Legal
Data Processing Agreement
Acuerdo de Encargado del Tratamiento — in compliance with Article 28 of Regulation (EU) 2016/679 (GDPR)
Last updated: 23/07/2026
Parties
THE CONTROLLER: the Client contracting Airila's services (the “Controller”), identified in its account registration details.
THE PROCESSOR: Vadim Ziablov, Tax ID Z2810522L, domiciled at Avenida Rafael Nadal, 11, Esc. 04, Planta 1, Pta. D, 28108 Alcobendas (Madrid), Spain, trading as “Airila” (the “Processor”).
Both parties mutually acknowledge having the legal capacity necessary to enter into this Agreement, which forms an integral part of the Terms and Conditions accepted when contracting the Service.
Clause 1 — Purpose
This Agreement governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the provision of the AI reception assistant service (the “Service”).
Clause 2 — Description of the processing
- Categories of data subjects
- The Controller's clients, patients or end users who interact with the AI assistant
- Categories of data
- Name, phone number, messaging account identifier (WhatsApp/Instagram), conversation content, service of interest, appointment date/time
- Purpose of processing
- Provision of the AI assistant service: automated replies, appointment management, reminders
- Duration of processing
- For the duration of the contractual relationship with the Controller, plus any subsequent period required by legal obligation
Clause 3 — Obligations of the Processor
The Processor undertakes to:
- a) Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do otherwise by law.
- b) Ensure that persons authorized to process the personal data have committed themselves to confidentiality.
- c) Implement the technical and organizational security measures required by Article 32 of the GDPR, including:
- Encryption of sensitive credentials and access tokens
- Logical isolation of data between different Controllers (multi-tenant architecture)
- Role-based access control
- Audit logging of relevant administrative actions
- d) Respect the conditions for engaging another processor (sub-processor), in accordance with Clause 5.
- e) Assist the Controller, insofar as possible, in fulfilling its obligation to respond to requests for exercising data subjects' rights.
- f) Assist the Controller in ensuring compliance with obligations regarding security, personal data breach notification and, where applicable, data protection impact assessments.
- g) At the choice of the Controller, delete or return all personal data after the end of the provision of the Service, and delete existing copies, unless retention is required by law.
- h) Make available to the Controller all information necessary to demonstrate compliance with the obligations of this Agreement, and allow for reasonable audits, upon reasonable prior notice.
- i) Immediately inform the Controller if, in its opinion, an instruction received infringes the GDPR or other data protection provisions.
Clause 4 — Personal data breach notification
The Processor shall notify the Controller, without undue delay and no later than 48 hours after becoming aware of it, of any personal data breach affecting the data processed under this Agreement, providing available information on the nature of the breach, the categories and approximate number of data subjects affected, the measures taken and those recommended.
Clause 5 — Sub-processors
The Controller authorizes the Processor to engage the following sub-processors for the provision of the Service:
| Provider | Purpose | Data location |
|---|---|---|
| OpenAI, L.L.C. | Generating the AI assistant's replies | United States |
| Meta Platforms, Inc. | Sending and receiving WhatsApp and Instagram messages | United States / International |
| Supabase Inc. | Database storage | Ireland (European Union) |
| Google LLC | Appointment syncing with Google Calendar; corporate email hosting (Google Workspace) | United States / International |
| Vercel Inc. | Application hosting | United States |
| Arsys (Nominalia Internet, S.L.) | Registration and management of the airila.es domain | Spain |
The Processor will inform the Controller of any intended changes to this list, giving the Controller the opportunity to object to such changes within a reasonable period.
The Processor guarantees that it imposes the same data protection obligations set out in this Agreement on these sub-processors.
Clause 6 — International transfers
Some sub-processors (OpenAI, Meta, Google) may process data outside the European Economic Area. The Processor guarantees that such transfers are carried out under appropriate safeguards in accordance with Chapter V of the GDPR (for example, the European Commission's Standard Contractual Clauses).
Clause 7 — Duration
This Agreement remains in effect for as long as the Processor processes personal data on behalf of the Controller in connection with the Service.
Clause 8 — Governing law
This Agreement is governed by Spanish law and the GDPR.
Note: This document is a standard Data Processing Agreement template and is automatically incorporated when contracting the Service, in compliance with Article 28(3) of the GDPR. To negotiate specific terms, contact kirill@airila.es.
Back to home