Data Processing Agreement

Effective Date: July 3, 2026

1. Introduction and scope

This Data Processing Agreement (the 'DPA') forms part of, and is subject to, the Breezaro Terms of Service (the 'Agreement') between Breezaro s.r.o., ID No. 23465344, with registered office at Zborovská 2049/27, 616 00 Brno, Czech Republic ('Breezaro' or the 'Processor'), and the customer that has accepted the Agreement (the 'Customer' or the 'Controller').

It applies to the extent Breezaro processes personal data on behalf of the Customer when providing the Service (the Breezaro AI chatbot and related features). Where its terms conflict with the Agreement on the subject of the processing of personal data, this DPA prevails.

'Applicable Data Protection Law' means Regulation (EU) 2016/679 (the 'GDPR') together with any national legislation implementing or supplementing it, including Czech Act No. 110/2019 Coll. Terms such as 'personal data', 'processing', 'controller', 'processor', 'data subject' and 'personal data breach' have the meanings given in the GDPR.

2. Roles of the parties

For the personal data of the Customer's website visitors and other end users that Breezaro processes through the Service ('Customer Personal Data'), the Customer acts as the controller and Breezaro acts as the processor. Where the Customer is itself a processor acting on behalf of a third-party controller, Breezaro acts as a sub-processor and the Customer warrants that it has the authorisation of that third party to engage Breezaro on these terms.

The Customer is responsible for establishing a lawful basis for the processing, for providing all information and notices required towards data subjects (including in the Customer's own privacy policy), for the accuracy of any personal data it or its visitors provide, and for the lawfulness of the instructions it gives to Breezaro.

3. Subject matter and processing instructions

Breezaro processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers of personal data to a third country, unless required to process by Union or Member State law to which Breezaro is subject; in that case Breezaro informs the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Agreement, this DPA (including Annex 1), and the Customer's use and configuration of the Service constitute the Customer's complete and final documented instructions for the processing. Any additional or alternative instruction must be agreed in writing.

Breezaro informs the Customer without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law.

4. Confidentiality

Breezaro ensures that the persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the data only on the Customer's instructions unless required to act otherwise by law.

5. Security of processing

Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks of varying likelihood and severity to the rights and freedoms of data subjects, Breezaro implements appropriate technical and organisational measures pursuant to Article 32 GDPR. The measures in force are described in Annex 3. Breezaro may update those measures from time to time provided the overall level of protection is not diminished.

6. Sub-processors

The Customer grants Breezaro general written authorisation to engage sub-processors to carry out specific processing activities on its behalf. The sub-processors engaged as at the effective date are listed in Annex 2.

Breezaro imposes on each sub-processor, by way of a written contract, data protection obligations that are no less protective than those set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. Breezaro remains fully liable to the Customer for the performance of each sub-processor's obligations.

Breezaro informs the Customer of any intended addition or replacement of a sub-processor and gives the Customer a reasonable opportunity to object on reasonable, data-protection-related grounds. If the Customer objects and the parties cannot agree on a resolution, the Customer may, as its sole remedy, terminate the part of the Service that cannot be provided without the objected-to sub-processor.

7. International transfers

Certain sub-processors listed in Annex 2 are established in the United States. Where such a sub-processor is certified under the EU-U.S. Data Privacy Framework, Breezaro relies on the European Commission's adequacy decision of 10 July 2023 (Article 45 GDPR) as the transfer mechanism. Where a sub-processor is not so certified, Breezaro transfers Customer Personal Data on the basis of the European Commission's Standard Contractual Clauses (Article 46 GDPR).

For transfers made on the basis of the Standard Contractual Clauses, Breezaro has carried out a transfer impact assessment and applies supplementary technical and organisational measures where appropriate, including encryption of data in transit and at rest and data minimisation. The transfer mechanism applicable to each sub-processor is identified in Annex 2, and a copy of the relevant safeguards is available from Breezaro on request.

8. Assistance with data subject rights

Taking into account the nature of the processing, Breezaro assists the Customer, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Customer's obligation to respond to requests by data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability and objection). The self-service tools within the Service, including conversation deletion, the data-deletion request flow and account deletion, are the primary means by which Breezaro provides this assistance.

If Breezaro receives a request directly from a data subject that relates to Customer Personal Data, it forwards the request to the Customer without undue delay and does not otherwise respond to the request except on the Customer's documented instruction or where required to do so by law.

9. Personal data breaches

Breezaro notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the Customer with the information reasonably available to it to enable the Customer to meet its obligations under Articles 33 and 34 GDPR, including a description of the nature of the breach, its likely consequences and the measures taken or proposed.

10. Data protection impact assessments

Taking into account the nature of the processing and the information available to it, Breezaro provides the Customer with reasonable assistance in carrying out data protection impact assessments and, where required, prior consultations with the competent supervisory authority under Articles 35 and 36 GDPR.

11. Records, information and audits

Breezaro makes available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR. At the Customer's written request and no more than once in any twelve-month period (unless required by a supervisory authority or following a personal data breach affecting Customer Personal Data), Breezaro allows for and contributes to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer. Audits are subject to reasonable prior notice, are conducted during business hours in a manner that does not disrupt Breezaro's operations, are bound by confidentiality, and respect Breezaro's security and the confidentiality of other customers' data.

