1. Definitions
The terms defined below have the meaning given to them in Regulation (EU) 2016/679 (the "GDPR") :
- Controller: the Customer (the training institution) that determines the purposes and means of the processing of personal data through the Service.
- Processor: Navescale, Lda, trading under the commercial name Qaptivo, which processes personal data on behalf of the Customer.
- Sub-processor: a third party engaged by Qaptivo to carry out part of the processing (Annex 3).
- Customer Personal Data: any information relating to an identified or identifiable natural person, processed by Qaptivo within the scope of the Service on behalf of the Customer.
- Data subject: a visitor or prospect of the Customer's website, whose data is processed through the Service.
- Service: the Qaptivo AI chatbot SaaS platform, as described in the Terms and Conditions.
- Terms and Conditions: the Qaptivo Terms and Conditions available at qaptivo.com/en/terms.
- Data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data.
2. Roles of the parties
The parties acknowledge that, within the scope of the Service:
- The Customer acts as controller; it alone determines the purposes, scope and terms of use of the Service.
- Qaptivo acts as processor within the meaning of article 4(8) GDPR; it processes personal data only on the documented instructions of the Customer.
This DPA constitutes the Customer's documented instructions to Qaptivo, together with the configuration of the Service carried out by the Customer in its dashboard (chatbot settings, knowledge base, integrations).
3. Subject matter, duration, nature and purpose of the processing
The elements referred to in article 28(3) GDPR are described in Annex 1. The duration of the processing corresponds to the duration of the Customer's subscription to the Service, plus a maximum period of 30 days for the deletion or return of the data in accordance with section 5.8.
4. Type of data and categories of data subjects
See Annex 1. The Customer undertakes not to collect special categories of data within the meaning of article 9 GDPR through the Service (health, opinions, racial origin, religion, biometric data, etc.). By default, the Service includes a warning to visitors advising them not to share this type of information.
5. Obligations of Qaptivo (processor)
5.1 Processing on documented instructions
Qaptivo processes the Customer's personal data only on the basis of the Customer's documented instructions (this DPA, the configuration of the Service by the Customer, the Terms and Conditions). If Qaptivo considers that an instruction infringes the GDPR or any other applicable law, it shall immediately inform the Customer.
Qaptivo does not process personal data for any other purpose and, in particular, does not use it for its own commercial purposes or to train its artificial intelligence models.
5.2 Confidentiality
Qaptivo ensures that all persons authorised to process the Customer's personal data (employees, contractors, directors) are bound by a contractual obligation of confidentiality or by an appropriate statutory obligation of confidentiality. Access is limited to what is strictly necessary ("need-to-know" principle).
5.3 Technical and organisational security measures
Qaptivo implements the technical and organisational measures described in Annex 2, in accordance with article 32 GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons.
5.4 Sub-processors
The Customer hereby grants Qaptivo a general authorisation to engage the sub-processors listed in Annex 3. Qaptivo undertakes to:
- Enter into a contract with each sub-processor imposing the same data protection obligations as those set out in this DPA, in particular with regard to security measures.
- Notify the Customer by email of any addition or replacement of a sub-processor, with reasonable notice of at least 30 days before the new sub-processor is engaged.
- Allow the Customer to object to the change of sub-processor within that period. In the event of a reasoned and reasonable objection, Qaptivo shall endeavour to propose an alternative solution; failing that, the Customer may terminate the subscription without charge or penalty, with a pro rata refund.
- Remain fully liable to the Customer for the performance of the sub-processor's obligations.
5.5 Assistance with data subject rights
Qaptivo provides the Customer with the technical features required (export, deletion, access) to respond to requests from data subjects exercising their rights (articles 12 to 23 GDPR: access, rectification, erasure, restriction, portability, objection). In the event of a specific request not covered by the features of the Service, Qaptivo assists the Customer within a reasonable period not exceeding 15 working days.
5.6 Assistance with impact assessments (DPIA)
Qaptivo assists the Customer, to the extent reasonable and taking into account the information available to it, in carrying out data protection impact assessments (article 35 GDPR) and in prior consultations with the supervisory authority (article 36 GDPR).
5.7 Notification of data breaches
Qaptivo notifies the Customer of any personal data breach of which it becomes aware, without undue delay and at the latest within 72 hours after becoming aware of it. The notification specifies, as far as possible:
- The nature of the breach, the categories and approximate number of data subjects and records concerned;
- The name and contact details of the point of contact;
- The likely consequences of the breach;
- The measures taken or proposed to address the breach and mitigate its adverse effects.
