Data Processing Agreement

Effective as of July 25, 2025 — pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR)

This Data Processing Agreement ("DPA") forms part of the Terms of Service between PragueCoding s.r.o. ("Processor", "we") and the B2B client ("Controller", "you") who has subscribed to the Lobot.chat platform. By accepting the Terms of Service, the Controller also accepts the terms of this DPA.

1. Definitions

  1. "Controller" means the B2B client (e-shop operator) who determines the purposes and means of processing personal data of their end-customers.
  2. "Processor" means PragueCoding s.r.o., with registered office at V Horkách 1730/3, Nusle, 140 00 Praha 4, ID number: 07811225, which processes personal data on behalf of the Controller.
  3. "Data Subject" means any identified or identifiable natural person whose personal data is processed under this DPA — primarily end-customers interacting with the chatbot deployed by the Controller.
  4. "Personal Data" means any information relating to an identified or identifiable natural person as defined in Article 4(1) of the GDPR.
  5. "Sub-Processor" means any third party engaged by the Processor to carry out processing activities on behalf of the Controller.
  6. "Services" means the Lobot.chat AI chatbot platform provided pursuant to the Terms of Service.

2. Subject Matter and Duration

  1. The Processor processes personal data on behalf of the Controller solely to provide the Services as described in the Terms of Service.
  2. This DPA commences on the date the Controller accepts the Terms of Service and remains in effect for the duration of the Services. Upon termination of the Terms of Service, the obligations of this DPA survive to the extent necessary to fulfil the requirements of Article 28 GDPR.

3. Nature, Purpose, and Categories of Data

  1. Nature and purpose. The Processor processes personal data to operate the AI-powered chatbot on the Controller's website, including: receiving and processing chatbot conversation inputs, generating AI responses using the Controller's product feed and instructions, storing conversation logs for analytics and improvement of the service, and providing customer support to the Controller.
  2. Categories of personal data. The processing may involve the following categories of personal data:
    • Content of chatbot conversations (questions and messages submitted by end-customers),
    • Technical identifiers (IP address, session ID, browser type),
    • Any personal data voluntarily provided by end-customers within the conversation (e.g., name, email, order number).
  3. Categories of data subjects. End-customers (natural persons) visiting the Controller's website and interacting with the Lobot chatbot.
  4. Special categories. The Processor does not intentionally process special categories of personal data (Article 9 GDPR). The Controller must not configure the chatbot in a way that solicits or processes such data.

4. Obligations of the Processor

The Processor shall:

  1. Process only on documented instructions. Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by applicable law. In such case, the Processor shall inform the Controller before processing, unless prohibited by law.
  2. Ensure confidentiality. Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement security measures. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 of the GDPR, including as appropriate: pseudonymisation and encryption of personal data; measures to ensure ongoing confidentiality, integrity, availability and resilience of processing systems; and processes for regularly testing, assessing and evaluating the effectiveness of those measures.
  4. Respect conditions for Sub-Processors. Not engage another processor (Sub-Processor) without prior specific or general written authorisation of the Controller. The Controller provides general authorisation for the Sub-Processors listed in Section 6. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors, giving the Controller the opportunity to object.
  5. Assist the Controller. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III of the GDPR.
  6. Assist with compliance obligations. Assist the Controller in ensuring compliance with obligations pursuant to Articles 32 to 36 GDPR (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and the information available to the Processor.
  7. Delete or return data. At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless applicable law requires storage of the personal data. The Processor will delete all personal data within 30 days after termination of the Services, unless a longer period is required by law.
  8. Make information available. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Controller shall provide reasonable advance notice of at least 30 days for any audit request.
  9. Notify of data breaches. Notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed under this DPA, and no later than 72 hours after becoming aware, providing sufficient information to allow the Controller to meet its obligations under Article 33 GDPR.

5. Obligations of the Controller

The Controller shall:

  1. Ensure that there is a valid legal basis for the processing of personal data of end-customers and that data subjects have been informed of the processing in accordance with Articles 13 and 14 GDPR.
  2. Provide the Processor with documented instructions regarding the processing of personal data and notify the Processor promptly of any changes to such instructions.
  3. Not configure the chatbot to solicit, process, or store special categories of personal data (Article 9 GDPR) or personal data of children under 16 years of age without implementing appropriate safeguards.
  4. Be responsible for the accuracy, quality, and legality of the personal data and the means by which the Controller acquired such personal data.
  5. Maintain its own privacy policy informing end-customers about the use of the Lobot chatbot and the processing of their personal data.

6. Approved Sub-Processors

The Controller provides general authorisation for the Processor to engage the following Sub-Processors. The Processor shall impose data protection obligations on each Sub-Processor equivalent to those set out in this DPA.

Sub-Processor Role Location Transfer mechanism
Google LLC (Gemini AI) AI language model for generating chatbot responses. Google processes data pursuant to its own Data Processing Addendum. USA Standard Contractual Clauses (SCCs)
Supabase, Inc. Database and authentication infrastructure USA / EU Standard Contractual Clauses (SCCs)
Stripe, Inc. Payment processing (Controller billing only) USA / EU Standard Contractual Clauses (SCCs)

The Processor shall notify the Controller of any intended addition or replacement of Sub-Processors at least 30 days in advance. The Controller may object to such changes in writing within 14 days of notification. If no objection is raised, the change is deemed accepted.

7. International Data Transfers

  1. Where the Processor transfers personal data to Sub-Processors located outside the European Economic Area (EEA), such transfers are subject to appropriate safeguards as required by Chapter V of the GDPR — in particular, Standard Contractual Clauses adopted by the European Commission.
  2. The Processor shall ensure that any international transfer is made only to countries providing an adequate level of protection, or subject to appropriate safeguards as listed in Article 46 GDPR.

8. Liability

  1. Each party shall be liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to lawful instructions of the Controller.
  2. The Processor shall be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage. The liability of the Processor under this DPA is subject to the limitations set forth in the Terms of Service.

9. Termination and Data Deletion

  1. This DPA terminates automatically upon termination of the Terms of Service.
  2. Upon termination, the Processor shall, at the Controller's written choice, either delete or return all personal data processed under this DPA within 30 days, and certify in writing that it has done so. Copies retained for legal or compliance purposes are exempt from deletion until the relevant retention period expires.

10. Governing Law

This DPA is governed by the laws of the Czech Republic and is subject to the exclusive jurisdiction of the courts of the Czech Republic, consistent with the governing law of the Terms of Service.

Questions about this DPA?

If you have any questions regarding data processing or wish to exercise your rights under this DPA, please contact us at info@lobot.chat.