This Data Processing Agreement (“DPA”) is part of every Contract under our Terms & Conditions in which BotBridge processes personal data on the Client’s behalf. It takes effect when the Client accepts a Quote, without a separate signature. If you need a countersigned copy for your records, email hello@botbridge.org and we will send one with the details filled in.
01Parties and rolesArt. 28 GDPR
- The Client — the business that accepted the Quote — is the controller. If the Client itself acts as a processor for someone else, BotBridge is its sub-processor and the Client confirms that its controller has authorised this.
- BotBridge is the processor.
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given in Art. 4 GDPR. Data Protection Law means Regulation (EU) 2016/679 (GDPR), the national laws implementing it (including Romanian Law No. 190/2018), Law No. 195/2024 of the Republic of Moldova, and other data protection laws applicable to the processing. Client Personal Data means personal data BotBridge processes on the Client’s behalf under the Contract.
02Subject matter, duration, nature and purposeArt. 28(3)
- Subject matter: providing the Services described in the Quote — building, hosting, operating, supporting and improving AI chatbots, AI workflows and automations, websites and related documentation.
- Duration: for as long as the Contract lasts, and afterwards until Client Personal Data is returned or deleted under section 13.
- Nature of processing: collection, recording, organisation, structuring, storage, retrieval, consultation, transmission, analysis through AI models, alignment or combination, restriction, erasure and destruction — as needed for the Services.
- Purpose: only to provide the Services to the Client, as further described per service in Annex I.
- The types of personal data and categories of data subjects are listed in Annex I.
03Processing only on documented instructionsArt. 28(3)(a) · Art. 29
- BotBridge processes Client Personal Data only on the Client’s documented instructions, including regarding international transfers. The Contract, the Quote, the configuration agreed during the project and the Client’s written requests (including by email) are the Client’s instructions.
- BotBridge may process Client Personal Data otherwise only where required by EU or Member State law, or by Moldovan law, to which it is subject. In that case it informs the Client before processing, unless that law prohibits it on important grounds of public interest.
- BotBridge immediately informs the Client if, in its opinion, an instruction infringes Data Protection Law, and may suspend following that instruction until it is confirmed or changed.
- BotBridge does not use Client Personal Data for its own purposes, does not sell it, and does not combine it with data from other clients.
04The Client’s obligations
The Client is responsible for:
- having a valid legal basis under Arts. 6 and, where relevant, 9 GDPR for all processing it instructs;
- giving data subjects the information required by Arts. 13 and 14 GDPR, including in its privacy notice that it uses an AI chatbot or automation and the providers involved;
- making sure its instructions comply with Data Protection Law and the AI Act;
- not sending BotBridge special categories of data (Art. 9), data about criminal convictions (Art. 10) or children’s data unless expressly agreed in the Quote with appropriate safeguards;
- carrying out any data protection impact assessment required for its processing (Art. 35), with BotBridge’s assistance under section 10.
05Confidentiality of personnelArt. 28(3)(b)
BotBridge ensures that everyone authorised to process Client Personal Data — employees, contractors and sub-processors’ staff — is bound by a written confidentiality obligation or an appropriate statutory duty of confidentiality, receives appropriate data protection training, and only accesses the data they need for their tasks.
06Security of processingArt. 28(3)(c) · Art. 32
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks for the rights and freedoms of individuals, BotBridge implements and maintains the technical and organisational measures in Annex II. BotBridge may update those measures as technology evolves, provided the overall level of protection is not reduced.
07Sub-processorsArt. 28(2) and (4)
- The Client gives BotBridge general written authorisation to engage the sub-processors listed in Annex III, and those named for a specific project in the Quote.
- BotBridge informs the Client of any intended addition or replacement of a sub-processor at least 30 days in advance by email. The Client may object on reasonable data protection grounds within that period. The parties will then discuss in good faith an alternative; if none is found, the Client may terminate the affected Services without penalty for the part not yet performed.
- BotBridge imposes on each sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, in particular sufficient guarantees for appropriate technical and organisational measures.
- BotBridge remains fully liable to the Client for the performance of its sub-processors’ obligations.
08International transfersChapter V GDPR
- BotBridge transfers Client Personal Data to a country outside the European Economic Area only on the Client’s instructions and in compliance with Chapter V GDPR.
- Transfers rely on an adequacy decision under Art. 45 GDPR (including the EU–US Data Privacy Framework, Decision (EU) 2023/1795, for certified recipients) or, failing that, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, supplemented by a transfer impact assessment and additional measures where needed.
- Where BotBridge processes Client Personal Data subject to the GDPR from the Republic of Moldova, which has no adequacy decision, the parties agree that Module 2 (controller to processor) — or Module 3 (processor to processor) where the Client is itself a processor — of the Standard Contractual Clauses is incorporated by reference into this DPA, with the Client as data exporter and BotBridge as data importer; Annexes I–III of this DPA serve as the Annexes to those Clauses; clause 7 (docking) does not apply; option 2 (general authorisation, 30 days’ notice) applies under clause 9; the optional wording in clause 11 does not apply; and clauses 17 and 18 refer to the law and courts of Romania.