12. Retention, return and deletion

At the choice of the Customer, Breezaro deletes or returns all Customer Personal Data after the end of the provision of the Service and deletes existing copies, unless Union or Member State law requires storage of the personal data.

During the term, retention operates as described in the Privacy Policy: conversations are retained for as long as the Customer's account is active; a conversation that the Customer deletes from its dashboard is permanently erased after a configurable period (90 days by default, adjustable between 60 and 730 days per chatbot); and the visitor page trail is deleted after 90 days. Residual copies may persist in encrypted backups for a limited period as described in the Privacy Policy, after which they are permanently removed.

13. Liability

Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement, including the limitation of the Provider's aggregate liability for direct damages to the fees paid in the preceding twelve months and the exclusion of indirect and consequential damages. Nothing in this DPA or the Agreement limits or excludes any liability that cannot be limited or excluded under Applicable Data Protection Law.

14. Term

This DPA takes effect when the Customer accepts it or first uses the Service, whichever is earlier, and continues in force for as long as Breezaro processes Customer Personal Data on the Customer's behalf under the Agreement.

15. Governing law

This DPA is governed by the laws of the Czech Republic and, where applicable, by Applicable Data Protection Law. Disputes are subject to the jurisdiction agreed in the Agreement.

16. Contact

Questions about this DPA or about Breezaro's processing of Customer Personal Data may be sent to info@breezaro.com.

Annex 1 - Description of the processing

This Annex describes the processing that Breezaro carries out on the Customer's behalf.

  • Subject matter: the processing of Customer Personal Data through the Breezaro AI chatbot and related features.
  • Duration: the term of the Agreement, together with the retention and deletion periods described in Section 12.
  • Nature and purpose: hosting and operating an AI chatbot that answers the Customer's website visitors, generating and storing conversation records, retrieving answers from the Customer's knowledge base, and providing the Customer with an operator dashboard, analytics and notifications.
  • Categories of data subjects: the Customer's website visitors and end users who interact with the chatbot; individuals referenced in content the Customer uploads to its knowledge base; and the Customer's own operators and team members.
  • Types of personal data: online identifiers (IP address, approximate country, device type, browser, operating system, language, referrer and campaign parameters); the content of chat messages, which may contain any personal data a visitor chooses to provide, such as name, email address, telephone number or order details; channel identifiers where the Customer connects messaging channels (for example a WhatsApp profile name); AI-generated conversation summaries; the visitor page trail; and any personal data contained in documents the Customer uploads to its knowledge base.
  • Special categories of personal data: the Service is not intended to process special categories of personal data. The Customer must not configure the Service to solicit such data, and Breezaro does not intentionally process it.

Annex 2 - Sub-processors

The following sub-processors are engaged as at the effective date. The current list is available on request, and Breezaro notifies the Customer of changes as set out in Section 6. Meta is engaged only where the Customer connects the relevant messaging channel. Sub-processors established in the European Economic Area may transfer personal data onward to their own affiliates or sub-processors outside the EEA under their respective transfer safeguards; the transfer mechanism for each sub-processor established outside the EEA is indicated below.

  • OpenAI (OpenAI Ireland Ltd, Ireland): generation of chatbot replies and audio transcription.
  • Google (Google Ireland Limited, Ireland): generation of chatbot replies using Gemini models.
  • Pinecone (Pinecone Systems, Inc., United States): vector search over the Customer's knowledge base and conversation content. Transfers to the United States are made under the Standard Contractual Clauses (Article 46 GDPR).
  • Amazon Web Services (Amazon Web Services EMEA SARL, Luxembourg): storage of uploaded files and assets.
  • Resend (Plus Five Five, Inc. d/b/a Resend, United States): delivery of transactional and operator notification emails. Plus Five Five is certified under the EU-U.S. Data Privacy Framework; transfers to the United States rely on that certification (Article 45 GDPR).
  • Sentry (Functional Software, Inc. d/b/a Sentry, United States): application error monitoring. Sentry is certified under the EU-U.S. Data Privacy Framework; transfers to the United States rely on that certification (Article 45 GDPR).
  • Meta (Meta Platforms Ireland Limited, Ireland): delivery of messages where the Customer connects WhatsApp, Facebook Messenger or Instagram channels.

Annex 3 - Technical and organisational measures

Breezaro maintains the following technical and organisational measures, which it may update provided the overall level of protection is not reduced.

  • Encryption of personal data in transit using TLS, and encryption of data at rest in the production database and object storage.
  • Hashing of account passwords using a strong one-way algorithm, and encryption of third-party access tokens.
  • Logical multi-tenant separation so that each Customer's data is segregated and access is scoped to the Customer's own tenant.
  • Access controls based on the principle of least privilege, with authenticated, role-based access to the operator dashboard and administrative systems.
  • Protection of server-side outbound requests against server-side request forgery through pinned DNS resolution.
  • Audit logging of significant administrative and team actions.
  • Regular backups with a defined retention period and documented restoration procedures.
  • Rate limiting and abuse protections on public endpoints.
  • Retention and deletion controls that enable the Customer to delete conversations and request erasure, with automated purging as described in Section 12.