Data Processing Agreement (DPA)

This is an English translation provided for convenience. The legally binding version is the Czech original; in case of any discrepancy, the Czech version prevails.

Data Processing Agreement (DPA)

Processor: Digital D&A s.r.o. | Company ID: 23691271

Processor’s seat: Školská 660/3, Nové Město, 110 00 Prague

Contact: support@awentail.com | awentail.com

Controller: [CUSTOMER NAME] | Company ID: [CUSTOMER COMPANY ID]

Controller’s seat: [CUSTOMER ADDRESS]

This DPA forms an annex to the Awentail Terms of Service

Effective from: 14 March 2026

Preamble

This Data Processing Agreement (the “DPA”) is concluded between:

The Processor: Digital D&A s.r.o., Company ID: 23691271, Školská 660/3, Nové Město, 110 00 Prague, operator of the Awentail platform (the “Processor”)

The Controller: [CUSTOMER NAME], Company ID/ID: [ID], with its seat at [ADDRESS] (the “Controller”)

The Controller uses the Awentail platform, and this use involves the processing of personal data of third parties (visitors of the Controller’s website). The Controller acts as the controller of personal data within the meaning of Art. 4(7) of Regulation (EU) 2016/679 (GDPR) and the Processor as the processor within the meaning of Art. 4(8) GDPR.

This DPA is concluded in accordance with Art. 28 GDPR and forms an integral part of the contractual relationship between the Controller and the Processor, supplementing the Awentail Terms of Service. In case of conflict, this DPA prevails.

Art. 1 – Definitions

The definitions of GDPR apply for the purposes of this DPA, and in addition:

Art. 2 – Subject matter, nature and scope of processing

2.1 Description of processing

The Processor processes personal data solely for the purpose of providing the Service to the Controller, to the extent necessary for the operation of the Platform.

Processing parameterDescription
Nature of processingStorage, transfer, analysis and generation of responses via AI models; management of CRM contacts and bookings
Purpose of processingOperation of the AI assistant on the Controller’s website — customer service, lead capture, appointment booking
Categories of personal dataContact data (e-mail, phone), conversation content, technical identifiers (IP, session ID), and possibly other data voluntarily provided by the visitor in the conversation
Categories of data subjectsVisitors of the Controller’s website who interact with the AI assistant
Duration of processingFor the term of the contract between the Controller and the Processor, unless agreed otherwise

2.3 Processing infrastructure

The Controller acknowledges that the processing of personal data takes place via third-party cloud infrastructure and AI models (Sub-processors under Art. 4). These Sub-processors may be located outside the EEA, with data transfers secured in accordance with Art. 5 of this DPA.

2.2 Special categories of personal data

The processing of special categories of personal data under Art. 9 GDPR (health data, racial origin, biometric data, etc.) is neither anticipated nor intended for the operation of the Platform. The Controller must not use the Platform to collect or process such data unless the Processor expressly provides otherwise in writing. The Controller bears sole responsibility for a breach of this prohibition.

Art. 3 – Obligations of the Processor

In accordance with Art. 28(3) GDPR, the Processor undertakes to:

Process personal data only on the documented instructions of the Controller, unless required otherwise by EU or Member State law to which the Processor is subject — in which case the Processor informs the Controller of that requirement before processing, unless that law prohibits such disclosure on important grounds of public interest.

Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Take all measures required under Art. 32 GDPR (see Art. 6 of this DPA).

Comply with the conditions for engaging another processor (Sub-processor) under Art. 4 of this DPA.

Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subjects’ rights.

Assist the Controller in ensuring compliance with the obligations under Art. 32–36 GDPR (security of processing, incident notification, data protection impact assessment, prior consultation with the supervisory authority).

At the Controller’s choice, delete or return all personal data after the provision of the Service ends, and delete existing copies, unless EU or Member State law requires their storage.

Make available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller.

The Processor immediately informs the Controller if it considers that an instruction of the Controller infringes GDPR or other EU or Member State data protection law. The Processor is not liable for processing carried out on the basis of the Controller’s instructions that conflict with applicable law.