5.8 Deletion or return at the end of the contract
Upon termination of the Service (termination, expiry, end of a trial not converted into a subscription), Qaptivo proceeds with the deletion of all of the Customer's personal data within a maximum of 30 days, unless Union or Member State law requires its retention. At the Customer's written request made before termination, Qaptivo returns the data in a structured, commonly used format (CSV/JSON export) before deletion.
Backups containing personal data are automatically purged within an additional period of no more than 30 days.
5.9 Audits and inspections
Qaptivo makes available to the Customer, upon written request, all information necessary to demonstrate compliance with the obligations of this DPA. The Customer may, once a year and at its own expense, carry out an audit (or appoint an independent third party bound by confidentiality) with reasonable notice of at least 30 days, under conditions that do not interfere with the normal operation of Qaptivo. Qaptivo may satisfy this obligation by providing relevant attestations, certifications or independent audit reports.
6. Obligations of the Customer (controller)
The Customer warrants that it:
- Has a valid legal basis (article 6 GDPR) for each processing operation carried out through the Service;
- Informs data subjects of the processing of their data in accordance with articles 13 and 14 GDPR (accessible privacy policy, notice in the widget);
- Configures the Service so as to comply with the principles of data minimisation and accuracy;
- Refrains from collecting through the Service special categories of data (article 9) or data relating to criminal convictions (article 10);
- Responds directly to requests from data subjects for whom it is the controller, relying where appropriate on the assistance provided for in section 5.5;
- Notifies the competent supervisory authorities of the data breaches notified to it by Qaptivo, where notification is required by article 33 GDPR.
7. International data transfers
Some sub-processors (Annex 3) are established outside the European Union. Any transfer to a third country is governed by one of the following mechanisms:
- An adequacy decision of the European Commission (article 45 GDPR), in particular the EU-US Data Privacy Framework for certified US sub-processors;
- Failing that, the Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision (EU) 2021/914), module 3 (EU processor to non-EU sub-processor), deemed to be entered into between the Customer (through Qaptivo) and the sub-processor concerned;
- Any supplementary protective measure where applicable (encryption, pseudonymisation), assessed according to the nature of the data and the jurisdiction of destination.
By accepting this DPA, the Customer authorises Qaptivo to enter into and perform these SCCs in its name and on its behalf with the sub-processors concerned.
8. Liability
The liability of each party under this DPA is governed by the limitation of liability provisions set out in section 10 of the Terms and Conditions, without prejudice to the mandatory provisions of the GDPR relating to the rights of data subjects and the powers of supervisory authorities.
9. Confidentiality
Each party treats information relating to this DPA and its performance as confidential, unless its disclosure is required by law or by a competent authority, or the other party has expressly consented to its disclosure.
10. Term and termination
This DPA takes effect on the date the Customer accepts the Terms of Sale and remains in force for as long as Qaptivo processes personal data on behalf of the Customer. Its termination follows that of the Terms and Conditions and triggers the deletion / return obligations provided for in section 5.8.
11. Amendments to the DPA
Qaptivo reserves the right to amend this DPA to reflect changes in applicable law, in sub-processors or in technical and organisational measures. Any substantial amendment is notified to the Customer by email with at least 30 days' notice before it comes into force. Continued use of the Service after the effective date constitutes acceptance of the new version. In the absence of acceptance, the Customer may terminate without charge with a pro rata refund.
The version history of the DPA is available on request at [email protected].
12. Order of precedence
In the event of a conflict between this DPA and the Terms and Conditions or any other agreement between the parties, the provisions of this DPA prevail for everything relating to the processing of personal data. For everything else, the Terms and Conditions apply.
13. Governing law and jurisdiction
This DPA is governed by Portuguese law, without prejudice to the mandatory provisions of the GDPR and the rights of data subjects to bring a matter before the supervisory authority or the courts of their place of habitual residence. Any dispute between the parties relating to this DPA is subject to the exclusive jurisdiction of the courts of Lisbon (Portugal).
