Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement (“DPA”) applies where Ninjabot processes personal data on behalf of a customer in connection with the Ninjabot service, and forms part of the service agreement. A countersigned copy is available on request: privacy@ninjabot.eu.
1. Roles & scope
The customer is the data controller of the personal data in its lists, conversations, and CRM records; Ninjabot is the data processor. Processing covers contact and conversation data needed to respond to, qualify, and book the customer’s leads.
2. Processor obligations
- Process personal data only on documented instructions from the customer.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational measures (encryption in transit and at rest, role-based access, logging).
- Assist the customer with data subject requests and with obligations under Articles 32–36 GDPR.
- Delete or return personal data at the end of the engagement, at the customer’s choice.
- Make available information necessary to demonstrate compliance and allow audits.
3. Sub-processors
Ninjabot uses vetted sub-processors (hosting, telephony, email delivery, AI model providers) under written agreements imposing equivalent obligations. The current sub-processor list is available on request; customers are notified of changes with an opportunity to object.
4. International transfers
Data is stored in the EU. Where a sub-processor processes data outside the EU/EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
5. Security incidents
Ninjabot notifies the customer without undue delay after becoming aware of a personal data breach affecting customer data, with information reasonably needed for the customer’s own notification obligations.
For the signable version of this DPA — required by many clinics, brokers, and legal buyers — contact privacy@ninjabot.eu.