DATA PROCESSING AGREEMENT
This Data Processing Agreement (the "DPA") is made by and between:
Empacer Limited, a company incorporated under the laws of the Republic of Cyprus, with registered office at 6 Vasili Vrionidi Str, 5th floor, Limassol, 3095, Cyprus ("Processor" or "Empacer"); and
the customer entity or individual agreeing to these terms ("Controller" or "Customer").
This DPA forms part of, and is incorporated by reference into, the Terms of Service or other written or electronic agreement under which Empacer provides the Services (the "Principal Agreement"). Where this DPA and the Principal Agreement conflict in respect of the Processing of Personal Data, this DPA prevails. By accepting the Principal Agreement or by using the Services, the Customer agrees to this DPA.
Empacer may update this DPA where required by a change in law, regulatory guidance or the Services. If Empacer makes a material change, Empacer will notify Customer, and the updated DPA will be effective upon posting or as otherwise communicated in writing.
Definitions
1.1 Capitalised terms not defined below have the meaning given in Applicable Data Protection Law or in the Principal Agreement.
1.2 "Applicable Data Protection Law" means all data protection and privacy laws applicable to the Processing of Customer Personal Data under the Principal Agreement, as amended or replaced from time to time, including, where applicable, Regulation (EU) 2016/679 ("EU GDPR"), the UK GDPR together with the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US Privacy Laws.
1.3 "US Privacy Laws" means the data protection and privacy laws applicable to residents of the United States, including the California Consumer Privacy Act as amended ("CCPA").
1.4 "Customer Personal Data" means Personal Data that Customer or its authorised users submit to the Services, or that Empacer accesses through a third-party account connected on Customer's instruction, and that Empacer Processes on Customer's behalf. This includes the content of Customer's communications with its own clients in a connected mailbox, messaging account or calendar.
1.5 "Services" means the AI assistant, applications and related services Empacer provides under the Principal Agreement.
1.6 "Sub-processor" means any third party engaged by Empacer to Process Customer Personal Data, as listed in Annex 1.
1.7 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data stored, transmitted or otherwise Processed by Empacer, its Sub-processors or any other third party acting on Empacer's behalf.
1.8 "Standard Contractual Clauses" means the contractual clauses approved by the European Commission for the transfer of Personal Data to third countries, as updated or replaced from time to time.
Roles of the parties
2.1 Customer acts as Controller and Empacer as Processor in respect of Customer Personal Data. Where Customer is itself a processor for a third party, Empacer acts as a sub-processor and Customer warrants that it is authorised to appoint Empacer.
2.2 Empacer acts as an independent controller in respect of account, billing, authentication and security data, and in respect of the generation record described in clause 8.2, which it processes under its own privacy notice.
2.3 Customer instructions. This DPA, the Principal Agreement, the configuration Customer selects within the Services, and commands given by Customer's authorised users together constitute Customer's documented instructions. Empacer Processes Customer Personal Data only in accordance with those instructions, unless required otherwise by applicable law, in which case Empacer will inform Customer before Processing unless legally prohibited from doing so.
2.4 Notices to Customer. Empacer will promptly inform Customer in writing if, in its opinion, an instruction infringes Applicable Data Protection Law. Empacer will, to the extent legally permitted, inform Customer if it receives a legally binding request for disclosure of Customer Personal Data from a law enforcement or other public authority.
Details of the Processing
3.1 Subject matter and duration. The subject matter is the provision of the Services under the Principal Agreement. The duration is the term of the Principal Agreement and such further time as is required for the parties to perform their obligations following the end of the term, including deletion of data.
3.2 Nature and purpose of the Processing:
- reading and organising content in connected mailboxes, messaging accounts and calendars;
- preparing drafts of replies, posts and other content for Customer's approval;
- carrying out approved actions through connected accounts;
- retaining facts extracted from the above so that the Services provide continuity between sessions;
- generating text, images and other content on Customer's instruction;
- transcribing voice commands given by Customer's authorised users;
- account management, subscription and billing, and product analytics and improvement.
3.3 Categories of Customer Personal Data. The categories depend on Customer's use of the Services, which Customer determines and controls, and may include but are not limited to: contact details; communication content, including attachments and the drafts produced from it; appointment and scheduling details; facts extracted into the assistant's memory; transcripts of voice commands; technical identifiers and access tokens for connected accounts; and any other information provided by Customer or by Customer's clients in unstructured data.
3.4 Categories of Data Subjects. These may include but are not limited to Customer's authorised users; Customer's clients and prospective clients who communicate with Customer through a connected channel; and any other individual whose Personal Data appears in a connected channel or is submitted by Customer.
3.5 Customer should not intentionally submit special categories of Personal Data, including health, genetic, biometric or children's data, unless the parties have agreed in writing to the necessary safeguards. If such data is submitted inadvertently, Empacer will apply appropriate security measures to it and will process it as directed by the Customer.
Empacer's obligations
4.1 Confidentiality. Empacer ensures that all persons authorised to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and receive data protection and security training.
