You are in Armenia. What does that mean for personal data?
Your documents and databases stay on infrastructure registered to you; nothing is copied to my systems and nothing trains a model. What crosses a border is my access — I work from Armenia, which is not on the European Commission's adequacy list, and the EDPB's Guidelines 05/2021 (v2.0, 14 February 2023, section 2.2, page 8) treat remote access from a third country as a transfer even when the data itself never moves. I put that on the table before your DPO has to.
Then the choice is yours, before signing. Either the engagement runs with no access to production data on my side — build, tuning and the acceptance test on a synthetic or anonymised corpus, with your own people running anything that touches live records — or you grant named, time-boxed, revocable access and we paper it: an Article 28 data-processing agreement plus the Commission's Standard Contractual Clauses, Module Two, with completed annexes. For UK data, the corresponding UK instrument.
On request, before any contract and under NDA if you prefer, within two business days: the DPA, the SCC annexes, a written description of the Article 32 measures, the sub-processor list, the incident-notification procedure with its timings, and an importer information pack — the factual material on the Armenian legal regime and a log of government access requests. Annexes filled in for your specific engagement follow a scoping call.
What I do not have, plainly: no ISO 27001 or SOC 2 certification, no professional indemnity insurance as standard, no EU establishment. If one of those is a hard requirement in your procurement, say so in your first message and we both save a month. Your DPO classifies the arrangement; my job is to hand over everything they need to finish that in an afternoon.