Art. 4 – Sub-processors

4.1 The Controller grants the Processor a general written authorisation to engage Sub-processors. The Processor must inform the Controller of intended changes concerning the addition or replacement of Sub-processors — by publishing an update at awentail.com/subprocessors at least 14 days in advance.

4.2 The Controller may raise a legitimate objection to the engagement of a specific Sub-processor within 10 business days of the notification. If the parties do not agree on an acceptable solution, the Controller may terminate the contract with respect to the affected services.

4.3 The Processor engages Sub-processors under a contract imposing on them the same data protection obligations as set out in this DPA. The Processor remains fully liable to the Controller for the performance of the Sub-processor’s obligations.

4.4 The current list of Sub-processors is available at awentail.com/subprocessors.

Sub-processorPurposeLocationTransfer mechanism
Cloud infrastructure providerHosting the Platform and databasesEEANot required
AI model provider (current list at awentail.com/subprocessors)Generating AI responsesUSA / EEASCC under Art. 46 GDPR
Payment gatewayPayment processingEEA / USASCC under Art. 46 GDPR
E-mail infrastructure providerTransactional e-mailsEEA / USASCC under Art. 46 GDPR
Analytics toolAnonymised analyticsEEANot required

Art. 5 – Transfer of personal data to third countries

5.1 Any transfer of personal data outside the European Economic Area (EEA) takes place only on the basis of appropriate safeguards under Art. 46 GDPR — in particular Standard Contractual Clauses (SCC) approved by the European Commission, or another transfer mechanism valid at the time of transfer.

5.2 The Processor ensures that all Sub-processors involved in cross-border data exchange meet the conditions for transfer under GDPR.

5.3 The Processor continuously monitors developments in adequacy decisions and other transfer mechanisms and, in the event of a change, adopts corresponding measures without undue delay.

Art. 6 – Security measures

6.1 The Processor implements and maintains technical and organisational measures appropriate to the level of risk under Art. 32 GDPR. These measures include at least:

6.2 The Processor is entitled to update the measures under paragraph 6.1 on an ongoing basis, provided the new measures maintain or increase the level of protection.

6.3 At the Controller’s request, the Processor provides summary information about the security measures in place, or allows an audit within the scope of Art. 8 of this DPA.

Art. 7 – Security incident notification

7.1 Without undue delay, and no later than 48 hours after becoming aware, the Processor informs the Controller of any Security incident concerning personal data processed on the Controller’s behalf.

7.2 The incident notification contains at least:

7.3 The Processor immediately takes all appropriate technical and organisational measures to limit the impact of the Security incident and restore security.

7.4 The Processor provides the Controller with the cooperation needed for the Controller to meet its obligation to notify the Security incident to the supervisory authority under Art. 33 GDPR within 72 hours of becoming aware of it. The Processor is not liable for this deadline provided it cooperated with the Controller without undue delay.

Art. 8 – Data subjects’ rights and audit

8.1 Assistance with the exercise of data subjects’ rights

The Processor provides the Controller with reasonable cooperation in handling data subjects’ requests to exercise their rights under Art. 15–22 GDPR (access, rectification, erasure, restriction, portability, objection). The Processor forwards requests received directly from data subjects to the Controller without undue delay.

The Controller bears sole responsibility for handling data subjects’ requests within the deadlines set by GDPR. The Processor is not liable for a failure to meet deadlines caused by delay on the Controller’s side.

8.2 Audit and inspection

The Controller is entitled to verify the Processor’s compliance with this DPA through:

The Controller bears the costs of the audit. The Processor is entitled to refuse access to information that is a trade secret or could jeopardise the security of other customers.

Art. 9 – Obligations of the Controller

The Controller undertakes to:

The Controller bears sole responsibility for the lawfulness of all instructions given to the Processor and for the lawfulness of the processing of personal data via the Platform — including the correctness of the AI assistant configuration, the manner of data collection and the securing of consents or other legal bases towards data subjects.

