Procurement-ready documentation starts with clear roles, data flows and launch gates.
This page is designed for municipalities, public authorities, data-protection officers, IT security teams and procurement reviewers. It explains EURtracker's intended GDPR operating model and the controls that must be documented before a public-sector production onboarding.
A processor model for customer project content, with separate service-administration responsibilities.
The intended model is that the customer organisation determines why project personal data is processed and therefore acts as controller for its project workspace. The EURtracker contracting entity processes that project data on the customer's documented instructions and acts as processor for that scope.
The EURtracker contracting entity may separately act as controller for limited service-administration data needed for account administration, security, billing, legal obligations and its own customer relationship. The final allocation of roles must be stated in the contract, privacy notice and Data Processing Agreement (DPA).
EURtracker is not designed to require special-category personal data. Customers should avoid entering sensitive personal data unless there is a documented lawful basis, necessity assessment and explicit processing instruction.
DATA MINIMISATION
Project evidence should be factual and proportionate.
Quick Updates should describe project events, not unnecessary personal details.
Reporting drafts are generated from selected project material rather than unrestricted account data.
Missing evidence remains visible instead of being silently invented.
Formal HR, health, case-management or citizen records should not be placed in EURtracker merely because they exist elsewhere in the organisation.
PUBLIC RECORDS BOUNDARY
EURtracker does not replace an authority's records-management duties.
Public authorities remain responsible for classification, retention, archiving, disclosure/public-access assessments and other records-management obligations that apply to their organisation. EURtracker can support export and traceability, but the customer's legal records process remains authoritative.
CORE SERVICE PROVIDERS
Subprocessor due diligence should follow the real technical data flow.
The following services are part of the current EURtracker architecture. A customer-facing subprocessor schedule should be frozen to the actual production configuration used for that contract and updated when providers or material processing locations change.
Application hosting, server-side execution and delivery
Data involved
HTTP request metadata and the application data needed to serve or execute a requested EURtracker function.
Public-sector baseline
Public-sector production should use a plan covered by Vercel's applicable DPA and document any international transfer mechanism used by the hosting service.
AI-assisted Progress synthesis and reporting drafts
Data involved
Only the project context and reviewed/captured reporting material selected by the relevant AI workflow is sent when a user requests AI assistance.
Public-sector baseline
EURtracker API requests use store:false. Public-sector production should additionally document the OpenAI project region, retention configuration and DPA/transfer safeguards. Eligible customers can use European API data residency and Zero Data Retention on supported configurations.
AI & DATA USE
AI assists drafting; it does not approve the report.
Current EURtracker AI workflows use the OpenAI API for Progress synthesis and reporting drafts. The application sends the selected source material needed for that request and uses store:false in the API request.
OpenAI states that API customer inputs and outputs are not used to train models by default.
store:false is not, by itself, a Zero Data Retention guarantee. The production OpenAI project and retention eligibility must be documented separately.
AI output remains editable and must be reviewed by a person before it becomes submitted reporting material.
European API data residency / ZDR should be evaluated as a public-sector production requirement where supported.
INTERNATIONAL TRANSFERS
Location and transfer mechanisms must be evidenced, not assumed.
EU/EEA hosting preferences reduce risk but do not automatically prove that every support, telemetry or subprocessor activity stays inside the EEA. Before onboarding a public authority, EURtracker should document the selected regions, applicable DPAs, subprocessors and any Standard Contractual Clauses or other lawful transfer mechanism relied upon.
RETENTION & DELETION
The customer contract should define the lifecycle.
How long live project data remains available during the contract.
How exports are returned before termination.
When active workspace data is deleted after termination or instruction.
How long provider backups/logs remain before expiry.
Which metadata must be retained for legal, security or accounting purposes.
INCIDENTS & DATA-SUBJECT REQUESTS
Operational procedures matter as much as product controls.
A public-sector contract should define a security/privacy contact, processor incident-notification procedure, cooperation with data-subject requests, export/deletion responsibilities and escalation path. EURtracker should never ask users to send passwords, API keys or other secrets in support screenshots.
DPIA & PROCUREMENT SUPPORT
Give the customer's DPO and IT team enough information to perform their own assessment.
EURtracker can support a customer's DPIA or security review by providing a system/data-flow description, purpose and categories of processing, access-control model, subprocessor schedule, locations/transfers, retention/deletion rules, incident process, AI data flow and technical/organisational measures. The customer remains responsible for deciding whether a DPIA is required and for completing its own legal assessment.
System & data-flow descriptionAccess & role modelSubprocessor scheduleRegion / transfer evidenceRetention & deletion annexIncident procedureAI processing descriptionDPA / Art. 28 terms
BEFORE A PUBLIC-SECTOR PRODUCTION CONTRACT
EURtracker's procurement pack should be completed against the exact production environment.
The pilot and preview environments are development environments. Before a municipality or authority is onboarded for production use, the contracting entity, vendor DPAs, production regions, retention schedule, security/privacy contact and customer DPA must be finalised and evidenced.