Agreement on the processing of personal data between the Customer, acting as Data Controller, and Stepcode SRL, provider of the Supportfast.ai platform, acting as external Data Processor pursuant to Article 28 of Regulation (EU) 2016/679. Constitutes Annex A to the General Terms of Service.
This Data Processing Agreement (“DPA”) constitutes Annex A to the General Terms of Service (“Agreement”) and forms an integral and substantial part of it. It governs the processing of personal data carried out by Stepcode SRL on behalf of the Customer in the context of the provision of the Supportfast.ai software and services.
In light of the foregoing, the Customer appoints Stepcode SRL as Processor of personal data pursuant to and for the purposes of Article 28 GDPR, in accordance with the terms and conditions set out below.
In addition to the terms defined in the Agreement, in this DPA the following capitalised terms shall have the meaning indicated:
2.1 “Personal Data”: any information relating to an identified or identifiable natural person (Data Subject), processed by the Processor on behalf of the Controller in performance of the Agreement.
2.2 “Special Categories of Data”: the data referred to in Article 9 GDPR.
2.3 “GDPR”: Regulation (EU) 2016/679.
2.4 “Italian DPA”: the Italian Data Protection Authority (Garante per la protezione dei dati personali).
2.5 “Data Subject”: the identified or identifiable natural person to whom the Personal Data relate. In the context of this DPA, Data Subjects are mainly the end users of the Customer who interact with the chatbots and voice assistants distributed through Supportfast.ai.
2.6 “Processing”: any operation applied to Personal Data, whether automated or not.
2.7 “Sub-processor”: the third party engaged by the Processor to carry out specific processing activities on behalf of the Controller, pursuant to Article 28(2), (3) and (4) GDPR.
2.8 “Personal Data Breach”: the security breach that accidentally or unlawfully results in the destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
2.9 “Customer Data”: the set of contents, configurations, knowledge bases, conversation logs, audio recordings and any other data that the Customer or end users upload or generate through the platform.
2.10 “DPF”: the EU-U.S. Data Privacy Framework, subject of the European Commission’s adequacy decision of 10 July 2023.
2.11 “SCC”: the standard contractual clauses adopted by the European Commission with Decision 2021/914/EU.
3.1 The Customer, by signing the Agreement, appoints Stepcode SRL as Processor of the processing pursuant to Article 28 GDPR, authorising it to process Personal Data on behalf of the Controller, exclusively for the purposes, in accordance with the instructions and within the limits defined by this DPA.
3.2 The subject matter of the processing includes:
3.3 This DPA does not govern the processing carried out by Stepcode SRL as autonomous Controller for its own purposes (account, billing, marketing towards the Customer, system security), which is regulated by the Privacy Policy.
4.1 The categories of Personal Data and Data Subjects processed by the Processor on behalf of the Controller are detailed in Annex C.
The Customer undertakes to configure the service in such a way as not to solicit, collect or induce end users to communicate Special Categories of Data without a suitable legal basis pursuant to Article 9(2) GDPR and without adequate notice. Should such categories need to be processed, the Customer is required to give prior notice to the Processor and to request a specific addendum to this DPA.
4.3 Upon written request of the Controller, the Processor updates, modifies, corrects or deletes the Personal Data processed within 15 days of receipt of the request, save where legal obligations prevent this.
5.1 The Processor processes Personal Data exclusively for the following purposes, in strict performance of the Agreement:
5.2 The Processor does not use Customer Data for its own further purposes beyond those listed. In particular, Customer Data is not used for the training or improvement of artificial intelligence models (see Section 7).
5.3 The Processor may process Personal Data in aggregated and anonymised form, no longer traceable to any Data Subject, for internal statistical, security and operational improvement purposes of the service.
5.4 Should the Processor consider that an instruction of the Controller infringes the GDPR or other applicable provisions, it immediately informs the Controller and reserves the right to suspend the execution of the instruction pending clarification.
The Processor undertakes to:
7.1 The Processor uses exclusively artificial intelligence model providers configured in such a way as to exclude the reuse of transmitted data for the training of their models (opt-out from training or zero data retention for training mode).
7.2 The Processor guarantees that the Sub-processors providing AI models (currently OpenAI, LLC; any future providers will be notified with prior notice pursuant to Section 8) are contractually bound to the same prohibition and, where available, to the APIs or endpoints that exclude the use of transmitted data for training purposes.
7.3 The Processor may, however, use aggregated and anonymised data, no longer traceable to any Data Subject, for service improvement purposes. Such use is limited to technical metrics, usage statistics and security analyses, and in no case entails the processing of Personal Data.
8.1 The Controller, by signing this DPA, grants the Processor general authorisation to engage Sub-processors for the processing activities necessary for the performance of the Agreement, pursuant to Article 28(2) GDPR.
8.2 The updated list of Sub-processors is publicly available at supportfast.ai/en/sub-processors and in Annex A to this DPA.
