ANNEX I: DATA PROCESSING AGREEMENT (DPA)
Data Processing Agreement pursuant to Regulation (EU) 2016/679 (GDPR)
📌 Important: This Data Processing Agreement (DPA) forms an integral part of the Terms and Conditions of Use and is binding pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
1. DEFINITIONS
For the purposes of this Agreement, the following definitions shall apply:
a) Data Controller: The Customer who contracts the chatbot Service and who determines the purposes and means of the processing of personal data of its end users.
b) Data Processor: Eloy Garrido Castro, operating under the trade name Solneko, who provides the chatbot Service and processes personal data on behalf of the Controller.
c) Sub-processor: Third parties authorized by the Processor to carry out specific data processing activities on behalf of the Controller.
d) Personal Data: Any information relating to an identified or identifiable natural person contained in chatbot conversations.
e) Processing: Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure or destruction.
f) Data Subject: End user of the Customer who interacts with the chatbot and whose personal data is processed.
g) Security Breach: Any breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
2. SUBJECT MATTER AND NATURE OF THE PROCESSING
2.1. Subject matter: The purpose of this DPA is to regulate the conditions under which the Processor will carry out the processing of personal data on behalf of the Controller, within the framework of the provision of the chatbot Service.
2.2. Nature of the processing: The Processor will process personal data exclusively for the following purposes:
- Processing of conversations using artificial intelligence technology (OpenAI API)
- Temporary storage of conversations for service quality analysis
- Generation of aggregated metrics and statistics on chatbot usage
- Service improvement and training of custom models (only with express authorization)
- Technical support and resolution of incidents reported by the Controller
2.3. Duration of the processing: The Processor will process personal data for the term of the services agreement and, following its termination, only for as long as necessary to comply with legal or contractual obligations.
3. TYPES OF DATA AND CATEGORIES OF DATA SUBJECTS
3.1. Types of personal data processed
Depending on the Controller's specific configuration and use, the Processor may process the following categories of data:
| Data category |
Description |
| Identification data |
Name, surname, username, session identifiers |
| Contact data |
Email address, telephone number (if provided by the user) |
| Browsing data |
IP address, timestamps, session metadata |
| Conversation content |
Text messages exchanged with the chatbot |
| Usage data |
Interactions, clicks, session time, conversational flows |
⚠️ Special categories of data (Art. 9 GDPR):
The Controller undertakes NOT to enter or allow its end users to share specially protected data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation) through the chatbot, unless expressly agreed in writing with the Processor and enhanced security measures have been implemented.
Should such data be received accidentally, the Controller will be notified immediately for its deletion.
3.2. Categories of data subjects
- Customers of the Controller (consumers, service users)
- Visitors to the Controller's website
- Prospective customers (leads) who interact with the chatbot
- Any person who uses the communication channel where the chatbot is integrated
4. OBLIGATIONS OF THE DATA PROCESSOR
The Processor undertakes to:
4.1. Processing in accordance with instructions
- Process personal data solely on the documented instructions of the Controller
- Not use the data for purposes other than those established in this DPA
- Immediately notify the Controller if it considers that an instruction infringes the GDPR or other data protection regulations
4.2. Confidentiality
- Ensure that personnel authorized to process personal data are subject to a duty of confidentiality under contract or equivalent statutory obligation
- Provide adequate data protection training to all personnel with access to personal data
- Restrict access to personal data solely to personnel who need to know it in order to provide the Service
4.3. Security measures
Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as a minimum:
Technical measures:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent)
- Pseudonymization of data where technically possible
- Access control through multi-factor authentication for authorized personnel
- Intrusion detection systems and security monitoring
- Periodic, encrypted backups of data
- Secure data deletion procedures
- Regular security audits and penetration testing
Organizational measures:
- Documented information security policy
- Management of passwords and access credentials
- Logging of access to personal data
- Security incident response procedures
- Privacy impact assessments where applicable
4.4. Sub-processors
4.4.1. Authorization: The Controller expressly authorizes the Processor to engage the following sub-processors:
| Sub-processor |
Service provided |
Location |
| OpenAI, Inc. |
Natural language processing via API (GPT models) |
United States |
| OVHcloud |
Infrastructure storage and hosting |
European Union |
4.4.2. New sub-processors: The Processor will inform the Controller at least 30 days in advance of any planned change involving the addition or replacement of sub-processors. The Controller may object on data protection grounds within that period.
