Parties
This data processing agreement is entered into between the customer who contracts the Aymar Agents platform (the "Controller") and AYMAR INNOVATIONS, S.L. (the "Processor"), which provides the service under the SaaS services agreement signed between both parties (the "Terms and conditions", available at aymaragents.com/legal/terminos), of which this Agreement forms an integral part as required by article 28.3 of the General Data Protection Regulation.
1. Subject matter
The subject matter of this Agreement is to govern the Processor's processing, on behalf of the Controller, of the personal data of the Controller's end customers — the people who interact with the Controller's AI conversational agents through the Aymar Agents platform — as required by article 28 of the General Data Protection Regulation.
2. Duration
This Agreement takes effect on the date the Controller accepts the Terms and conditions and remains in force for as long as the Aymar Agents service continues to be provided. The obligations relating to the deletion or return of data (clause 12) and confidentiality (clause 7) survive termination of this Agreement.
3. Nature and purpose of the processing
The Processor processes the personal data covered by this Agreement in order to operate, on behalf of the Controller, the AI conversational agents the Controller has contracted: receiving and responding to end-customer messages over the enabled channels (WhatsApp, Telegram, Messenger, Instagram Direct, voice and the web chat widget), capturing and managing leads and appointments, generating documents from the information provided, and delivering the rest of the platform's functionality as the Controller configures it.
4. Categories of personal data processed
The processing covers, among others: identifying and contact data (the end customer's name, phone number and, where applicable, email address); the content of conversations held with the Controller's conversational agents; attachments sent or received during those conversations (images, documents); and data associated with appointments, leads and documents generated through the platform. The Processor does not actively request special categories of data (GDPR article 9); if an end customer voluntarily provides them in a message, it is the Controller's responsibility to ensure a valid legal basis exists for that processing.
5. Categories of data subjects
The Controller's end customers: the individuals who contact, or are contacted through, the platform's conversational agents, regardless of the channel used.
6. Documented instructions
The Processor only processes personal data in accordance with the Controller's documented instructions, set out in this Agreement, in the Terms and conditions, and in the configuration the Controller itself performs on the platform (for example, the content and scope of its agents' instructions). If the Processor considers that an instruction infringes the General Data Protection Regulation or another data-protection provision, it will inform the Controller immediately. The Processor will not process data for its own purposes or for purposes other than those agreed, except where a legal obligation requires it to do so, in which case it will inform the Controller beforehand, unless that information is prohibited on important grounds of public interest.
7. Confidentiality
The Processor guarantees that personnel authorised to process personal data have committed to confidentiality or are under a statutory duty of confidentiality, and that such personnel receive the necessary training on data protection, including on the transparency requirements of Regulation (EU) 2024/1689 regarding the use of AI systems.
8. Security measures (GDPR article 32)
The Processor applies, among others, the following technical and organisational measures: encryption of the access credentials for the channels and external providers each customer configures; role-based access control (RBAC) and verified isolation between each customer's data (multi-tenant), including specific negative tests against cross-customer access; an audit log of actions performed on the data, kept for a limited retention period; rate limiting and abuse controls on messaging channels; and a procedure for effectively deleting an end customer's data on request, with technical verification that no trace remains in the Processor's systems. Further detail on these measures is available on the Controller's reasonable request.
9. Sub-processing
The Controller gives the Processor general authorisation to sub-contract the processing described in this Agreement to other processors (sub-processors), subject to the same data-protection obligations set out in this Agreement through the corresponding contract. The up-to-date list of named sub-processors, the service they provide, their location and the safeguard applicable to international transfers, is published in the sub-processors section of our privacy policy. The Processor will inform the Controller of any planned change to that list, giving the Controller the opportunity to object on reasonable data-protection grounds.
10. Assistance to the Controller
The Processor assists the Controller, through appropriate technical and organisational measures, in fulfilling its obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, objection and portability); in particular, the platform includes a feature for deleting an end customer's data on request, which the Controller can run directly from its dashboard. The Processor likewise assists the Controller in meeting its obligations regarding the security of processing, notification of security breaches and, where applicable, data protection impact assessments, taking into account the nature of the processing and the information available to the Processor.
11. Notification of security breaches
The Processor will notify the Controller, without undue delay and in any case within a reasonable period after becoming aware of it, of any breach of the security of personal data processed on the Controller's behalf, providing the information the Controller needs to comply, where applicable, with its own obligation to notify the competent supervisory authority and, where appropriate, the affected data subjects.
12. Deletion or return of data
Once the service ends, the Processor will, at the Controller's choice, return or delete the personal data processed, along with any copies of it, unless retention is required by a legal obligation applicable to the Processor. In practice, when the Controller closes its account, its data and its end customers' data are kept for a 30-day grace period (in case the closure was accidental) and, once that period elapses without the account being reactivated, are effectively purged from the Processor's databases, file storage and other systems, as described in our privacy policy.
13. Audits
The Processor will make available to the Controller the information necessary to demonstrate compliance with the obligations set out in this Agreement, and will allow and contribute to audits, including inspections, carried out by the Controller or an auditor authorised by the Controller, on reasonable notice and without prejudice to the confidentiality owed to the Processor's other customers.
14. Liability
Each party will be liable to data subjects and to supervisory authorities for damage caused by processing that infringes the General Data Protection Regulation, under the terms of its article 82 and the applicable Spanish data-protection law.
15. Governing law and jurisdiction
This Agreement is governed by Spanish and European data-protection law. For any dispute relating to its interpretation or performance, the parties submit to the courts and tribunals with jurisdiction under the service's Terms and conditions.