DATA PROCESSING AGREEMENT (DPA)
Entered into pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (GDPR) and § 34 of Act No. 18/2018 Coll. on Personal Data Protection
between:
Controller (Customer): Name: ___________________________________ Company ID: ___________________________________ Registered office: ___________________________________ Represented by: ___________________________________ Email: ___________________________________
(hereinafter the "Controller")
and
Processor (Chatbot Provider): Blue Yasuo Consulting, s. r. o. Company ID (IČO): 53199341 Registered office: Romanova 1678/33, 851 02 Bratislava — Petržalka, Slovak Republic Represented by: the managing director Email: blueyasuoconsulting@gmail.com
(hereinafter the "Processor")
(collectively the "Parties")
Article 1 — Subject and Purpose
1.1 This Data Processing Agreement (hereinafter "DPA") governs the rights and obligations of the Parties regarding the processing of personal data by the Processor on behalf of the Controller in connection with the provision of custom chatbot development, deployment, and operation services (hereinafter the "Main Agreement").
1.2 The Processor processes personal data solely for the purpose of performing the Main Agreement, in particular:
- Providing the chatbot service to the Controller's End Users;
- Storing and managing conversational data;
- Technical operation and maintenance of the chatbot.
1.3 This DPA constitutes an integral part of the Main Agreement and remains valid for its entire duration.
Article 2 — Categories of Data Subjects and Personal Data
2.1 Categories of data subjects:
- End Users of the Controller's chatbot (customers, website visitors, clients of the Controller, etc.).
2.2 Categories of personal data:
| Category | Description |
|---|---|
| Conversational data | Text content of messages between the End User and the chatbot |
| Technical data | IP address, browser type, operating system, date and time of interaction |
| Identification data | Name, email, phone number — only if the chatbot actively collects this data per the Controller's configuration |
| Other data | Any additional data the End User voluntarily provides in the conversation |
2.3 Special categories of data: The Processor is not authorized to intentionally process special categories of personal data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR), unless the Controller provides an express written instruction along with the corresponding legal basis.
Article 3 — Controller's Instructions
3.1 The Processor shall process personal data only on the basis of documented instructions from the Controller, including instructions regarding the transfer of personal data to a third country or an international organization.
3.2 The Controller's instructions are contained in:
- This DPA;
- The Main Agreement and General Terms and Conditions;
- Written instructions sent by email or through another agreed communication channel.
3.3 If the Processor considers that an instruction from the Controller infringes the GDPR or other data protection regulations, it shall promptly inform the Controller.
Article 4 — Obligations of the Processor
4.1 The Processor undertakes to:
a) Processing according to instructions: Process personal data solely in accordance with the Controller's documented instructions and for the purposes specified in Article 1.
b) Confidentiality: Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
c) Security measures: Implement all measures required under Article 32 GDPR, as further specified in Annex 1 to this DPA.
d) Sub-processors: Comply with the conditions for engaging sub-processors as set out in Article 5 of this DPA.
e) Assistance to the Controller: Assist the Controller in fulfilling obligations regarding:
- Handling data subject requests to exercise their rights (Art. 15–22 GDPR);
- Ensuring the security of processing (Art. 32 GDPR);
- Notification of personal data breaches (Art. 33 and 34 GDPR);
- Data protection impact assessments — DPIA (Art. 35 GDPR);
- Prior consultation with the supervisory authority (Art. 36 GDPR).
f) Deletion or return of data: Upon termination of the services related to processing, at the Controller's choice, delete all personal data or return them to the Controller and delete existing copies, unless applicable law requires retention of the personal data.
g) Audit: Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
Article 5 — Sub-processors
5.1 The Controller grants the Processor general written authorization to engage sub-processors for the processing of personal data.
5.2 Current list of sub-processors as of the date of this DPA:
| Sub-processor | Purpose | Headquarters | Data Location |
|---|---|---|---|
| OpenAI, LLC | Processing conversations through the AI model (GPT) | San Francisco, USA | USA |
| Supabase, Inc. | Database — storage of conversational and user data | San Francisco, USA | EU (Stockholm, Sweden) |
| Hostinger International Ltd. | VPS hosting — chatbot operation | Kaunas, Lithuania | EU (Frankfurt, Germany) |
5.3 Change notification: The Processor shall inform the Controller of any intended change (addition or replacement) of a sub-processor at least 30 days before the planned change.
5.4 Objection: The Controller has the right to object to a new sub-processor within 14 days of receiving the notification. In case of an objection, the Parties shall seek a mutually acceptable solution. If no solution is found, the Controller has the right to terminate the Main Agreement.
5.5 The Processor shall ensure that sub-processors are bound by the same data protection obligations as set out in this DPA.
Article 6 — Transfer of Personal Data to Third Countries
6.1 Processing of personal data through the OpenAI API involves the transfer of data to the United States of America.
6.2 This transfer is safeguarded on the basis of:
- Standard Contractual Clauses (SCC) pursuant to the European Commission Implementing Decision (EU) 2021/914; and/or
- EU-US Data Privacy Framework (DPF) pursuant to the European Commission's adequacy decision of July 10, 2023.
6.3 Supplementary safeguards:
- Data encryption in transit (TLS 1.2+);
- Data minimization — only data necessary for generating the chatbot response is transferred;
- Under its API Data Usage Policy, OpenAI does not use data submitted via the API to train its models;
- The Processor continuously monitors the legal framework for data transfers to the USA and informs the Controller of relevant changes.