4.4.3. Obligations: The Processor shall ensure that sub-processors comply with the same data protection obligations set out in this DPA, by means of a written contract.
4.4.4. Updated list: The complete, up-to-date list of sub-processors is publicly available at: here
4.5. Exercise of data subjects' rights
4.5.1. The Processor will assist the Controller, through appropriate technical and organizational measures, insofar as this is possible, so that the Controller may comply with its obligation to respond to requests for the exercise of the following rights:
- Right of access: Providing a copy of the data processed
- Right to rectification: Correcting inaccurate data
- Right to erasure ("right to be forgotten"): Deleting data where applicable
- Right to restriction of processing: Temporarily blocking processing
- Right to data portability: Providing data in a structured, machine-readable format
- Right to object: Ceasing processing in certain circumstances
4.5.2. Procedure: When a data subject contacts the Processor directly to exercise their rights:
- The Processor will notify the Controller within a maximum of 48 hours
- The Processor will provide the Controller with all information necessary to handle the request
- The Controller shall be the party that formally responds to the data subject, being responsible for the final decision
4.5.3. Assistance timeframe: The Processor will provide the data or carry out the necessary technical actions within a maximum of 7 calendar days from the Controller's request.
4.5.4. Tools: The Processor will provide the Controller with access to tools within the control panel to:
- Search conversations by user identifier
- Export data in CSV/JSON format
- Permanently delete conversations
- Anonymize personal data while retaining analytical value
4.6. Notification of security breaches
4.6.1. Notification obligation: In the event of a security breach affecting personal data, the Processor will notify the Controller without undue delay and, at the latest, within 24 hours of becoming aware of it.
4.6.2. Content of the notification:
- Description of the nature of the breach (type of incident, how it occurred)
- Categories and approximate number of data subjects affected
- Categories and approximate number of personal data records affected
- Likely consequences of the breach
- Measures taken or proposed to remedy the breach and mitigate its possible adverse effects
- Contact details of the person responsible for managing the incident
4.6.3. Cooperation: The Processor will actively cooperate with the Controller in:
- Assessing the risk to the rights and freedoms of data subjects
- Preparing the communication to the supervisory authority (AEPD in Spain)
- Communicating with data subjects if necessary
- Implementing corrective measures
4.6.4. It is the Controller's responsibility to decide whether the breach must be notified to the supervisory authority or to the data subjects, pursuant to Articles 33 and 34 of the GDPR.
4.7. Support with impact assessments and prior consultations
- Assist the Controller in carrying out data protection impact assessments (DPIAs) where the type of processing entails high risk
- Cooperate with the Controller on prior consultations with the supervisory authority where applicable
- Provide information on the security measures implemented and any necessary technical documentation
4.8. Data retention and deletion
4.8.1. Retention periods: The Processor will retain personal data according to the following periods (configurable by the Controller):
- Complete conversations: 90 days by default, configurable between 30 and 180 days
- Aggregated analytical data: Indefinitely (anonymized data, not subject to the GDPR)
- Security logs: 12 months
- Backups: 30 days in backup systems, then automatic deletion
4.8.2. Automatic deletion: The Processor implements automated deletion processes that permanently erase data upon expiry of the established periods.
4.8.3. Fate of the data upon termination of the contract: Once the contract has terminated, the Processor shall, at the Controller's choice:
- Delete all personal data and confirm in writing its complete deletion, or
- Return all personal data in a structured format (CSV/JSON) and delete all existing copies
This operation will be completed within a maximum of 30 days from the termination of the contract, unless applicable legislation requires the retention of data.
4.9. Audits and inspections
4.9.1. The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA.
4.9.2. The Controller or an authorized auditor may carry out inspections, including audits, upon written notice given at least 15 days in advance.
4.9.3. The Processor will facilitate audits and cooperate reasonably, and limitations may be agreed to protect the confidentiality of other customers or sensitive information.
4.9.4. Audits will be carried out during business hours and may not disproportionately interfere with the Processor's operations.
4.9.5. As an alternative, the Processor may provide current certifications (SOC2, ISO27001, etc.) demonstrating compliance with the security measures.
5. OBLIGATIONS OF THE DATA CONTROLLER
The Controller undertakes to:
5.1. Lawfulness of processing
- Have an appropriate legal basis for the processing of data (consent, performance of a contract, legitimate interest, etc.)
