This Data Processing Agreement ("DPA") is entered into between Dialogis.ai s.r.o., ID No. 23985348, Sokolská 1883/8, Nové Město, 120 00 Prague 2, Czech Republic ("Dialogis" or "Processor") and the Customer identified in the Customer's workspace or Order Form ("Customer" or "Controller"). It forms part of the Terms of Use (the "Agreement") and takes precedence over the Terms of Use in matters of personal-data processing.
1. Definitions
Terms defined in the Agreement have the same meaning here. In addition:
- "Data Protection Law" means the GDPR (Regulation (EU) 2016/679), Czech Act No. 110/2019 Coll., the ePrivacy Directive as implemented, and any other law applicable to the processing of Customer Personal Data, including the UK GDPR and the Swiss FADP where the Customer is established there.
- "Customer Personal Data" means personal data contained in Customer Content and Conversation Data that Dialogis processes on behalf of the Customer.
- "Sub-processor" means a third party engaged by Dialogis to process Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the clauses adopted by Commission Implementing Decision (EU) 2021/914.
- "Personal Data Breach", "controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings given in the GDPR.
2. Roles and scope
2.1 The Customer is the controller (or, where the Customer acts for another controller, a processor authorised to appoint Dialogis as sub-processor) and Dialogis is the processor of Customer Personal Data. Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.
2.2 This DPA does not apply to personal data for which Dialogis is an independent controller (Customer account, billing, security and legal data), which is governed by the Privacy Policy.
2.3 The Customer warrants that it has, and will maintain, a lawful basis for the processing, that it has provided data subjects with the information required by Data Protection Law, and that its instructions comply with Data Protection Law.
3. Instructions
3.1 Dialogis will process Customer Personal Data only on the documented instructions of the Customer, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which Dialogis is subject; in that case Dialogis will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
3.2 The Customer's documented instructions are: the Agreement, this DPA, the Customer's configuration of the Platform (including which Knowledge Sources to ingest, which Minds to publish, which Channels and integrations to connect, and which conversations to delete), and any additional written instructions agreed by both parties. Instructions that would require Dialogis to process outside the functionality of the Platform may be subject to additional fees.
3.3 Dialogis will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend the instruction until it is confirmed or amended.
4. Confidentiality
Dialogis ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process Customer Personal Data only to the extent needed for their role.
5. Security
5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks for data subjects, Dialogis implements and maintains the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
5.2 Dialogis may update the measures from time to time provided the overall level of security is not materially reduced during the term.
5.3 The Customer is responsible for the security of its own systems, credentials and configuration, including the choice of which personal data to submit to the Platform, the configuration of Minds, and the access rights it grants to Authorised Users.
6. Sub-processors
6.1 The Customer gives Dialogis a general written authorisation to engage Sub-processors. The Sub-processors engaged at the effective date of this DPA are listed at dialogis.io/legal/subprocessors (the "Sub-processor List"), which forms Annex 3.
6.2 Dialogis will inform the Customer of any intended addition or replacement of a Sub-processor at least 30 days before the change takes effect, by updating the Sub-processor List and by email to the workspace owner. The Customer may object on reasonable, data-protection-related grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected part of the Agreement, with a pro-rata refund of prepaid fees for the unused period, before the change takes effect. Dialogis may engage a replacement Sub-processor on shorter notice where necessary to maintain the security or continuity of the Platform, in which case it will inform the Customer as soon as possible.
6.3 Dialogis will impose on each Sub-processor, by way of a written contract, data-protection obligations that provide substantially the same level of protection as this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Dialogis remains fully liable to the Customer for the performance of each Sub-processor's obligations.
7. Data subject requests
7.1 Taking into account the nature of the processing, Dialogis will assist the Customer, by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.
7.2 The Platform allows the Customer to access, export, correct and delete Customer Personal Data directly (Knowledge Sources, Mind configuration, conversations, leads, channel connections). Where a request cannot be fulfilled through the Platform, Dialogis will assist within 10 business days of a written request.
7.3 If a data subject contacts Dialogis directly about Customer Personal Data, Dialogis will not respond on the merits except to direct the data subject to the Customer, and will inform the Customer of the request without undue delay, unless prohibited by law. Where the Customer cannot be reached for 30 days after Dialogis has informed it of a deletion request, Dialogis may delete the data subject's Conversation Data to protect the data subject's rights, and will inform the Customer.
