Data Processing Agreement
Effective from: 11.9.2026
Version: 2.0
This Data Processing Agreement forms part of the contractual relationship between the customer of the ELIA Asistent service as controller and ELIA, s.r.o. as processor.
1. Parties
Processor:
ELIA, s.r.o.
Hviezdoslavovo námestie 7, 811 02 Bratislava
Company ID: 35 878 185
VAT ID: SK2021791981
Registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert No.: 30925/B
Email: contact@elia.sk
Controller:
The customer of the ELIA Asistent service who has entered into a contract, order, or other contractual relationship with ELIA, s.r.o. for the provision of the service.
2. Purpose and Legal Framework
This agreement governs the processing of personal data that the Processor carries out on behalf of the Controller when providing the ELIA Asistent service and related implementation, integration, support, and operational services.
This agreement is concluded under Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Act No. 18/2018 Coll. on Personal Data Protection.
If stricter personal data protection rules are agreed in a contract, order, or separate agreement, those stricter rules apply.
3. Subject Matter, Nature, and Purpose of Processing
The subject matter of processing is the provision, configuration, operation, security protection, maintenance, and support of the ELIA Asistent service.
Processing may include in particular:
- receiving, storing, and displaying messages and interactions from the chat widget, email, WhatsApp, Telegram, Microsoft Teams, or other channels,
- automated classification, summarization, routing, and generation of replies,
- searching the knowledge base and using data to create replies,
- managing customer accounts, permissions, and users,
- connecting to the Controller's systems, such as CRM, calendars, e-shops, or booking systems,
- providing technical support and handling incidents,
- logging, monitoring, backups, security checks, and operational diagnostics.
The Processor processes personal data only on the basis of documented instructions from the Controller, including instructions arising from the contract, service settings, service use, and this agreement.
4. Duration of Processing
The Processor processes personal data during the term of the contractual relationship and afterwards only for the time necessary to:
- export or return data to the Controller,
- delete data from the service and backups,
- comply with legal obligations,
- protect legal claims,
- handle a security incident or dispute.
Unless agreed otherwise, after the end of the contractual relationship the Processor will allow the Controller to export available data for a reasonable period of 30 days and will then begin deleting or anonymizing the data. Data in backups may be removed later as part of the normal backup restoration and overwrite cycle, but no later than according to internal retention rules and the capabilities of the providers used.
5. Categories of Data Subjects
Processing may concern in particular:
- customers, clients, website visitors, app users, and prospects of the Controller,
- persons communicating with the Controller through chat, email, social networks, WhatsApp, Telegram, Teams, or another channel,
- employees, contractors, agents, sales representatives, and administrators of the Controller,
- contact persons of the Controller's business partners,
- persons included in knowledge materials, documents, or integrations provided by the Controller.
6. Categories of Personal Data
The scope of processing depends on what data the Controller enters into the service and what channels and integrations the Controller enables. This may include in particular:
- identification data, such as name, surname, username, customer identifier, or case number,
- contact data, such as email, phone number, address, or communication identifier,
- communication content, questions, replies, notes, attachments, conversation history, and feedback,
- technical data, such as IP address, user agent, timestamps, session identifiers, logs, and delivery data,
- interaction data, such as case status, priority, tags, categories, assigned agent, and handling history,
- data from integrated systems, such as order, booking, calendar, service, or customer profile data,
- account data of service users, such as role, tenant, permissions, and last login,
- knowledge materials, documents, and database records provided by the Controller.
The service is not intended for processing special categories of personal data, criminal-offence data, children's data, or other highly sensitive data unless this is expressly agreed and legally secured.
7. Obligations of the Controller
The Controller is responsible for:
- the lawfulness of personal data processing,
- determining the purposes and legal bases of processing,
- fulfilling information obligations toward data subjects,
- obtaining consents, where necessary,
- the accuracy, adequacy, and minimization of data entered into the service,
- configuring the service and communication channels in accordance with legal requirements,
- informing end users about automated communication or AI where required by law or by the nature of the service,
- ensuring that instructions given to the Processor are lawful and sufficiently specific.
The Controller must not enter into the service any data for which it has no legal basis for processing or which the service is not intended to process under the contract.
8. Obligations of the Processor
The Processor undertakes to:
- process personal data only on the basis of documented instructions from the Controller,
- inform the Controller without undue delay if it believes that an instruction infringes the GDPR or other legal requirements,
- ensure that persons authorized to process data are bound by confidentiality or a statutory duty of confidentiality,
- implement appropriate technical and organizational measures under Article 32 GDPR,
- maintain appropriate internal records of processing activities where required by the GDPR,
- provide the Controller with reasonable assistance in fulfilling its GDPR obligations,
- not sell personal data and not use it for its own marketing purposes without a separate legal basis,
- not use the Controller's data to train foundation AI models unless expressly agreed or legally permitted.
9. Subcontractors and Other Processors
The Controller grants the Processor general authorization to engage other processors necessary for providing the service.
