Contents
- 1. Subject Matter and Duration of Processing
- 2. Nature and Purpose of Processing
- 3. Types of Personal Data
- 4. Categories of Data Subjects
- 5. Obligations of the Processor
- 6. Sub-processors
- 7. Technical and Organizational Measures
- 8. Retention Periods
- 9. Rights of Data Subjects
- 10. Notification of Personal Data Breaches
- 11. Deletion and Return
- 12. Audit Rights
- 13. Liability
- 14. Final Provisions
- Signatures
- Annex 1 pursuant to Art. 28 GDPR
- Annex 2 pursuant to Art. 28 GDPR
- Annex 3 pursuant to Art. 28 GDPR
Last updated: September 2026
Note: This Data Processing Agreement (DPA) pursuant to Art. 28 GDPR governs the processing of personal data by the Provider as Processor on behalf of the Customer (Controller) in connection with the use of InsightHub.
1. Subject Matter and Duration of Processing
The subject matter of this Agreement is the processing of personal data by the Processor in connection with the use of InsightHub — a SaaS platform for AI-powered product search, chat assistance, and search analytics.
The duration of the processing corresponds to the term of the service agreement between the Controller (Customer) and the Processor (Provider).
2. Nature and Purpose of Processing
The processing comprises the following activities:
- Provision of the AI assistant on the Customer's website/shop (chat widget) and — where the add-on is subscribed — via WhatsApp and telephone (InsightHub Voice)
- Storage and analysis of search queries, chat sessions, and click paths
- Creation and display of analytics dashboards in the Customer's admin area
- Synchronization of product, content, customer, and order data from connected shop and website systems
- Lead and contact management incl. document storage, helpdesk tickets, review and survey invitations, cart reminders, and automations on behalf of the Customer
- Delivery of transactional and notification emails (e.g., reports, alerts)
3. Types of Personal Data
The following categories of personal data may be processed:
- Search queries, chat messages, WhatsApp messages, and telephone call transcripts (text, no audio recording) of end users
- Contact and lead data: name, email, telephone number (including callers' phone numbers), inquiry, status, notes, custom fields
- Customer and order data from the Customer's shop system (name, email, order number, line items, status), shopping carts incl. proof of consent
- Reviews and survey responses (name, email, rating, free text)
- Technical data: visitor ID, IP address, user agent, timestamps, session assignment
- Customer identifiers optionally passed by the Customer: customer ID, email address, name
- Account data of the Customer's administrators: name, email, password hash, locale, role
- Usage data (page views, timestamps, actions taken)
- Documents and files uploaded by the Customer or by end users (e.g., contracts, ID copies, invoices, images) including file name, file type, size, and assignment to the respective lead — including all personal data contained in these documents
4. Categories of Data Subjects
- End users (customers, visitors) of the website or shop operated by the Customer
- Employees and administrators of the Customer who operate InsightHub
5. Obligations of the Processor
The Processor undertakes:
- To process personal data only on documented instructions from the Controller
- To ensure that persons authorized to process the personal data have committed themselves to confidentiality
- To take all technical and organizational measures required pursuant to Art. 32 GDPR (see Annex 2)
- Not to engage any further sub-processors beyond those listed in Annex 3 without prior authorization
- To assist the Controller in fulfilling its obligations toward data subjects (Art. 12–22 GDPR)
- To assist the Controller with data protection impact assessments and notification obligations
- To delete or return all personal data after the end of the processing
- To make available to the Controller all information necessary to demonstrate compliance and to allow for audits
6. Sub-processors
The Processor engages sub-processors for hosting and network, AI services, email delivery, payment processing, and — only where the respective add-ons are subscribed — for WhatsApp messaging and telephony. A complete list including purpose and server location is set out in Annex 3.
Where further sub-processors are engaged, the Controller will be informed in advance with reasonable notice and given the opportunity to object. In the event of a justified objection, both parties have a right of extraordinary termination.