8. Personal Data Breach
8.1 Dialogis will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available.
8.2 Dialogis will assist the Customer in complying with its obligations under Articles 33 and 34 GDPR, taking into account the nature of the processing and the information available to Dialogis, and will not inform data subjects or authorities about a breach of Customer Personal Data on the Customer's behalf unless the Customer instructs it or the law requires it.
9. Impact assessments and prior consultation
Dialogis will provide the Customer with reasonable assistance, taking into account the nature of the processing and the information available to it, in carrying out data protection impact assessments and prior consultations with supervisory authorities that relate to the processing under this DPA. The AI Transparency Notice, the Sub-processor List and Annex 2 provide the standard information for that purpose; further assistance may be charged at reasonable rates where it requires significant effort.
10. International transfers
10.1 Dialogis processes Customer Personal Data primarily in the European Union. Dialogis will not transfer Customer Personal Data to a third country or international organisation except (a) to a Sub-processor listed in the Sub-processor List under the transfer mechanism stated there, (b) on the Customer's instruction (for example when the Customer connects a Channel or integration operated outside the EU), or (c) as required by Union or Member State law.
10.2 For transfers to Sub-processors outside the EEA that are not covered by an adequacy decision, Dialogis relies on the SCCs (Module 3, processor to processor) or on the Sub-processor's certification under the EU-U.S. Data Privacy Framework, together with any supplementary measures needed following a transfer impact assessment. Copies of the relevant clauses are available on request.
10.3 If the Customer is established outside the EEA and its transfer of Customer Personal Data to Dialogis is a restricted transfer under the Customer's law (for example the UK GDPR or the Swiss FADP), the parties agree that the SCCs (Module 2, controller to processor), or the applicable national addendum, apply to that transfer with the Customer as data exporter and Dialogis as data importer, completed with the information in the Annexes.
11. Audits
11.1 Dialogis will make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
11.2 The Customer will in the first instance rely on the documentation Dialogis provides (this DPA and its Annexes, the Sub-processor List, security documentation and, where available, third-party reports of Sub-processors) and on written responses to reasonable questions, which Dialogis will answer within 20 business days.
11.3 Where an on-site or remote inspection is reasonably required, it will take place no more than once per 12 months (unless required by a supervisory authority or following a Personal Data Breach), on at least 30 days' written notice, during business hours, under a confidentiality agreement, in a manner that does not compromise the security or confidentiality of other customers, and at the Customer's expense. Findings are confidential and will be shared with Dialogis.
12. Return and deletion
12.1 During the term, the Customer can delete Customer Personal Data at any time through the Platform.
12.2 After the end of the Agreement, Dialogis will make Customer Personal Data available for export for 30 days (the retrieval period in Section 18 of the Terms of Use) and will then delete all Customer Personal Data, including copies held by Sub-processors, within 30 days, unless Union or Member State law requires storage. Backup copies expire within a further 14 days. Dialogis will confirm deletion in writing on request.
12.3 Aggregated or anonymised data that no longer relates to an identifiable person is not Customer Personal Data and may be retained.
13. Liability
The liability of each party under this DPA is subject to the exclusions and limitations in Section 16 of the Terms of Use, except that nothing in this DPA limits either party's liability towards data subjects under Article 82 GDPR.
14. Term and precedence
14.1 This DPA applies for as long as Dialogis processes Customer Personal Data and survives termination of the Agreement until all Customer Personal Data has been deleted or returned.
14.2 If this DPA conflicts with the Terms of Use, this DPA prevails. If it conflicts with the SCCs where they apply, the SCCs prevail.
14.3 Dialogis may update this DPA as described in Section 20 of the Terms of Use, and will not reduce the level of protection for Customer Personal Data during a paid term without the Customer's agreement.
Annex 1 — Details of the processing
Subject matter. Provision of the Dialogis platform: creation and operation of AI Minds that answer End Users' questions in text and voice from the Customer's Knowledge Sources, on the Customer's website, hosted pages and messaging Channels, including conversation management, human handoff, lead capture, analytics and related support.
Duration. The term of the Agreement plus the retrieval and deletion periods in Section 12.
Nature of the processing. Collection, recording, storage, organisation, structuring, transcription (audio to text), optical character recognition, summarisation, vector embedding and indexing, retrieval, generation of answers by large language models, text-to-speech synthesis, transmission to Channels and Customer-selected integrations, display to Authorised Users, backup, and deletion.
