedy. Every sub-processor is bound by a written contract to at least these obligations, and we remain responsible for them.
5. **Transfers outside the EU.** Only to Anthropic in the United States, under the EU standard contractual clauses in its data processing addendum, with the supplementary measures in annex C. We transfer nothing else outside the European Economic Area. The platforms you publish to receive the post on the executive's own instruction, as independent controllers; that is not a transfer by us.
6. **Helping with people's rights.** If someone asks you to see, correct or erase their data and you cannot do it yourself in Retorik, we help within a reasonable time. If they ask us directly, we send them to you and tell you.
7. **Breaches.** If we learn of a personal data breach affecting your content, we tell your administrators within 48 hours with what we know: what happened, whose data, what we did, what we advise. We keep you updated. Telling the authority and the people concerned is your duty as controller; we help with the facts.
8. **Helping with assessments.** If you need to assess a risk or consult the authority about the processing in Retorik, we give you the information we have.
9. **At the end.** When the agreement ends we keep your content available for export for 30 days, then erase it within a further 30 days and its backups within 30 days after that, unless the law requires us to keep something, in which case we tell you what and for how long. Export before the end; after erasure there is nothing to return.
10. **Showing you.** On request we give you the information needed to show that we keep this agreement: this document, annex B, the sub-processor list, our record of processing, and any external security review once one exists. If that is not enough, you may audit, once a year, on 30 days' notice, at a reasonable time, at your cost, with a scope we agree beforehand so that other institutions' data is not exposed.


## iv. Liability and precedence


The responsibility section of the terms of service applies to this agreement too. Where this agreement and the terms say different things about personal data, this agreement wins. Where the law gives you as controller, or the people concerned, more than this agreement does, the law wins.


## A. Annex A — the processing


| | |
|---|---|
| Controller | You: the institution, or the solo executive acting for their business |
| Processor | RAAK.work, trading as Retorik, the Netherlands |
| Purpose | Running Retorik for you: voice profiling, drafting, review, publishing, export, backup |
| The executive's writing | Posts, articles, speeches, memos and other text the institution uploads or pastes, with titles, dates and the ideas and style extracted from them. Personal data of the executive, and of anyone the writing names |
| Drafts and the record | Drafts and their versions, review notes, references and their extracted claims, images, and the workflow record: who wrote, checked, approved, scheduled and published what, and when |
| Users | Name, work email and role of each administrator, comms person and executive you let in, and their actions in the workflow |
| Connected accounts | Encrypted access tokens, the platform's account name and identifier, and the identifiers of published posts |
| People concerned | The executive; your administrators and comms staff; people named in the executive's writing or in drafts |
| Special categories | None expected. If the executive's writing touches political opinions, health or similar, you take the extra care the law requires; our security is the same for all data |
| Duration | While you use Retorik, then export for 30 days and erasure within the periods in section 3.9 |
| Location | European Economic Area, except the AI model at Anthropic in the United States |


## B. Annex B — security measures


- **Separation between institutions.** Every query to the database carries the institution's identity; no page, action or export can reach another institution's data. Executives' writing is stored in a separate database per executive.
- **Sign-in.** Passwords stored only as salted hashes; passkeys supported; sessions carry a version so that all of a person's sessions can be ended at once; sign-in attempts limited per account and per address; invitation and reset links single-use, stored as hashes, expiring after seven days.
- **Leavers.** An administrator at the institution can remove a person's access at once. It takes effect everywhere on that person's next request, and it also stops what would otherwise outlive their sessions: invitations they had sent, API keys they held, and — for an executive — the connected accounts they could no longer disconnect themselves. The person's name stays on the work they did, because that is the editorial record; erasing a person is the separate deletion right in annex A.
- **Roles.** Administrators, comms and executives see and do only what their role allows, decided on the server from the session, never from the browser. Executives' own artifacts (audience, calibration, boundaries, background) can be changed only by the executive.
- **Tokens.** Platform access tokens encrypted with keys held outside the database, one key per platform; deleted on disconnect.
- **Inputs.** Uploads capped by size and checked by content (the bytes, not the file name) before they are read. Every URL a user asks Retorik to fetch is checked against internal and private addresses before and after redirects. AI generation rate-limited per user.
- **Headers and transport.** Strict security headers (content security policy, HSTS, no framing) on every response; TLS on every connection, including to the database.
- **Audit.** Every workflow action written to an audit log with who did it and when, visible to the institution; actions by our own staff inside an institution recorded in that institution's log.
- **Backups.** The database and the executives' writing backed up nightly, every copy integrity-checked, 30 nightly copies kept and the oldest pruned; a restore rehearsal takes place before the first institutional contract.
- **Least people.** One operator; no support staff with standing access.
- **The AI provider.** Anthropic does not train on API data and deletes inputs and outputs within 30 days; we send it only what a request needs and never the institution's user list or tokens.
- **Review.** An external security review takes place before the first institutional contract; its summary is available to institutions on request.


## C. Annex C — sub-processors


We tell administrators 30 days before a change.

| Company | Where | What it does for Retorik | Safeguards |
|---|---|---|---|
| Scaleway SAS | France; servers in Paris and Amsterdam | The server that runs Retorik, the managed database, the storage of the executives' writing and the backups, and the email we send (invitations, resets, notices) | In the EU; Scaleway's data processing agreement |
| Anthropic, PBC | United States | The AI model that drafts, refines and checks text, and its web search | EU standard contractual clauses in Anthropic's data processing addendum; no training on API data; deletion within 30 days; TLS; we send only the text a request needs, never user lists or tokens |

Not sub-processors: LinkedIn, X and Bluesky receive the posts the institution publishes, on the executive's own instruction, as independent controllers under their own terms.


Questions about this document go to info@retorik.pro.
