Data Processing Agreement (DPA)
This is an English translation provided for convenience. The legally binding version is the Czech original; in case of any discrepancy, the Czech version prevails.
Data Processing Agreement (DPA)
Processor: Digital D&A s.r.o. | Company ID: 23691271
Processor’s seat: Školská 660/3, Nové Město, 110 00 Prague
Contact: support@awentail.com | awentail.com
Controller: [CUSTOMER NAME] | Company ID: [CUSTOMER COMPANY ID]
Controller’s seat: [CUSTOMER ADDRESS]
This DPA forms an annex to the Awentail Terms of Service
Effective from: 14 March 2026
Preamble
This Data Processing Agreement (the “DPA”) is concluded between:
The Processor: Digital D&A s.r.o., Company ID: 23691271, Školská 660/3, Nové Město, 110 00 Prague, operator of the Awentail platform (the “Processor”)
The Controller: [CUSTOMER NAME], Company ID/ID: [ID], with its seat at [ADDRESS] (the “Controller”)
The Controller uses the Awentail platform, and this use involves the processing of personal data of third parties (visitors of the Controller’s website). The Controller acts as the controller of personal data within the meaning of Art. 4(7) of Regulation (EU) 2016/679 (GDPR) and the Processor as the processor within the meaning of Art. 4(8) GDPR.
This DPA is concluded in accordance with Art. 28 GDPR and forms an integral part of the contractual relationship between the Controller and the Processor, supplementing the Awentail Terms of Service. In case of conflict, this DPA prevails.
Art. 1 – Definitions
The definitions of GDPR apply for the purposes of this DPA, and in addition:
- “Personal data” – any information relating to an identified or identifiable natural person within the meaning of Art. 4(1) GDPR.
- “Processing” – any operation performed on personal data within the meaning of Art. 4(2) GDPR.
- “Platform” – the Awentail cloud application available at awentail.com, through which the Processor provides the Service to the Controller.
- “Service” – the operation of the AI assistant, lead capture, appointment booking and associated Platform features.
- “Conversation” – text communication between the AI assistant and a visitor of the Controller’s website.
- “Knowledge Base” – documents and data uploaded by the Controller to the Platform for the purpose of training the AI assistant.
- “Sub-processor” – a third party engaged by the Processor to process personal data on behalf of the Controller.
- “Security incident” – a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data.
Art. 2 – Subject matter, nature and scope of processing
2.1 Description of processing
The Processor processes personal data solely for the purpose of providing the Service to the Controller, to the extent necessary for the operation of the Platform.
| Processing parameter | Description |
|---|---|
| Nature of processing | Storage, transfer, analysis and generation of responses via AI models; management of CRM contacts and bookings |
| Purpose of processing | Operation of the AI assistant on the Controller’s website — customer service, lead capture, appointment booking |
| Categories of personal data | Contact data (e-mail, phone), conversation content, technical identifiers (IP, session ID), and possibly other data voluntarily provided by the visitor in the conversation |
| Categories of data subjects | Visitors of the Controller’s website who interact with the AI assistant |
| Duration of processing | For the term of the contract between the Controller and the Processor, unless agreed otherwise |
2.3 Processing infrastructure
The Controller acknowledges that the processing of personal data takes place via third-party cloud infrastructure and AI models (Sub-processors under Art. 4). These Sub-processors may be located outside the EEA, with data transfers secured in accordance with Art. 5 of this DPA.
2.2 Special categories of personal data
The processing of special categories of personal data under Art. 9 GDPR (health data, racial origin, biometric data, etc.) is neither anticipated nor intended for the operation of the Platform. The Controller must not use the Platform to collect or process such data unless the Processor expressly provides otherwise in writing. The Controller bears sole responsibility for a breach of this prohibition.
Art. 3 – Obligations of the Processor
In accordance with Art. 28(3) GDPR, the Processor undertakes to:
Process personal data only on the documented instructions of the Controller, unless required otherwise by EU or Member State law to which the Processor is subject — in which case the Processor informs the Controller of that requirement before processing, unless that law prohibits such disclosure on important grounds of public interest.
Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Take all measures required under Art. 32 GDPR (see Art. 6 of this DPA).
Comply with the conditions for engaging another processor (Sub-processor) under Art. 4 of this DPA.
Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subjects’ rights.
Assist the Controller in ensuring compliance with the obligations under Art. 32–36 GDPR (security of processing, incident notification, data protection impact assessment, prior consultation with the supervisory authority).
At the Controller’s choice, delete or return all personal data after the provision of the Service ends, and delete existing copies, unless EU or Member State law requires their storage.
Make available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller.
The Processor immediately informs the Controller if it considers that an instruction of the Controller infringes GDPR or other EU or Member State data protection law. The Processor is not liable for processing carried out on the basis of the Controller’s instructions that conflict with applicable law.
