Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you, the customer (“Controller”), and Sen Balance Limited (“AOVA”, the “Processor”). It applies whenever AOVA processes personal data on your behalf in providing the Service, and it sets out the terms required by Article 28 of the GDPR. You accept it by accepting the Terms; no separate signature is needed. If this DPA conflicts with the Terms, this DPA prevails on data protection matters.
1. Definitions
“GDPR” means Regulation (EU) 2016/679. “Data Protection Law” means the GDPR, the Irish Data Protection Acts 1988–2018 and any other data protection law that applies to the processing. “Customer Personal Data” means personal data that AOVA processes on your behalf as described in section 2. Terms such as “controller”, “processor”, “data subject”, “personal data breach” and “processing” have the meanings given in the GDPR.
2. Details of the processing
| Subject matter and purpose | Providing the Service: storing and indexing Knowledge Base content, transcribing media, generating AI answers, delivering messages through connected channels, and keeping conversation history for your dashboard. |
|---|---|
| Nature of processing | Collection, storage, retrieval, transcription, indexing (vector embeddings), AI inference, transmission and deletion. |
| Duration | For the term of the Terms of Service, plus up to 30 days after termination for deletion. |
| Categories of data subjects | Your end users who interact with your assistants; individuals named or described in content you upload; your staff and authorised users. |
| Types of personal data | Messages and their content; channel identifiers (for example a Telegram chat ID, WhatsApp phone number or widget contact ID); names and contact details your end users share; any personal data contained in documents, audio or video you upload. |
| Special categories | Not intended. You must not submit special category data (GDPR Art. 9) or criminal-offence data (Art. 10) unless you have a lawful basis and appropriate safeguards for it. |
3. Your obligations as controller
You are responsible for the lawfulness of the processing you instruct. That includes having a lawful basis, giving your end users the privacy information required by GDPR Articles 13 and 14, telling them they are interacting with an AI system, and making sure your instructions comply with Data Protection Law. Your use of the Service and its configuration are your documented instructions to AOVA.
4. AOVA’s obligations as processor
- Instructions. AOVA processes Customer Personal Data only on your documented instructions, including for international transfers, unless EU or Member State law requires otherwise. If so, AOVA will tell you before processing unless the law prohibits it. AOVA will tell you if it believes an instruction infringes Data Protection Law.
- No other use. AOVA will not use Customer Personal Data for its own purposes. It will not sell it, and it will not use it to train AI models.
- Confidentiality. AOVA ensures that everyone authorised to process Customer Personal Data is bound by confidentiality.
- Security. AOVA implements the technical and organisational measures required by GDPR Article 32, described in section 8.
- Data subject requests. Taking into account the nature of the processing, AOVA will assist you with appropriate measures in responding to data subjects exercising their rights. AOVA will pass on any request it receives directly and will not respond itself unless you authorise it.
- Assistance. AOVA will reasonably assist you with your obligations under GDPR Articles 32 to 36, considering the information available to it. Those obligations cover security, breach notification, data protection impact assessments and prior consultation.
- Deletion. When the Terms end, AOVA will delete Customer Personal Data within 30 days, unless EU or Member State law requires it to keep the data. Before then, you can delete content yourself in the dashboard or ask us for a copy of it.
- Information and audits. AOVA will make available the information reasonably needed to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, by you or an auditor you appoint. Audits happen on reasonable notice, no more than once a year unless a breach or a regulator requires otherwise, and under confidentiality. AOVA may first answer with documentation, including its sub-processors' certifications (for example AWS ISO 27001 and SOC 2 reports).
5. Sub-processors
You give AOVA general authorisation to engage sub-processors. AOVA imposes data protection obligations on each sub-processor that are no less protective than this DPA, and it remains liable to you for their performance. AOVA's current sub-processors are:
| Sub-processor | Service | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, storage, databases, AI model inference (Amazon Bedrock), transcription (Amazon Transcribe), email delivery | EU (Ireland). For models offered only through AWS global inference (currently xAI Grok), a request may be processed in other AWS regions. |
AOVA will update this page and notify you by email at least 30 days before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot reasonably accommodate your objection, you may terminate the affected Service and receive a refund of any prepaid amount for the unused period.
Messaging platforms you choose to connect, such as Telegram or WhatsApp (Meta), are not AOVA sub-processors. You engage them directly under their own terms. Stripe processes AOVA's billing data about you, not Customer Personal Data.
6. International transfers
AOVA stores Customer Personal Data in the EU. AOVA will not transfer it outside the European Economic Area except to a country with an adequacy decision or under appropriate safeguards (GDPR Article 46). Such safeguards include the European Commission's Standard Contractual Clauses that AWS incorporates in its data processing terms. If you choose a model that runs on AWS global inference, you instruct AOVA to process the relevant requests on that basis.
7. Personal data breaches
AOVA will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information you reasonably need to meet your obligations under GDPR Articles 33 and 34, as far as that information is available, and AOVA will provide further information as it becomes available. AOVA will take reasonable steps to contain the breach and reduce its effects. Notifying you is not an admission of fault.
8. Technical and organisational measures
- Encryption in transit (TLS) and at rest (AWS-managed keys).
- Logical separation of each customer's data. Every request is authorised against the account that owns the data.
- Access control: least-privilege IAM roles for each service, access to production limited to authorised personnel, and multi-factor authentication for administrative access.
- Authentication through Amazon Cognito. Passwords are never stored in plain text.
- Secrets kept in AWS Secrets Manager. Webhook requests are verified by signature.
- Monitoring, logging and alerting on errors and unusual activity.
- Infrastructure defined as code and changes reviewed before deployment.
- Hosting on AWS data centres, which hold ISO 27001, ISO 27017, ISO 27018 and SOC 2 certifications.
9. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where Data Protection Law does not allow those limitations. This DPA stays in force for as long as AOVA processes Customer Personal Data on your behalf. It is governed by the laws of Ireland. For questions about this DPA, email senlimitedie@gmail.com.