Data Processing Agreement

for the Odpovídej.cz Service

This Data Processing Agreement is concluded pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation, hereinafter referred to as the „GDPR“.

1. Contracting Parties

Data Controller

The Data Controller is the customer of the Odpovídej.cz service who has ordered, uses, or administers the service for its website.

The Controller is identified by the details provided in the user account, order, billing information, agreement, terms and conditions, or other contractual documentation relating to the Odpovídej.cz service.

Hereinafter referred to as the „Controller“.

Data Processor

Apps24 s.r.o.
Karlovarská 254
271 01 Nové Strašecí – Nové Strašecí
Company ID (IČO): 07193467
VAT ID (DIČ): CZ07193467
E-mail: info@apps24.cz
Web:
 www.odpovidej.cz

Hereinafter referred to as the „Processor“.

The Controller and Processor are hereinafter jointly referred to as the „Parties“.

2. Conclusion of the Agreement

This Agreement is concluded electronically.

The Controller accepts this Agreement in particular by creating a user account, ordering the service, activating the service, confirming it in the administration panel, ticking the relevant consent box, or by any other electronic confirmation expressing agreement with the terms and conditions, this Agreement, or the use of the Odpovídej.cz service.

The Processor is entitled to record the date and time of acceptance of this Agreement, the identification of the user account, the Controller's contact or billing details, IP address, version of the Agreement, and other technical data necessary to document the conclusion of the Agreement.

This Agreement forms an integral part of the contractual relationship between the Controller and the Processor, in particular the terms and conditions, order, service agreement, or other similar arrangement.

3. Purpose of the Agreement

This Agreement governs the conditions for the processing of personal data in connection with the use of the Odpovídej.cz service, in particular the chat window deployed on the Controller's website.

The Processor processes personal data for the Controller only to the extent and for the purpose necessary for the provision of the Odpovídej.cz service and in accordance with the Controller's instructions.

4. Subject Matter, Nature, and Purpose of Processing

The subject matter of the processing is the processing of personal data of visitors to the Controller's website who use the Odpovídej.cz chat window, as well as of any other persons whose data is entered into the chat.

The nature of the processing includes in particular:

The purpose of the processing is in particular:

5. Categories of Data Subjects

The processing may concern in particular the following categories of data subjects:

6. Categories of Personal Data

The Processor may process the following categories of personal data for the Controller, in particular:

The Controller acknowledges that the user may enter other data into the chat as well. The Controller is obliged to configure the use of the service and inform users in such a way that sensitive data, passwords, payment details, national identification numbers, or other data not necessary to handle the inquiry are not unnecessarily entered into the chat.

7. Duration of Processing

The processing of personal data takes place for the duration of the contractual relationship between the Controller and the Processor.

Data from chat communication is retained for the period set within the service or agreed between the Parties. Unless otherwise agreed, data from chat communication is retained for no longer than 6 months from the time it was obtained, unless longer retention is necessary to comply with a legal obligation, resolve a security incident, protect legal claims, or ensure the technical operation of the service.

After the termination of the contractual relationship, the Processor shall delete the personal data or return it to the Controller in accordance with the Controller's instructions, unless legal regulations require further retention.

8. Instructions of the Controller

The Processor processes personal data only on the basis of documented instructions from the Controller.

The Controller's instructions include in particular:

The Processor does not sell personal data to third parties and does not use it for its own independent marketing purposes.

The Processor is entitled to process personal data beyond the scope of the Controller's instructions only where required to do so by law. In such a case, the Processor shall inform the Controller thereof, unless prohibited from doing so by law.

If the Processor considers that an instruction from the Controller infringes the GDPR or other data protection laws, it shall inform the Controller without undue delay. The Processor is entitled to suspend the execution of such an instruction until the Controller confirms or amends it. A mere notification by the Processor does not relieve the Controller of responsibility for the content and lawfulness of the instructions it has given.

9. Obligations of the Processor

The Processor undertakes in particular to:

  1. process personal data only in accordance with the Controller's instructions,
  2. maintain confidentiality regarding the personal data processed,
  3. ensure that persons authorized to process personal data are bound by confidentiality,
  4. adopt appropriate technical and organizational measures to secure personal data,
  5. assist the Controller in handling requests from data subjects, insofar as this is possible given the nature of the processing,
  6. assist the Controller in fulfilling its obligations under the GDPR, in particular regarding security, incident notification, impact assessments, and consultations with the supervisory authority,
  7. notify the Controller of a personal data breach without undue delay after becoming aware of it,
  8. delete or return the personal data upon termination of the service, in accordance with the Controller's instructions,
  9. provide the Controller with reasonable assistance in demonstrating compliance with this Agreement and the GDPR.