- Obtain the consent of data subjects when necessary, before using the Service
- Clearly inform data subjects about the processing of their data through the chatbot
5.2. Information to data subjects
The Controller will include in its Privacy Policy information about:
- The use of chatbot services provided by Solneko
- The use of artificial intelligence technology (OpenAI)
- The purposes of the processing (customer service, quality analysis)
- The retention periods for conversations
- International transfers to third countries (OpenAI in the USA)
- The rights of data subjects and how to exercise them
Suggested text for the Controller's Privacy Policy:
Customer Service Chatbot
We use a chatbot service provided by SolnekoChat (chat.solneko.es) to handle your inquiries efficiently.
Data processed: The conversations you have with our chatbot, including the messages you send, your session identifier and technical metadata (date, time, IP address).
Purpose: To provide automated assistance through the chatbot and analyze the quality of the service in order to improve it.
AI processing: The chatbot uses artificial intelligence technology provided by OpenAI Inc. (United States) to generate responses. Your messages will be processed by this service.
Retention: Conversations are retained for [7/90/365] days and are then automatically deleted. Aggregated analytical data (without personal identification) is retained indefinitely.
International transfers: Your data may be transferred to the United States (OpenAI) under appropriate safeguards through the European Commission's Standard Contractual Clauses. OpenAI retains processed messages for a maximum of 30 days for the sole purpose of abuse detection, after which it automatically deletes them. OpenAI does not use this data to train its models.
Your rights: You may exercise your rights of access, rectification, erasure, restriction, portability and objection by contacting us at [your email]. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
Legal basis: Legitimate interest (Art. 6.1.f GDPR). We process your chatbot messages on the basis of our legitimate interest in providing efficient assistance and improving our customer service. You may object to this processing at any time by contacting us at [your email] or simply by not using the chatbot.
5.3. Widget configuration
- Configure the chatbot to display a visible privacy notice before the user starts the conversation
- Include a link to the Privacy Policy in the chatbot widget
- Implement consent mechanisms when necessary
5.4. Sensitive data
- Warn end users that they must NOT share special categories of data (Art. 9 GDPR) through the chatbot
- Not configure the chatbot to actively request sensitive data without the Processor's prior authorization
5.5. Instructions
- Provide clear, documented instructions to the Processor regarding the processing of data
- Not issue instructions that infringe the GDPR or other applicable regulations
6. INTERNATIONAL DATA TRANSFERS
6.1. Transfers to third countries: Due to the use of OpenAI Inc. (United States) as a sub-processor, international transfers of personal data to a third country will occur.
6.2. Appropriate safeguards: These transfers are carried out on the basis of the following safeguards:
- Standard Contractual Clauses (SCC): OpenAI has signed the Standard Contractual Clauses approved by the European Commission (Decision 2021/914)
- Supplementary measures: End-to-end encryption, data minimization, periodic risk assessments
6.3. Transfer assessment: The Processor has assessed that US law does not prevent OpenAI from complying with the safeguards set out in the SCC, and that adequate technical and organizational measures exist to protect the data.
6.4. Additional information: The Controller may request a copy of the SCC and of the international transfer impact assessments.
6.5. No transfers will be made to other third countries without the Controller's prior consent and without appropriate safeguards.
7. LIABILITY AND LIMITATION
7.1. Processor's liability: The Processor shall be liable to the Controller for damages caused by non-compliance with the obligations set out in this DPA.
7.2. Liability before authorities: Pursuant to Article 82 of the GDPR:
- The Processor shall only be liable for damage caused by processing where it has not complied with the obligations of the GDPR specifically directed at processors, or where it has acted outside or contrary to the lawful instructions of the Controller
- The Controller shall be liable where the processing has effectively been decided by the Controller
7.3. Limits of liability: Without prejudice to the foregoing, the Processor's liability towards the Controller shall be limited as set out in Section 11 of the Terms and Conditions of Use.
7.4. Indemnification: The Controller shall indemnify the Processor against claims, fines or penalties arising from:
- Instructions from the Controller that infringe data protection regulations
- Lack of an adequate legal basis for the processing on the part of the Controller
- The Controller's failure to comply with its obligations to inform data subjects
8. RECORD OF PROCESSING ACTIVITIES
8.1. The Processor will maintain a record of all categories of processing activities carried out on behalf of the Controller, pursuant to Article 30.2 of the GDPR.
