euro.support euro.support
euro.support euro.support
  • Caratteristiche
  • Supporto internazionale
  • Agenti AI
  • Listino prezzi
  • Contatto
Accedi
Inizia gratis
Inizia gratis
  • resoconto

  • Chat dal vivo e traduzione in tempo reale

  • Email e biglietti

  • Fonti di dati per AI

  • Caratteristiche API Agent AI

  • Connettere AI a un essere umano

  • Statistica

Home
euro.support
    • resoconto
    • Chat dal vivo e traduzione in tempo reale
    • Email e biglietti
    • Fonti di dati per AI
    • Caratteristiche API Agent AI
    • Connettere AI a un essere umano
    • Statistica
  • Supporto internazionale
  • Agenti AI
  • Listino prezzi
  • Contatto
Accedi
Inizia gratis
Inizia gratis

euro.support / centro legale

Documenti legali

Un unico luogo per condizioni contrattuali, protezione dei dati personali, cookie, subfornitori e regole per l'uso dell'AI.

Documenti

Condizioni del servizio Privacy DPA Per gli utenti della chat Cookie Subfornitori Principi dell'AI
Questo documento non è ancora disponibile nella lingua selezionata. Viene visualizzata la versione inglese.

EURO.SUPPORT / LEGAL DOCUMENTS

Data Processing Addendum (DPA)

Terms for processing personal data on behalf of the Client pursuant to Article 28 of the GDPR

1. Purpose, scope and contracting parties

This Data Processing Addendum (the “DPA”) forms part of the agreement for the euro.support Service between the Client as controller or processor (the “Client”) and European Business Solutions s. r. o. as processor or sub-processor (the “Processor”). It applies when the Processor processes personal data on behalf of the Client in providing the Service.

The DPA is an agreement under Article 28 of the GDPR in electronic form. The terms personal data, processing, controller, processor, data subject and personal data breach have the meanings assigned to them by Regulation (EU) 2016/679 (GDPR). If the Client is a processor for its customer, it represents that it is authorised to engage the Processor and issue instructions to it.

2. Subject matter, duration, nature and purpose of processing

The subject matter of the processing is the operation of international customer support, in particular chats, tickets, attachments, translations, AI assistance and agents, knowledge sources, product feeds, search, integrations, statistics, support and security. Processing continues for the duration of the provision of the Service and for the periods required for export, deletion, backups and lawful retention under this DPA.

The nature of the operations includes collection, recording, organisation, storage, retrieval, display, translation, summarisation, categorisation, creation of embeddings, transmission, disclosure to authorised persons, restriction, export, deletion and anonymisation. The specific scope is determined by the Client’s configuration and Annex 1.

3. Client instructions

The Processor processes personal data only on the Client’s documented instructions, consisting of the agreement, this DPA, the Service settings, authorised use of the interfaces and other written instructions received by the Processor. The instructions include transfers necessary for the use of approved sub-processors.

If, in the Processor’s opinion, an instruction violates data protection law, it shall inform the Client without undue delay and may suspend its implementation until the instruction is confirmed or amended. If the processing is required by EU or Member State law, the Processor shall inform the Client in advance unless prohibited by law. The parties shall agree in advance on any additional instruction requiring a material change to the Service or incurring costs.

4. Client obligations

The Client is responsible in particular for ensuring that it:

  • has a lawful purpose, legal basis and fulfils the necessary information obligations for all data provided to the Service;
  • collects only adequate and necessary data and does not provide special categories of data or data concerning criminal convictions and offences without prior assessment and agreement;
  • configures permissions, retention, AI automation, integrations and human oversight proportionately to the risk;
  • handles data subject requests and decides on rectification, restriction, export and deletion;
  • ensures the lawfulness of instructions and the authorisation of users, systems and stores connected to the account;
  • does not enter payment cards, passwords, secret keys or other data that the Service does not require for the relevant purpose.

5. Confidentiality and authorised persons

The Processor shall ensure that persons authorised to process personal data are bound by contractual or statutory confidentiality obligations, have access only on a need-to-know basis and receive appropriate security and data protection instructions. The confidentiality obligation continues after their authorisation ends.

6. Security of processing

The Processor shall implement and maintain appropriate technical and organisational measures pursuant to Article 32 of the GDPR, taking into account the state of the art, costs, the nature of the data and the risks. The current baseline of measures is set out in Annex 2. The measures may be enhanced provided that the overall level of protection is not materially reduced.

