Version 1.1  ·  Effective: 15 September 2026  ·  Governing law: Spain (GDPR + LOPDGDD)
17 September 2026: editorial, product term pAIq replaced by the Platform, brand casing PAIQ, no change to rights or obligations.

1. Parties, roles and scope

1.1. This Data Processing Agreement (the "DPA") is entered into between PAIQ RAAS, S.L., NIF B27677392, Companies Registry of Málaga, Sheet MA-198105, registered office at C/ Poeta Francisco Coronado y Delicado nº 6, 3A, 29011 Málaga, Spain ("PAIQ", the "Processor"), and the business customer that uses the Platform (the "Customer", the "Controller"). It forms part of, and is governed by, the Terms of Service at paiq.io/terms.html (the "Terms"). Capitalised terms not defined here have the meaning given in the Terms.

1.2. This DPA applies only to the processing of personal data contained in end-user conversations handled by the Platform (the "Conversation Data"), where the Customer is the controller and PAIQ is the processor, as stated in Terms clause 13.1. It does not apply to PAIQ Access, and it does not apply to the Customer's own account, purchase and support data, for which PAIQ is an independent controller (Terms clause 13.2).

1.3. Terms of the defined processing (subject matter, duration, nature and purpose, categories of data and of data subjects) are set out in Annex 1. This satisfies Article 28(3), first paragraph, GDPR.

1.4. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails (Terms clause 1.3).

2. Processing on documented instructions

2.1. PAIQ processes Conversation Data only on the Customer's documented instructions, including as to transfers to a third country, unless required to do otherwise by Union or Member State law to which PAIQ is subject; in that case PAIQ informs the Customer of that legal requirement before processing, unless the law prohibits it (Article 28(3)(a)).

2.2. The documented instructions are these Terms, this DPA, the configuration the Customer sets in the dashboard, and any further written instruction the Customer gives. PAIQ does not process Conversation Data for its own purposes, does not sell it, does not use it for advertising, and does not use it to train AI models (Terms clause 13.3).

2.3. PAIQ informs the Customer without delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law (Article 28(3), final paragraph).

3. Confidentiality

PAIQ ensures that persons authorised to process Conversation Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b)).

4. Security

PAIQ implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32), as described in Annex 3 and in the Privacy Policy. PAIQ holds no ISO 27001 or SOC 2 certification at this time and makes no certification claim (Terms clause 17.2).

5. Sub-processors

5.1. The Customer gives PAIQ general written authorisation to engage sub-processors (Article 28(2)). The current sub-processors, with each one's role and location, are listed at paiq.io/subprocessors.html, which is the authoritative and maintained list. A summary is in Annex 2.

5.2. PAIQ updates that page before adding or replacing a sub-processor that processes Conversation Data, giving the Customer the opportunity to object on reasonable data protection grounds. If the parties cannot resolve a timely objection, the Customer may terminate the Platform subscription for the affected processing (Terms clause 14.2).

5.3. PAIQ imposes on each sub-processor, by contract, the same data protection obligations as in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures (Article 28(4)). PAIQ remains fully liable to the Customer for the performance of each sub-processor's obligations.

5.4. AI language responses are generated by third-party AI providers listed on the sub-processor page. Conversation Data necessary to generate a response is transmitted to those providers under agreements that prohibit training on that data. Those providers may retain API request data for a limited period for abuse monitoring in accordance with their published policies. PAIQ does not currently operate under a zero-data-retention arrangement with its AI providers and makes no zero-retention claim; if PAIQ obtains one, this DPA and the sub-processor page will be updated (Terms clause 14.5).

6. International transfers

Where Conversation Data is transferred to or processed by a sub-processor outside the European Economic Area, the transfer is made under an adequacy decision or the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), with supplementary measures where required, as documented in the sub-processor page and in PAIQ's transfer assessments (Article 46; Terms clause 14.3). PAIQ makes the relevant transfer mechanism available to the Customer on request.