Art. 4 – Sub-processors
4.1 The Controller grants the Processor a general written authorisation to engage Sub-processors. The Processor must inform the Controller of intended changes concerning the addition or replacement of Sub-processors — by publishing an update at awentail.com/subprocessors at least 14 days in advance.
4.2 The Controller may raise a legitimate objection to the engagement of a specific Sub-processor within 10 business days of the notification. If the parties do not agree on an acceptable solution, the Controller may terminate the contract with respect to the affected services.
4.3 The Processor engages Sub-processors under a contract imposing on them the same data protection obligations as set out in this DPA. The Processor remains fully liable to the Controller for the performance of the Sub-processor’s obligations.
4.4 The current list of Sub-processors is available at awentail.com/subprocessors.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Cloud infrastructure provider | Hosting the Platform and databases | EEA | Not required |
| AI model provider (current list at awentail.com/subprocessors) | Generating AI responses | USA / EEA | SCC under Art. 46 GDPR |
| Payment gateway | Payment processing | EEA / USA | SCC under Art. 46 GDPR |
| E-mail infrastructure provider | Transactional e-mails | EEA / USA | SCC under Art. 46 GDPR |
| Analytics tool | Anonymised analytics | EEA | Not required |
Art. 5 – Transfer of personal data to third countries
5.1 Any transfer of personal data outside the European Economic Area (EEA) takes place only on the basis of appropriate safeguards under Art. 46 GDPR — in particular Standard Contractual Clauses (SCC) approved by the European Commission, or another transfer mechanism valid at the time of transfer.
5.2 The Processor ensures that all Sub-processors involved in cross-border data exchange meet the conditions for transfer under GDPR.
5.3 The Processor continuously monitors developments in adequacy decisions and other transfer mechanisms and, in the event of a change, adopts corresponding measures without undue delay.
Art. 6 – Security measures
6.1 The Processor implements and maintains technical and organisational measures appropriate to the level of risk under Art. 32 GDPR. These measures include at least:
- Encryption of personal data in transit (TLS) and at rest.
- Ensuring the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
- The ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
- A process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures in place.
- Access control on a least-privilege (need-to-know) basis and multi-factor authentication for access to production systems.
- Data isolation at User account level — one Controller’s data is not accessible to the Processor’s other customers.
- Or other appropriate measures corresponding to the state of the art and security standards.
6.2 The Processor is entitled to update the measures under paragraph 6.1 on an ongoing basis, provided the new measures maintain or increase the level of protection.
6.3 At the Controller’s request, the Processor provides summary information about the security measures in place, or allows an audit within the scope of Art. 8 of this DPA.
Art. 7 – Security incident notification
7.1 Without undue delay, and no later than 48 hours after becoming aware, the Processor informs the Controller of any Security incident concerning personal data processed on the Controller’s behalf.
7.2 The incident notification contains at least:
- a description of the nature of the Security incident, including the categories and approximate number of data subjects and records concerned;
- the contact details of the data protection officer or another point of contact where more information can be obtained;
- a description of the likely consequences of the incident;
- a description of the measures taken or proposed by the Processor to address the incident, including any measures to mitigate its adverse effects.
7.3 The Processor immediately takes all appropriate technical and organisational measures to limit the impact of the Security incident and restore security.
7.4 The Processor provides the Controller with the cooperation needed for the Controller to meet its obligation to notify the Security incident to the supervisory authority under Art. 33 GDPR within 72 hours of becoming aware of it. The Processor is not liable for this deadline provided it cooperated with the Controller without undue delay.
Art. 8 – Data subjects’ rights and audit
8.1 Assistance with the exercise of data subjects’ rights
The Processor provides the Controller with reasonable cooperation in handling data subjects’ requests to exercise their rights under Art. 15–22 GDPR (access, rectification, erasure, restriction, portability, objection). The Processor forwards requests received directly from data subjects to the Controller without undue delay.
The Controller bears sole responsibility for handling data subjects’ requests within the deadlines set by GDPR. The Processor is not liable for a failure to meet deadlines caused by delay on the Controller’s side.
8.2 Audit and inspection
The Controller is entitled to verify the Processor’s compliance with this DPA through:
- written enquiries and requests for documentation — free of charge, once a year;
- an audit conducted by the Controller or an independent auditor mandated by it — subject to prior written notice at least 30 days in advance, no more than once a year, unless a substantiated security incident is demonstrated.
The Controller bears the costs of the audit. The Processor is entitled to refuse access to information that is a trade secret or could jeopardise the security of other customers.
Art. 9 – Obligations of the Controller
The Controller undertakes to:
The Controller bears sole responsibility for the lawfulness of all instructions given to the Processor and for the lawfulness of the processing of personal data via the Platform — including the correctness of the AI assistant configuration, the manner of data collection and the securing of consents or other legal bases towards data subjects.