Ensure that the processing of personal data via the Platform has a valid legal basis under Art. 6 GDPR (or Art. 9 GDPR for special categories).

Inform data subjects (visitors of its website) about the processing of their personal data via the AI assistant, in accordance with Art. 13 or 14 GDPR.

Not transfer special categories of personal data under Art. 9 GDPR to the Platform without the Processor’s prior written consent.

Give the Processor only lawful instructions regarding the processing of personal data.

Maintain records of processing activities under Art. 30 GDPR to the extent they relate to processing carried out via the Platform.

Immediately inform the Processor of any change in the nature or scope of processing that could affect this DPA.

Bear sole responsibility for the Knowledge Base content uploaded to the Platform, including ensuring that the upload and processing of this content complies with applicable law.

Art. 10 – Data protection impact assessment (DPIA)

10.1 If the Controller is required to carry out a data protection impact assessment (DPIA) under Art. 35 GDPR in connection with its use of the Platform, the Processor provides reasonable cooperation — in particular by providing available information about the nature of the processing and the security measures in place.

10.2 The Processor is not obliged to carry out a DPIA on the Controller’s behalf and is not liable for the conclusions of a DPIA carried out by the Controller.

10.3 According to the Processor’s current assessment, the standard operation of the Awentail AI assistant for the purposes of customer service, lead capture and appointment booking does not constitute high-risk processing within the meaning of Art. 35 GDPR. This assessment may change depending on regulatory developments, supervisory authority guidance or the specific deployment context. The Controller is obliged to carry out its own DPIA with regard to its specific use case.

Art. 11 – Termination of the DPA and erasure of personal data

11.1 This DPA terminates automatically upon termination of the contractual relationship between the Controller and the Processor (i.e. cancellation of the User account or termination of the Terms of Service).

11.2 After termination of the contractual relationship, the Processor:

11.3 Conversation records and the Knowledge Base are deleted in accordance with paragraph 11.2. Billing and operational records may be retained for the period set by tax and accounting regulations (typically 10 years), with such data pseudonymised to the maximum extent possible.

11.4 The Processor is not liable for data loss occurring after the 14-day period under paragraph 11.2, or for data loss caused by the Controller’s failure to export data before that period expires.

Art. 12 – Liability and indemnification

12.1 The Processor is liable to the Controller for damage caused by a breach of the Processor’s obligations expressly set out in this DPA or by directly applicable provisions of GDPR that apply to processors.

12.2 The Processor is not liable for damage arising:

12.3 The Processor’s total liability to the Controller for all claims arising out of or in connection with this DPA within one calendar year is limited to the payments for the Service paid by the Controller in the last 3 months, but no more than EUR 300.

12.4 These limitations of liability do not apply to harm caused intentionally or by gross negligence.

Art. 13 – Final provisions

13.1 This DPA is governed by the law of the Czech Republic and the directly applicable provisions of GDPR. The court with local jurisdiction for disputes under this DPA is the court determined by the Processor’s seat (Prague).

13.2 This DPA may be amended only by written agreement of both parties or unilaterally by the Processor in accordance with the terms of the Awentail Terms of Service (30-day notice) — with changes arising from GDPR obligations taking effect without undue delay.

13.3 If any provision of the DPA becomes invalid or unenforceable, this does not affect the validity of the remaining provisions.

13.4 This DPA supersedes all previous arrangements between the parties concerning the processing of personal data.

13.5 The Controller is not entitled to assign the rights and obligations under this DPA to a third party without the Processor’s prior written consent.

Annex A – Signature page

This DPA takes effect on the date of signature by both contracting parties, or on the date of the Controller’s registration on the Awentail Platform where the DPA is accepted electronically via the Terms of Service.

For the ProcessorFor the Controller
Digital D&A s.r.o.[CUSTOMER NAME]
Name and position: ____________________Name and position: ____________________
Date: _____________________________Date: _____________________________
Signature: ____________________________Signature: ____________________________

Digital D&A s.r.o. | Company ID: 23691271 | support@awentail.com | awentail.com | DPA v1.0 | 14 March 2026