Legal
Data Processing Agreement
The Article 28 GDPR agreement under which PAIQ processes conversation data on behalf of Platform customers. Incorporated into the Terms of Service.
1. Parties, roles and scope
1.1. This Data Processing Agreement (the "DPA") is entered into between PAIQ RAAS, S.L., NIF B27677392, Companies Registry of Málaga, Sheet MA-198105, registered office at C/ Poeta Francisco Coronado y Delicado nº 6, 3A, 29011 Málaga, Spain ("PAIQ", the "Processor"), and the business customer that uses the Platform (the "Customer", the "Controller"). It forms part of, and is governed by, the Terms of Service at paiq.io/terms.html (the "Terms"). Capitalised terms not defined here have the meaning given in the Terms.
1.2. This DPA applies only to the processing of personal data contained in end-user conversations handled by the Platform (the "Conversation Data"), where the Customer is the controller and PAIQ is the processor, as stated in Terms clause 13.1. It does not apply to PAIQ Access, and it does not apply to the Customer's own account, purchase and support data, for which PAIQ is an independent controller (Terms clause 13.2).
1.3. Terms of the defined processing (subject matter, duration, nature and purpose, categories of data and of data subjects) are set out in Annex 1. This satisfies Article 28(3), first paragraph, GDPR.
1.4. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails (Terms clause 1.3).
2. Processing on documented instructions
2.1. PAIQ processes Conversation Data only on the Customer's documented instructions, including as to transfers to a third country, unless required to do otherwise by Union or Member State law to which PAIQ is subject; in that case PAIQ informs the Customer of that legal requirement before processing, unless the law prohibits it (Article 28(3)(a)).
2.2. The documented instructions are these Terms, this DPA, the configuration the Customer sets in the dashboard, and any further written instruction the Customer gives. PAIQ does not process Conversation Data for its own purposes, does not sell it, does not use it for advertising, and does not use it to train AI models (Terms clause 13.3).
2.3. PAIQ informs the Customer without delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law (Article 28(3), final paragraph).
3. Confidentiality
PAIQ ensures that persons authorised to process Conversation Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b)).
4. Security
PAIQ implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32), as described in Annex 3 and in the Privacy Policy. PAIQ holds no ISO 27001 or SOC 2 certification at this time and makes no certification claim (Terms clause 17.2).
5. Sub-processors
5.1. The Customer gives PAIQ general written authorisation to engage sub-processors (Article 28(2)). The current sub-processors, with each one's role and location, are listed at paiq.io/subprocessors.html, which is the authoritative and maintained list. A summary is in Annex 2.
5.2. PAIQ updates that page before adding or replacing a sub-processor that processes Conversation Data, giving the Customer the opportunity to object on reasonable data protection grounds. If the parties cannot resolve a timely objection, the Customer may terminate the Platform subscription for the affected processing (Terms clause 14.2).
5.3. PAIQ imposes on each sub-processor, by contract, the same data protection obligations as in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures (Article 28(4)). PAIQ remains fully liable to the Customer for the performance of each sub-processor's obligations.
5.4. AI language responses are generated by third-party AI providers listed on the sub-processor page. Conversation Data necessary to generate a response is transmitted to those providers under agreements that prohibit training on that data. Those providers may retain API request data for a limited period for abuse monitoring in accordance with their published policies. PAIQ does not currently operate under a zero-data-retention arrangement with its AI providers and makes no zero-retention claim; if PAIQ obtains one, this DPA and the sub-processor page will be updated (Terms clause 14.5).
6. International transfers
Where Conversation Data is transferred to or processed by a sub-processor outside the European Economic Area, the transfer is made under an adequacy decision or the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), with supplementary measures where required, as documented in the sub-processor page and in PAIQ's transfer assessments (Article 46; Terms clause 14.3). PAIQ makes the relevant transfer mechanism available to the Customer on request.
7. Assistance with data subject rights
Taking into account the nature of the processing, PAIQ assists the Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests to exercise the data subject rights in Chapter III GDPR (Article 28(3)(e)). If PAIQ receives such a request directly from a data subject, it does not respond on its own account and forwards the request to the Customer without undue delay. The dashboard export and deletion features (Terms clauses 16.3 and 19.1) are the primary means of this assistance.
8. Assistance with security, breach and impact assessments
8.1. PAIQ assists the Customer in ensuring compliance with the obligations in Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to PAIQ (Article 28(3)(f)).
8.2. PAIQ notifies the Customer without undue delay after becoming aware of a personal data breach affecting Conversation Data, with the information the Customer reasonably needs to meet its own obligations under Articles 33 and 34 (Terms clause 17.3). PAIQ does not notify supervisory authorities or data subjects on the Customer's behalf unless the Customer instructs it in writing.
