← На головну

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between Individual Entrepreneur Dmytro Buslov ("Processor", "ChatsControl") and the customer ("Controller") and governs the processing of personal data by the Processor on behalf of the Controller in connection with the ChatsControl translation service.

1. Definitions

"Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Sub-Processor" have the meanings given in the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"). "Service" means the ChatsControl document translation service.

2. Subject matter and duration

The Processor processes Personal Data on behalf of the Controller solely to provide the Service. Processing continues for the term of the underlying service agreement plus the data retention periods specified in Annex 2.

3. Nature and purpose of processing

The Processor processes Personal Data uploaded by the Controller's authorized users (account credentials, document contents) for the purpose of (a) performing document translation, (b) authenticating users, (c) providing technical support requested by the Controller, and (d) producing aggregated, anonymized service metrics.

4. Categories of Data Subjects and Personal Data

5. Obligations of the Processor

6. Obligations of the Controller

7. Sub-Processors

The Controller authorizes the Processor to engage the Sub-Processors listed in Annex 3. The Processor will:

8. International transfers

Where the Processor or its Sub-Processors transfer Personal Data outside the European Economic Area, such transfers are made under (a) an adequacy decision of the European Commission, or (b) the EU Standard Contractual Clauses (SCCs) approved by Decision (EU) 2021/914 (Module 3, Processor to Sub-Processor), or (c) other appropriate safeguards under Art. 46 GDPR. The SCCs are incorporated by reference where applicable.

9. Security, incidents, and audits

10. Liability

Liability under this DPA is subject to the liability limitations of the underlying service agreement, except where prohibited by applicable law.

11. Term and termination

This DPA remains in effect for as long as the Processor processes Personal Data on behalf of the Controller. Sections 5 (last bullet), 9, 10, and 11 survive termination.

Annex 1 — Technical and organizational measures (summary)

Full details, including a transparent list of measures not yet implemented (disk encryption at rest, automated backups, SOC 2, external pentest): /security.

Annex 2 — Retention

Annex 3 — Sub-Processors

Sub-ProcessorPurposeLocationPrivacy
OpenRouter, Inc. LLM gateway for translation and OCR. All requests are routed to Google Gemini via OpenRouter. United States link
Mailgun Technologies, Inc. Transactional email delivery (verification codes) European Union link
Stripe, Inc. Payment processing United States / EU link
Hetzner Online GmbH Server hosting and data storage European Union (Germany / Finland) link
Cloudflare, Inc. DNS, DDoS protection, CDN Global link
Google LLC (Analytics) Website usage analytics (consent-based) United States / EU link