Legal

Data Processing Agreement

This Data Processing Agreement (“DPA”) applies where Ninjabot processes personal data on behalf of a customer in connection with the Ninjabot service, and forms part of the service agreement. A countersigned copy is available on request: privacy@ninjabot.eu.

1. Roles & scope

The customer is the data controller of the personal data in its lists, conversations, and CRM records; Ninjabot is the data processor. Processing covers contact and conversation data needed to respond to, qualify, and book the customer’s leads.

2. Processor obligations

  • Process personal data only on documented instructions from the customer.
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational measures (encryption in transit and at rest, role-based access, logging).
  • Assist the customer with data subject requests and with obligations under Articles 32–36 GDPR.
  • Delete or return personal data at the end of the engagement, at the customer’s choice.
  • Make available information necessary to demonstrate compliance and allow audits.

3. Sub-processors

Ninjabot uses vetted sub-processors (hosting, telephony, email delivery, AI model providers) under written agreements imposing equivalent obligations. The current sub-processor list is available on request; customers are notified of changes with an opportunity to object.

4. International transfers

Data is stored in the EU. Where a sub-processor processes data outside the EU/EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.

5. Security incidents

Ninjabot notifies the customer without undue delay after becoming aware of a personal data breach affecting customer data, with information reasonably needed for the customer’s own notification obligations.

For the signable version of this DPA — required by many clinics, brokers, and legal buyers — contact privacy@ninjabot.eu.