9. Return and deletion
9.1. At the Customer's choice, PAIQ deletes or returns all Conversation Data after the end of the provision of the Platform, and deletes existing copies, unless Union or Member State law requires storage (Article 28(3)(g)).
9.2. In practice this follows the schedule in Terms Section 16 and Annex 1 of this DPA: on disconnection or termination, Instagram access tokens are deleted at disconnection; message and reply data is permanently deleted 30 days after disconnection; operational logs rotate on a 30-day cycle; encrypted backups expire within a further 30 days. During the 30-day window the data is retained only to allow reconnection and export, and is not otherwise processed. Earlier deletion can be requested at hello@paiq.io and is honoured within 30 days except where retention is legally required.
9.3. Contract acceptance and checkout consent records are kept for 6 years after account closure (art. 30 Código de Comercio; Art. 17(3)(e) GDPR), then deleted. They hold the Customer's identification and the accepted Terms version, not Conversation Data.
10. Records, information and audits
PAIQ makes available to the Customer all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates (Article 28(3)(h)). Audits take place on reasonable prior notice, no more than once a year except where a supervisory authority requires otherwise or following a breach, subject to confidentiality, and during business hours without disrupting the service. PAIQ may satisfy an audit by providing its security documentation and completing a reasonable questionnaire.
11. Liability, term and general
11.1. The limitation of liability in Terms Section 21 applies to this DPA. Nothing in this DPA limits liability that cannot be limited under applicable law.
11.2. This DPA takes effect when the Customer creates its account or first uses the Platform and remains in force for as long as PAIQ processes Conversation Data, and the deletion obligations in Section 9 survive termination.
11.3. This DPA is governed by Spanish law, and the parties submit to the courts of the city of Málaga, Spain, consistent with Terms Section 23. Data protection questions are decided under the GDPR and Spanish Organic Law 3/2018 (LOPDGDD).
11.4. Data protection contact: hello@paiq.io. PAIQ's internal Privacy Oversight Lead is Andre Luis Marcal (administrador solidario). This is an internal designation and not the appointment of a data protection officer under Article 37 GDPR; the DPO assessment is documented in the Privacy Policy.
Annex 1. Details of the processing
- Subject matter: processing of end-user conversation data so that the Platform can answer the Customer's Instagram direct messages on its behalf.
- Duration: the term of the Customer's Platform subscription, plus the wind-down and deletion periods in Section 9 (up to 30 days post-disconnection for message data, plus a further 30 days for encrypted backups).
- Nature and purpose: receiving inbound Instagram direct messages, generating replies in the Customer's brand voice using the Customer's knowledge base, classifying and scoring leads, triggering automated follow-ups, and recording activity in the dashboard, through the Meta Graph API.
- Categories of data subjects: the Customer's end users, that is the Instagram users who send direct messages to the Customer's account ("Contacts"). Contacts are never PAIQ subscribers.
- Categories of personal data: Instagram username and user identifier, the content of messages exchanged, message metadata (timestamps, conversation identifiers), lead classification and scores, and any contact details a Contact volunteers within a message.
- Special categories (Article 9): none. The Customer must not instruct the service to collect special category data and configures its agent so such data is not solicited (Terms clause 12.3). Any special category data that a Contact volunteers unprompted is not processed for any purpose beyond delivering the conversation.
Annex 2. Sub-processors
The authoritative, maintained list is at paiq.io/subprocessors.html. At the date of this draft the categories are: production hosting in the EU; large language model inference for reply generation (primary and fallback AI providers); encrypted off-site backup; and transactional email. The page states each provider's legal entity, role, location and transfer mechanism. Because the page is the source of truth, this annex is not re-issued each time the list changes; changes follow Section 5.2 (notice and objection).
Meta Platforms Ireland Ltd. (Instagram, Meta Graph API) is the third-party service that PAIQ connects to on the Customer's instruction to send and receive the Customer's Instagram direct messages. Meta acts as an independent controller under its own terms, not as a PAIQ sub-processor, so it is not a category in this annex or an entry in the sub-processor list.
Annex 3. Technical and organisational measures (Article 32)
- Encryption of Conversation Data in transit and at rest.
- Access control on the principle of least privilege, with authentication for administrative access.
- Production hosting within the European Union, with tenant isolation between customers.
- Encrypted off-site backups, client-side encrypted so the backup provider has no access to the keys.
- Deletion of Instagram access tokens at disconnection, and the retention and rotation schedule in Section 9.
- Logging and monitoring of access and processing activity.
- A personal data breach process that notifies the Customer without undue delay (Section 8.2).
- No ISO 27001 or SOC 2 certification at this time; measures are described here and in the Privacy Policy rather than certified.