Legal

Data Processing Agreement

Acuerdo de Encargado del Tratamiento — in compliance with Article 28 of Regulation (EU) 2016/679 (GDPR)

Last updated: 23/07/2026

Parties

THE CONTROLLER: the Client contracting Airila's services (the “Controller”), identified in its account registration details.

THE PROCESSOR: Vadim Ziablov, Tax ID Z2810522L, domiciled at Avenida Rafael Nadal, 11, Esc. 04, Planta 1, Pta. D, 28108 Alcobendas (Madrid), Spain, trading as “Airila” (the “Processor”).

Both parties mutually acknowledge having the legal capacity necessary to enter into this Agreement, which forms an integral part of the Terms and Conditions accepted when contracting the Service.

Clause 1 — Purpose

This Agreement governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the provision of the AI reception assistant service (the “Service”).

Clause 2 — Description of the processing

Categories of data subjects
The Controller's clients, patients or end users who interact with the AI assistant
Categories of data
Name, phone number, messaging account identifier (WhatsApp/Instagram), conversation content, service of interest, appointment date/time
Purpose of processing
Provision of the AI assistant service: automated replies, appointment management, reminders
Duration of processing
For the duration of the contractual relationship with the Controller, plus any subsequent period required by legal obligation

Clause 3 — Obligations of the Processor

The Processor undertakes to:

  • a) Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do otherwise by law.
  • b) Ensure that persons authorized to process the personal data have committed themselves to confidentiality.
  • c) Implement the technical and organizational security measures required by Article 32 of the GDPR, including:
    • Encryption of sensitive credentials and access tokens
    • Logical isolation of data between different Controllers (multi-tenant architecture)
    • Role-based access control
    • Audit logging of relevant administrative actions
  • d) Respect the conditions for engaging another processor (sub-processor), in accordance with Clause 5.
  • e) Assist the Controller, insofar as possible, in fulfilling its obligation to respond to requests for exercising data subjects' rights.
  • f) Assist the Controller in ensuring compliance with obligations regarding security, personal data breach notification and, where applicable, data protection impact assessments.
  • g) At the choice of the Controller, delete or return all personal data after the end of the provision of the Service, and delete existing copies, unless retention is required by law.
  • h) Make available to the Controller all information necessary to demonstrate compliance with the obligations of this Agreement, and allow for reasonable audits, upon reasonable prior notice.
  • i) Immediately inform the Controller if, in its opinion, an instruction received infringes the GDPR or other data protection provisions.

Clause 4 — Personal data breach notification

The Processor shall notify the Controller, without undue delay and no later than 48 hours after becoming aware of it, of any personal data breach affecting the data processed under this Agreement, providing available information on the nature of the breach, the categories and approximate number of data subjects affected, the measures taken and those recommended.

Clause 5 — Sub-processors

The Controller authorizes the Processor to engage the following sub-processors for the provision of the Service:

ProviderPurposeData location
OpenAI, L.L.C.Generating the AI assistant's repliesUnited States
Meta Platforms, Inc.Sending and receiving WhatsApp and Instagram messagesUnited States / International
Supabase Inc.Database storageIreland (European Union)
Google LLCAppointment syncing with Google Calendar; corporate email hosting (Google Workspace)United States / International
Vercel Inc.Application hostingUnited States
Arsys (Nominalia Internet, S.L.)Registration and management of the airila.es domainSpain

The Processor will inform the Controller of any intended changes to this list, giving the Controller the opportunity to object to such changes within a reasonable period.

The Processor guarantees that it imposes the same data protection obligations set out in this Agreement on these sub-processors.

Clause 6 — International transfers

Some sub-processors (OpenAI, Meta, Google) may process data outside the European Economic Area. The Processor guarantees that such transfers are carried out under appropriate safeguards in accordance with Chapter V of the GDPR (for example, the European Commission's Standard Contractual Clauses).

Clause 7 — Duration

This Agreement remains in effect for as long as the Processor processes personal data on behalf of the Controller in connection with the Service.

Clause 8 — Governing law

This Agreement is governed by Spanish law and the GDPR.

Note: This document is a standard Data Processing Agreement template and is automatically incorporated when contracting the Service, in compliance with Article 28(3) of the GDPR. To negotiate specific terms, contact kirill@airila.es.

Back to home