Purpose. To provide the Platform to the Customer as configured by the Customer; to keep it secure; and to evaluate and improve the quality of the Customer's Minds.
Categories of data subjects.
- The Customer's Authorised Users and staff;
- Persona Subjects (experts whose knowledge, name, likeness or voice a Mind represents);
- End Users who interact with a Mind (website visitors, subscribers, customers, prospects, followers on messaging channels);
- other persons whose personal data appears in Knowledge Sources (for example clients, colleagues or people quoted in the Customer's material) or in conversations.
Categories of personal data.
- Identification and contact data (name, email, phone number, company, job title);
- channel identifiers (Telegram user ID and username, WhatsApp phone number and profile name, Instagram account ID and username, web session identifiers);
- conversation content and history, attachments, voice recordings and transcripts, requests and interests expressed by End Users, consent records;
- content of Knowledge Sources, which may include any personal data the Customer chooses to include;
- voice recordings of a Persona Subject for a Voice Clone, with the Persona Subject's explicit consent;
- technical data (IP address, device and browser information, timestamps, logs).
Special categories of data. The Platform is not designed for special categories of personal data or criminal-offence data. The Customer must not submit such data unless it has a lawful basis under Article 9 or 10 GDPR, has implemented appropriate safeguards, and has informed Dialogis in advance. End Users may nevertheless volunteer such data in conversations; it is processed only as part of the conversation and deleted with it.
Retention. As set out in Section 9 of the Privacy Policy and Section 12 of this DPA.
Annex 2 — Technical and organisational measures
Hosting and infrastructure. Production systems run on Google Cloud in the europe-west3 region (Frankfurt, Germany) in data centres certified to ISO/IEC 27001, 27017, 27018 and SOC 2. Identity services and transactional email run on Amazon Web Services in the EU (Stockholm and Ireland). Infrastructure is defined as code and changes are reviewed.
Encryption. All data in transit is encrypted with TLS 1.2 or higher. Data at rest (databases, object storage, backups, secrets) is encrypted with provider-managed keys. Integration credentials, channel tokens and provider API keys are additionally encrypted at the application level before storage.
Access control. Access to production systems is limited to named Dialogis personnel with a business need, uses individual accounts with multi-factor authentication, follows least privilege, and is reviewed when roles change and at least annually. Customer workspaces are logically separated by tenant identifiers enforced at the application and database layers. The chat widget validates the tenant and the authorised origin of every request.
Authentication of Customers. Sign-in is provided through a managed identity provider (Amazon Cognito) with email verification, password policy and optional Google sign-in. Web sessions use HttpOnly, Secure cookies with absolute and idle expiry. Role-based access within workspaces.
Logging and monitoring. Security-relevant events, administrative actions and API requests are logged centrally with retention of 30 days (longer for audit records of workspace actions). Alerts are configured for availability and error conditions. Rate limiting is applied to public endpoints.
Backups and continuity. Databases are backed up automatically every day with 14-day retention and point-in-time recovery for 7 days; object storage retains deleted objects for 7 days. Backups are stored encrypted in the same region. Restore procedures are tested.
Secure development. Code is version-controlled, peer-reviewed and covered by automated tests that run before deployment. Dependencies are updated regularly and scanned for known vulnerabilities. Secrets are stored in a managed secret store, never in code. Separate development, staging and production environments; production data is not used in development.
Sub-processor management. Sub-processors are selected for their security posture and bound by written data-processing terms; the list is reviewed at least annually.
AI-specific measures. Providers receive only the data needed for a request; provider accounts are configured not to use data for training and, where available, for zero retention. Prompts include guardrails against disclosure of other tenants' data. Outputs are labelled as AI-generated.
Personnel. Everyone with access to Customer Personal Data is bound by confidentiality, receives security and data-protection guidance, and loses access immediately when their engagement ends.
Incident response. A documented process covers detection, containment, assessment, notification (Section 8) and post-incident review.
Data deletion. Deletion in the Platform removes data from live systems immediately and from backups within 14 days; Sub-processors are instructed to delete on termination.
Annex 3 — Sub-processors
The current Sub-processor List, including each Sub-processor's location, purpose and transfer mechanism, is published and maintained at dialogis.io/legal/subprocessors and is incorporated into this DPA by reference.