Data Processing Agreement

Version 1.0 · Last updated: 5 May 2026

School compliance kit

How this DPA is entered into: this Data Processing Agreement is incorporated by reference into the Qaptivo Terms and Conditions. Accepting the Terms and Conditions at the time of subscription constitutes acceptance of this DPA in its version in force. Any substantial change to the DPA is notified to Customers by email with 30 days' notice, in accordance with section 11 below.

To file the DPA in your internal records, use the Print / save as PDF button above. The generated PDF will include today's date and the canonical URL. For any legal question: [email protected].

1. Definitions

The terms defined below have the meaning given to them in Regulation (EU) 2016/679 (the "GDPR") :

2. Roles of the parties

The parties acknowledge that, within the scope of the Service:

This DPA constitutes the Customer's documented instructions to Qaptivo, together with the configuration of the Service carried out by the Customer in its dashboard (chatbot settings, knowledge base, integrations).

3. Subject matter, duration, nature and purpose of the processing

The elements referred to in article 28(3) GDPR are described in Annex 1. The duration of the processing corresponds to the duration of the Customer's subscription to the Service, plus a maximum period of 30 days for the deletion or return of the data in accordance with section 5.8.

4. Type of data and categories of data subjects

See Annex 1. The Customer undertakes not to collect special categories of data within the meaning of article 9 GDPR through the Service (health, opinions, racial origin, religion, biometric data, etc.). By default, the Service includes a warning to visitors advising them not to share this type of information.

5. Obligations of Qaptivo (processor)

5.1 Processing on documented instructions

Qaptivo processes the Customer's personal data only on the basis of the Customer's documented instructions (this DPA, the configuration of the Service by the Customer, the Terms and Conditions). If Qaptivo considers that an instruction infringes the GDPR or any other applicable law, it shall immediately inform the Customer.

Qaptivo does not process personal data for any other purpose and, in particular, does not use it for its own commercial purposes or to train its artificial intelligence models.

5.2 Confidentiality

Qaptivo ensures that all persons authorised to process the Customer's personal data (employees, contractors, directors) are bound by a contractual obligation of confidentiality or by an appropriate statutory obligation of confidentiality. Access is limited to what is strictly necessary ("need-to-know" principle).

5.3 Technical and organisational security measures

Qaptivo implements the technical and organisational measures described in Annex 2, in accordance with article 32 GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons.

5.4 Sub-processors

The Customer hereby grants Qaptivo a general authorisation to engage the sub-processors listed in Annex 3. Qaptivo undertakes to:

5.5 Assistance with data subject rights

Qaptivo provides the Customer with the technical features required (export, deletion, access) to respond to requests from data subjects exercising their rights (articles 12 to 23 GDPR: access, rectification, erasure, restriction, portability, objection). In the event of a specific request not covered by the features of the Service, Qaptivo assists the Customer within a reasonable period not exceeding 15 working days.

5.6 Assistance with impact assessments (DPIA)

Qaptivo assists the Customer, to the extent reasonable and taking into account the information available to it, in carrying out data protection impact assessments (article 35 GDPR) and in prior consultations with the supervisory authority (article 36 GDPR).

5.7 Notification of data breaches

Qaptivo notifies the Customer of any personal data breach of which it becomes aware, without undue delay and at the latest within 72 hours after becoming aware of it. The notification specifies, as far as possible:

5.8 Deletion or return at the end of the contract

Upon termination of the Service (termination, expiry, end of a trial not converted into a subscription), Qaptivo proceeds with the deletion of all of the Customer's personal data within a maximum of 30 days, unless Union or Member State law requires its retention. At the Customer's written request made before termination, Qaptivo returns the data in a structured, commonly used format (CSV/JSON export) before deletion.

Backups containing personal data are automatically purged within an additional period of no more than 30 days.

5.9 Audits and inspections

Qaptivo makes available to the Customer, upon written request, all information necessary to demonstrate compliance with the obligations of this DPA. The Customer may, once a year and at its own expense, carry out an audit (or appoint an independent third party bound by confidentiality) with reasonable notice of at least 30 days, under conditions that do not interfere with the normal operation of Qaptivo. Qaptivo may satisfy this obligation by providing relevant attestations, certifications or independent audit reports.

6. Obligations of the Customer (controller)

The Customer warrants that it:

7. International data transfers

Some sub-processors (Annex 3) are established outside the European Union. Any transfer to a third country is governed by one of the following mechanisms:

By accepting this DPA, the Customer authorises Qaptivo to enter into and perform these SCCs in its name and on its behalf with the sub-processors concerned.

8. Liability

The liability of each party under this DPA is governed by the limitation of liability provisions set out in section 10 of the Terms and Conditions, without prejudice to the mandatory provisions of the GDPR relating to the rights of data subjects and the powers of supervisory authorities.

9. Confidentiality

Each party treats information relating to this DPA and its performance as confidential, unless its disclosure is required by law or by a competent authority, or the other party has expressly consented to its disclosure.

10. Term and termination

This DPA takes effect on the date the Customer accepts the Terms of Sale and remains in force for as long as Qaptivo processes personal data on behalf of the Customer. Its termination follows that of the Terms and Conditions and triggers the deletion / return obligations provided for in section 5.8.

