Last Updated: 17 AUGUST 2026
Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) is an annex and an integral part of the End-User License Agreement (“EULA”) between Pametne Tehnologije d.o.o. (“Processor”) and the User (“Controller”).
This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the AI Leads Antispam Agent (the “Application”).
1. Subject and Duration
1.1. The Processor provides the Application to the Controller for the automated analysis and classification of incoming emails for spam and lead detection purposes.
1.2. In providing the Application, the Processor may process personal data contained in incoming emails obtained from the Controller’s Bitrix24 environment.
1.3. The Processor shall process personal data only on behalf of and in accordance with the documented instructions of the Controller, as set out in the EULA, this DPA, the applicable Privacy Policy, the Application configuration, and the Controller’s use of the Application.
1.4. This DPA shall remain in force for the duration of the EULA and for as long as the Processor processes personal data on behalf of the Controller.
1.5. The Processor shall not process personal data after termination of the EULA except to the extent necessary to comply with applicable law or to complete the deletion process described in this DPA and the Privacy Policy.
2. Roles of the Parties
2.1. The Controller determines the purposes and means of the processing of personal data and is responsible for ensuring that the processing is lawful.
2.2. The Processor processes personal data on behalf of the Controller for the purposes described in this DPA.
2.3. The Controller is responsible for determining the legal basis for processing personal data contained in incoming emails and for ensuring that the processing is permitted under applicable data-protection law.
2.4. The Controller is responsible for providing any required privacy notices to data subjects and for ensuring that its use of the Application complies with applicable laws.
2.5. Nothing in this DPA transfers responsibility for the lawfulness of the Controller’s processing activities from the Controller to the Processor.
3. Subject Matter and Purpose of Processing
3.1. The subject matter of processing is the provision of AI-powered email analysis and classification functionality within Bitrix24.
3.2. The purposes of processing include:
3.3. The Processor shall not use personal data for advertising, sale of personal data, or any purpose unrelated to providing the Application, except where otherwise required by applicable law.
4. Categories of Data Subjects
Depending on the content of incoming emails, the categories of data subjects may include:
The Controller determines which categories of data subjects are included in the data submitted to the Application.
5. Categories of Personal Data
The Processor may process the following categories of personal data:
The actual categories of personal data processed depend on the content of the incoming emails provided by the Controller.
6. Special Categories of Personal Data
6.1. The Application is not intended for the processing of special categories of personal data within the meaning of Article 9 GDPR.
6.2. The Controller shall not intentionally submit special categories of personal data to the Application unless such processing is permitted by applicable law and the Controller has established an appropriate legal basis and implemented the required safeguards.
6.3. If special-category data is inadvertently contained in an incoming email, the Processor shall process such data only to the extent necessary to provide the Application and in accordance with the Controller’s documented instructions and applicable law.
7. Processing Operations
The processing activities may include:
8. Instructions from the Controller
8.1. The Controller’s instructions for processing are defined by:
8.2. The Processor shall inform the Controller if, in its reasonable opinion, an instruction infringes the GDPR or other applicable data-protection law.
8.3. The Processor shall not be required to follow an instruction that would require it to violate applicable law.
9. Confidentiality
9.1. The Processor shall ensure that persons authorized to process personal data are subject to appropriate confidentiality obligations or an appropriate statutory obligation of confidentiality.
9.2. Access to personal data shall be limited to personnel and authorized service providers who require access for the performance of their duties.
9.3. The Processor shall take reasonable measures to ensure that persons authorized to process personal data process such data only in accordance with the Processor’s instructions and applicable law.
10. Technical and Organizational Measures
10.1. The Processor shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the requirements of Article 32 GDPR.
10.2. Such measures may include:
10.3. The Processor shall periodically review and, where appropriate, update its technical and organizational measures to maintain an appropriate level of security.
11. Subprocessors
11.1. The Controller generally authorizes the Processor to engage subprocessors where necessary to provide the Application.
11.2. The Processor currently uses or may use the following categories of subprocessors:
11.2.1. Mistral AI
11.2.2. OpenAI
11.2.3. Hosting and Infrastructure Providers
The Processor may use hosting and infrastructure providers located within the European Union to store and process data required to provide the Application, including embeddings, AI analysis results, configuration data, and technical data.
The Processor shall maintain an up-to-date list of applicable infrastructure subprocessors.