10. Obligations of the Controller

The Controller undertakes in particular to:

  1. process personal data in accordance with the GDPR and other applicable laws,
  2. determine an appropriate legal basis for the processing of personal data,
  3. inform website visitors about the processing of personal data via the chat,
  4. ensure that the chatbot is used only for lawful purposes,
  5. not enter or request, via the chat, data that is not necessary for the given purpose,
  6. ensure that any analytical or marketing functions beyond the necessary operation of the chat are used in compliance with consent requirements or another legal basis,
  7. provide the Processor only with instructions that comply with applicable law.

11. Security of Personal Data

The Processor shall implement appropriate technical and organizational measures having regard to the nature, scope, context, and purposes of the processing, as well as the risks to the rights and freedoms of natural persons.

These measures may include in particular:

Specific technical and organizational measures may be further described in the Processor's security documentation or in an annex to this Agreement.

12. Cookies, Local Storage and Similar Technologies

The Odpovídej.cz service may use cookies, Local Storage, or similar technologies necessary for the operation of the chat window, maintaining the conversation, storing the chat state, securing the service, and ensuring continuity of communication.

Where analytical or marketing functions beyond the necessary operation of the chat are used through the service, the Controller is responsible for ensuring their use complies with applicable law, in particular requirements to inform users and, where applicable, obtain their consent.

13. Automated Processing and AI

The Odpovídej.cz service may use automated processing and artificial intelligence technologies to understand inquiries, retrieve relevant information, and prepare responses.

The Processor does not use the content of conversations to train third-party models without the Controller's consent.

The chatbot's responses are informational in nature. The service is not intended for automated decision-making that would produce legal effects or similarly significant effects for the data subject.

The Controller is responsible for ensuring that the chatbot is not configured to independently make legally binding decisions regarding data subjects without an appropriate legal basis and human oversight.

14. Sub-processors

The Controller grants the Processor general authorization to engage sub-processors necessary for the operation, hosting, security, development, support, or functioning of the Odpovídej.cz service.

The Processor shall ensure that sub-processors are contractually bound by data protection obligations equivalent to those set out in this Agreement.

The Processor shall inform the Controller of any intended material changes concerning the engagement or replacement of sub-processors. Such notification may be made in particular by publication on the Odpovídej.cz service website, by e-mail, by notice in the administration panel, or by other suitable electronic means.

The Controller may raise a reasoned objection to such a change. If the Controller does not agree with the change and the Parties do not otherwise agree, the Controller may terminate use of the service.

The list of sub-processors is set out in Annex 3 to this Agreement. The current version of the list may also be published on the Odpovídej.cz service website.

15. Transfers of Personal Data Outside the EU/EEA

In the course of operating the Odpovídej.cz service, the Processor may use providers that process or make accessible personal data outside the European Union or the European Economic Area, in particular in the USA.

In such cases, the Processor shall ensure that the transfer takes place exclusively on the basis of one of the following legal mechanisms:

a) a European Commission adequacy decision under Article 45 GDPR, in particular for entities certified under the EU–U.S. Data Privacy Framework,

b) standard contractual clauses issued by the European Commission under Article 46(2)(c) GDPR, in particular pursuant to Commission Implementing Decision 2021/914, with the Processor ensuring these are concluded with the relevant sub-processor,

c) another appropriate legal mechanism permitted under the GDPR, of which the Processor shall inform the Controller in advance.

An up-to-date overview of sub-processors and the legal bases used for transfers outside the EU/EEA is set out in Annex 3 to this Agreement or in the public list of sub-processors published on the Odpovídej.cz service website.

The Processor continuously monitors developments in the legal framework governing the transfer of personal data to third countries and, should the legal basis used cease to be valid or sufficient, shall adopt alternative measures without undue delay and inform the Controller thereof.

16. Personal Data Breach

If the Processor becomes aware of a personal data breach concerning personal data processed for the Controller, it shall notify the Controller without undue delay after becoming aware of the breach.

The notification will contain the available information necessary for the Controller to assess the risks, fulfill its obligations under the GDPR, and, where applicable, notify the breach to the supervisory authority or to data subjects.

The Processor shall provide the Controller with reasonable assistance in resolving the incident and implementing remedial measures.

17. Assistance with Data Subject Rights

If a data subject contacts the Processor directly with a request concerning personal data processed for the Controller, the Processor shall forward the request to the Controller or refer the data subject to the Controller, where appropriate and possible.

The Processor shall provide the Controller with reasonable assistance in handling requests from data subjects, in particular requests for access, rectification, erasure, restriction of processing, data portability, or objection to processing.

18. Audit and Demonstration of Compliance

The Processor shall provide the Controller with the information necessary to demonstrate compliance with the obligations under this Agreement and the GDPR.

The Controller is entitled to verify compliance with this Agreement by reasonable means, in particular through questionnaires, requests for documentation, or other similar procedures.

A physical inspection of the Processor's premises is possible only by prior written agreement, to a reasonable extent, and subject to the protection of confidential information, system security, and the rights of the Processor's other customers.

The costs of an extraordinary audit shall be borne by the Controller, unless the Parties agree otherwise.

19. Confidentiality

The Processor shall ensure that persons with access to personal data are bound by a duty of confidentiality or are subject to a statutory duty of confidentiality.

