Data Processing Agreement (DPA)
This agreement, pursuant to Art. 28 GDPR, governs the processing of personal data that PappaChat (Processor) carries out on behalf of the Customer (Controller) in delivering the service. It forms an integral part of the Terms and Conditions and is accepted on subscription.
Last updated: 9 September 2026
This is a convenience translation. The binding version of this document is the Italian one; in case of discrepancy, the Italian text prevails.
This Data Processing Agreement ("DPA") is entered into between the Customer who subscribes to the PappaChat service, acting as Data Controller, and Atakan Kayatekin (Sole proprietorship), VAT no. 01452450321, Tax Code KYTTKN96M02Z243J, with registered office at Via Giovanni Paisiello 5, 34148 Trieste (TS), Italy, operating the "PappaChat" brand (pappachat.com), acting as Data Processor.
PappaChat is a multi-tenant SaaS service that provides the Customer with AI-based assistants operating across multiple channels (including WhatsApp, Instagram, Telegram, website chat and email) for businesses in any sector. When the assistant communicates with the Customer's own patrons ("End Customers"), the Customer is the Data Controller of the related personal data and PappaChat acts as the Data Processor. This DPA governs that relationship only.
The Processor processes End Customers' personal data solely on the documented instructions of the Controller, comprising the subscription agreement, the platform settings and this DPA. This agreement is automatically entered into by every Customer who subscribes to the service and does not require a separate signature.
1Definitions
For the purposes of this DPA:
- Personal Data: any information relating to an identified or identifiable natural person, processed by the Processor on behalf of the Controller within the service.
- Special categories of data: the data referred to in Art. 9 GDPR (e.g. data concerning health, religious beliefs, sexual orientation), the processing of which is subject to particular safeguards.
- Data Subjects: the natural persons to whom the Personal Data relate, namely the Controller's End Customers and prospective customers.
- Processing: any operation performed on the Personal Data, such as collection, recording, storage, use, disclosure, transmission and erasure.
- Data Controller: the Customer who subscribes to the service and determines the purposes and means of processing the data of its own End Customers.
- Data Processor: PappaChat, which processes the Personal Data on behalf of the Controller.
- Sub-processor: the third party engaged by the Processor to carry out specific processing activities on behalf of the Controller.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, the Personal Data.
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data.
- Garante: the Italian Data Protection Authority (Garante per la protezione dei dati personali), the competent supervisory authority in Italy.
2Subject matter and roles
By this DPA the Controller appoints the Processor, pursuant to Art. 28 GDPR, to process the End Customers' Personal Data necessary to deliver the service. The Processor accepts the appointment and undertakes to process the Personal Data in compliance with the GDPR and applicable law.
The Processor processes the Personal Data solely on the Controller's documented instructions, including this DPA, the subscription and the platform settings, unless required to do so by Union or Member State law; in that case the Processor informs the Controller before processing, unless prohibited by law.
3Categories of data and data subjects
The Data Subjects are the Controller's End Customers and prospective customers who interact with the assistant.
The categories of Personal Data processed include:
- identification and contact data (name, phone number/WhatsApp and, where provided, email address);
- the content of the messages exchanged with the assistant;
- reservation and order details;
- interaction metadata (date, time, channel, technical conversation identifiers).
4Nature, purpose and duration of the processing
The nature and purpose of the processing consist in operating the AI-based assistant and its related features on the Controller's channels: replying to End Customers' messages, handling reservations and orders, human takeover and ancillary functions configured by the Controller.
The processing operations include the collection, recording, storage, use, transmission to the listed sub-processors and erasure of the Personal Data.
The duration of the processing matches the term of the Terms and Conditions: the Processor processes the Personal Data for the entire term of the contract and, thereafter, as set out in the 'Term and termination' section.
5Obligations of the Processor
Pursuant to Art. 28(3) GDPR, the Processor undertakes to:
- 1.process the Personal Data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required by law;
- 2.ensure that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- 3.implement all appropriate technical and organisational measures required by Art. 32 GDPR;
- 4.respect the conditions for engaging a sub-processor laid down by the GDPR and this DPA;
- 5.assist the Controller, taking into account the nature of the processing, by appropriate measures in responding to data subjects' requests to exercise their rights (Arts. 12-23 GDPR);
- 6.assist the Controller in ensuring the security of processing, breach notification, data protection impact assessment (DPIA) and prior consultation (Arts. 32-36 GDPR);
- 7.at the Controller's choice, delete or return all Personal Data at the end of the provision of services, save for statutory retention obligations;
- 8.make available to the Controller all information necessary to demonstrate compliance and allow for and contribute to audits, including inspections;
- 9.maintain a record of the processing activities carried out on behalf of the Controller pursuant to Art. 30(2) GDPR;
- 10.inform the Controller without undue delay of any complaints or requests received from data subjects or supervisory authorities relating to the data processed on its behalf.