11.3. The Processor shall enter into a written agreement with each subprocessor requiring the subprocessor to provide appropriate data-protection guarantees and to comply with obligations applicable to the processing activities delegated to it.
11.4. The Processor shall remain responsible to the Controller for the performance of the Processor’s obligations concerning the processing activities carried out by its subprocessors, to the extent required by Article 28 GDPR.
12. Changes to Subprocessors
12.1. The Processor may appoint, replace, or remove subprocessors where reasonably necessary to provide, maintain, secure, or improve the Application.
12.2. The Processor shall inform the Controller of intended changes concerning the addition or replacement of subprocessors in accordance with Article 28 GDPR.
12.3. Where required by applicable law, the Controller may object to the appointment of a new subprocessor on reasonable data-protection grounds.
12.4. If the Controller objects to a proposed subprocessor and the parties cannot reasonably resolve the objection, the Processor may, where permitted by applicable law, provide an alternative configuration or terminate the affected service in accordance with the EULA.
13. International Data Transfers
13.1. The Processor shall not transfer personal data to a third country or international organization except in accordance with Chapter V GDPR.
13.2. For EU Users, Mistral is selected by default in order to provide a GDPR-oriented configuration.
13.3. Depending on the selected AI provider, model, geographic configuration, and applicable technical infrastructure, personal data may be processed outside the European Economic Area.
13.4. The Controller acknowledges and authorizes the use of the authorized AI subprocessors described in this DPA, including processing that may involve international transfers where applicable.
13.5. Where a transfer of personal data to a third country requires an appropriate safeguard under Chapter V GDPR, the Processor shall implement an applicable transfer mechanism, such as:
13.6. Where required, the Processor shall take into account applicable transfer impact assessments and supplementary measures in relation to international transfers.
13.7. The Controller remains responsible for determining whether its instructions concerning international transfers are appropriate for its particular processing activities and legal obligations.
13.8. Where the Controller manually selects an AI provider or model that may result in processing outside the European Economic Area, the Controller acknowledges that such selection may result in an international transfer of personal data.
13.9. The “Use GDPR compliant model” label in the Application is an interface indication only and does not constitute a representation or guarantee that a particular model, provider, configuration, or processing activity is compliant with the GDPR.
13.10. The Controller remains responsible for assessing whether the selected AI provider and configuration satisfy the Controller’s applicable data-protection obligations.
14. Assistance with Data Subject Rights
14.1. Taking into account the nature of the processing, the Processor shall assist the Controller, insofar as reasonably possible, with the Controller’s obligations to respond to requests from data subjects exercising their rights under Chapter III GDPR.
14.2. Such assistance may include:
• locating personal data processed through the Application;
14.3. If a data subject contacts the Processor directly regarding personal data processed on behalf of the Controller, the Processor shall, unless otherwise required by law, refer the request to the Controller and shall not independently respond to the request except as authorized by the Controller or required by applicable law.
15. Assistance with Controller Obligations
15.1. Taking into account the nature of processing and the information available to the Processor, the Processor shall provide reasonable assistance to the Controller with obligations under Articles 32 to 36 GDPR where applicable.
15.2. Such assistance may include information concerning:
15.3. The Processor is not responsible for performing the Controller’s legal obligations on behalf of the Controller.
16. Personal Data Breaches
16.1. The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller.
16.2. Where reasonably available, the notification shall include:
16.3. The Processor shall take reasonable measures to contain, investigate, and mitigate a personal data breach.
16.4. The Processor shall cooperate reasonably with the Controller in connection with regulatory notifications and other legally required responses.
17. Retention of Personal Data
17.1. Personal data processed by the Application is retained for the duration of the applicable license and in accordance with the Privacy Policy.
17.2. The Processor may retain:
17.3. Unless otherwise required by law, such data shall not be retained beyond the periods specified in the Privacy Policy.
17.4. Embeddings associated with a previous AI model shall be deleted when the Controller changes the selected AI model and may subsequently be regenerated using the newly selected model.
18. Deletion of Personal Data
18.1. Upon termination or expiration of the Application license, personal data associated with the Controller’s use of the Application shall be deleted no later than one month after the end of the license, subject to applicable legal retention requirements.
