Skip to content
AymarAgents
PlatformPartner programSolutionsSecurity
Docs
  • For partners
  • For customers
EnglishEN
  • Español
  • English
  • Italiano
Sign inTalk to the team
PlatformPartner programSolutionsSecurityDocs for partnersDocs for customers
EnglishEN
  • Español
  • English
  • Italiano
Talk to the team

AYMAR INNOVATIONS, S.L.

Data processing agreement (GDPR article 28)

How we process, on behalf of the customer who contracts Aymar Agents, the personal data of their end customers.

Version 1.0 · In effect from 1 October 2026admin@aymaragents.com+34 603 293 908

Parties

This data processing agreement is entered into between the customer who contracts the Aymar Agents platform (the "Controller") and AYMAR INNOVATIONS, S.L. (the "Processor"), which provides the service under the SaaS services agreement signed between both parties (the "Terms and conditions", available at aymaragents.com/legal/terminos), of which this Agreement forms an integral part as required by article 28.3 of the General Data Protection Regulation.

1. Subject matter

The subject matter of this Agreement is to govern the Processor's processing, on behalf of the Controller, of the personal data of the Controller's end customers — the people who interact with the Controller's AI conversational agents through the Aymar Agents platform — as required by article 28 of the General Data Protection Regulation.

2. Duration

This Agreement takes effect on the date the Controller accepts the Terms and conditions and remains in force for as long as the Aymar Agents service continues to be provided. The obligations relating to the deletion or return of data (clause 12) and confidentiality (clause 7) survive termination of this Agreement.

3. Nature and purpose of the processing

The Processor processes the personal data covered by this Agreement in order to operate, on behalf of the Controller, the AI conversational agents the Controller has contracted: receiving and responding to end-customer messages over the enabled channels (WhatsApp, Telegram, Messenger, Instagram Direct, voice and the web chat widget), capturing and managing leads and appointments, generating documents from the information provided, and delivering the rest of the platform's functionality as the Controller configures it.

4. Categories of personal data processed

The processing covers, among others: identifying and contact data (the end customer's name, phone number and, where applicable, email address); the content of conversations held with the Controller's conversational agents; attachments sent or received during those conversations (images, documents); and data associated with appointments, leads and documents generated through the platform. The Processor does not actively request special categories of data (GDPR article 9); if an end customer voluntarily provides them in a message, it is the Controller's responsibility to ensure a valid legal basis exists for that processing.

5. Categories of data subjects

The Controller's end customers: the individuals who contact, or are contacted through, the platform's conversational agents, regardless of the channel used.

6. Documented instructions

The Processor only processes personal data in accordance with the Controller's documented instructions, set out in this Agreement, in the Terms and conditions, and in the configuration the Controller itself performs on the platform (for example, the content and scope of its agents' instructions). If the Processor considers that an instruction infringes the General Data Protection Regulation or another data-protection provision, it will inform the Controller immediately. The Processor will not process data for its own purposes or for purposes other than those agreed, except where a legal obligation requires it to do so, in which case it will inform the Controller beforehand, unless that information is prohibited on important grounds of public interest.

7. Confidentiality

The Processor guarantees that personnel authorised to process personal data have committed to confidentiality or are under a statutory duty of confidentiality, and that such personnel receive the necessary training on data protection, including on the transparency requirements of Regulation (EU) 2024/1689 regarding the use of AI systems.

8. Security measures (GDPR article 32)

The Processor applies, among others, the following technical and organisational measures: encryption of the access credentials for the channels and external providers each customer configures; role-based access control (RBAC) and verified isolation between each customer's data (multi-tenant), including specific negative tests against cross-customer access; an audit log of actions performed on the data, kept for a limited retention period; rate limiting and abuse controls on messaging channels; and a procedure for effectively deleting an end customer's data on request, with technical verification that no trace remains in the Processor's systems. Further detail on these measures is available on the Controller's reasonable request.

9. Sub-processing

The Controller gives the Processor general authorisation to sub-contract the processing described in this Agreement to other processors (sub-processors), subject to the same data-protection obligations set out in this Agreement through the corresponding contract. The up-to-date list of named sub-processors, the service they provide, their location and the safeguard applicable to international transfers, is published in the sub-processors section of our privacy policy. The Processor will inform the Controller of any planned change to that list, giving the Controller the opportunity to object on reasonable data-protection grounds.

10. Assistance to the Controller

The Processor assists the Controller, through appropriate technical and organisational measures, in fulfilling its obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, objection and portability); in particular, the platform includes a feature for deleting an end customer's data on request, which the Controller can run directly from its dashboard. The Processor likewise assists the Controller in meeting its obligations regarding the security of processing, notification of security breaches and, where applicable, data protection impact assessments, taking into account the nature of the processing and the information available to the Processor.

11. Notification of security breaches

The Processor will notify the Controller, without undue delay and in any case within a reasonable period after becoming aware of it, of any breach of the security of personal data processed on the Controller's behalf, providing the information the Controller needs to comply, where applicable, with its own obligation to notify the competent supervisory authority and, where appropriate, the affected data subjects.

12. Deletion or return of data

Once the service ends, the Processor will, at the Controller's choice, return or delete the personal data processed, along with any copies of it, unless retention is required by a legal obligation applicable to the Processor. In practice, when the Controller closes its account, its data and its end customers' data are kept for a 30-day grace period (in case the closure was accidental) and, once that period elapses without the account being reactivated, are effectively purged from the Processor's databases, file storage and other systems, as described in our privacy policy.

13. Audits

The Processor will make available to the Controller the information necessary to demonstrate compliance with the obligations set out in this Agreement, and will allow and contribute to audits, including inspections, carried out by the Controller or an auditor authorised by the Controller, on reasonable notice and without prejudice to the confidentiality owed to the Processor's other customers.

14. Liability

Each party will be liable to data subjects and to supervisory authorities for damage caused by processing that infringes the General Data Protection Regulation, under the terms of its article 82 and the applicable Spanish data-protection law.

15. Governing law and jurisdiction

This Agreement is governed by Spanish and European data-protection law. For any dispute relating to its interpretation or performance, the parties submit to the courts and tribunals with jurisdiction under the service's Terms and conditions.

AymarAgents

The infrastructure for selling and operating digital workers under your brand.

ProductPlatformPartner programSolutionsSecurityDocs for partnersDocs for customers
AymarContactadmin@aymaragents.comPartner access
LegalLegal noticePrivacyCookiesData processing agreement (DPA)TermsPartner agreement
© 2026 AYMAR INNOVATIONS, S.L.Digital workers powered by artificial intelligence.