6.4 Other sub-processors (Supabase, Hostinger) store data within the EU/EEA.
Article 7 — Personal Data Breach Notification
7.1 The Processor shall, without undue delay and no later than 48 hours after becoming aware of a personal data breach, notify the Controller.
7.2 The notification shall include at a minimum:
- a) A description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and personal data records concerned;
- b) The name and contact details of the contact person;
- c) A description of the likely consequences of the breach;
- d) A description of the measures taken or proposed to address the breach, including measures to mitigate its adverse effects.
7.3 The Processor shall provide the Controller with full cooperation in fulfilling its notification obligations towards the supervisory authority (Art. 33 GDPR) and data subjects (Art. 34 GDPR).
Article 8 — Assistance with Data Subject Rights
8.1 The Processor shall assist the Controller in handling data subject requests to exercise their rights under Chapter III of the GDPR (right of access, rectification, erasure, restriction of processing, portability, and objection).
8.2 If the Processor receives a request directly from a data subject, it shall promptly inform the Controller and shall not respond to the request without the Controller's instructions, unless required to do so by applicable law.
8.3 The Processor shall assist the Controller through appropriate technical and organizational measures in fulfilling its obligations.
Article 9 — Audit
9.1 The Processor shall, upon request, make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR.
9.2 The Controller or an auditor mandated by the Controller is entitled to audit the Processor's processing of personal data, subject to the following conditions:
- a) The audit shall be conducted at the Controller's expense;
- b) The Controller shall give at least 30 days' prior notice of the intent to audit;
- c) The audit shall take place during business hours and shall not unreasonably disrupt the Processor's normal operations;
- d) The auditor is bound by a duty of confidentiality;
- e) The Controller is entitled to conduct a maximum of 1 audit per year, unless the audit is triggered by a personal data breach or instructions from the supervisory authority.
9.3 The Processor may, instead of a physical audit, provide a current certification or independent auditor's report (e.g., SOC 2) if such certification adequately covers the scope of the audit.
Article 10 — Deletion and Return of Data
10.1 Upon termination of the Main Agreement, the Processor shall, at the Controller's choice:
- a) Return all personal data to the Controller in a standard, machine-readable format (JSON/CSV); or
- b) Delete all personal data and existing copies.
10.2 The Controller shall communicate its choice within 30 days of the termination of the Main Agreement. If the Controller fails to communicate its choice, the Processor shall delete the data.
10.3 The Processor shall carry out the return or deletion within 30 days of the Controller's notification or the expiry of the period referred to in Section 10.2.
10.4 The Processor shall confirm the deletion to the Controller in writing (by email).
10.5 The obligation to delete shall not apply to personal data whose retention is required by applicable law (e.g., accounting records). Such data shall continue to be protected in accordance with this DPA.
Article 11 — Duration and Termination
11.1 This DPA enters into force on the date of its execution by both Parties.
11.2 The DPA remains valid for the entire duration of the Main Agreement and terminates upon termination of the Main Agreement, with the exception of provisions that, by their nature, survive termination (in particular Articles 7, 9, and 10).
11.3 In the event of a conflict between this DPA and the Main Agreement on matters of personal data protection, this DPA shall prevail.
Article 12 — Final Provisions
12.1 This DPA is governed by the laws of the Slovak Republic.
12.2 Any disputes shall be resolved in accordance with the provisions of the Main Agreement.
12.3 This DPA is executed in two counterparts, one for each Party.
12.4 This DPA is drawn up in the Slovak and English languages. In case of any discrepancy, the Slovak version shall prevail.
12.5 Amendments to this DPA shall only be valid in the form of a written addendum signed by both Parties.
For the Controller (Customer):
Name: ___________________________________ Position: ___________________________________ Signature: ___________________________________ Date: ___________________________________
For the Processor (Provider):
Name: ___________________________________ Position: ___________________________________ Signature: ___________________________________ Date: ___________________________________
ANNEX 1 — Technical and Organizational Measures (TOMs)
The Processor has implemented the following technical and organizational measures to ensure the protection of personal data pursuant to Article 32 GDPR:
1. Encryption
- Data encryption in transit: TLS 1.2+ for all communications
- Data encryption at rest in the Supabase database
2. Access Control
- Access to personal data is restricted to authorized persons only
- Strong authentication (minimum 12 characters + 2FA for administrative access)
- Principle of least privilege
- Regular review of access permissions
3. Availability and Resilience
- Regular database backups
- Service availability monitoring (SLA 99.5%)
- Disaster recovery plan
4. Pseudonymization and Minimization
- Conversational data is stored with minimal identifying information
- API calls to OpenAI do not contain direct identifiers unless the End User provides them in the conversation text
5. Physical Security
- VPS hosting (Hostinger, Frankfurt) and database (Supabase, Stockholm) are located in certified data centers with physical security
6. Organizational Measures
- Confidentiality obligation for all persons with access to data
- Regular software and security patch updates
- Records of processing activities pursuant to Art. 30 GDPR
ANNEX 2 — List of Sub-processors
| Sub-processor | Headquarters | Data Location | Purpose | Transfer Mechanism (if outside EU) |
|---|---|---|---|---|
| OpenAI, LLC | San Francisco, CA, USA | USA | Conversation processing by AI model | SCC / EU-US DPF |
| Supabase, Inc. | San Francisco, CA, USA | EU (Stockholm, SE) | Database — data storage | N/A (data in EU) |
| Hostinger International Ltd. | Kaunas, Lithuania | EU (Frankfurt, DE) | VPS hosting | N/A (data in EU) |
This list is valid as of the DPA signing date. The current list is available upon request at blueyasuoconsulting@gmail.com.