18.2. Upon uninstalling the Application, personal data associated with the Application shall be deleted in accordance with the Processor’s deletion procedures and the Privacy Policy.
18.3. When the Controller changes the selected AI model, embeddings associated with the previous model shall be deleted and may be regenerated using the newly selected model.
18.4. The Processor may retain limited information where necessary to establish, exercise, or defend legal claims, comply with legal obligations, maintain security, or otherwise as required by applicable law.
18.5. Where personal data is retained under this section, it shall remain subject to applicable confidentiality and security obligations and shall be deleted when the applicable retention requirement expires.
19. Return or Deletion of Personal Data
19.1. Upon termination of the processing services, the Processor shall, at the Controller’s choice where technically applicable and unless otherwise required by law, delete or return personal data processed on behalf of the Controller.
19.2. Because the Application is primarily designed as an automated processing service and does not generally provide a separate data-export repository, deletion shall normally be the applicable method of returning or disposing of personal data.
19.3. The Processor shall ensure that personal data held by its subprocessors is deleted in accordance with the applicable subprocessor agreements, subject to legally required retention.
20. Bitrix24 and Controller-Directed Transfers
20.1. The Application receives incoming email data from the Controller’s Bitrix24 environment.
20.2. Bitrix24 remains a separate third-party service and is governed by its own terms, privacy policy, and data-processing arrangements.
20.3. To the extent that Bitrix24 processes personal data on behalf of the Controller, the Controller is responsible for maintaining an appropriate contractual and data-protection relationship with Bitrix24.
20.4. The Processor is not responsible for processing performed independently by Bitrix24 outside the Processor’s control.
20.5. The Processor shall remain responsible for processing performed by the Processor within the scope of this DPA, including the transmission of personal data from Bitrix24 to authorized LLM subprocessors.
21. Audit and Compliance Information
21.1. The Controller may request information reasonably necessary to demonstrate the Processor’s compliance with its obligations under Article 28 GDPR.
21.2. The Processor shall make available relevant information concerning its processing activities and applicable technical and organizational measures, subject to confidentiality, security, and intellectual-property restrictions.
21.3. Where reasonably necessary and proportionate, the Controller may conduct an audit of the Processor’s processing activities.
21.4. Audits shall:
21.5. The Processor may satisfy audit requests by providing relevant certifications, audit reports, security documentation, questionnaires, or other appropriate evidence where such information reasonably demonstrates compliance.
22. Regulatory Cooperation
22.1. The Processor shall reasonably cooperate with competent supervisory authorities where required by applicable law.
22.2. The Processor shall promptly inform the Controller where it receives a legally binding request from a supervisory authority concerning personal data processed on behalf of the Controller, unless prohibited by applicable law.
22.3. Nothing in this DPA prevents the Processor from complying with a legally binding obligation imposed by EU or Member State law.
23. Controller Responsibilities
The Controller shall:
24. Security of Controller Instructions
24.1. The Controller shall take reasonable measures to ensure that its instructions and configuration do not expose personal data unnecessarily.
24.2. The Controller shall notify the Processor of any relevant restrictions or special requirements concerning the processing of personal data.
24.3. The Controller shall not instruct the Processor to process personal data in a manner that violates applicable law.
25. Liability
25.1. Each party shall remain responsible for compliance with the obligations applicable to it under the GDPR and other applicable data-protection laws.
25.2. The liability of the parties in connection with processing under this DPA shall be governed by the EULA, except to the extent that mandatory applicable data-protection law provides otherwise.
25.3. Nothing in this DPA limits any liability that cannot lawfully be limited under the GDPR or other applicable law.
26. Order of Precedence
26.1. This DPA forms part of the EULA.
26.2. In the event of a conflict between this DPA and the EULA concerning the processing of personal data, this DPA shall prevail with respect to data-protection matters.
26.3. In the event of a conflict between this DPA and mandatory applicable law, the mandatory legal provision shall prevail.
27. Governing Law
27.1. This DPA is governed by the laws of the Republic of Slovenia and applicable European Union data-protection law.
27.2. Mandatory provisions of applicable data-protection law shall apply regardless of the governing-law provision.
28. Contact Information
For GDPR and data-processing matters, the Processor can be contacted at:
gdpr@pamteh.si
Pametne Tehnologije d.o.o.
Dunajska cesta 113
1000 Ljubljana
Slovenia