Legal

Data Processing Agreement (DPA)

Status: Draft template — pending legal review

Placeholder — not final legal text

This page is a structural template prepared for the AIMER launch. It is not legal advice and must be reviewed and completed by qualified legal counsel before the service is offered commercially.

This template will form the data processing agreement between the business customer (controller) and AIMER (processor) under Art. 28 GDPR.

1. Parties & roles

Placeholder: the business customer acts as data controller; AIMER acts as data processor for end-customer personal data handled by the AI Employee.

2. Subject matter & duration

Placeholder: processing tied to the service subscription and its duration.

3. Nature & purpose of processing

Placeholder: operating AI-assisted customer conversations, bookings and follow-ups on behalf of the controller.

4. Categories of data & data subjects

Placeholder: end customers of the business; identification and contact data, conversation content and booking details.

5. Processor obligations

Placeholder: process only on documented instructions, ensure confidentiality, support audits.

6. Sub-processors

Placeholder: the authorized sub-processor list (hosting, database, AI model providers) and the notification mechanism for changes.

7. Security measures (Art. 32)

Placeholder: technical and organizational measures including encryption in transit, access controls, tenant isolation and password hashing.

8. Assistance with data subject rights

Placeholder: how the processor assists the controller with access, export and erasure requests.

9. Personal data breach notification

Placeholder: notification duties and timelines toward the controller.

10. Deletion & return of data

Placeholder: deletion or return of all personal data at contract end, as also supported by the in-app deletion controls.

Contact details for legal and privacy questions will be published here at launch.