7. Assistance with data subject rights

Taking into account the nature of the processing, PAIQ assists the Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests to exercise the data subject rights in Chapter III GDPR (Article 28(3)(e)). If PAIQ receives such a request directly from a data subject, it does not respond on its own account and forwards the request to the Customer without undue delay. The dashboard export and deletion features (Terms clauses 16.3 and 19.1) are the primary means of this assistance.

8. Assistance with security, breach and impact assessments

8.1. PAIQ assists the Customer in ensuring compliance with the obligations in Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to PAIQ (Article 28(3)(f)).

8.2. PAIQ notifies the Customer without undue delay after becoming aware of a personal data breach affecting Conversation Data, with the information the Customer reasonably needs to meet its own obligations under Articles 33 and 34 (Terms clause 17.3). PAIQ does not notify supervisory authorities or data subjects on the Customer's behalf unless the Customer instructs it in writing.

9. Return and deletion

9.1. At the Customer's choice, PAIQ deletes or returns all Conversation Data after the end of the provision of the Platform, and deletes existing copies, unless Union or Member State law requires storage (Article 28(3)(g)).

9.2. In practice this follows the schedule in Terms Section 16 and Annex 1 of this DPA: on disconnection or termination, Instagram access tokens are deleted at disconnection; message and reply data is permanently deleted 30 days after disconnection; operational logs rotate on a 30-day cycle; encrypted backups expire within a further 30 days. During the 30-day window the data is retained only to allow reconnection and export, and is not otherwise processed. Earlier deletion can be requested at hello@paiq.io and is honoured within 30 days except where retention is legally required.

9.3. Contract acceptance and checkout consent records are kept for 6 years after account closure (art. 30 Código de Comercio; Art. 17(3)(e) GDPR), then deleted. They hold the Customer's identification and the accepted Terms version, not Conversation Data.

10. Records, information and audits

PAIQ makes available to the Customer all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates (Article 28(3)(h)). Audits take place on reasonable prior notice, no more than once a year except where a supervisory authority requires otherwise or following a breach, subject to confidentiality, and during business hours without disrupting the service. PAIQ may satisfy an audit by providing its security documentation and completing a reasonable questionnaire.

11. Liability, term and general

11.1. The limitation of liability in Terms Section 21 applies to this DPA. Nothing in this DPA limits liability that cannot be limited under applicable law.

11.2. This DPA takes effect when the Customer creates its account or first uses the Platform and remains in force for as long as PAIQ processes Conversation Data, and the deletion obligations in Section 9 survive termination.

11.3. This DPA is governed by Spanish law, and the parties submit to the courts of the city of Málaga, Spain, consistent with Terms Section 23. Data protection questions are decided under the GDPR and Spanish Organic Law 3/2018 (LOPDGDD).

11.4. Data protection contact: hello@paiq.io. PAIQ's internal Privacy Oversight Lead is Andre Luis Marcal (administrador solidario). This is an internal designation and not the appointment of a data protection officer under Article 37 GDPR; the DPO assessment is documented in the Privacy Policy.

Annex 1. Details of the processing

Annex 2. Sub-processors

The authoritative, maintained list is at paiq.io/subprocessors.html. At the date of this draft the categories are: production hosting in the EU; large language model inference for reply generation (primary and fallback AI providers); encrypted off-site backup; and transactional email. The page states each provider's legal entity, role, location and transfer mechanism. Because the page is the source of truth, this annex is not re-issued each time the list changes; changes follow Section 5.2 (notice and objection).

Meta Platforms Ireland Ltd. (Instagram, Meta Graph API) is the third-party service that PAIQ connects to on the Customer's instruction to send and receive the Customer's Instagram direct messages. Meta acts as an independent controller under its own terms, not as a PAIQ sub-processor, so it is not a category in this annex or an entry in the sub-processor list.

Annex 3. Technical and organisational measures (Article 32)