The Processor will ensure that each other processor is bound by contractual personal data protection obligations at least to the extent required by Article 28 GDPR and provides appropriate guarantees of security and lawfulness of processing.
The Processor is responsible for the performance of the obligations of other processors as required by the GDPR.
Categories of subcontractors may include in particular:
- cloud infrastructure, hosting, databases, authentication, and storage,
- automation and integration platforms,
- AI model or AI gateway providers,
- analytics, monitoring, logging, and security tools,
- communication providers, such as email, SMS, WhatsApp, Telegram, Microsoft Teams, or telephony services,
- payment, invoicing, and accounting services,
- support, ticketing, and customer communication tools.
Examples of services used or optionally available may include Supabase, n8n, Microsoft Azure, Stripe, PostHog, Google Analytics, Cloudflare, Better Stack, Application Insights, Twilio, Meta, Telegram, Microsoft, Google, OpenRouter, or another AI model provider according to the current configuration. The specific list must be maintained separately and updated according to the services actually deployed.
If the Processor engages a new subcontractor that materially changes the processing risk, it will notify the Controller in an appropriate manner. The Controller may object within a reasonable period for serious reasons relating to personal data protection. If the objection cannot be resolved by an acceptable measure, the parties will agree to restrict the affected functionality or terminate the relevant performance.
10. International Transfers
The Processor may process personal data outside the European Economic Area only if a valid mechanism under the GDPR is in place, in particular:
- an adequacy decision of the European Commission,
- standard contractual clauses,
- binding corporate rules,
- a GDPR derogation, where applicable,
- another valid legal mechanism.
If standard contractual clauses are used, the Processor and the relevant subcontractor will adopt appropriate supplementary measures where necessary, taking into account the nature of the data and the country of transfer.
11. Security Measures
The Processor implements appropriate technical and organizational measures, including:
- encrypted data transmission using TLS,
- access control, roles, and the principle of least privilege,
- separation of tenants and customer data,
- user authentication and session management,
- logging of security-relevant events,
- protection of public interfaces through rate limiting and security checks,
- encryption or secure storage of secrets and integration credentials where technically available,
- backups and recovery according to the capabilities of the providers used,
- regular maintenance, updates, and remediation of known vulnerabilities,
- restriction of internal access only to cases where it is necessary for providing the service or support,
- procedures for handling security incidents.
Measures may be adapted to the nature of the service, the risk, the scope of processing, and the current state of the art.
12. Personal Data Breach
The Processor will notify the Controller of a personal data breach without undue delay after becoming aware of it, generally no later than within 48 hours where possible in light of the circumstances.
The notice will include available information necessary to assess the incident, in particular:
- the nature of the incident,
- categories and approximate number of affected data subjects and records, if known,
- likely consequences,
- measures taken or proposed,
- contact point for handling the incident.
If all information is not available at once, the Processor will provide it gradually without undue delay.
13. Assistance with Data Subject Rights
If a data subject exercises their rights directly with the Processor and the request clearly concerns the Controller's data, the Processor will forward the request to the Controller without undue delay or refer the data subject to the Controller.
The Processor will provide the Controller with reasonable technical and organizational assistance in handling data subject rights, in particular access, rectification, erasure, restriction of processing, portability, and objection.
14. DPIA, Consultations, and Controls
The Processor will provide the Controller with reasonable assistance in carrying out data protection impact assessments, prior consultation with a supervisory authority, and demonstrating GDPR compliance where such assistance is necessary in light of the nature of processing and the information available to the Processor.
15. Audit and Compliance Information
The Processor will make available to the Controller information necessary to demonstrate compliance with the obligations under Article 28 GDPR to a reasonable extent.
The Controller may request an audit of processing no more than once every 12 months, unless there is a serious security reason for a more frequent audit. Before the audit, the parties will agree on the scope, timing, method of execution, security rules, confidentiality, and reasonable limitation of interference with the Processor's operations.
Instead of a direct audit, the Processor may first provide reasonable documents, statements, security descriptions, or results of independent controls if such information is sufficient to verify compliance. The auditor must not be a direct competitor of the Processor and must be bound by confidentiality.
16. Return and Deletion of Data
After the end of the service provision, the Processor will delete or return personal data according to the Controller's instructions, unless legal requirements require further retention.
If the Controller gives no specific instruction, the Processor may delete or anonymize data after a reasonable export period. Deletion from backups may take place gradually according to the normal backup cycle.
17. Order of Documents
This agreement supplements the terms and conditions, order, and service contract. In matters of personal data protection, this agreement prevails over the terms and conditions in case of conflict.
18. Final Provisions
This agreement is governed by the laws of the Slovak Republic. Disputes will be resolved by the competent courts of the Slovak Republic, unless mandatory law provides otherwise.
If any provision is found invalid or unenforceable, this does not affect the validity of the remaining provisions. The parties will replace it with a provision that most closely reflects the original purpose and complies with the law.