8.3 The Processor selects Sub-processors on the basis of criteria of reliability, security and compliance, and imposes on them in writing, through agreements pursuant to Article 28 GDPR, obligations equivalent to those set out in this DPA, including the prohibition on the use of Customer Data for AI training purposes referred to in Section 7.
8.4 Notification of changes. The Processor communicates to the Controller any change to the list of Sub-processors (addition or replacement) with at least 30 days’ prior notice, through publication on the dedicated page, notice in the console and, for material changes, communication by e-mail.
8.5 Right to object. The Controller may object on legitimate and documented grounds to a change in the list of Sub-processors within the notice period. In such case, the Parties shall negotiate in good faith a solution; failing agreement, the Controller may withdraw from the Agreement without penalty.
8.6 The Processor is liable to the Controller for breaches of the GDPR committed by Sub-processors within the limits set out in Article 28(4) GDPR.
8.7.1 The Controller may choose to configure its Chatbots using an API key in its own name towards an artificial intelligence model provider (for example, an OpenAI key from the Controller’s own account). In such mode, conversational data flows directly from the Processor’s system to the AI provider using the Controller’s credentials.
8.7.2 In BYOK mode, the Controller:
9.1 The Processor prefers the use of Sub-processors with servers located in the European Economic Area (EEA). The main application infrastructure and the storage of conversational data are hosted on servers located in EU territory (Hetzner DE, Amazon S3 eu-central-1 Frankfurt). The voice module uses LiveKit Cloud with EU region pinning (Belgium).
9.2 For Sub-processors that process data outside the EEA (in particular AI model and CDN providers), the transfer takes place exclusively on the basis of:
Where the Sub-processor is certified to the EU-U.S. Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023), the transfer takes place on the basis of that decision. The certification is verifiable on the official register dataprivacyframework.gov.
For Sub-processors not certified to the DPF or located in countries without an adequacy decision, the Processor signs the Standard Contractual Clauses 2021/914/EU, supplemented by additional technical and organisational measures (encryption, pseudonymisation) on the basis of a documented assessment.
9.3 Upon written request of the Controller, the Processor makes available, in redacted form where necessary for reasons of commercial confidentiality, a copy of the SCCs signed with individual Sub-processors and the summary of the transfer impact assessments.
10.1 The Processor adopts and maintains the technical and organisational measures listed in Annex B, suitable to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR.
10.2 The measures include, on a non-exhaustive basis: encryption in transit (TLS 1.2/1.3) and at rest, robust authentication with optional MFA, role-based access controls, audit logs of administrative accesses, logical data segregation per Customer, periodic backups with disaster recovery procedures, continuous security monitoring, vulnerability management, staff training.
10.3 The Processor reviews and updates security measures periodically to take account of technological evolution and risks.
11.1 The Processor assists the Controller, with appropriate technical and organisational measures, in particular for:
11.2 Assistance provided within the standard functionalities of the platform is included in the fee under the Agreement. Further or non-standard assistance activities may be invoiced to the Controller, subject to written quotation.
12.1 The Processor makes available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR.
12.2 Ordinary procedure. The Controller is entitled to request, with at least 30 days’ written notice, a copy of the documentation relating to security measures, current certifications, internal audit reports and the results of penetration tests, in redacted form where necessary for confidentiality reasons.
12.3 On-site inspection. In exceptional and reasoned circumstances (e.g. serious security incident, documented suspected non-compliance, request from Authorities), the Controller may request an on-site audit, with at least 60 days’ written notice, to be carried out during working hours. The audit is subject to confidentiality obligations and costs are borne by the Controller, unless a material breach of the DPA by the Processor emerges.
12.4 The Processor may satisfy the obligations of this Section also through the sharing of independent third-party audit reports (e.g. ISO 27001, SOC 2), where available.
13.1 In the event of a Personal Data Breach in processing carried out on behalf of the Controller, even if caused by a Sub-processor, the Processor:
13.2 Notification to the Italian DPA pursuant to Article 33 GDPR and any communication to Data Subjects pursuant to Article 34 GDPR remain the responsibility of the Controller. The Processor provides the support necessary to enable the Controller to fulfil such obligations within the time limits set by law.
13.3 The 48-hour deadline under clause 13.1 is specific to the relationship between Processor and Controller and is more stringent than the 72-hour deadline provided by Article 33 GDPR for the Controller’s notification to the Italian DPA, in order to enable the Controller to comply with the latter deadline.
14.1 This DPA enters into force on the date of acceptance of the Agreement and remains effective for the entire duration thereof. Upon termination of the Agreement, for any cause, the DPA automatically ceases to have effect, save for the provisions which by their nature must survive (e.g. confidentiality, liability).
