Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Aweb Design SRL, CUI RO30874746, registered office Str. Crangasi, nr. 40, Bl. 11, Sc.1, Ap. 37 ("Processor", "we"), and the Customer ("Controller", "you"). It applies where we process personal data on the Customer's behalf in the course of providing the Service, and reflects the requirements of Article 28 of Regulation (EU) 2016/679 (the "GDPR") and, where applicable, the UK GDPR. Where the Customer is itself a processor for a third-party controller, this DPA applies on a back-to-back basis.
1. Roles and scope
For personal data of End-Customers and other data subjects processed through the AI widget and Workspace, the Customer is the controller (or processor for its own controller) and we act as processor (or sub-processor). We process such personal data only on the Customer's documented instructions — including those given through the configuration and normal use of the Service — unless required to act by EU or Member-State law, in which case we inform the Customer beforehand unless the law prohibits it. We will inform the Customer if, in our opinion, an instruction infringes data-protection law. For our own account, billing and security data we act as an independent controller under our Privacy Policy, and that processing is outside this DPA.
2. Subject-matter, duration, nature and purpose
The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I. Processing lasts for the term of the Terms of Service and for any additional period during which we are required or permitted to retain data under this DPA and applicable law.
3. Confidentiality
We ensure that persons authorised to process the personal data are bound by an appropriate duty of confidentiality and process the data only as necessary to provide the Service.
4. Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risks to individuals, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. Those measures are described in Annex II and include pseudonymisation and PII redaction, encryption in transit (TLS) and at rest, access controls and multi-factor authentication, tenant isolation, logging, backups, and IP anonymisation.
5. Sub-processors
The Customer gives general written authorisation for us to engage sub-processors to process personal data for the provision of the Service. Our current sub-processors are listed at https://account.ovebot.ai/en/legal/sub-processors. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to the Customer for their performance. We give the Customer at least 30 days' notice before adding or replacing a sub-processor; the Customer may object on reasonable data-protection grounds within that period, and the parties will work in good faith to resolve the objection, failing which the Customer may terminate the affected part of the Service.
6. Data subject rights
Taking into account the nature of the processing, we assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests by data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability and objection). The Service provides self-service tools so End-Customers can download or delete their own conversation directly. If we receive a request that relates to the Customer's data, we forward it to the Customer without undue delay and do not respond directly except on the Customer's instruction or as required by law.
7. Assistance with security, breaches and DPIAs
Taking into account the nature of processing and the information available to us, we assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including security of processing, personal-data-breach notification, data-protection impact assessments and prior consultation with the supervisory authority.
8. Personal data breach notification
We notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and in any event in time to allow the Customer to meet its own notification deadlines under Articles 33–34 GDPR. The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We take reasonable steps to mitigate and remediate the breach. Such notification is not an acknowledgement of fault or liability.
9. International transfers
Personal data is primarily processed within the EU/EEA. Some sub-processors (notably LLM providers) are located in the United States. Where personal data is transferred outside the EU/EEA, the transfer is covered by an adequacy decision, the EU-US Data Privacy Framework, or the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with any supplementary measures required, and for UK data by the UK Addendum / IDTA. Copies of the relevant transfer mechanism are available on request.
10. Audits
We make available to the Customer information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by it. Audits take place on reasonable prior notice, during business hours, no more than once per year (unless required by a supervisory authority or following a breach), subject to confidentiality, and in a manner that does not disrupt our operations. We may first satisfy an audit request by providing relevant certifications and reports.
11. Return and deletion of data
On termination of the Service and at the Customer's choice, we delete or return all personal data processed on the Customer's behalf and delete existing copies, unless EU or Member-State law requires storage. Where deletion is not immediately practicable (for example in backups), we isolate the data from further processing and delete it in the ordinary backup-rotation cycle. Automated retention and anonymisation also apply throughout the term according to the plan-based retention schedule and the Customer's configured retention window.
12. Prohibited data
The Customer must not submit through the Service, and must configure its widget so as not to request or collect, any special categories of personal data (Article 9 GDPR), data relating to criminal convictions and offences (Article 10 GDPR), government-issued identifiers, payment-card numbers, credentials, biometric or genetic data, or precise geolocation.
The chat interface accepts free-text input from End-Customers, and neither party can prevent an End-Customer from volunteering such data on their own initiative. We do not request, require or knowingly process prohibited data. Where it is submitted regardless, we apply the redaction and security measures described in section 4 and Annex II to limit its capture, and it is deleted or anonymised under section 11. Automated redaction detects structured patterns — email addresses, phone numbers, IBANs, national identification numbers and payment-card numbers — and cannot detect special categories of data expressed in free text. Beyond those measures we accept no responsibility for prohibited data that an End-Customer chooses to submit, or that the Customer submits or causes to be submitted. As controller, the Customer remains responsible for the privacy information presented to End-Customers and for the legal basis of the processing it instructs.
If either party becomes aware that prohibited data has been submitted, it informs the other without undue delay, and we delete the data on the Customer's instruction.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In the event of conflict, the order of precedence is: (1) the Standard Contractual Clauses (where they apply), (2) this DPA, (3) the Terms of Service, (4) the Privacy Policy.
14. Governing law
This DPA is governed by the same law and jurisdiction as the Terms of Service (the laws of Romania), except where the Standard Contractual Clauses or mandatory data-protection law require otherwise. This DPA is drawn up in English; translations are provided for convenience and the English version prevails in case of conflict.
Annex I — Details of processing
- Subject-matter: provision of the Ovebot AI customer-engagement Service.
- Duration: the term of the Terms of Service plus applicable retention periods.
- Nature and purpose: hosting, receiving, storing, redacting, analysing and transmitting personal data to operate the AI chat assistant, generate replies and recommendations, route human handoffs, and attribute orders for the Customer's analytics.
- Categories of data subjects: the Customer's website visitors and End-Customers, and its Users.
- Categories of personal data: conversation content, IP address (truncated after 90 days), email address and order details provided in the in-chat handoff form, order-tracking identifiers, product references clicked, and pseudonymous cookie identifiers (ovebot_vid, ovebot_sid).
- Special categories: not requested and not knowingly processed — prohibited under section 12. Any such data volunteered by an End-Customer is subject to redaction and is deleted or anonymised under section 11.
Annex II — Technical and organisational measures
- PII redaction (email, phone, IBAN, national ID, card numbers) before storage and before sending to the LLM.
- Encryption in transit (TLS) and encryption at rest for stored data and backups.
- Per-tenant database isolation and manual Redis key namespacing to prevent cross-tenant leakage.
- Access control, least-privilege, multi-factor authentication and IP allow-listing for administrative access.
- IP-address anonymisation after 90 days; salted-hash attribution keys purged after 90 days.
- Plan-based retention with automated anonymisation of conversation content when the retention window elapses.
- Signed, first-party, strictly-necessary cookies (no third-party tracking, no fingerprinting).
- Audit trails of consent/privacy-notice acknowledgement and of GDPR erasure actions.
- Scheduled purge jobs, backup procedures with periodic testing, logging and monitoring.
- Sub-processor agreements imposing equivalent obligations.
Annex III — Sub-processors
The current list of authorised sub-processors, their purpose, location and transfer safeguards is maintained at https://account.ovebot.ai/en/legal/sub-processors and forms part of this DPA.