The Client acknowledges that security is a shared responsibility: it manages users, roles, devices, content, integration permissions and its own export backups. The Processor does not provide certification or a specific regulatory regime unless expressly agreed.

7. Sub-processors

The Client grants general written authorisation to engage the sub-processors listed in the Sub-processors and Platform Partners document. The Processor shall impose on each sub-processor data protection obligations substantially equivalent to those in this DPA and remains responsible to the Client for the sub-processor’s performance of its obligations to the extent required by the GDPR.

The Processor shall inform the Client of any intended new or replacement sub-processor that may process Client Content at least 20 days before engagement, generally by updating the list and providing electronic notice. The Client may raise a reasoned objection within this period on data protection grounds. The parties shall seek an appropriate solution; if none is possible, the Client may terminate the affected functionality or the agreement without penalty as of the date of engagement. An urgent security replacement may be notified later, without undue delay.

8. International transfers

The primary operating infrastructure is used in the European Economic Area unless the configuration or order specifies otherwise. Certain global providers may provide support or carry out further processing outside the EEA. The Processor shall ensure an applicable mechanism under Chapter V of the GDPR, in particular an adequacy decision or standard contractual clauses, and, where necessary, appropriate supplementary measures and a transfer impact assessment.

Upon a reasoned request, it shall provide the Client with information about the transfer mechanism and the relevant part of the documentation to the extent that this does not compromise confidentiality or security. The Client is responsible for transfers caused by its own integration, user or instruction outside the approved providers.

9. Data subject rights

If a data subject contacts the Processor regarding data processed for the Client, the Processor shall generally refer the data subject to the Client and forward the request to the Client without undue delay if the Client can be identified. Without an instruction, it shall not respond on the merits, except where legally required.

Taking into account the nature of the processing, the Processor shall provide appropriate technical and organisational assistance with access, rectification, deletion, restriction, portability, objection and automated decision-making. Ordinary self-service features are included in the Service; extraordinary work may be charged subject to prior agreement.

10. Assistance with compliance

The Processor shall provide the Client with appropriate assistance in ensuring the security of processing, notifying personal data breaches, carrying out data protection impact assessments and conducting prior consultations under Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to it.

11. Personal data breaches

Upon becoming aware of a personal data breach concerning Client Content, the Processor shall notify the Client of the incident without undue delay. The aim is to send an initial notification within 48 hours of reasonable confirmation that the incident concerns the Client’s data; this target timeframe does not alter the legal obligation to notify without undue delay or constitute an admission of liability.

The notification shall, to the extent available, state the nature of the incident, the systems affected and categories of data, the likely consequences, the measures taken or proposed and a contact point. Information may be provided progressively. The Client shall decide whether to notify the supervisory authority and data subjects; the Processor shall provide appropriate assistance and preserve evidence.

12. Audits and demonstrating compliance

The Processor shall make available information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, preferably through security documentation, a questionnaire, a test summary or independent assurance, where available. The Client shall maintain the confidentiality of such information.

If the documentation is insufficient, the Client may conduct an audit, at most once every 12 months, through an independent auditor who is not a competitor, upon at least 30 days’ notice, during business hours and without disrupting operations or the data of other clients. The frequency limitation does not apply following a serious incident or at the order of a supervisory authority. Each party shall bear its own costs; unreasonable extraordinary costs may be agreed in advance.

13. Return, Export and Deletion

During the term of the agreement, the Client may use the available export functions. After termination, the Client may request a standard available export within 30 days. At the Client’s instruction or upon expiry of the export period, the Processor shall delete or anonymize the personal data, unless the law requires its retention.

Deletion from active systems shall generally be carried out within 60 days of the effective instruction or expiry of the export period. Copies in backups shall be deleted or overwritten in the ordinary cycle, no later than within 180 days, and until then shall remain protected and shall not be used for any purpose other than recovery, security or a legal obligation. The Processor may retain the minimum records necessary to demonstrate deletion, for billing, to defend a claim or to comply with the law.

14. Liability and Term of the DPA

The parties’ liability under the DPA is subject to the limitations set out in the Terms of Service to the extent permitted by the GDPR and without limiting the rights of data subjects or the powers of the supervisory authority. The DPA shall remain in effect for as long as the Processor processes the Client’s personal data. In the event of a conflict concerning data protection, the DPA shall prevail.