- If the Standard Contractual Clauses conflict with this DPA, the Clauses prevail.
09Data subject requestsArt. 28(3)(e)
- Taking into account the nature of the processing, BotBridge assists the Client with appropriate technical and organisational measures, as far as possible, to answer requests to exercise data subjects’ rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection and automated decision-making).
- If BotBridge receives a request directly, it forwards it to the Client within 5 working days and does not respond to it except to direct the data subject to the Client, unless the Client instructs otherwise.
- Where a solution is designed for it, BotBridge provides the Client with the means to search, export, correct and delete an individual’s data, such as conversation logs.
10Assistance with the Client’s complianceArt. 28(3)(f) · Arts. 32–36
Taking into account the nature of the processing and the information available to it, BotBridge assists the Client in ensuring compliance with its obligations on security of processing (Art. 32), notification of personal data breaches (Arts. 33–34), data protection impact assessments (Art. 35) and prior consultation of the supervisory authority (Art. 36). Assistance beyond providing the documentation BotBridge already maintains may be charged at the rates in the Quote, except where the need for it results from BotBridge’s breach of this DPA.
11Personal data breachesArt. 33(2)
- BotBridge notifies the Client without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Client Personal Data, so the Client can meet its own 72-hour deadline under Art. 33 GDPR.
- The notification describes, as far as then known: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact person. Information that isn’t yet available is provided in phases as soon as it is.
- BotBridge takes reasonable steps immediately to contain the breach, investigate it and prevent recurrence, and documents it.
- BotBridge does not notify supervisory authorities or data subjects about a breach of Client Personal Data on the Client’s behalf without the Client’s prior written approval, unless the law requires it.
12AI-specific commitments
- No model training. BotBridge does not use Client Personal Data to train, fine-tune or improve AI models for itself or others, and uses AI providers only under business or API terms that exclude using customer data for model training.
- Minimal retention at providers. Where an AI provider offers reduced or zero data retention, BotBridge enables it where compatible with the Services, and documents the provider’s retention in the Quote.
- Data minimisation. Prompts, knowledge bases and workflows are designed to send AI providers only the data needed for the task. Where feasible, identifiers are removed or masked first.
- Conversation logs. Chatbot conversation logs are kept for the period agreed in the Quote — by default 90 days — for quality, safety and support, then deleted automatically, unless the Client instructs a different period.
- Transparency by design. Chatbots disclose that users are interacting with AI (Art. 50(1) AI Act) and, where agreed, offer a route to a human.
- No solely automated significant decisions. BotBridge does not configure solutions to take decisions producing legal or similarly significant effects on individuals (Art. 22 GDPR) unless the Client expressly instructs it in writing and has put the safeguards required by Art. 22(3) in place.
13Return and deletion at the endArt. 28(3)(g)
- When the Services end, BotBridge, at the Client’s choice, returns Client Personal Data in a common machine-readable format (such as CSV or JSON) and/or deletes it, including existing copies, within 30 days.
- If the Client makes no choice within 30 days of the end of the Services, BotBridge deletes the data.
- Data in backups is deleted through the normal backup cycle, within at most 90 days, and remains protected by this DPA until then.
- This doesn’t apply where EU, Member State or Moldovan law requires BotBridge to keep the data; BotBridge then keeps it only for that purpose and period.
- On request, BotBridge confirms the deletion in writing.
14Information and auditsArt. 28(3)(h)
- BotBridge makes available to the Client all information necessary to demonstrate compliance with Art. 28 GDPR and this DPA, including answers to reasonable security questionnaires and a copy of the relevant records of processing.
- BotBridge allows for and contributes to audits, including inspections, by the Client or an independent auditor it mandates who is bound by confidentiality and is not a competitor of BotBridge.
- Audits are announced at least 30 days in advance, take place during business hours without unreasonably disrupting operations, and are limited to once a year — unless a personal data breach has occurred or a supervisory authority requires it.
- Each party bears its own costs. Where information requested is already available in documentation, BotBridge may provide it in that form.
15Liability
Each party’s liability under this DPA is subject to the limitations in our Terms & Conditions, to the extent Data Protection Law allows. This does not limit either party’s liability to data subjects under Art. 82 GDPR, or the allocation of responsibility between controller and processor in Art. 82(2) and (4) GDPR.
16Duration, precedence and governing law
- This DPA applies for as long as BotBridge processes Client Personal Data, even after the Contract ends.
- For matters concerning personal data, this DPA prevails over the Terms and the Quote. The Standard Contractual Clauses, where incorporated, prevail over this DPA.