Ensure that the processing of personal data via the Platform has a valid legal basis under Art. 6 GDPR (or Art. 9 GDPR for special categories).
Inform data subjects (visitors of its website) about the processing of their personal data via the AI assistant, in accordance with Art. 13 or 14 GDPR.
Not transfer special categories of personal data under Art. 9 GDPR to the Platform without the Processor’s prior written consent.
Give the Processor only lawful instructions regarding the processing of personal data.
Maintain records of processing activities under Art. 30 GDPR to the extent they relate to processing carried out via the Platform.
Immediately inform the Processor of any change in the nature or scope of processing that could affect this DPA.
Bear sole responsibility for the Knowledge Base content uploaded to the Platform, including ensuring that the upload and processing of this content complies with applicable law.
Art. 10 – Data protection impact assessment (DPIA)
10.1 If the Controller is required to carry out a data protection impact assessment (DPIA) under Art. 35 GDPR in connection with its use of the Platform, the Processor provides reasonable cooperation — in particular by providing available information about the nature of the processing and the security measures in place.
10.2 The Processor is not obliged to carry out a DPIA on the Controller’s behalf and is not liable for the conclusions of a DPIA carried out by the Controller.
10.3 According to the Processor’s current assessment, the standard operation of the Awentail AI assistant for the purposes of customer service, lead capture and appointment booking does not constitute high-risk processing within the meaning of Art. 35 GDPR. This assessment may change depending on regulatory developments, supervisory authority guidance or the specific deployment context. The Controller is obliged to carry out its own DPIA with regard to its specific use case.
Art. 11 – Termination of the DPA and erasure of personal data
11.1 This DPA terminates automatically upon termination of the contractual relationship between the Controller and the Processor (i.e. cancellation of the User account or termination of the Terms of Service).
11.2 After termination of the contractual relationship, the Processor:
- retains the Controller’s personal data for 14 days from account cancellation — during this period the Controller may export the data via Platform features, where technically available;
- after the 14-day period expires, permanently and irrevocably deletes the personal data from all of the Processor’s systems, except for data whose retention is required by applicable law;
- at the Controller’s request, issues a written confirmation of data deletion.
11.3 Conversation records and the Knowledge Base are deleted in accordance with paragraph 11.2. Billing and operational records may be retained for the period set by tax and accounting regulations (typically 10 years), with such data pseudonymised to the maximum extent possible.
11.4 The Processor is not liable for data loss occurring after the 14-day period under paragraph 11.2, or for data loss caused by the Controller’s failure to export data before that period expires.
Art. 12 – Liability and indemnification
12.1 The Processor is liable to the Controller for damage caused by a breach of the Processor’s obligations expressly set out in this DPA or by directly applicable provisions of GDPR that apply to processors.
12.2 The Processor is not liable for damage arising:
- as a result of the Controller’s instructions that conflict with applicable law or this DPA;
- as a result of Knowledge Base content or other data uploaded by the Controller to the Platform;
- as a result of the Controller’s breach of its obligations as a data controller;
- as a result of the engagement of Sub-processors selected or requested by the Controller;
- indirect, consequential or punitive damages, lost profits or loss of data;
- from the content of responses generated by the AI models used within the Platform, or from decisions made by the Controller or third parties on the basis of those responses.
12.3 The Processor’s total liability to the Controller for all claims arising out of or in connection with this DPA within one calendar year is limited to the payments for the Service paid by the Controller in the last 3 months, but no more than EUR 300.
12.4 These limitations of liability do not apply to harm caused intentionally or by gross negligence.
Art. 13 – Final provisions
13.1 This DPA is governed by the law of the Czech Republic and the directly applicable provisions of GDPR. The court with local jurisdiction for disputes under this DPA is the court determined by the Processor’s seat (Prague).
13.2 This DPA may be amended only by written agreement of both parties or unilaterally by the Processor in accordance with the terms of the Awentail Terms of Service (30-day notice) — with changes arising from GDPR obligations taking effect without undue delay.
13.3 If any provision of the DPA becomes invalid or unenforceable, this does not affect the validity of the remaining provisions.
13.4 This DPA supersedes all previous arrangements between the parties concerning the processing of personal data.
13.5 The Controller is not entitled to assign the rights and obligations under this DPA to a third party without the Processor’s prior written consent.
Annex A – Signature page
This DPA takes effect on the date of signature by both contracting parties, or on the date of the Controller’s registration on the Awentail Platform where the DPA is accepted electronically via the Terms of Service.
| For the Processor | For the Controller |
|---|---|
| Digital D&A s.r.o. | [CUSTOMER NAME] |
| Name and position: ____________________ | Name and position: ____________________ |
| Date: _____________________________ | Date: _____________________________ |
| Signature: ____________________________ | Signature: ____________________________ |
Digital D&A s.r.o. | Company ID: 23691271 | support@awentail.com | awentail.com | DPA v1.0 | 14 March 2026