Annex 1 – Description of Processing

Element

Description

Data Subjects

End users, customers and visitors of the Client; agents and Account Users; contact persons of the Client’s suppliers and partners.

Basic Identification and Contact Data

Name, nickname, email, telephone number, user identifier, company, language, country and information provided in communications.

Communications and Support

The content of chats, tickets and emails, subject matter, attachments, translations, categories, priorities, notes, ratings, timestamps and resolution history.

Commercial and Integration Data

Order identifier, status, items, shipping, tracking, inventory, product data, feed data and the result of the permitted action; the scope depends on the integration.

Technical Data

IP address, browser, device, URL and page origin, widget and chat identifier, operational logs, events and diagnostic data.

AI and Knowledge Data

Instructions, questions and answers, knowledge sources, product texts, embeddings, model, token consumption, inputs and outputs necessary for the activated function.

Special Categories

Not intended. They may exceptionally appear in unstructured communications for which the Client is responsible and in accordance with the Client’s instructions.

Frequency

Continuously, depending on the use of the Service and the Client’s settings.

Purpose

Providing support, translation, AI assistance, search, performing permitted commercial functions, security, support and carrying out the Client’s instructions.

Duration

During the term of the agreement and the subsequent periods for export, deletion and backups under Section 13.

Annex 2 – Technical and Organizational Measures

  • Access management: individual accounts, roles and permissions on a need-to-know basis, administrative permissions separated from ordinary work, and regular access reviews.
  • Authentication and secrets: password hashing through a standard identity framework, session protection, secure storage of application secrets, and restricted access to keys and tokens.
  • Data transmission: encrypted HTTPS/TLS connections for user and integration interfaces; secure provider protocols for email, storage and APIs.
  • Client segregation: logical association of operational records with the Client, authorization checks upon access, and separation of configuration and integration data.
  • Minimization: processing data according to activated functions, limiting the AI context sent to the necessary content, and enabling the Client to manage sources, functions and retention.
  • Logging and oversight: operational and security records appropriate to the function, monitoring of errors, billing events and integration webhooks, and restricted access to logs.
  • Availability and recovery: appropriate backups of operational databases and storage in accordance with the internal plan, monitoring of key processes, and outage recovery procedures.
  • Secure development and changes: code versioning, change control, separation of configuration secrets, dependency updates, and assessment of the security impact of significant functions.
  • Incidents: procedures for identification, containment, remediation, documentation, preservation of evidence and communication under Section 11.
  • Providers: assessment of the adequacy of key providers, contractual data protection obligations, control of the region and transfer mechanism, and records of sub-processors.
  • Personnel measures: confidentiality, access on a need-to-know basis, and appropriate professional training in data protection, security and the use of AI.
  • Physical security: use of professional data centers and cloud providers with controlled physical access; the Provider does not operate publicly accessible production servers in its office.
  • Deletion: controlled removal from active systems followed by overwriting of backups in accordance with Section 13.

Annex 3 – Sub-processors

The current list, purpose, location and status of providers is set out in the document Sub-processors and Platform Partners, which is incorporated into this DPA. In the event of a change, Section 7 shall apply.

Version

1.0

Document date

21 July 2026

Controller

European Business Solutions s. r. o. | Budatínska 20, 851 06 Bratislava, Slovak Republic | Company ID: 54 230 012 | VAT ID: SK2121621689 | info@euro.support

La fonte della pagina è data-processing-addendum.docx. L'HTML viene aggiornato automaticamente dalla cache dopo la modifica del file Word.

euro.support
euro.support
Contatto Termini del servizio Privacy Accordo sul trattamento dei dati Utenti della chat Cookie
Italiano
Le lingue
Čeština Dansk Deutsch English Español Français Hrvatski Italiano Limba română Magyar Nederlands Polski Português Slovenčina Slovenščina Suomi Svenska ελληνικά Български

© euro.support · Eurion

Questo sito web utilizza i cookie.

Sul nostro sito web utilizziamo i cookie. Alcuni sono essenziali per il corretto funzionamento del sito, mentre altri ci aiutano ad analizzare il traffico e a personalizzare contenuti e pubblicità.

Personalizzare