4.2 Security. Taking into account the nature, scope, context and purposes of the Processing and the risk to Data Subjects, Empacer implements and maintains the technical and organisational measures set out in Annex 2, and will not make changes that materially reduce the overall level of security.
4.3 Sub-processors. Customer acknowledges and agrees that Empacer uses third parties to provide the Services. A list of current Sub-processors is maintained and updated by Empacer and is set out in Annex 1. Empacer will give notice of new Sub-processors by posting an update or by email. If Customer reasonably objects to a new Sub-processor on legitimate data protection grounds, Empacer will work with Customer in good faith to address the objection, which may include offering an alternative arrangement or the option for Customer to terminate the affected Services.
4.4 Sub-processor obligations. Empacer enters into contractual arrangements with each Sub-processor imposing obligations comparable to those imposed on Empacer under this DPA, including confidentiality and appropriate technical and organisational measures. Subject to the limitations of liability in the Principal Agreement, Empacer remains liable for the acts and omissions of its Sub-processors to the same extent as it would be liable under this DPA had it performed those acts or omissions itself.
4.5 Data Subject requests. Taking into account the nature of the Processing, Empacer will, to the extent legally permitted, inform Customer if it receives a request from a Data Subject in respect of Customer Personal Data. Empacer will not respond to such a request without Customer's prior written authorisation, except that Customer authorises Empacer to redirect the request as necessary to allow Customer to respond directly. Empacer will provide reasonable assistance to enable Customer to respond.
4.6 Personal Data Breach. Empacer will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, describing the nature of the breach, its likely consequences, the measures taken or proposed and a contact point, and will provide reasonable assistance to enable Customer to comply with its own obligations. Empacer will not notify a supervisory authority or Data Subjects on Customer's behalf unless instructed in writing or required by law. Customer may contact privacy@empacer.com to report an incident.
4.7 Assistance with impact assessments. Where the type of Processing, in particular using new technologies, and taking into account the nature, scope, context and purposes of the Processing, is likely to result in a high risk to the rights and freedoms of natural persons, Empacer will, prior to the Processing and taking into account the nature of the Processing and the information available to it, provide reasonable assistance to Customer in carrying out an assessment of the impact of the envisaged Processing operations on the protection of Personal Data.
4.8 Supervisory Authority. Empacer will provide Customer with reasonable assistance in any prior consultation with a supervisory authority arising from such an assessment, limited to information concerning the Processing carried out by Empacer. Empacer acknowledges that a supervisory authority may address written recommendations to Empacer and exercise its powers under Applicable Data Protection Law, and will inform Customer, to the extent legally permitted, of any such recommendation or exercise of powers that concerns the Processing of Customer Personal Data.
4.9 Deletion and return. Following expiry or termination of the Principal Agreement, Empacer will, at Customer's choice, return or delete Customer Personal Data. Where deletion is requested, or where no choice is made, Empacer will delete Customer Personal Data from its active systems within thirty (30) days, except that:
(a) technical logs and generation records are deleted within ninety (90) days of their creation; and
(b) copies in backups held with our hosting Sub-processor are deleted within fourteen (14) days after deletion from active systems.
4.10 Rectification and deletion on request. Empacer will rectify or delete individual items of Customer Personal Data within thirty (30) days of Customer's request, unless retention is required by law. Copies in technical logs, generation records and backups are deleted on the timelines in Section 4.9.
Customer's obligations
5.1 Customer represents, warrants and covenants that it has provided all necessary notices and holds and will maintain all necessary rights, consents and authorisations required under Applicable Data Protection Law to provide Customer Personal Data to Empacer and to authorise Empacer to Process it in accordance with this DPA and the Principal Agreement.
5.2 Customer represents and warrants that it has complied and will continue to comply with Applicable Data Protection Law, that Customer Personal Data has been collected lawfully and is limited to what is necessary for the purposes for which it is Processed, and that its instructions comply with applicable law.
5.3 Configurations. Without prejudice to Empacer's obligations under clause 4.2, Customer is responsible for the configuration and design decisions it makes within the Services, including which third-party accounts to connect, which automations to enable, which approval settings to apply and which retention and deletion settings to select, and for implementing them in a manner that complies with Applicable Data Protection Law.
5.4 Where Customer submits or provides access to Personal Data relating to third parties, including its own clients, Customer is solely responsible for ensuring that it has the necessary legal basis to do so. Empacer accepts no responsibility where Customer lacks such a basis.
5.5 Customer will reasonably cooperate with Empacer to assist Empacer in performing its obligations under Applicable Data Protection Law.
