DM Butler
Legal

Data Processing Agreement

Version 2026-10-09 · Art. 28 GDPR

This agreement is part of the Terms of Service between the customer ("Controller") and the provider named in our imprint ("Processor"). It is accepted when the Controller signs up.

1. Subject, duration, nature and purpose

The Processor receives, stores and answers direct messages of the Controller's customers on Instagram and Telegram, manages contacts, orders and the product catalogue, and generates replies with AI, for as long as the Controller's workspace exists.

2. Data and data subjects

3. Instructions

The Processor processes the data only on documented instructions of the Controller, given by these terms and by the settings in the panel, unless EU or member state law requires otherwise; in that case it informs the Controller first unless the law forbids this. It tells the Controller if it thinks an instruction breaks data protection law.

4. Confidentiality and security

Everyone authorised to process the data is bound to confidentiality. The Processor takes the technical and organisational measures of Art. 32 GDPR, in particular: encryption in transit, encryption of channel tokens and keys at rest, separation of customers' data by workspace, role-based access, audit logs of sensitive actions, backups and regular tests of restore.

5. Sub-processors

The Controller authorises the sub-processors below. The Processor informs the Controller of intended changes at least 30 days in advance in the panel; the Controller may object and, if no solution is found, terminate. The Processor binds every sub-processor to the same obligations.

6. Assistance

The Processor helps the Controller answer data subject requests (export and deletion of contacts and conversations are available in the panel), and with security, breach notifications, impact assessments and prior consultations.

7. Personal data breaches

The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting the Controller's data, with the information required by Art. 33(3) GDPR.

8. Deletion and return

When the workspace is deleted, the Processor deletes the data after the retention period chosen in the panel and at the latest within 30 days, and removes it from backups in their normal rotation, unless law requires storage. Before deletion the Controller can export the data.

9. Audits

The Processor makes available the information needed to show compliance and allows for and contributes to audits, including inspections, by the Controller or an auditor it mandates, with reasonable notice and at the Controller's cost.

10. International transfers

Data is transferred outside the EU/EEA only under Chapter V GDPR, in particular on the basis of an adequacy decision or the Standard Contractual Clauses.