Data Processing Agreement
Last updated: 2026-07-20 · askVela Limited
Preamble
This Data Processing Agreement (DPA) implements Art. 28 GDPR between the workspace owner (the Controller) and askVela Limited, 56 Grange View, England, LS7 4ER (the Processor).
The DPA forms part of the Terms of Service and applies automatically from the start of the contract – no separate signature is required. If you need a signed copy for your records, request it informally at the address above and we will return it for electronic signature.
1. Subject matter and duration
The subject matter is the processing of personal data collected by the Controller through the askVela platform – in particular chat messages from its website visitors, contact details, uploaded files and knowledge content.
Processing takes place for the term of the service contract and ends upon its termination; the deletion obligations under section 8 survive.
2. Nature, purpose and instructions
The Processor processes the data solely to provide the service: storing and displaying conversations, generating AI replies, making the knowledge base searchable, notifications and analytics for the Controller.
Processing is carried out strictly on documented instructions. Instructions are given primarily through the dashboard configuration and additionally in text form. If the Processor considers an instruction unlawful, it informs the Controller without undue delay and may suspend execution.
The data is never used for the Processor's own purposes – no sale, no cross-workspace profiling and no training of the Processor's own AI models on customer content.
3. Categories of data subjects and data
Data subjects: website visitors and customers of the Controller, and the Controller's staff with dashboard access.
Types of data: communication content (chat, email, direct messages), contact details (name, email, optionally phone), technical data (visitor identifier, IP address, browser and page context), uploaded files, and content supplied by the Controller (knowledge articles, product data).
Special categories under Art. 9 GDPR are not part of the engagement. If a visitor volunteers such data in a chat, the Processor handles it like any other content without evaluating it separately.
4. Place of processing
The application and database are operated in Frankfurt am Main, Germany. AI processing takes place in the EU region of the AI provider used (EEA or Switzerland).
Where processing exceptionally takes place in a third country, this occurs only on the basis of an adequacy decision or the EU Standard Contractual Clauses together with any required supplementary measures.
5. Technical and organisational measures
The Processor implements the measures described in Annex 2 pursuant to Art. 32 GDPR and maintains them for the term of the contract. Measures may evolve provided the level of protection is not reduced.
6. Sub-processors
The Controller consents to the sub-processors listed in Annex 1. Agreements under Art. 28 GDPR are in place with all of them.
The Processor announces intended changes at least 30 days in advance. The Controller may object within that period; if the objection cannot be resolved, the Controller may terminate the contract with effect from the change taking effect.
7. Assistance to the Controller
The Processor assists the Controller with data subject requests (Art. 15–22 GDPR), data protection impact assessments and notification duties under Art. 33/34 GDPR.
Personal data breaches are reported without undue delay and at the latest within 48 hours of becoming aware, including the information required for notification.
If a data subject contacts the Processor directly, the request is forwarded to the Controller without undue delay and is not answered independently.
8. Deletion and return
The Controller can delete conversations, contacts and content at any time in the dashboard and export its data.
After the contract ends, workspace data is deleted within 30 days unless a statutory retention obligation applies. Backups expire on their regular cycle.
9. Evidence and audits
The Processor demonstrates compliance in text form on request. The Controller may carry out audits or have them carried out; they must be announced with reasonable notice, must not unreasonably disrupt operations and must not affect the confidentiality interests of other customers.
10. Confidentiality
All persons involved in the processing are bound to confidentiality. The obligation continues beyond the end of their activity.
11. Authorised persons and communication
Instructions may be given by the persons designated as administrators in the workspace. Changes to the dashboard configuration constitute documented instructions; supplementary instructions are given in text form to the address stated above.
The Processor documents instructions and their implementation and retains that documentation for the term of the contract.
12. Transfers to third countries
Personal data is transferred outside the EEA only where the conditions of Art. 44 et seq. GDPR are met – on the basis of an adequacy decision, the EU Standard Contractual Clauses (Module 3, processor to sub-processor) or another permitted safeguard.
Before engaging a sub-processor in a third country, the Processor assesses whether the destination country provides an essentially equivalent level of protection and applies supplementary measures where required (such as encryption or pseudonymisation).
On request, the Controller is informed which transfer mechanisms are in place.
13. Remuneration for assistance
Assistance with data subject requests, notification duties and data protection impact assessments is included in the service fee to the extent that it does not exceed customary effort.
Where the Controller requests services beyond that – for example extensive bespoke reporting or on-site audits – these are remunerated on a time-and-materials basis after prior agreement.
14. Liability
Liability is governed by Art. 82 GDPR and the provisions of the service contract. As between the parties, each bears the share of damage corresponding to its contribution to the infringement.
The Processor is liable in particular where it has acted contrary to its obligations under this agreement or to the lawful instructions given to it.
15. Precedence and amendments
In the event of conflict between this DPA and the service contract, this DPA prevails on matters of data protection. Mandatory statutory requirements prevail over both.
Amendments to this DPA are announced in text form with 30 days' notice. If the Controller objects in time and the objection cannot be resolved, it may terminate the contract with effect from the amendment taking effect.
16. Final provisions
Should any provision of this agreement be invalid, the validity of the remaining provisions is unaffected. The invalid provision is replaced by one that comes closest to its commercial purpose.
For controllers established in the EU, the GDPR remains fully applicable irrespective of the choice of law in the service contract; the competence of the supervisory authority at the Controller's establishment remains unaffected.
Annex 1 – Sub-processors
OpenAI – AI replies and embeddings · processed in the EU region (EEA/Switzerland) · content is not used for model training
Hostinger International Ltd. – operation of application, database and email delivery · server location Frankfurt am Main, Germany
Stripe – payment processing for direct customers (full card data never reaches the Processor)
Shopify – installation, billing and shop data, only when used as a Shopify app
Resend – system and notification emails
Annex 2 – Technical and organisational measures (Art. 32 GDPR)
Physical access control. Application and database run in a data centre in Frankfurt am Main. Physical access, fire protection and power supply are the responsibility of the data centre operator; no own hardware is operated.
Confidentiality. Dashboard access only via a personal account with a password; passwords are stored as hashes only. Access is limited to the user's own workspace – every database query is bound to the workspace identifier, so cross-workspace access is technically excluded. Within a workspace, graduated roles apply (administration, agent). Credentials for third-party systems (e.g. mailboxes) are stored encrypted (AES) and never displayed in clear text.
Integrity. All connections to the platform and the chat widget are TLS-encrypted. Incoming webhooks are verified by signature. Widget access uses a per-workspace key that can be rotated at any time.
Transfer control. Data is disclosed only to the sub-processors listed in Annex 1, in each case over encrypted connections. The Controller can export its own data at any time; access by other customers to that data is excluded.
Input control. Changes to conversations and content are attributed to the acting account; messages carry author and timestamp. Security-relevant events are logged.
Availability and resilience. Automated daily backups with verified restore. The application is process-monitored and restarted automatically after a failure. Releases are deployed with minimal interruption via an atomic switch with self-healing on failure.
Separation. Data of different workspaces is strictly separated by workspace identifier; demo environments are isolated from production data and deleted automatically on expiry.
Deletion. Conversations, contacts and content can be deleted in the dashboard. A dedicated account-deletion function removes all associated data.
Sub-processor control. Sub-processors are selected by their level of data protection and bound contractually under Art. 28 GDPR; the providers used are disclosed in Annex 1.
Review. The measures are reviewed and updated whenever the architecture or providers change. The status of this document is stated above.