Data Processing Agreement
Version 2026-10-09 · Art. 28 GDPR
This agreement is part of the Terms of Service between the customer ("Controller") and the provider named in our imprint ("Processor"). It is accepted when the Controller signs up.
1. Subject, duration, nature and purpose
The Processor receives, stores and answers direct messages of the Controller's customers on Instagram and Telegram, manages contacts, orders and the product catalogue, and generates replies with AI, for as long as the Controller's workspace exists.
2. Data and data subjects
- Data subjects: the Controller's customers and prospects, and the Controller's team members.
- Data: names and usernames, profile pictures, message contents and attachments, phone numbers, delivery addresses, order and payment status, notes and tags.
- The Controller does not ask customers for special categories of data (Art. 9 GDPR) through the service.
3. Instructions
The Processor processes the data only on documented instructions of the Controller, given by these terms and by the settings in the panel, unless EU or member state law requires otherwise; in that case it informs the Controller first unless the law forbids this. It tells the Controller if it thinks an instruction breaks data protection law.
4. Confidentiality and security
Everyone authorised to process the data is bound to confidentiality. The Processor takes the technical and organisational measures of Art. 32 GDPR, in particular: encryption in transit, encryption of channel tokens and keys at rest, separation of customers' data by workspace, role-based access, audit logs of sensitive actions, backups and regular tests of restore.
5. Sub-processors
The Controller authorises the sub-processors below. The Processor informs the Controller of intended changes at least 30 days in advance in the panel; the Controller may object and, if no solution is found, terminate. The Processor binds every sub-processor to the same obligations.
| Provider | Purpose | Location / safeguard |
|---|---|---|
| Hosting provider (to be announced) | Hosting of the application and database | Latvia |
| Meta Platforms Ireland Ltd. | Instagram messaging (Instagram API) | EU / USA (EU–US Data Privacy Framework) |
| Telegram Messenger Inc. | Telegram messaging (Bot API) | United Arab Emirates / Netherlands |
| Google Ireland Ltd. (Gemini API) | Generating assistant replies | EU / USA (EU–US Data Privacy Framework) |
| OpenRouter, Inc. | Generating assistant replies (fallback) | USA (Standard Contractual Clauses) |
6. Assistance
The Processor helps the Controller answer data subject requests (export and deletion of contacts and conversations are available in the panel), and with security, breach notifications, impact assessments and prior consultations.
7. Personal data breaches
The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting the Controller's data, with the information required by Art. 33(3) GDPR.
8. Deletion and return
When the workspace is deleted, the Processor deletes the data after the retention period chosen in the panel and at the latest within 30 days, and removes it from backups in their normal rotation, unless law requires storage. Before deletion the Controller can export the data.
9. Audits
The Processor makes available the information needed to show compliance and allows for and contributes to audits, including inspections, by the Controller or an auditor it mandates, with reasonable notice and at the Controller's cost.
10. International transfers
Data is transferred outside the EU/EEA only under Chapter V GDPR, in particular on the basis of an adequacy decision or the Standard Contractual Clauses.