Data Processing Agreement

  • Last Revised : 14th Aug, 2026

This Data Processing Agreement ("DPA") applies to the processing of personal data by SVGHMI ("we", "us", the "Processor") on behalf of a customer ("you", the "Controller") when you use svghmi.pro or Coilmind (the "Service"). It forms part of, and is governed by, our Terms of Service, and it complements our Privacy Policy.

If you need a countersigned copy for your own records, write to support@svghmi.pro and we will send one.

1. Roles of the parties

For personal data you submit to the Service, or that the Service processes on your instruction, you are the controller and we are the processor. Where a member of your team is also an individual whose data we hold — for example the e-mail address on the account — we act as controller for that limited purpose, as described in the Privacy Policy.

2. Subject matter, nature and purpose

We process personal data only to provide, secure and support the Service: authenticating your account, issuing and validating licences, processing your subscription, and — for Coilmind — passing the material you send to an AI model and returning the result.

3. Duration

Processing lasts for as long as your account exists, and afterwards only for the period described in section 10.

4. Categories of personal data

Account and billing data. Name, e-mail address, country, subscription and payment status, and the technical identifiers of the machines a licence is activated on.

Usage and diagnostic data. IP address, browser and application version, timestamps, and error reports.

Project content, incidentally. This one deserves saying plainly. The PLC and HMI material Coilmind reads is normally not personal data — it is logic, tags and comments. But it can carry personal data without anyone intending it: an author name in block metadata, an engineer's initials in a comment, a customer contact in a project description. When you send such a block to a cloud model, that content goes with it. You decide what you send; if project content in your organisation routinely contains personal data, use Coilmind's offline mode, where nothing leaves the machine.

5. Categories of data subjects

Your employees, contractors and other authorised users of the Service, and any individual whose personal data happens to appear in the project content you process.

6. Your instructions

We process personal data only on your documented instructions, which are given by your use of the Service and by this DPA, unless we are required to do otherwise by law — in which case we will tell you first, unless the law forbids it. We will inform you if, in our opinion, an instruction infringes data protection law.

7. Confidentiality

Everyone we authorise to process personal data is bound by a duty of confidentiality and processes it only as needed to provide the Service.

8. Security

We apply appropriate technical and organisational measures under Article 32 GDPR. These are described in Annex II and include encryption in transit, access control on a need-to-know basis, isolation of production credentials, and self-hosted error monitoring so that diagnostic data is not shared with a third party.

9. Subprocessors

You give us general authorisation to engage subprocessors. The current list is published in the Subprocessors section of our Privacy Policy and is kept up to date. We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

We will announce any intended addition or replacement of a subprocessor by updating that list at least thirty (30) days before the change takes effect. If you object on reasonable data protection grounds within that period, write to support@svghmi.pro and we will work with you to find a solution; if none can be found, you may terminate the affected part of the Service and receive a pro-rata refund of any prepaid fees.

10. Deletion and return

On termination of your account we delete the personal data we hold, on the same periods stated in the Privacy Policy:

  • Account, licence and subscription data — deleted within 60 days of the account being closed.
  • Usage and diagnostic data — deleted no later than 14 months after collection.
  • Invoices and payment records — retained for as long as tax and bookkeeping law requires, currently seven years. This is a statutory obligation under Article 17(3)(b) GDPR and survives termination; the records stay protected under this DPA for as long as we hold them.

You can ask for a copy of your account data before deletion.

Coilmind holds no copy of your project content on our servers. Project content exists on your machine and, transiently, at the AI subprocessor while a request is being answered. One subprocessor, DeepInfra, states that it may retain API inputs and outputs briefly for debugging purposes; neither AI subprocessor uses the traffic to train models without explicit opt-in.

11. International transfers

Some of our subprocessors are established in the United States, so providing the Service involves transferring personal data outside the EEA. We make those transfers under the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference, together with supplementary measures: transport encryption, minimisation of the data sent, and the providers' own commitments not to use the traffic for training. Fireworks AI transfers under the standard contractual clauses and has appointed an EEA and UK privacy representative; DeepInfra's security measures are certified to SOC 2 and ISO 27001.

The Standard Contractual Clauses prevail if anything in this DPA conflicts with them.

12. Assisting you

Data subject rights. Taking account of the nature of the processing, we will assist you with appropriate technical and organisational measures in responding to requests to exercise rights under Chapter III GDPR. If a request reaches us directly, we will forward it to you rather than answer it ourselves.

Impact assessments. We will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, given the information available to us.

13. Personal data breaches

We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will describe what we know, the likely consequences, and the measures taken or proposed.

14. Audit

We will make available all information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits take place during business hours, on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, and subject to confidentiality.

15. Order of precedence

If there is a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service, in each case only in respect of the processing of personal data.

16. Annex I — description of the processing

Controller: the customer identified on the account.

Processor: SVGHMI, contactable at support@svghmi.pro.

Subject matter: provision of the svghmi.pro and Coilmind services.

Duration: the term of the account, plus the retention described in section 10.

Nature and purpose: authentication, licensing, subscription management, AI-assisted engineering support, support and security.

Personal data and data subjects: as described in sections 4 and 5.

Frequency: continuous, for the duration of the account.

17. Annex II — technical and organisational measures
  • Encryption of personal data in transit (TLS) between the application, our servers and every subprocessor.
  • Access to production systems restricted to named administrators, on a need-to-know basis, with credentials held outside the application repository.
  • Separation of production and development environments and data.
  • Licence and device binding, so that access to the Service is tied to authorised machines.
  • Error and diagnostic monitoring hosted on our own infrastructure, not shared with a third-party observability provider.
  • Regular backups of account and subscription data, restricted to the same access controls.
  • Minimisation: only the project context needed to answer a request is sent to an AI subprocessor, and nothing of it is retained by us.
  • Deletion routines that remove account data on termination, subject to statutory retention.
18. Annex III — subprocessors

The current list, with the role and location of each, is maintained in the Subprocessors section of the Privacy Policy. It forms part of this DPA.

Contact

Questions about this agreement, or a request for a signed copy, go to support@svghmi.pro.