This Data Processing Agreement (DPA) is concluded between the customer (controller) and AbdeX e.U. (processor) and forms part of the main contract. The customer consents to it upon registration.
between the customer (the "controller") and AbdeX e.U., Dr.-Theodor-Körner-Platz 2, A-2460 Bruck an der Leitha (the "processor").
The subject matter is the processing of personal data by the processor on behalf of the controller within the scope of using the "aiarbeiter" service. The duration corresponds to the term of the main contract.
Automated receipt, processing and answering of WhatsApp messages from the controller's end customers, as well as handling of appointments, orders, reservations and enquiries via the processor's software. The purpose is the provision of the contractually agreed services.
Processed in particular: phone number, WhatsApp-provided profile name, contents of the chat messages, and transaction-related details (e.g. requested appointment, order details, reservation data). Data subjects are the controller's end customers and prospective customers.
The processor processes the data exclusively within the scope of the main contract and in accordance with the documented instructions of the controller. Operation of the software by the controller (configuration, settings, entries in the cockpit) is deemed an instruction. If the processor considers an instruction to be unlawful, it informs the controller.
The processor uses for processing only persons who are committed to confidentiality or subject to an appropriate statutory duty of secrecy.
The processor takes appropriate technical and organisational measures, in particular:
The controller approves the use of the following categories of sub-processors: (a) EU hosting and e-mail providers, (b) providers of the WhatsApp message infrastructure (Meta), (c) providers of AI language-model services (USA), (d) optionally payment service providers. The processor provides the current, named list of sub-processors used on request at info@aiarbeiter.at. The processor informs of intended changes; the controller may object for good cause. Contracts with equivalent data-protection obligations are in place with each sub-processor.
Insofar as processing takes place outside the EEA (in particular the USA), the processor ensures appropriate safeguards under Art. 44 et seq. GDPR (in particular EU standard contractual clauses and/or certification under the EU-US Data Privacy Framework).
The processor supports the controller, to a reasonable extent, in responding to requests from data subjects (Art. 12–22 GDPR) and in complying with the obligations under Art. 32–36 GDPR (security, notification of breaches, data protection impact assessment).
The processor informs the controller without undue delay after becoming aware of a personal data breach within the area of responsibility of the processing, and provides the information required to fulfil the notification obligations.
After termination of the contract, the processor deletes the data processed on behalf or returns it at the controller's choice, unless a statutory retention obligation prevents this.
The processor provides the controller, on request, with the information required to demonstrate compliance with these obligations and enables reasonable audits with reasonable advance notice and without disproportionate disruption to operations.
Liability within the scope of processing on behalf is governed by Art. 82 GDPR and by the liability provisions of the main contract (§ 12 Terms).