Legal Português

Data Processing Agreement

Last updated: 6 October 2026

This Data Processing Agreement ("DPA") applies when a customer ("Customer") uses Probator.ai to process personal data for which the Customer is the controller, for example essays written by students, CVs from job applicants, or documents from clients. It supplements the Terms of Service between the Customer and Spawncore Unipessoal Lda ("Processor") and is entered into automatically when the Customer uses the Service for that purpose. If you need a countersigned copy, write to legal@probator.ai.

1. Subject matter and roles

The Customer is the controller and Spawncore is the processor of the personal data contained in the texts and documents the Customer submits ("Customer Personal Data"). Spawncore processes Customer Personal Data only to provide the Service described in the Terms. Details of the processing are in Annex 1.

2. Processing on instructions

Spawncore processes Customer Personal Data only on the Customer's documented instructions, which are given by these Terms, the DPA and the Customer's use of the Service's features, unless EU or Member State law requires otherwise; in that case Spawncore will inform the Customer before processing unless the law prohibits it. Spawncore will tell the Customer if, in its opinion, an instruction infringes data-protection law. Spawncore will not use Customer Personal Data to train AI models or for any purpose of its own.

3. Confidentiality

Spawncore ensures that everyone authorised to process Customer Personal Data is bound by confidentiality obligations.

4. Security

Spawncore implements the technical and organisational measures described in Annex 2, appropriate to the risk, as required by GDPR article 32. Spawncore may update these measures provided the overall level of protection is not reduced.

5. Sub-processors

The Customer gives general authorisation for Spawncore to engage the sub-processors listed on the sub-processor page. Spawncore will announce any intended addition or replacement on that page and, for customers who have subscribed to updates by writing to legal@probator.ai, by email at least 30 days in advance. The Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a refund of any prepaid, unused period. Spawncore imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains responsible for their performance.

6. International transfers

Where Customer Personal Data is transferred outside the European Economic Area, Spawncore ensures an adequate level of protection by relying on an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, which are incorporated by reference where required, together with supplementary measures where appropriate.

7. Assistance

Taking into account the nature of the processing, Spawncore will assist the Customer, by appropriate technical and organisational measures, in responding to requests from data subjects; the Service lets the Customer delete documents and export account data directly. Spawncore will also provide reasonable assistance with data-protection impact assessments and prior consultations, and with the Customer's security obligations, using the information available to it.

8. Personal data breaches

Spawncore will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal-data breach affecting Customer Personal Data, with the information required by GDPR article 33(3) as it becomes available, and will take reasonable steps to contain and remedy it.

9. Deletion and return

The Customer can delete Customer Personal Data at any time through the Service. When the Customer's account is deleted, Spawncore deletes Customer Personal Data from its live systems immediately and from backups within 30 days, unless EU or Member State law requires storage. The Customer can export its data before deletion.

10. Information and audits

Spawncore will make available the information necessary to demonstrate compliance with GDPR article 28, including this DPA, its security description and its sub-processors' certifications. Where this is not sufficient, the Customer may carry out an audit, at its own cost, by an independent auditor bound by confidentiality, with at least 30 days' notice, no more than once a year (unless required by a supervisory authority or after a breach), and in a way that does not disrupt the Service or compromise other customers' data.

11. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms, except where the law does not permit limitation. If this DPA and the Terms conflict regarding personal data, this DPA prevails. This DPA ends when Spawncore no longer processes Customer Personal Data.

Annex 1: details of the processing

Nature and purposeHosting, analysing and storing texts and documents to provide grammar suggestions, AI-detection results, plagiarism results and hidden-mark analysis, as requested by the Customer
Categories of data subjectsAuthors of, and people mentioned in, the texts the Customer submits (for example students, job applicants, employees, clients); the Customer's authorised users
Categories of personal dataAny personal data contained in the submitted texts and file metadata (such as names, contact details, education and employment history, opinions); user account data
Special categoriesNot intended. The Customer should avoid submitting special categories of data unless necessary and lawful.
DurationFor the duration of the Terms, and until deletion as described in section 9
RetentionDocuments saved by the Customer: until deleted by the Customer. Texts checked without saving: not stored in the account; a report cache of up to 24 hours (never for plagiarism results). Backups: up to 30 days.

Annex 2: technical and organisational measures