ANNEX I: DATA PROCESSING AGREEMENT (DPA)

Data Processing Agreement pursuant to Regulation (EU) 2016/679 (GDPR)

Document linked to: Terms and Conditions of Use of the Chatbot Service

1. DEFINITIONS

For the purposes of this Agreement, the following definitions shall apply:

a) Data Controller: The Customer who contracts the chatbot Service and who determines the purposes and means of the processing of personal data of its end users.

b) Data Processor: Eloy Garrido Castro, operating under the trade name Solneko, who provides the chatbot Service and processes personal data on behalf of the Controller.

c) Sub-processor: Third parties authorized by the Processor to carry out specific data processing activities on behalf of the Controller.

d) Personal Data: Any information relating to an identified or identifiable natural person contained in chatbot conversations.

e) Processing: Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure or destruction.

f) Data Subject: End user of the Customer who interacts with the chatbot and whose personal data is processed.

g) Security Breach: Any breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

2. SUBJECT MATTER AND NATURE OF THE PROCESSING

2.1. Subject matter: The purpose of this DPA is to regulate the conditions under which the Processor will carry out the processing of personal data on behalf of the Controller, within the framework of the provision of the chatbot Service.

2.2. Nature of the processing: The Processor will process personal data exclusively for the following purposes:

2.3. Duration of the processing: The Processor will process personal data for the term of the services agreement and, following its termination, only for as long as necessary to comply with legal or contractual obligations.

3. TYPES OF DATA AND CATEGORIES OF DATA SUBJECTS

3.1. Types of personal data processed

Depending on the Controller's specific configuration and use, the Processor may process the following categories of data:

Data category Description
Identification data Name, surname, username, session identifiers
Contact data Email address, telephone number (if provided by the user)
Browsing data IP address, timestamps, session metadata
Conversation content Text messages exchanged with the chatbot
Usage data Interactions, clicks, session time, conversational flows

⚠️ Special categories of data (Art. 9 GDPR):

The Controller undertakes NOT to enter or allow its end users to share specially protected data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation) through the chatbot, unless expressly agreed in writing with the Processor and enhanced security measures have been implemented.

Should such data be received accidentally, the Controller will be notified immediately for its deletion.

3.2. Categories of data subjects

4. OBLIGATIONS OF THE DATA PROCESSOR

The Processor undertakes to:

4.1. Processing in accordance with instructions

4.2. Confidentiality

4.3. Security measures

Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as a minimum:

Technical measures:

Organizational measures:

4.4. Sub-processors

4.4.1. Authorization: The Controller expressly authorizes the Processor to engage the following sub-processors:

Sub-processor Service provided Location
OpenAI, Inc. Natural language processing via API (GPT models) United States
OVHcloud Infrastructure storage and hosting European Union

4.4.2. New sub-processors: The Processor will inform the Controller at least 30 days in advance of any planned change involving the addition or replacement of sub-processors. The Controller may object on data protection grounds within that period.

4.4.3. Obligations: The Processor shall ensure that sub-processors comply with the same data protection obligations set out in this DPA, by means of a written contract.

4.4.4. Updated list: The complete, up-to-date list of sub-processors is publicly available at: here

4.5. Exercise of data subjects' rights

4.5.1. The Processor will assist the Controller, through appropriate technical and organizational measures, insofar as this is possible, so that the Controller may comply with its obligation to respond to requests for the exercise of the following rights:

4.5.2. Procedure: When a data subject contacts the Processor directly to exercise their rights:

  1. The Processor will notify the Controller within a maximum of 48 hours
  2. The Processor will provide the Controller with all information necessary to handle the request
  3. The Controller shall be the party that formally responds to the data subject, being responsible for the final decision

4.5.3. Assistance timeframe: The Processor will provide the data or carry out the necessary technical actions within a maximum of 7 calendar days from the Controller's request.

4.5.4. Tools: The Processor will provide the Controller with access to tools within the control panel to:

4.6. Notification of security breaches

4.6.1. Notification obligation: In the event of a security breach affecting personal data, the Processor will notify the Controller without undue delay and, at the latest, within 24 hours of becoming aware of it.

4.6.2. Content of the notification:

4.6.3. Cooperation: The Processor will actively cooperate with the Controller in:

4.6.4. It is the Controller's responsibility to decide whether the breach must be notified to the supervisory authority or to the data subjects, pursuant to Articles 33 and 34 of the GDPR.

4.7. Support with impact assessments and prior consultations

4.8. Data retention and deletion

4.8.1. Retention periods: The Processor will retain personal data according to the following periods (configurable by the Controller):

4.8.2. Automatic deletion: The Processor implements automated deletion processes that permanently erase data upon expiry of the established periods.

4.8.3. Fate of the data upon termination of the contract: Once the contract has terminated, the Processor shall, at the Controller's choice:

This operation will be completed within a maximum of 30 days from the termination of the contract, unless applicable legislation requires the retention of data.

4.9. Audits and inspections

4.9.1. The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA.

4.9.2. The Controller or an authorized auditor may carry out inspections, including audits, upon written notice given at least 15 days in advance.

4.9.3. The Processor will facilitate audits and cooperate reasonably, and limitations may be agreed to protect the confidentiality of other customers or sensitive information.

4.9.4. Audits will be carried out during business hours and may not disproportionately interfere with the Processor's operations.

4.9.5. As an alternative, the Processor may provide current certifications (SOC2, ISO27001, etc.) demonstrating compliance with the security measures.

