Data Processing Agreement
Last updated: 22 July 2026
This Data Processing Agreement ("DPA") forms part of the Merchant Terms of Service between you ("Merchant", "Controller") and Aristokrates OÜ ("AgentaOS", "Processor", "we", "us"). It governs our processing of personal data on your documented instructions when you use merchant-directed features of the Service, for example, analytics or AI features that run on your own data. It reflects Article 28 of the EU General Data Protection Regulation (GDPR).
Contents
- Definitions
- Roles and scope
- Processing on instructions
- Confidentiality
- Security of processing
- Sub-processors
- Assisting with data-subject rights
- Assisting the Controller (Art. 32–36)
- Personal data breaches
- International transfers
- Deletion or return of data
- Audits and inspections
- Liability and precedence
- Term and termination
- Governing law
- Annex I: Details of processing
- Annex II: Security measures
- Annex III: Sub-processors
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the GDPR. "Data Protection Law" means the GDPR and any other data-protection or privacy law that applies to the processing. "Sub-processor" means a third party engaged by us to process personal data on your behalf. Capitalised terms not defined here have the meaning given in the Merchant Terms of Service.
2. Roles and scope
For processing carried out on your documented instructions in connection with merchant-directed features, you are the Controller and we are the Processor. Each party will comply with its obligations under Data Protection Law. You are responsible for the lawfulness of the personal data you provide and of your instructions, and for having a valid legal basis for the processing, including where you provide us with personal data about your own customers.
3. Processing on instructions
We will process personal data only on your documented instructions, including the Merchant Terms, this DPA, your configuration and use of the Service, and any additional written instructions you give, unless we are required to process by EU or member-state law, in which case we will inform you before processing, unless that law prohibits it. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I. If we consider an instruction to infringe Data Protection Law, we will inform you.
4. Confidentiality
We will ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to provide the Service.
5. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to individuals, we will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II. We may update those measures over time, provided the level of protection is not reduced.
6. Sub-processors
You give us general authorisation to engage Sub-processors to help provide the Service. The categories of Sub-processors are set out in Annex III, and an itemised list identifying each Sub-processor is available on request. We will impose data-protection obligations on each Sub-processor that are, in substance, no less protective than those in this DPA, and we remain responsible for their performance. We will give you reasonable prior notice of any intended addition or replacement of a Sub-processor (for example, through the dashboard or by email), so that you have the opportunity to object on reasonable data-protection grounds. If you object and we cannot reasonably accommodate the objection, you may terminate the affected part of the Service.
7. Assisting with data-subject rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Data Protection Law (such as access, rectification, erasure, restriction, portability, and objection). If we receive such a request directly, we will, unless legally required to act, refer the data subject to you.
8. Assisting the Controller (Art. 32–36)
Taking into account the nature of processing and the information available to us, we will assist you in ensuring compliance with your obligations relating to security of processing, notification of personal data breaches, communication of breaches to data subjects, data-protection impact assessments, and prior consultation with a supervisory authority.
9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, and will provide information reasonably available to us to help you meet your own notification obligations. Our notification is not an acknowledgement of fault or liability.
10. International transfers
We and our Sub-processors may process personal data outside the European Economic Area. Where we do, we will ensure an appropriate transfer mechanism is in place, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with any supplementary measures required. Where the Standard Contractual Clauses apply, they are incorporated into this DPA by reference and prevail over any conflicting term for that transfer.
11. Deletion or return of data
On termination of the Service, and at your choice, we will delete or return the personal data processed on your behalf and delete existing copies, unless EU or member-state law requires us to retain it. We may retain personal data to the extent, and for as long as, required by law (for example, tax, accounting, or anti-money-laundering record-keeping), and this DPA continues to apply to any retained data.
12. Audits and inspections
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To minimise disruption and protect confidentiality and the security of other customers' data, we may satisfy audit requests by providing relevant certifications, third-party audit reports, and written responses, and any on-site inspection will be on reasonable prior notice, during business hours, no more than once a year (unless required by a supervisory authority or following a breach), and subject to confidentiality.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Merchant Terms of Service. In the event of a conflict between this DPA and the Merchant Terms in relation to the processing of personal data, this DPA prevails; where the Standard Contractual Clauses apply, they prevail over this DPA for the transfer they govern.
14. Term and termination
This DPA takes effect when you accept the Merchant Terms and continues while we process personal data on your behalf. It terminates automatically on termination of the Merchant Terms, subject to the provisions that survive (including deletion or return of data and any required retention).
15. Governing law
This DPA is governed by the laws of Estonia, without prejudice to the mandatory application of the GDPR and the Standard Contractual Clauses where they apply.
Annex I: Details of processing
| Subject matter | Provision of merchant-directed features of the AgentaOS Service (such as analytics and AI features) that process personal data on the Controller's behalf. |
|---|---|
| Duration | For the term of the Merchant Terms, plus any period required for deletion, return, or legally required retention. |
| Nature and purpose | Hosting, storage, analysis, generation of insights, and related processing carried out to provide the merchant-directed features the Controller configures and uses. |
| Categories of data subjects | The Controller's customers, prospects, contacts, and end users whose personal data the Controller submits to or generates through the Service. |
| Categories of personal data | Identifiers and contact details (such as name and email), transaction and order data, billing country, usage and analytics data, communications, and other data the Controller chooses to submit. The Service is not intended for special categories of personal data, and the Controller should not submit them. |
| Frequency | Continuous, for the duration of the Controller's use of the relevant features. |
Annex II: Technical and organisational security measures
We maintain measures appropriate to the risk, which include:
- Encryption: encryption of personal data in transit (TLS) and at rest.
- Access control: role-based access on a least-privilege, need-to-know basis; unique credentials; multi-factor authentication for administrative access.
- Network and application security: firewalls, segregation, secure development practices, and regular patching of systems.
- Confidentiality, integrity, availability, and resilience: measures to protect processing systems and to restore availability after an incident, including backups.
- Logging and monitoring: logging of relevant access and events, and monitoring for anomalies.
- Sub-processor assurance: contractual data-protection obligations and use of reputable, security-certified infrastructure providers.
- Testing and review: periodic testing, assessment, and evaluation of the effectiveness of these measures.
- Personnel: confidentiality commitments and data-protection awareness for staff with access.
Annex III: Sub-processors
We engage the following categories of Sub-processors to provide the Service. A current, itemised list identifying each Sub-processor and its role is available on request to [email protected].
| Category | Purpose |
|---|---|
| Cloud hosting & infrastructure | Hosting of the Service and storage of data |
| Analytics providers | Privacy-friendly product and usage analytics |
| Communications / email providers | Transactional and support communications |
| AI / model providers | Generating merchant-directed insights, where the Controller enables such features |
Contact
Aristokrates OÜ · Estonia, EU · Registry code 16948108 · [email protected]