6Security measures (Art. 32)
Taking into account the state of the art, the costs of implementation, the nature of the processing and the risks to data subjects, the Processor implements appropriate technical and organisational measures, including:
- encryption of data in transit (TLS);
- access control based on the least-privilege principle and operator authentication;
- hosting of the infrastructure at data centres located in the European Union;
- logical segregation of data between different customers (multi-tenant);
- periodic backups and restore procedures;
- event logging and monitoring;
- confidentiality obligations for authorised staff;
- incident and data breach handling procedures.
7Sub-processors
The Controller grants the Processor a general written authorisation to engage the sub-processors listed below. The Processor binds each sub-processor, by contract, to data protection obligations equivalent to those of this DPA and remains fully liable to the Controller for the performance of the sub-processors' obligations.
The Processor informs the Controller, with reasonable notice, of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data protection grounds.
| Provider | Service and purpose | Location and transfer safeguards |
|---|---|---|
| Meta Platforms Ireland Ltd | Messaging over WhatsApp and Instagram | Ireland (EU); any transfers to the USA are covered by the EU-US Data Privacy Framework and Standard Contractual Clauses |
| SendSeven GmbH | Routing and handling of Instagram channel messages (delivered through the linked Facebook Page) | Germany (EU); processing within the European Union |
| Anthropic, PBC | Generating the assistant's replies (Claude models) on plans with AI included | USA; Standard Contractual Clauses (Art. 46 GDPR) |
| Google Ireland Ltd | Generating the assistant's replies (Gemini models) and the website demo | Ireland (EU) / USA; EU-US Data Privacy Framework and Standard Contractual Clauses |
| Stripe Payments Europe Ltd | Payment processing and subscription billing | Ireland (EU) / USA; EU-US Data Privacy Framework and Standard Contractual Clauses |
| Resend, Inc. | Sending transactional emails (sign-up, notifications, confirmations) | USA; Standard Contractual Clauses (Art. 46 GDPR) |
| Amazon Web Services EMEA SARL | File and backup storage (data centres in the European Union) | EU; EU-US Data Privacy Framework and Standard Contractual Clauses for any non-EU services |
| DigitalOcean LLC | Hosting of the application infrastructure (data centres in the European Union) | EU (Amsterdam); Standard Contractual Clauses |
| Cloudflare, Inc. | Anti-abuse protection (Turnstile), CDN and network security | USA; EU-US Data Privacy Framework and Standard Contractual Clauses |
On plans that include artificial intelligence, the AI provider (Anthropic, Google) acts as the Processor's sub-processor. On bring-your-own-key ('BYO key') plans, the AI provider chosen by the Controller is contracted directly by the Controller and acts under the terms agreed between the Controller and that provider, not as the Processor's sub-processor.
8Transfers to third countries
The Processor uses, where possible, data centres located in the European Union. Where processing involves a transfer of Personal Data outside the European Economic Area, the transfer takes place solely on the basis of an adequacy decision, the EU-US Data Privacy Framework and/or Standard Contractual Clauses adopted by the European Commission (Art. 46 GDPR), together with any necessary supplementary measures.
A copy of the safeguards applied to transfers is available on request from the Controller, by writing to [email protected].
9Assistance to the Controller
Taking into account the nature of the processing and the information available to it, the Processor assists the Controller by appropriate technical and organisational measures in responding to requests for the exercise of data subjects' rights (Arts. 12-23 GDPR).
The Processor also assists the Controller in fulfilling its obligations relating to the security of processing, notification of personal data breaches, data protection impact assessments and prior consultation of the supervisory authority (Arts. 32-36 GDPR).
10Personal data breach
After becoming aware of a personal data breach affecting the data processed on behalf of the Controller, the Processor notifies the Controller without undue delay and in any case within 48 hours.
The notification includes, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed to address the breach and mitigate its effects.
11Audits and inspections
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and this DPA.
The Processor allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable prior notice and in a manner that does not compromise the security and confidentiality of other customers' data.
12Term and termination
This DPA takes effect upon subscription to the service and lasts for the term of the Terms and Conditions to which it relates.
Upon termination of the contract, at the Controller's choice, the Processor deletes or returns all Personal Data and existing copies, unless Union or Member State law requires the data to be retained for the period strictly necessary to fulfil the related legal obligations.
13Liability
Each party is liable for damage caused by the processing as provided by Art. 82 GDPR and applicable law. The allocation of liability between the Controller and the Processor follows their respective roles and obligations.
The limitation of liability set out in the Terms and Conditions applies to the extent permitted by law.
14Governing law and competent court
This DPA is governed by Italian law and is interpreted in accordance with the GDPR. Any dispute is subject to the exclusive jurisdiction of the Court of Trieste, without prejudice to any mandatory jurisdiction provided by law.