This duty of confidentiality continues even after the termination of the contractual relationship.

20. Termination of Processing

Upon termination of the provision of the service or of the contractual relationship, the Processor shall delete the personal data or return it to the Controller, in accordance with the Controller's instructions.

If the Controller does not provide instructions within a reasonable time, the Processor is entitled to delete the personal data after the expiry of the service's standard retention period, unless legal regulations require further retention.

The Processor is not obliged to delete data that it is required to retain under applicable law, for the protection of legal claims, or that is stored in backups pending their regular overwrite cycle, provided such data is adequately protected.

21. Liability

Each Party is responsible for fulfilling the obligations arising from the GDPR, this Agreement, and other applicable laws.

The Controller is responsible in particular for the lawfulness of the processing, the legal basis, informing data subjects, and the content of the instructions given to the Processor.

The Processor is responsible in particular for processing personal data in accordance with the Controller's instructions, the security of the processing, and fulfilling the Processor's obligations under the GDPR.

22. Final Provisions

This Agreement takes effect upon its electronic acceptance by the Controller, but no later than upon the Controller's commencement of use of the Odpovídej.cz service.

This Agreement is concluded electronically and does not require the handwritten signature of the Parties.

In the event of any conflict between this Agreement and other contractual documents, this Agreement shall prevail on matters of personal data processing, unless expressly agreed otherwise.

Legal relationships not governed by this Agreement shall be governed by the GDPR and the laws of the Czech Republic.

Annex 1 — Overview of Processing

Service: Odpovídej.cz
Type of processing: Operation of a website chatbot, processing of inquiries, forwarding of messages and inquiries, technical administration of the service
Data subjects: Website visitors, customers, potential customers, contact persons
Categories of data: Content of messages, contact details, technical data, chat usage data
Purpose: Customer support, answering inquiries, forwarding inquiries, operation and security of the service
Retention period: As per service settings or agreement between the Parties; unless otherwise agreed, no longer than 6 months for chat communication
Role of the Controller: Customer of the Odpovídej.cz service who uses the service on its own website or administers it for a third party's website
Role of the Processor: Apps24 s.r.o., operator of the Odpovídej.cz service

Annex 2 — Technical and Organizational Measures

The Processor implements in particular the following measures:

  1. restricting access to the service's administration to authorized persons only,
  2. use of access credentials and permissions management,
  3. secure data transmission where technically possible,
  4. protection of server infrastructure and regular updates,
  5. data backup and service availability recovery procedures,
  6. logging of selected security and operational events,
  7. protection against unauthorized access,
  8. separation of customer data within the application,
  9. limiting access by the Processor's staff on a need-to-know basis,
  10. internal rules for handling personal data,
  11. procedures for handling security incidents,
  12. regular review and reasonable improvement of security measures.

Annex 3 — List of Sub-processors

The Processor uses the following sub-processors in providing the Odpovídej.cz service:

1. WEDOS Internet, a.s.

Masarykova 1230
373 41 Hluboká nad Vltavou
Czech Republic
Company ID (IČO): 28115708

Purpose: Web hosting, server infrastructure, database and storage services, e-mail and notification services.
Country of processing: Czech Republic, European Union.
Legal basis for transfer outside the EU/EEA: Not applicable — processing takes place within the EU.

2. OpenAI Ireland Ltd. / OpenAI, L.L.C. / OpenAI OpCo, LLC

OpenAI Ireland Ltd.
1st Floor, The Liffey Trust Centre
117–126 Sheriff Street Upper
Dublin 1, D01 YC43
Ireland

OpenAI, L.L.C. / OpenAI OpCo, LLC
San Francisco, CA
USA

Purpose: Processing of inquiries via a language model, retrieval of relevant information, and generation of chatbot responses.
Country of processing: European Union / USA, depending on the service configuration and contractual relationship.
Legal basis for transfer outside the EU/EEA: EU standard contractual clauses under Commission Implementing Decision 2021/914, or a European Commission adequacy decision under Article 45 GDPR, where applicable to the specific transfer.

3. Google LLC

1600 Amphitheatre Parkway
Mountain View, CA 94043
USA

Purpose: Google Workspace, in particular e-mail communication, administrative processing, document storage, and internal operational matters related to the Odpovídej.cz service.
Country of processing: European Union / USA, depending on the service configuration.
Legal basis for transfer outside the EU/EEA: European Commission adequacy decision under Article 45 GDPR for entities certified under the EU–U.S. Data Privacy Framework; alternatively, EU standard contractual clauses under Commission Implementing Decision 2021/914.

The Processor undertakes to keep this list up to date. The Controller will be informed of any planned material changes regarding the engagement of sub-processors in the manner set out in Article 14 of this Agreement, in particular by publishing an updated version of the list on the Odpovídej.cz service website, by e-mail, by notice in the administration panel, or by other suitable electronic means.

The current version of the list of sub-processors is available at:

https://www.odpovidej.cz/zpracovatele/