14.2 End of processing. Upon termination of the Agreement, the Processor, subject to different legal obligations:
14.3 Upon request, the Processor provides written confirmation of deletion at the end of the periods referred to above.
15.1 The liability of each Party under this DPA is governed by Article 82 GDPR. Each Party is liable for damages caused by processing carried out in breach of the GDPR or of this DPA.
15.2 Save as mandatorily provided by law, the overall liability of the Processor for damages arising from this DPA is subject to the same limits of liability provided by the Agreement, with the exception of damages caused by wilful misconduct or gross negligence.
15.3 The Customer, as Controller, indemnifies the Processor against third-party claims arising from processing carried out on the Controller’s instructions in breach of the GDPR, unless the breach is attributable to the Processor.
16.1 Communications relating to this DPA are made in writing, to the addresses indicated in the Agreement or to [email protected] for communications directed to the Processor.
16.2 The Processor may amend this DPA to reflect regulatory developments, organisational changes or improvements in the guarantees in favour of the Controller. Amendments are communicated to the Controller with at least 30 days’ prior notice by e-mail and in-console notice. The Controller is entitled to withdraw from the Agreement within such period should it consider the amendments prejudicial.
16.3 Purely formal updates, correction of typos or non-material regulatory updates may be made without prior notice, with indication of the version change in the document header.
17.1 This DPA is governed by Italian law.
17.2 Any dispute concerning the validity, effectiveness, interpretation or performance of this DPA is subject to the exclusive and mandatory jurisdiction of the Court of Verona.
The updated and complete list is available at supportfast.ai/en/sub-processors. The following is a representation of the main Sub-processors as at the date of publication of this DPA.
| Vendor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the main application infrastructure (servers, databases) | Nuremberg, Germany (EU) | Intra-EU |
| Amazon Web Services EMEA SARL | Storage and CDN for cdn.supportfast.ai | Frankfurt, Germany (eu-central-1) | Intra-EU |
| OpenAI, LLC | Language models (LLM) for chatbots and voice, Stepcode mode | San Francisco, CA, USA | DPF |
| Acumbamail S.L. | Sending of transactional and marketing e-mails | Cuenca, Spain (EU) | Intra-EU |
| Cloudflare, Inc. | CDN, WAF, anti-DDoS, SSL | USA / global (EU PoP) | DPF |
| Stripe Payments Europe Ltd. | Payment processing | Dublin, Ireland (EU) | Intra-EU |
| Google Ireland Ltd. | Google Workspace (internal corporate e-mails) | Ireland, USA group | SCC + DPF |
| Microsoft Ireland Operations Ltd. | Microsoft Clarity (product analytics) | Ireland + USA | SCC + DPF |
| PostHog Inc. | Product analytics, EU region (Frankfurt) | Frankfurt (EU) | Intra-EU |
| Meta Platforms Ireland Ltd. | WhatsApp Business API, Instagram, Messenger (if active) | Ireland, USA group | SCC + DPF |
| LiveKit, Inc. | LiveKit Cloud, WebRTC orchestration and SIP telephony for voice module | EU, region pinning Belgium | DPF + SCC |
| Deepgram, Inc. | Speech-to-text, voice module | USA | DPF |
| ElevenLabs Inc. | Text-to-speech, voice module | USA | DPF |
The Processor may, during the term of the Agreement, replace, add or remove Sub-processors in accordance with the procedure set out in Section 8. The updated list on the public page constitutes the current list.
Measures adopted by the Processor pursuant to Article 32 GDPR, suitable to ensure a level of security appropriate to the risk.
Specifications of the processing carried out by the Processor on behalf of the Controller, pursuant to Article 28(3) GDPR.
The processing consists in the provision of the Supportfast.ai software and services as configured by the Controller: configuration of chatbots and voice assistants, execution of conversations on integrated channels, storage and management of conversations and audio, integration with third-party systems configured by the Controller, generation of reporting.
| Category | Examples |
|---|---|
| Identification data | Name, surname, channel identifiers (WhatsApp number, Instagram ID, e-mail). |
| Contact data | E-mail, telephone number. |
| Conversational content | Text of messages, attachments, audio recordings (voice module), transcriptions. |
| Conversational metadata | Timestamp, channel, duration, outcome, rating. |
| Enriched profile data | Categories and tags attributed by the Customer to conversations or contacts. |
| Technical data | IP, user-agent, device, in pseudonymised form. |
| Any other data | Data communicated voluntarily by end users in the interactions, under the responsibility of the Controller. |
By default, the Processor does not process Special Categories of Data. Should the Controller configure the service in such a way as to process such categories (e.g. chatbots in the healthcare sector), the Controller is required to give prior notice to the Processor, to verify the existence of a suitable legal basis pursuant to Article 9(2) GDPR, to provide adequate notice to Data Subjects and to request a specific addendum to this DPA.
For the entire duration of the Agreement, with retention periods of individual data defined by the Customer’s configurations in the console and, failing that, by the default values:
Upon termination of the Agreement, the procedure under Section 14 applies.