- This DPA is governed by the law that governs the Contract, except where the Standard Contractual Clauses or Data Protection Law require otherwise.
- BotBridge may update this DPA to reflect changes in law or its Services, and notifies clients of material changes at least 30 days in advance. Changes may not reduce the protection of Client Personal Data.
Annex I — Details of processing
The table below describes the standard processing per service. The Quote for a specific project can narrow it or add to it.
| Service | Data subjects | Personal data | Default retention |
|---|---|---|---|
| AI chatbots (website widget, Instagram, Messenger and other channels) | The Client’s website visitors, customers and prospects who use the chatbot; the Client’s staff who handle escalations | Message content; name, email, phone or order number if the user provides them; channel username or ID; conversation metadata (timestamps, language, channel); technical identifiers such as session ID | Conversation logs 90 days; configuration for the Contract |
| AI workflows and automations | The Client’s customers, leads, suppliers and staff, as needed for the workflow | Contact details; content of emails, forms, tickets, orders and invoices; CRM records; workflow run logs | Run logs 30 days; data in the Client’s own systems stays under the Client’s retention rules |
| Websites | Visitors and people who submit forms on the Client’s site | Form submissions; technical data in server logs; analytics data only if the Client enables it with consent | As configured for the Client; while BotBridge manages hosting, logs no longer than the hosting provider’s standard period |
| GDPR documents | The Client’s contact people and, where examples are needed, staff | Names, roles and business contact details; descriptions of the Client’s processing activities | For the Contract plus 3 years |
| Support, tuning and retainers | Any of the above, as needed to investigate and fix issues | Any of the above, accessed only as needed | No separate copies kept beyond the ticket |
Special categories of data: not intended. Solutions are not designed to collect them, and the Client must not configure them to do so unless agreed in writing with additional safeguards. Frequency: continuous for the duration of the Services.
Annex II — Technical and organisational measuresArt. 32
| Area | Measures |
|---|---|
| Access control | Unique personal accounts; multi-factor authentication on all systems holding Client Personal Data; role-based least-privilege access; access removed within 24 hours when no longer needed; quarterly access review |
| Credentials and secrets | Company password manager; API keys and tokens kept in secret stores or environment variables, never in source code or chat; keys rotated after staff changes or suspected exposure |
| Encryption | TLS 1.2 or higher for all data in transit; encryption at rest on providers’ infrastructure; full-disk encryption on all work devices |
| Data minimisation | Only data required for the use case is collected and sent to AI providers; masking of identifiers where feasible; no production personal data used for testing where synthetic data will do |
| Separation | Separate workspaces, projects or accounts per client; test and production environments separated |
| Availability and resilience | Reputable cloud providers with redundancy; backups where BotBridge hosts data; error alerts and monitoring on workflows |
| Secure development | Version control with access controls; reviews before production changes; dependencies kept updated; guardrails and prompt-injection testing for AI features |
| Logging | Administrative access and changes logged where the platforms support it; logs protected against modification and kept for limited periods |
| Devices | Supported operating systems with automatic security updates; screen lock; remote wipe where available; no Client Personal Data on removable media |
| People | Written confidentiality undertakings; data protection and security training at onboarding and yearly |
| Vendor management | Due diligence on each sub-processor’s security and data processing terms before use; Art. 28 agreements in place; annual review |
| Incident response | Documented breach procedure with severity assessment, containment, Client notification within 48 hours, and a breach register |
| Retention and deletion | Automated deletion of logs where platforms allow; deletion or return at contract end with written confirmation on request |
| Testing and evaluation | Yearly review of these measures and after any significant incident or change |
Annex III — Sub-processors
Used across client projects
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Google Ireland Ltd / Google LLC (Gmail) | Email and document storage for project communication | European Union; United States | EU–US Data Privacy Framework; SCCs |
| Vercel Inc. | Hosting websites and applications that BotBridge manages | United States | EU–US Data Privacy Framework; SCCs |
| GitHub, Inc. | Source code and configuration version control — not used to store Client Personal Data | United States | EU–US Data Privacy Framework; SCCs |
Selected per project
Depending on the solution, a project uses providers from the categories below. The exact providers, their locations and retention settings are named in the Quote, which the Client approves before any processing begins; that approval is the Client’s authorisation for those sub-processors.
| Category | Purpose | Typical safeguard |
|---|---|---|
| AI model providers | Generating chatbot answers, classifying and extracting information in workflows | EEA processing where available; otherwise DPF or SCCs; no training on customer data |
| Chatbot and messaging platforms | Chat widget, Instagram, Messenger and other channels | DPF or SCCs |
| Automation platforms | Running workflows that connect the Client’s tools | EEA processing or self-hosting where available; otherwise DPF or SCCs |
| Vector databases and storage | Knowledge bases and conversation logs | EEA region selected where available |