Skip to main content
HomeEngagement ModelLegal / Privacy
Legal · for procurement, legal & DPO

EU entity. GDPR-native. Artifacts ready.

The legal, GDPR and sub-processor evidence your vendor-risk review and DPIA require — a clear EU counterparty, signed processor terms, and fileable documents on request.

Legal entity

An EU company you can name in the DPIA.

A clear, EU-incorporated counterparty under EU law — the first box on any vendor-risk checklist.

EU legal entity

Celthrac EOOD · Sofia, Bulgaria

Registered EU company. Bulgarian commercial register ID and VAT number provided on the imprint and in contracting documents.

Governing law

EU jurisdiction

Contracts governed by EU member-state law, disputes seated in the EU. No US jurisdiction over your production data.

GDPR & data processing

Processor terms, ready to sign.

The processing terms and artifacts a DPIA requires — pre-prepared, not promised.

Role

Processor / sub-processor

We act as processor under Art. 28 GDPR, on documented instructions, under a signed DPA.

DPA

Standard Data Processing Agreement

A ready DPA with Art. 28 terms, SCCs where relevant, and Annexes describing processing, security and sub-processors.

Rights

Data-subject support

Tooling and process to support access, rectification, erasure and portability within statutory deadlines.

Sub-processor transparency

Who touches the data — and where.

A minimal, EU-resident sub-processor set with documented transfer safeguards.

Sub-processorPurposeRegionTransfer safeguard
Microsoft Azure (EU)Cloud infrastructureEUEU Data Boundary · SCCs
Databricks (EU)Data & ML platformEUEU residency · DPA
Self-hosted modelsSovereign inferenceEU / customer perimeterNo third-country transfer
Imprint
EntityCelthrac EOODSeatSofia, Bulgaria (EU)DPOdpo@celthrac.comReg / VATprovided in contracting docs
Let's build

Cleared.For contracting.

Send your DPIA template and vendor questionnaire — we return them completed under NDA.