Data processing agreement
The template we sign with customers. Public before any sales conversation, so a legal team can read it without asking anyone for a favour.
This is an English rendering for convenience. The binding version is the Polish one, available at aivatary.com/pl/dpa/. In case of discrepancy, the Polish text prevails.
When this agreement is needed
We conclude it whenever a customer deploys an Agent conversing with their own customers. The controller of those people's data is then our customer, and we are a processor acting on their instruction. The split of roles is described more fully in the privacy policy.
1. Definitions
Personal data, processing, controller, processor, personal data breach and data subject carry the meanings given in Regulation 2016/679 (GDPR). The Controller is the customer using the Service. The Processor is MH Daniel Możdżyński, ul. Sędziwoja 49 lok. 3, 61-063 Poznań, Poland.
2. Subject matter, nature and purpose
- The Controller entrusts the Processor with processing personal data for the purpose of providing the service described in the terms of service.
- Nature of processing: storage, retrieval, disclosure within a conversation with the data subject, transfer to the providers listed in Annex 3, and erasure.
- A detailed description of processing is in Annex 1.
3. Duration
This agreement runs for the term of the main contract. It expires when processing ends and the obligations under section 12 have been fulfilled.
4. Types of data and categories of data subjects
Types of data and categories of data subjects are set out in Annex 1. The Controller is responsible for ensuring that the data reaching the Knowledge base and conversations does not exceed what is necessary for the purpose.
5. Controller instructions
- The Processor processes data only on the Controller's documented instruction. Use of Service functions by the Controller counts as such an instruction.
- If, in the Processor's view, an instruction infringes the GDPR or other data protection provisions, the Processor informs the Controller without delay.
6. Confidentiality
The Processor ensures that persons authorised to process the data have committed to confidentiality or are under an appropriate statutory obligation. Authorisations are granted individually and only to the extent necessary.
7. Security of processing
The Processor applies technical and organisational measures appropriate to the risk, listed in Annex 2, in accordance with Article 32 GDPR.
8. Subprocessors
- The Controller gives general authorisation for the subprocessors listed in Annex 3.
- The Processor informs the Controller of an intended addition or replacement of a subprocessor at least 30 days in advance, naming the entity, the scope of operations entrusted to it, the country of processing and the basis for any transfer outside the European Economic Area.
- The Controller may raise a reasoned objection within that period. If the parties find no solution, the Controller may terminate the contract in the part the objection concerns.
- The Processor imposes on subprocessors the same data protection obligations as arise from this agreement and remains liable for their acts as for its own.
9. Assistance with data subject rights
- The Processor provides a Service function allowing the Controller to satisfy erasure requests themselves, including a preview of the erasure scope before it runs and a record of how the requesting person’s identity was verified.
- Access, rectification and portability requests are satisfied by the Processor on the Controller’s documented instruction, within a period allowing the Controller to meet the deadline under Article 12(3) GDPR. The scope of self-service functions may be extended, and such extension does not require an amendment to the Agreement.
- A request addressed directly to the Processor is passed to the Controller without undue delay, and the requester is told that it was.
10. Assistance with Articles 32 to 36 GDPR
Taking into account the nature of processing and the information available to it, the Processor assists the Controller in meeting obligations concerning security of processing, breach notification, communication to data subjects and data protection impact assessment.
11. Personal data breaches
- Having become aware of a personal data breach, the Processor notifies the Controller without undue delay and no later than 24 hours after becoming aware.
- The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken.
- Where full information is not available at once, it is provided in phases without waiting for completeness.
12. End of processing
- After the provision of services ends, the Processor deletes or returns the data at the Controller's choice and deletes existing copies.
- The Knowledge base is exported in an open format on the Controller's request.
- The deletion obligation does not apply to data whose storage is required by Union or Member State law.
13. Demonstrating compliance and audit
- The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR.
- The Controller may carry out an audit, including an inspection, after at least 30 days' notice, no more than once per calendar year, unless the audit follows a personal data breach.
- An audit may not compromise the confidentiality of other customers' data or the security of the platform.
14. Transfers outside the European Economic Area
Transfers to a third country occur only to the extent stated in Annex 3 and only under a mechanism provided for in Chapter V GDPR.
15. Liability
The parties are liable on the principles set out in Article 82 GDPR and in the main contract. Provisions of the main contract limiting liability do not exclude liability towards data subjects.
16. Final provisions
- This agreement requires documentary form to be valid.
- In case of conflict between the main contract and this agreement on data protection matters, this agreement prevails.
- Matters not covered are governed by the GDPR and Polish law.
Annex 1. Description of processing
| Item | Content |
|---|---|
| Subject matter | Holding conversations with the Controller's customers through the Agent and storing the Knowledge base |
| Duration | The term of the main contract |
| Nature and purpose | Storage, retrieval, disclosure in conversation, transfer to subprocessors, erasure |
| Types of data | Identification and contact data, conversation content, voice session data, data contained in the Knowledge base, technical session data |
| Categories of data subjects | The Controller's end customers, the Controller's Operators |
| Retention | The period set by the Controller in the Organisation settings |
The Controller decides whether special category data under Article 9 GDPR may appear in conversations. If so, the parties agree this separately before the Agent goes live, because it changes the risk assessment on both sides.
Annex 2. Technical and organisational measures
- Encrypted connections between the browser and the platform and between the platform and providers.
- Encrypted channel credentials in the database, with a rotation procedure provided for.
- Separation between organisations enforced at the level of the database query rather than by a filter over results.
- Role based access control, checked on every request.
- An append only audit log accepting only events after sensitive data redaction.
- Protection of content import against reaching internal network addresses.
- Signature verification of inbound events and protection against replaying the same event.
- Channel kill switches enforced in the transport layer.
- The application refuses to start when it detects configuration intended for local work.
- Database backup as a logical dump, kept on the server for a defined retention period, after which older copies are removed. Restoring from a backup requires a human decision and is not automated.
Annex 3. Subprocessors and transfers outside the EEA
The current list, with the scope of entrustment, country of processing and transfer basis, is the content of the subprocessor register, which carries its own version number and date. The version in force on the day of conclusion is attached to this agreement.
Your legal team has questions
We answer in writing, before the sales call. No we will send it after the NDA stage.