Data Processing Agreement

Last updated: 2 October 2026

1. Parties and scope

This Data Processing Agreement (“DPA”) is entered into between the customer using GatPilot (the “Controller”) and TOPFED WEB S.R.L. (IDNO 1026023125543, registered office: s. Pepeni, r-nul Sîngerei, MD-6234, Republic of Moldova), which provides GatPilot (the “Processor”). It applies whenever the Processor processes personal data on behalf of the Controller in providing the service, and forms part of the Terms of service. It is available to Pro and Custom customers; a signed copy is provided on request.

2. Subject matter, nature and purpose

The Processor processes personal data only to provide GatPilot to the Controller: indexing the documents the Controller uploads, generating the assistants' answers, showing conversations in the inbox, delivering messages on the channels the Controller connects and, on the Custom plan, reading data from the Controller's systems to produce reports.

3. Categories of data and data subjects

Data subjects: the Controller's customers who write to its assistants, the Controller's employees added as team members, the Controller's dashboard users and the people who receive reports. Personal data: names, contact details (email, phone number, messaging account), the content of messages, and any personal data contained in the documents or systems the Controller chooses to connect. The Controller should not upload special categories of data unless strictly necessary.

4. Duration

This DPA lasts as long as the Processor processes personal data for the Controller, including the period needed to delete it at the end of the service.

5. Processor obligations

The Processor: processes personal data only on the Controller's documented instructions, including those given through the dashboard settings; ensures that the people authorised to process it are bound by confidentiality; implements the security measures described below; assists the Controller, taking into account the nature of the processing, in responding to data subject requests and in its obligations on security, breach notification and impact assessments; and makes available the information needed to demonstrate compliance with Article 28 GDPR.

6. Security measures

Data stored on servers in Germany, in the EU; traffic encrypted in transit (TLS); AI keys and channel tokens stored encrypted and never shown after saving; role-based access to the dashboard (owner, admin, agent); every request limited to the Controller's own organisation; backups kept for 30 days; read-only access to the Controller's systems on the Custom plan.

7. Sub-processors

The Controller authorises the Processor to use the following sub-processors: a hosting provider in Germany (Hetzner Online GmbH, data centre in Nuremberg); OpenAI and DeepSeek, for the model used on the Free plan; Google Firebase, for authentication; Brevo, for email delivery; Cloudflare, for network delivery and protection; and the messaging platforms the Controller connects. On Pro and Custom, the AI provider used with the Controller's own key acts under the Controller's own contract with that provider. The Processor informs the Controller of any intended change to this list at least 30 days in advance, giving the Controller the opportunity to object.

8. International transfers

Personal data is stored in the EU. The Processor is established in the Republic of Moldova, which does not benefit from an EU adequacy decision; access to personal data from Moldova, for operation and support, is governed by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this DPA by reference.

9. Personal data breaches

The Processor notifies the Controller without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the Controller's data, with the information available at that time, and keeps the Controller informed as the investigation progresses.

10. Audits

The Processor makes available all information necessary to demonstrate compliance with this DPA and allows audits by the Controller or an auditor it mandates, on reasonable notice, during business hours and no more than once a year, unless a breach or a supervisory authority requires otherwise.

11. Deletion or return

At the end of the service, the Processor deletes the Controller's personal data, or returns it if the Controller asks before closing the account, within 30 days, unless the law requires its storage. During the service, conversations are also deleted according to the retention of the Controller's plan.

12. Precedence and contact

In case of conflict between this DPA and the Terms of service, this DPA prevails on data protection matters, and the Standard Contractual Clauses prevail over both. To receive a signed copy, write to info@gatpilot.com with your company's details.