# Data Processing Agreement (DPA)

Source: https://chatmerce.eu/en/dpa/
Language: en
Effective: 2026-05-16

---

This Data Processing Agreement (the **DPA**) is an annex to the Chatmerce [Terms of Service](/en/terms) and sets out how **Prosit AS** processes personal data as Processor on behalf of the Customer acting as Controller. The DPA takes effect when the Customer accepts the Terms — no separate signature is required. Enterprise customers may request a signed version at [hello@chatmerce.eu](mailto:hello@chatmerce.eu).

## Parties

**Controller (Customer)** — the entity that opens an account in the Service and independently determines the purposes and means of processing its end-users' data. The Customer's details (name, address, registration number, signatory) follow from the account information provided at sign-up.

**Processor** — Prosit AS, a company registered in Norway (organisasjonsnummer 932 184 110), email: [hello@chatmerce.eu](mailto:hello@chatmerce.eu). Registered address to be added after registration in the Brønnøysund Register Centre.

## 1. Definitions

- **Controller** — the Customer, who independently determines the purposes and means of processing its end-users' personal data.
- **Processor** — Prosit AS, which processes personal data on behalf of the Controller solely on its documented instructions.
- **Personal Data** — any information relating to an identified or identifiable natural person processed within the Platform on the Controller's instructions.
- **Service / Platform** — the Chatmerce SaaS platform available at `app.chatmerce.eu`.
- **GDPR** — Regulation (EU) 2016/679 of 27 April 2016.
- **Personal Data Breach** — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
- **Sub-processor** — a third party engaged by the Processor for further processing of Personal Data (list in section 10).

## 2. Subject matter, nature and purpose

The Processor processes Personal Data solely to provide the Service to the Controller, i.e. to deliver and operate an AI conversational platform integrated with the Controller's website, store or RCS channel.

The nature of processing includes: collecting, storing, analysing, disclosing and deleting Personal Data as needed to operate the conversational agents. Processing continues for the term of the Agreement unless law requires longer retention.

Scope of data and categories of data subjects:

| Categories of data subjects             | Types of personal data processed                                                                              |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
| End users (agent conversation partners) | Name, email address, chat message content, conversation history, IP address, session identifiers, preferences |
| Controller's staff / representatives    | Name, business email address (Platform account data)                                                          |

## 3. Processor obligations

1. Processes Personal Data only on the Controller's documented instructions, including transfers to third countries, unless required by EU or Member State law.
2. Ensures that persons authorised to process have committed to confidentiality or are under a statutory duty of confidentiality.
3. Implements technical and organisational measures under art. 32 GDPR, including at least: (a) encryption in transit (TLS) and at rest, (b) access control on a least-privilege basis, (c) regular backups and security monitoring, (d) regular testing of security measures.
4. Does not engage another Sub-processor without the Controller's prior general authorisation. By accepting the DPA, the Controller gives general authorisation for the Sub-processors listed in section 10.
5. Informs the Controller of changes to Sub-processors at least 14 days in advance, allowing the Controller to object.
6. Assists the Controller — through appropriate measures — in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection).
7. Assists the Controller in complying with art. 32–36 GDPR (security, breaches, DPIA, prior consultation).
8. On termination of the Service — at the Controller's choice — deletes or returns Personal Data and deletes existing copies, unless law requires retention. The Controller has 30 days to specify the handling.
9. Makes available the information needed to demonstrate compliance with art. 28 GDPR and allows audits on the following terms: (a) 14 days' notice; (b) no more than once per calendar year unless an incident justifies otherwise; (c) costs borne by the Controller; (d) auditors sign an NDA; (e) an ISO 27001 / SOC 2 certificate or an independent auditor's report is an accepted alternative to an on-site audit.

## 4. Controller obligations

1. Represents that it is entitled to process and to entrust the Personal Data.
2. Complies with the GDPR and other data-protection laws applicable to its activity.
3. Provides data subjects with all required information about the processing, including the use of Chatmerce as Processor.
4. Does not issue processing instructions that would breach data-protection law.

## 5. Sub-processors and transfers outside the EEA

The Processor uses the Sub-processors listed in section 10 and concludes with each one a contract imposing the same data-protection obligations as under this DPA. Where a Sub-processor is established outside the EEA, appropriate safeguards apply, in particular Standard Contractual Clauses (SCC) or other mechanisms under Chapter V GDPR.

## 6. Personal data breaches

In case of a Personal Data Breach affecting data processed on behalf of the Controller, the Processor notifies the Controller without undue delay and no later than 48 hours after becoming aware. The notification includes at least: the nature of the breach (categories and approximate number of data subjects affected), the contact point, likely consequences, and the measures taken or proposed. The Processor assists the Controller in notifying the supervisory authority (72 hours) and the affected data subjects.

## 7. Term and termination

The DPA applies for the entire term of the Service under the Terms and terminates automatically when the service agreement expires or terminates. On termination the Processor performs its obligations under section 3(8) (deletion or return of data).

## 8. Liability

Each Party is liable for breaches of its obligations under the DPA and the GDPR as provided by law. The Processor is liable for damage caused by processing only where it has not complied with obligations the GDPR directs specifically to processors, or where it acted outside or contrary to the Controller's lawful instructions. The Controller indemnifies the Processor against claims by third parties or supervisory authorities where the breach resulted from the Controller's incorrect or unlawful instructions.

## 9. Final provisions

This DPA is governed by **Norwegian law**, subject to the mandatory provisions of the GDPR. Amendments require written or electronic form; the Processor may update the DPA on 30 days' notice in the manner provided for changes to the Terms. If any provision is invalid, the remainder stays in force. This DPA prevails over any earlier data-protection arrangements between the Parties on the same subject matter.

## 10. Approved sub-processors

Prosit AS uses the following Sub-processors when processing Personal Data on behalf of Controllers:

| Sub-processor                                 | Location                   | Scope of processing               | Transfer safeguard |
| --------------------------------------------- | -------------------------- | --------------------------------- | ------------------ |
| Google Cloud (Cloud Run, Firestore, BigQuery) | europe-west4 (Netherlands) | Hosting, database, secrets        | Data in EEA        |
| Google (Gemini API)                           | europe-west4               | LLM query processing              | Data in EEA        |
| Clerk, Inc.                                   | USA                        | User authentication               | SCC + DPF          |
| Cloudflare, Inc.                              | Global                     | CDN, site hosting, bot protection | SCC + DPF          |
| SerwerSMS (Vercom S.A.)                       | Poland                     | RCS message delivery              | Data in EEA        |
| Stripe Payments Europe                        | Ireland                    | Subscription billing              | Data in EEA        |

The list may change. The Controller will be notified at least 14 days in advance. We send the current list on request: [hello@chatmerce.eu](mailto:hello@chatmerce.eu).