Right to audit
6.1 Upon Customer's reasonable written request, and subject to reasonable confidentiality controls, Empacer will make available to Customer any available audit reports or certifications and other information reasonably necessary to demonstrate compliance with this DPA. To the extent that this information does not provide sufficient information, following a Personal Data Breach, or where Customer is required to respond to a regulatory authority audit, Customer agrees to a mutually agreed-upon audit plan with Empacer that: (a) provides written notice to Empacer in a timely fashion; (b) requests access only during business hours and requires that the audit be conducted in a manner that causes minimal disruption; (c) accepts billing to Customer at Empacer's reasonable costs of supporting the audit; (d) occurs no more than once annually, except following a Personal Data Breach or where a regulatory authority requires it; (e) restricts its findings to only data relevant to Customer; and (f) obligates Customer and any auditor, to the extent permitted by law or regulation, to keep confidential any information gathered that, by its nature, should be confidential.
International data transfers
7.1 Empacer is established in the European Union. Customer Personal Data is hosted on Amazon Web Services in the United States and may also be Processed by other Sub-processors outside the EU/EEA, including in the United States, as set out in Annex 1.
7.2 Where required by Applicable Data Protection Law for cross-border transfers (e.g., EU/EEA, UK, or Swiss Personal Data), Empacer relies on legally recognized transfer mechanisms such as Standard Contractual Clauses or other adequacy frameworks.
7.3 Empacer will provide a copy of the relevant transfer mechanism on request. Where Empacer redacts any part of it to protect business secrets, it will provide a meaningful summary of what has been redacted.
Generated content
8.1 Content generated through the Services, including posts and images, is stored in the Customer's account. Customer can delete individual items, including images at any time. Deletion takes effect in accordance with clause 4.10.
8.2 Empacer keeps an internal record of generation events containing a content hash, the prompt, the safety classification result and the provenance marking status. Empacer keeps this record as an independent controller for the purposes of detecting misuse of the Services and of establishing, exercising and defending legal claims, for a period of 90 days. The record is not disclosed to other customers and is not used to train or improve any model.
US Privacy Laws
9.1 To the extent US Privacy Laws apply, Empacer agrees:
- not to provide Customer with monetary or other valuable consideration in exchange for Customer Personal Data. The parties acknowledge that Customer has not "sold" Customer Personal Data to Empacer;
- not to "sell" or "share" Customer Personal Data as those terms are defined in US Privacy Laws;
- where Customer Personal Data is subject to the CCPA: not to retain, use, disclose or otherwise Process it except as necessary for the business purposes specified in this DPA and the Principal Agreement; not to retain, use, disclose or otherwise Process it outside the direct business relationship between the parties; not to combine it with Personal Data received from or on behalf of a third party or collected from Empacer's own interactions with individuals, except as permitted under the CCPA or as directed by Customer; to notify Customer without undue delay if Empacer determines that it can no longer meet its obligations under the CCPA; and, where Customer reasonably believes that Empacer's Processing is inconsistent with the CCPA, to work with Customer in good faith to remedy the issue or, failing that, to stop Processing the affected data on Customer's written instruction.
9.2 Customer agrees not to take any action that would render the provision of Customer Personal Data to Empacer a "sale" or a "share" under US Privacy Laws, or that would render Empacer not a "service provider" under the CCPA or a "processor" under other US Privacy Laws.
Liability
10.1 Liability under this DPA is subject to the limitations and exclusions set out in the Principal Agreement, except to the extent Applicable Data Protection Law does not permit them.
10.2 Each party indemnifies the other against costs, damages and fines arising from its own breach of this DPA or of Applicable Data Protection Law, to the extent provided in the Principal Agreement.
Annex 1 — Sub-processors
Below is a non-exhaustive list of the key Sub-processors used by Empacer for hosting, data processing or other activities related to the Services. This list may be updated from time to time in accordance with clause 4.3.
- Amazon Web Services (Cloud infrastructure)
- Google Cloud Platform (hosting, data storage)
- Google Vertex (AI infrastructure)
- OpenAI (AI infrastructure)
- Anthropic (AI infrastructure)
- OpenRouter (AI infrastructure)
- Soniox (AI infrastructure: Speech to Text)
- LiveKit (realtime communication, AI infrastructure)
- Composio (connection layer for third-party accounts)
- Vanta (Security compliance automation and monitoring)
Annex 2 — Technical and organisational measures
Security controls:
- Access controls: role-based access on a least-privilege basis; multi-factor authentication for administrative access; access revoked when no longer required.
- Encryption: data encrypted in transit (TLS 1.2 and TLS 1.3) and at rest, including backups; access tokens for connected accounts stored encrypted.
- Cloud data centres with industry-standard physical security and access restricted to authorised personnel.
- Monitoring and logging: activity logs, security alerting and anomaly detection.
- Incident response: defined process for handling security incidents and Personal Data Breaches, with notification to Customer in accordance with this DPA.
- Employee training: security and data protection training for personnel with access to Customer Personal Data.
- Logical separation of customer data; regular backups with restoration testing.
- Vulnerability scanning, patch management and change management with review before deployment to production.
- Data minimisation and retention: Customer Personal Data kept only as long as needed to provide the Services or to comply with a legal obligation.
- Data deletion: secure deletion in accordance with clauses 4.9 and 4.10.