Legal
Data Processing Agreement
Last updated: 7 October 2026.
This page summarises the data processing terms under which KontextNews processes personal data on behalf of business customers, as required by Article 28 GDPR. A signable DPA is available on request.
Roles
For account and usage data, Codex Neuralis is the controller (see the Privacy Policy). For any personal data a customer submits through the API or asks us to process, the customer is the controller and Codex Neuralis is the processor.
Subject matter and duration
Processing covers the provision of the API service for the term of the customer's subscription and until data is deleted.
Sub-processors
| Provider | Role | Location |
|---|---|---|
| Hostinger | Website hosting | EU (Frankfurt) |
| OVH | API and database hosting | EU |
| Supabase | Authentication | EU / US (SCCs) |
| Stripe | Payments | EU / US (SCCs) |
We inform customers of any intended change to sub-processors so they can object.
Security measures
- Encryption in transit (TLS) and secrets encrypted at rest.
- Least-privilege database roles; the public API is read-only on its own schema.
- Per-key rate limiting, quotas and automatic banning of abusive traffic.
- Access limited to what is needed to operate the service.
Assistance and breach notification
We assist customers in responding to data subject requests and notify them without undue delay of any personal data breach affecting their data.
Deletion and return
On termination, personal data is deleted or returned as agreed, subject to legal retention obligations.
To execute a DPA, contact legal@codexneuralis.com.
See also: Privacy Policy ยท Terms of Service.