11. Amendments to the DPA

Qaptivo reserves the right to amend this DPA to reflect changes in applicable law, in sub-processors or in technical and organisational measures. Any substantial amendment is notified to the Customer by email with at least 30 days' notice before it comes into force. Continued use of the Service after the effective date constitutes acceptance of the new version. In the absence of acceptance, the Customer may terminate without charge with a pro rata refund.

The version history of the DPA is available on request at [email protected].

12. Order of precedence

In the event of a conflict between this DPA and the Terms and Conditions or any other agreement between the parties, the provisions of this DPA prevail for everything relating to the processing of personal data. For everything else, the Terms and Conditions apply.

13. Governing law and jurisdiction

This DPA is governed by Portuguese law, without prejudice to the mandatory provisions of the GDPR and the rights of data subjects to bring a matter before the supervisory authority or the courts of their place of habitual residence. Any dispute between the parties relating to this DPA is subject to the exclusive jurisdiction of the courts of Lisbon (Portugal).

14. Contact details

Annex 1: Description of the processing

Subject matter Provision of an AI chatbot SaaS service for engaging and capturing prospects on the Customer's website.
Duration Duration of the Customer's subscription + 30 days for deletion / return.
Nature of the processing Hosting, real-time processing, vector semantic search, automated generation of responses, automated scoring of commercial interest, email notification, data export.
Purpose Answering prospects' questions 24/7, capturing information requests, qualifying leads for the Customer's admissions teams.
Type of personal data
  • Identity: first name, email, phone number (when voluntarily provided by the visitor)
  • Conversations: text messages exchanged with the chatbot
  • Technical data: IP address (rate limiting and security only), user-agent, detected language
  • Browsing data: URL of the page visited, UTM parameters, referrer (only if the Customer has enabled source tracking)
  • Commercial qualification score (0 to 100) calculated automatically
Special categories (art. 9) None. The Customer undertakes not to collect special categories through the Service.
Categories of data subjects Visitors and prospects of the Customer's website, mostly adult natural persons (applicants to a programme, parents of students, employees retraining).
Frequency of the processing Continuous, in real time.
Location of the main processing Germany (Frankfurt, Hetzner infrastructure) with occasional sub-processing in the jurisdictions listed in Annex 3.

Annex 2: Technical and organisational measures

Pursuant to article 32 GDPR, Qaptivo implements the following measures:

Technical security

  • Encryption in transit: TLS 1.2 minimum (TLS 1.3 by default) on all HTTP, API, dashboard and widget communications.
  • Encryption of secrets: user passwords hashed with bcrypt (cost factor 12); API keys and OAuth tokens encrypted at rest.
  • Multi-tenant isolation: each Customer school ("tenant") is logically isolated by a unique identifier applied to every database query; no data leakage possible between Customers.
  • Access control: JWT authentication for the dashboard with 24-hour expiry; public API key authentication for the widget (limited to public endpoints).
  • Rate limiting: protection of public endpoints against abuse and denial-of-service attacks.
  • Backups: automated daily database backups, 30-day retention, restoration tested.
  • Monitoring and logging: application error monitoring via Sentry with active filtering of personal data (PII scrubbing); infrastructure access logs kept for 30 days.
  • Security updates: regular review of software dependencies, critical patches applied within 7 days.
  • Anti-bot protection: Cloudflare Turnstile in invisible mode on public endpoints.

Organisational security

  • Staff access: on a "need-to-know" basis, every access to production data is logged and revocable.
  • Confidentiality: all staff and contractors accessing production systems are bound by a confidentiality clause.
  • Incident response: formalised internal procedure, notification within 72 hours in accordance with section 5.7 of this DPA.
  • Business continuity: cloud infrastructure with redundancy, documented recovery plan.
  • Awareness: internal training on GDPR principles and security best practices.

Privacy by design

  • The widget sets no cookie and no local identifier until the visitor has opened the chat (ePrivacy exemption).
  • Warning built into the widget inviting visitors not to share sensitive data.
  • Automatic deletion of conversations at the end of the retention period (12 months).
  • Ability to export or delete a lead on request, from the Customer's dashboard.

Annex 3: List of sub-processors

List up to date as of 5 May 2026. Any change is notified by email with 30 days' notice in accordance with section 5.4.

Sub-processor Country Purpose Transfer safeguard
Hetzner Online GmbH Germany (Frankfurt) Server hosting, database, files EU, no transfer
Anthropic, PBC United States AI processing of conversations (Claude model) EU-US Data Privacy Framework + SCCs 2021/914
OpenAI, L.L.C. United States Generation of vector embeddings for semantic search EU-US Data Privacy Framework + SCCs 2021/914
Cloudflare, Inc. United States Browser Rendering (crawling of the Customer's website) + Turnstile (anti-bot protection) EU-US Data Privacy Framework + SCCs 2021/914
Stripe Payments Europe, Ltd. Ireland / United States Payment processing and Qaptivo invoicing (Customer data only, not prospects' data) EU + EU-US DPF
Sendinblue SAS (Brevo) France Sending of transactional emails (lead notifications, weekly reports) EU, no transfer
Giphy, Inc. United States Search and display of GIFs in responses (only if enabled by the Customer) EU-US Data Privacy Framework + SCCs 2021/914
Functional Software, Inc. (Sentry.io) United States Application error monitoring with PII filtering EU-US Data Privacy Framework + SCCs 2021/914

Note: DataFast (analytics for the qaptivo.com marketing website) is not a sub-processor of the Customer's data: it has no access to the chatbot widget or to the dashboard.