5. OBLIGATIONS OF THE DATA CONTROLLER

The Controller undertakes to:

5.1. Lawfulness of processing

5.2. Information to data subjects

The Controller will include in its Privacy Policy information about:

Suggested text for the Controller's Privacy Policy:

Customer Service Chatbot

We use a chatbot service provided by SolnekoChat (chat.solneko.es) to handle your inquiries efficiently.

Data processed: The conversations you have with our chatbot, including the messages you send, your session identifier and technical metadata (date, time, IP address).

Purpose: To provide automated assistance through the chatbot and analyze the quality of the service in order to improve it.

AI processing: The chatbot uses artificial intelligence technology provided by OpenAI Inc. (United States) to generate responses. Your messages will be processed by this service.

Retention: Conversations are retained for [7/90/365] days and are then automatically deleted. Aggregated analytical data (without personal identification) is retained indefinitely.

International transfers: Your data may be transferred to the United States (OpenAI) under appropriate safeguards through the European Commission's Standard Contractual Clauses. OpenAI retains processed messages for a maximum of 30 days for the sole purpose of abuse detection, after which it automatically deletes them. OpenAI does not use this data to train its models.

Your rights: You may exercise your rights of access, rectification, erasure, restriction, portability and objection by contacting us at [your email]. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

Legal basis: Legitimate interest (Art. 6.1.f GDPR). We process your chatbot messages on the basis of our legitimate interest in providing efficient assistance and improving our customer service. You may object to this processing at any time by contacting us at [your email] or simply by not using the chatbot.

5.3. Widget configuration

5.4. Sensitive data

5.5. Instructions

6. INTERNATIONAL DATA TRANSFERS

6.1. Transfers to third countries: Due to the use of OpenAI Inc. (United States) as a sub-processor, international transfers of personal data to a third country will occur.

6.2. Appropriate safeguards: These transfers are carried out on the basis of the following safeguards:

6.3. Transfer assessment: The Processor has assessed that US law does not prevent OpenAI from complying with the safeguards set out in the SCC, and that adequate technical and organizational measures exist to protect the data.

6.4. Additional information: The Controller may request a copy of the SCC and of the international transfer impact assessments.

6.5. No transfers will be made to other third countries without the Controller's prior consent and without appropriate safeguards.

7. LIABILITY AND LIMITATION

7.1. Processor's liability: The Processor shall be liable to the Controller for damages caused by non-compliance with the obligations set out in this DPA.

7.2. Liability before authorities: Pursuant to Article 82 of the GDPR:

7.3. Limits of liability: Without prejudice to the foregoing, the Processor's liability towards the Controller shall be limited as set out in Section 11 of the Terms and Conditions of Use.

7.4. Indemnification: The Controller shall indemnify the Processor against claims, fines or penalties arising from:

8. RECORD OF PROCESSING ACTIVITIES

8.1. The Processor will maintain a record of all categories of processing activities carried out on behalf of the Controller, pursuant to Article 30.2 of the GDPR.

8.2. This record will include, as a minimum:

8.3. The Processor will make the record available to the supervisory authority upon request.

9. SECURITY MEASURES AND CERTIFICATIONS

9.1. Infrastructure security: The Service's technical infrastructure is hosted on OVHcloud, a European hosting provider that maintains public security certifications (available at https://www.ovhcloud.com/en/compliance/). OVHcloud's security measures (encryption, backups, restricted access, monitoring) apply to the data stored within the Service.

9.2. Processor's certifications: The Processor does not maintain independent formal certifications (ISO 27001, SOC 2, etc.), but implements security practices in line with the GDPR and industry standards, including:

9.3. Controller's responsibility: The Controller is responsible for:

9.4. Audits: The Controller may request information on the security measures implemented. The Processor will provide evidence through technical documentation, third-party audit reports (if any), or OVHcloud certifications, as set out in clause 4.9.

10. TERM AND TERMINATION

10.1. Term: This DPA shall enter into force on the same date as the services agreement and shall remain in force for its entire duration.

10.2. Effects of termination: Termination of the services agreement shall automatically result in the termination of this DPA.

10.3. Post-contractual obligations: Following termination, the Processor shall remain bound by the duty of confidentiality and by the data deletion or return obligations set out in clause 4.8.3.

10.4. The clauses relating to liability, confidentiality and limitation of liability shall survive the termination of this DPA.

11. AMENDMENTS TO THE DPA

11.1. The Processor may amend this DPA to adapt it to regulatory changes or improvements in security measures.

11.2. Any amendment will be notified to the Controller at least 30 days before it takes effect.

11.3. If the Controller does not accept the amendments and they are substantial, it may terminate the contract without penalty within the notice period.

12. APPLICABLE LAW AND JURISDICTION

12.1. This DPA is governed by:

12.2. For any dispute arising from this DPA, the parties submit to the Courts and Tribunals of Seville.

13. CONTACT AND DATA PROTECTION OFFICER

Data Processor:

Eloy Garrido Castro

Trade name: Solneko

Email: solneko@solneko.es

Address: c/ de la Danza, 25, Mairena del Aljarafe, Spain

Data Protection Officer (DPO):

Not appointed. Pursuant to Art. 37 of the GDPR, the appointment of a DPO is not mandatory in this case.

ANNEX A: DETAILED TECHNICAL AND ORGANIZATIONAL MEASURES

(Confidential document to be provided under a non-disclosure agreement in the event of an audit or justified request)

The security measures implemented include, without limitation:

A.1. Access control

A.2. Encryption

A.3. Continuity and resilience

A.4. Network security

A.5. Secure development

A.6. Incident management

A.7. Training and awareness

Version 1.0 | Last updated: April 4, 2026