7. Technical and Organizational Measures
The Processor guarantees the following security measures:
7.1 Confidentiality
- Access control through authentication and role-based permissions
- Restriction of access to authorized employees
- Encryption of data in transit (TLS 1.2+)
- Encryption of sensitive data at rest
7.2 Integrity
- Logging of input, modification, and deletion operations
- Input validation and protection against injection attacks
- Secure transmission paths between application components
7.3 Availability
- Regular, automated, and encrypted backups (stored separately from the production system) with verified restoration
- Monitoring of services and incident notifications
- Documented recovery procedures
7.4 Resilience
- Scalable infrastructure in certified EU data centers
- Monitoring of system resources
- Redundant components where economically reasonable
8. Retention Periods
| Type of Data | Retention Period |
|---|---|
| Search queries, chat, WhatsApp, and telephone transcripts | for the term of the service agreement; individually deletable by the Controller at any time; complete deletion no later than 30 days after the end of the agreement |
| Leads, contacts, order, and review data | for the term of the service agreement or until deleted by the Controller |
| Captured shopping carts | according to the period configured by the Controller (default 60 days) |
| Aggregated analytics data | for the term of the service agreement |
| Account data of administrators | term of the service agreement |
| Technical records / logs | up to 90 days |
| Uploaded documents and files | for the term of the service agreement; deletion at any time by the Controller in the system or on instruction, at the latest upon the end of the agreement (Section 11). No automatic deletion takes place after expiry of a period. |
| Billing-relevant data | according to statutory retention periods |
9. Rights of Data Subjects
The Processor assists the Controller in fulfilling its obligations pursuant to Art. 12–22 GDPR, in particular with regard to:
- Requests for access (Art. 15 GDPR)
- Requests for rectification (Art. 16 GDPR)
- Requests for erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
10. Notification of Personal Data Breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. The notification shall at least contain:
- A description of the nature of the breach
- The categories and approximate number of data subjects and data records concerned
- The likely consequences of the breach
- The countermeasures taken or proposed
11. Deletion and Return
After the end of the contractual relationship, all personal data processed on behalf of the Controller will be deleted or — at the Controller's request — returned, unless statutory retention obligations prevent this. Confirmation of deletion will be provided upon request.
12. Audit Rights
The Controller has the right to verify compliance with the technical and organizational measures. The Processor shall provide the necessary information and shall allow audits in a reasonable manner after prior coordination.
13. Liability
Liability is governed by the provisions of Art. 82 GDPR. Each party is liable for the damage caused by processing that does not comply with the GDPR, in accordance with its degree of fault. In all other respects, the liability provisions of the General Terms and Conditions apply.
14. Final Provisions
This Data Processing Agreement is governed by Austrian law. Amendments and supplements must be made in writing (text form is sufficient). Should individual provisions be invalid, the validity of the remaining provisions shall remain unaffected.
Important: By using InsightHub, you accept this Data Processing Agreement as part of the General Terms and Conditions. A physical signature is optional (see below) and available upon request.
Signatures
Controller (Customer)
Annex 1 pursuant to Art. 28 GDPR
Register of Personal Data and Purpose of Processing
Types of Data
- Search queries, chat, WhatsApp, and telephone transcripts (text) of end users
- Lead, contact, customer, and order data as well as reviews, survey responses, and shopping carts (see Section 3)
- Identifiers: visitor ID, IP address, user agent, cookie/LocalStorage IDs
- Optionally passed customer identifiers: customer ID, email, name
- Product and content data synchronized from shop/CMS systems
- Administrator account data (name, email, password hash, two-factor secret if enabled)
- Usage and interaction logs (timestamps, actions taken, result metadata)
Data Subjects
- End customers and website visitors of the Controller
- Employees and administrators of the Controller
Purposes of Processing
- Provision of the contractually owed services (search, chat, analytics)
- Technical provision, troubleshooting, and security of the service
- Analysis to improve search quality (aggregated, pseudonymized)
- Billing, contact, and customer support
Annex 2 pursuant to Art. 28 GDPR
Technical and Organizational Measures pursuant to Art. 32 GDPR
I. Confidentiality
Encryption
- Data transmission via TLS 1.2+