8.2. This record will include, as a minimum:
- Name and contact details of the Processor and of each Controller on whose behalf it acts
- Categories of processing carried out on behalf of each Controller
- Transfers of data to third countries, identifying the country and safeguards
- General description of the technical and organizational security measures
8.3. The Processor will make the record available to the supervisory authority upon request.
9. SECURITY MEASURES AND CERTIFICATIONS
9.1. Infrastructure security: The Service's technical infrastructure is hosted on OVHcloud, a European hosting provider that maintains public security certifications (available at https://www.ovhcloud.com/en/compliance/). OVHcloud's security measures (encryption, backups, restricted access, monitoring) apply to the data stored within the Service.
9.2. Processor's certifications: The Processor does not maintain independent formal certifications (ISO 27001, SOC 2, etc.), but implements security practices in line with the GDPR and industry standards, including:
- System access control based on secure authentication
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Automatic backups and disaster recovery plans
- Security monitoring and access auditing
- Security testing and vulnerability scanning
9.3. Controller's responsibility: The Controller is responsible for:
- Configuring the Service securely (e.g., keeping credentials confidential)
- Notifying the Processor of any security breach or incident detected
- Ensuring that its end users provide data only through the authorized widget
- Implementing additional controls if it considers this necessary (e.g., prior identity verification)
9.4. Audits: The Controller may request information on the security measures implemented. The Processor will provide evidence through technical documentation, third-party audit reports (if any), or OVHcloud certifications, as set out in clause 4.9.
10. TERM AND TERMINATION
10.1. Term: This DPA shall enter into force on the same date as the services agreement and shall remain in force for its entire duration.
10.2. Effects of termination: Termination of the services agreement shall automatically result in the termination of this DPA.
10.3. Post-contractual obligations: Following termination, the Processor shall remain bound by the duty of confidentiality and by the data deletion or return obligations set out in clause 4.8.3.
10.4. The clauses relating to liability, confidentiality and limitation of liability shall survive the termination of this DPA.
11. AMENDMENTS TO THE DPA
11.1. The Processor may amend this DPA to adapt it to regulatory changes or improvements in security measures.
11.2. Any amendment will be notified to the Controller at least 30 days before it takes effect.
11.3. If the Controller does not accept the amendments and they are substantial, it may terminate the contract without penalty within the notice period.
12. APPLICABLE LAW AND JURISDICTION
12.1. This DPA is governed by:
- Regulation (EU) 2016/679 (GDPR)
- Organic Law 3/2018, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD)
- Complementary Spanish data protection legislation
12.2. For any dispute arising from this DPA, the parties submit to the Courts and Tribunals of Seville.
13. CONTACT AND DATA PROTECTION OFFICER
ANNEX A: DETAILED TECHNICAL AND ORGANIZATIONAL MEASURES
(Confidential document to be provided under a non-disclosure agreement in the event of an audit or justified request)
The security measures implemented include, without limitation:
A.1. Access control
- Multi-factor authentication (MFA) for all personnel with access to systems
- Strong password policies (minimum 12 characters, periodic rotation)
- Principle of least privilege and segregation of duties
- Access logging and monitoring
- Periodic review of permissions and automatic revocation upon staff departure
A.2. Encryption
- TLS 1.3 for data in transit (API connections, web panel)
- AES-256 for data at rest (database, backups)
- Secure management of encryption keys (rotation, storage in HSM/KMS)
A.3. Continuity and resilience
- Automatic, encrypted daily backups
- Database replicas across multiple availability zones
- Disaster recovery plan (RTO < 4 hours, RPO < 1 hour)
- Periodic restoration testing
A.4. Network security
- Firewalls and network segmentation
- Intrusion detection/prevention systems (IDS/IPS)
- 24/7 security event monitoring
- Quarterly vulnerability scanning
A.5. Secure development
- Code review and static security analysis
- Development environment separate from production
- Dependency management and security patching
A.6. Incident management
- Documented breach response procedure
- Designated incident management team
- Emergency communication channels
- Post-mortem review and continuous improvement following incidents
A.7. Training and awareness
- Initial data protection training for new personnel
- Annual refresher training on security and privacy
- Phishing drills and social engineering awareness
Version 1.0 | Last updated: April 4, 2026