14. Contact details
- Processor: Navescale, Lda, Praça Duque de Saldanha 1, 2º andar, 1050-094 Lisbon, Portugal, NIF 518556719
- GDPR contact / DPO: [email protected]
- Competent supervisory authority: Comissão Nacional de Proteção de Dados (CNPD), Portugal, www.cnpd.pt
Annex 1: Description of the processing
| Subject matter | Provision of an AI chatbot SaaS service for engaging and capturing prospects on the Customer's website. |
|---|---|
| Duration | Duration of the Customer's subscription + 30 days for deletion / return. |
| Nature of the processing | Hosting, real-time processing, vector semantic search, automated generation of responses, automated scoring of commercial interest, email notification, data export. |
| Purpose | Answering prospects' questions 24/7, capturing information requests, qualifying leads for the Customer's admissions teams. |
| Type of personal data |
|
| Special categories (art. 9) | None. The Customer undertakes not to collect special categories through the Service. |
| Categories of data subjects | Visitors and prospects of the Customer's website, mostly adult natural persons (applicants to a programme, parents of students, employees retraining). |
| Frequency of the processing | Continuous, in real time. |
| Location of the main processing | Germany (Frankfurt, Hetzner infrastructure) with occasional sub-processing in the jurisdictions listed in Annex 3. |
Annex 2: Technical and organisational measures
Pursuant to article 32 GDPR, Qaptivo implements the following measures:
Technical security
- Encryption in transit: TLS 1.2 minimum (TLS 1.3 by default) on all HTTP, API, dashboard and widget communications.
- Encryption of secrets: user passwords hashed with bcrypt (cost factor 12); API keys and OAuth tokens encrypted at rest.
- Multi-tenant isolation: each Customer school ("tenant") is logically isolated by a unique identifier applied to every database query; no data leakage possible between Customers.
- Access control: JWT authentication for the dashboard with 24-hour expiry; public API key authentication for the widget (limited to public endpoints).
- Rate limiting: protection of public endpoints against abuse and denial-of-service attacks.
- Backups: automated daily database backups, 30-day retention, restoration tested.
- Monitoring and logging: application error monitoring via Sentry with active filtering of personal data (PII scrubbing); infrastructure access logs kept for 30 days.
- Security updates: regular review of software dependencies, critical patches applied within 7 days.
- Anti-bot protection: Cloudflare Turnstile in invisible mode on public endpoints.
Organisational security
- Staff access: on a "need-to-know" basis, every access to production data is logged and revocable.
- Confidentiality: all staff and contractors accessing production systems are bound by a confidentiality clause.
- Incident response: formalised internal procedure, notification within 72 hours in accordance with section 5.7 of this DPA.
- Business continuity: cloud infrastructure with redundancy, documented recovery plan.
- Awareness: internal training on GDPR principles and security best practices.
Privacy by design
- The widget sets no cookie and no local identifier until the visitor has opened the chat (ePrivacy exemption).
- Warning built into the widget inviting visitors not to share sensitive data.
- Automatic deletion of conversations at the end of the retention period (12 months).
- Ability to export or delete a lead on request, from the Customer's dashboard.
Annex 3: List of sub-processors
List up to date as of 5 May 2026. Any change is notified by email with 30 days' notice in accordance with section 5.4.
| Sub-processor | Country | Purpose | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Germany (Frankfurt) | Server hosting, database, files | EU, no transfer |
| Anthropic, PBC | United States | AI processing of conversations (Claude model) | EU-US Data Privacy Framework + SCCs 2021/914 |
| OpenAI, L.L.C. | United States | Generation of vector embeddings for semantic search | EU-US Data Privacy Framework + SCCs 2021/914 |
| Cloudflare, Inc. | United States | Browser Rendering (crawling of the Customer's website) + Turnstile (anti-bot protection) | EU-US Data Privacy Framework + SCCs 2021/914 |
| Stripe Payments Europe, Ltd. | Ireland / United States | Payment processing and Qaptivo invoicing (Customer data only, not prospects' data) | EU + EU-US DPF |
| Sendinblue SAS (Brevo) | France | Sending of transactional emails (lead notifications, weekly reports) | EU, no transfer |
| Giphy, Inc. | United States | Search and display of GIFs in responses (only if enabled by the Customer) | EU-US Data Privacy Framework + SCCs 2021/914 |
| Functional Software, Inc. (Sentry.io) | United States | Application error monitoring with PII filtering | EU-US Data Privacy Framework + SCCs 2021/914 |
Note: DataFast (analytics for the qaptivo.com marketing website) is not a sub-processor of the Customer's data: it has no access to the chatbot widget or to the dashboard.