- Encryption of sensitive data at rest (AES-256 where possible)
- HTTPS on all public endpoints
Physical Access Control
- Server locations in certified EU data centers
- Physical access controls of the hosting providers
- 24/7 monitoring of the server infrastructure by the hosting provider
System Access Control
- Authentication with username/password, optional two-factor authentication (2FA)
- Password policies (minimum length, hashing)
- Logging of login attempts
- Firewall protection at server and application level
- API keys with restricted scope; separate public (widget ID) and private keys
Data Access Control
- Role- and permission-based access concept (least privilege)
- Regular review of access rights
- Audit logs for administrative actions
- Secure erasure of storage media before reuse
Separation Control
- Logical tenant separation (tenant ID) at application and database level
- Separation of production and test environments
II. Integrity
Transfer Control
- Encryption of all data transmissions (TLS)
- No unencrypted email transmission of sensitive data
- Secure API communication between gateway, app, and engine
Input Control
- Logging of security-relevant inputs, modifications, and deletion operations
- Traceability through individual user identification
- Retention of logs in accordance with purpose limitation and retention periods
III. Availability and Resilience
Availability Control
- Backup and recovery concept with regular backups
- Uninterruptible power supply and redundant servers at the hosting provider
- Monitoring of relevant services and alerting
- DDoS protection at the edge level (via hosting provider)
Rapid Recoverability (Art. 32(1)(c) GDPR)
- Defined escalation and recovery procedures
- Regular tests of backup restoration
IV. Procedures for Regular Review
- Internal security reviews of the TOMs
- Dependency and security updates in the deployment process
- Awareness-raising and training of employees on data protection
- Documentation of all processing activities
Annex 3 pursuant to Art. 28 GDPR
Sub-processors
For the processing of data on behalf of the Customer, the Provider uses the services of the following third parties ("sub-processors"):
Hosting, Storage, and Network
| Company | Purpose | Server Location |
|---|---|---|
| Hetzner Online GmbH Industriestr. 25, 91710 Gunzenhausen, Germany | Server infrastructure, databases, object storage for documents (unless the Customer uses its own storage), encrypted backups (Storage Box) | EU (Germany: Falkenstein, Nuremberg; Finland: Helsinki) |
| Webnestify s.r.o. https://webnestify.cloud | Managed hosting and server administration | EU |
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, USA | Network delivery, DDoS and bot protection, TLS termination | EU data centers; processing in the USA possible (EU-US Data Privacy Framework, standard contractual clauses) |
AI Services (Language Models and Embeddings)
| Company | Purpose | Server Location |
|---|---|---|
| Mistral AI 15 rue des Halles, 75001 Paris, France | Language models and embeddings (default); no training on customer data | EU |
| OpenAI Ireland Ltd. 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland | Language models — only if the Controller stores its own OpenAI keys | EU/USA (standard contractual clauses) |
Email Delivery
| Company | Purpose | Server Location |
|---|---|---|
| ActiveCampaign, LLC (Postmark) 1 N Dearborn St, Chicago, IL 60602, USA | Delivery of notification, confirmation, review, reminder, and report emails; processing of inbound replies | USA (EU-US Data Privacy Framework, standard contractual clauses) |
Payment Processing
| Company | Purpose | Server Location |
|---|---|---|
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland | Payment processing and subscription management (Customer account data, no end-user data) | EU/USA (standard contractual clauses) |
Messaging and Telephony (only where the add-on is subscribed)
| Company | Purpose | Server Location |
|---|---|---|
| Meta Platforms Ireland Ltd. Merrion Road, Dublin 4, Ireland | WhatsApp Business Cloud API — delivery and receipt of WhatsApp messages (WhatsApp add-on) | EU/USA (EU-US Data Privacy Framework) |
| Twilio Ireland Ltd. 3 Dublin Landings, North Wall Quay, Dublin 1, Ireland | Telephony (phone numbers, call signaling, media stream) for InsightHub Voice | EU region; USA possible (standard contractual clauses) |
| Deepgram, Inc. 548 Market St, San Francisco, CA 94104, USA | Speech recognition and speech synthesis for InsightHub Voice (audio is not stored permanently) | USA (standard contractual clauses) |
Other Integrations (only at the Controller's instigation)
| Company | Purpose | Server Location |
|---|---|---|
| Google Ireland Limited Gordon House, Barrow Street, Dublin 4, Ireland | Import of public Google reviews and replies via Google Business Profile when the Controller connects its account | EU/USA (EU-US Data Privacy Framework) |
The list may be adjusted in the course of changes; the Provider will inform the Customer in good time about new sub-processors.
