Preview of the blank contract template
This is the unsigned preview of the DPA template. The bracketed fields are populated on contract execution; the final signed copy is available in the admin under Settings → Compliance.
Data Processing Agreement (DPA)
pursuant to Article 28 GDPR
[Your company]
[Your address]
Represented by: [Signing contact]
Email: [Contact email]
– hereinafter "Controller" –
Renner & Schneider GbR
Donauwörther Straße 49
86663 Asbach-Bäumenheim
Germany
Email: info@werila.com
– hereinafter "Processor" –
§ 1 Subject Matter and Duration
(1) The subject of this Agreement is the processing of personal data by the Processor in the course of providing the SaaS chat-widget product "Wilow" on the Controller's websites, including the associated administration and analytics interface.
(2) The Processor performs the service on behalf of and according to the documented instructions of the Controller. The Processor is not the controller of the personal data of the Controller's website visitors.
(3) The term of this Agreement corresponds to the term of the main contract between the Parties for the use of the "Wilow" software. This Agreement terminates automatically upon termination of the main contract.
§ 2 Nature and Purpose of Processing
(1) The Processor processes personal data exclusively for the purpose of providing the following functions:
a) Operating an embedded chat-widget on the Controller's website and processing incoming messages from website visitors.
b) Generating responses through generative AI models ("Large Language Models") drawing on content supplied by the Controller (knowledge base, FAQs, documents, crawled website pages).
c) Capturing and forwarding lead data (email addresses, phone numbers, names) provided by visitors during a chat.
d) Handing conversations off to the Controller's human staff, including sending the corresponding notifications.
e) Providing the Controller with statistical analytics over conversation history.
f) Billing, authentication, and operational integrity.
(2) No further processing takes place. In particular, the Processor does not build profiles of the Controller's visitors for its own purposes or for those of any third party.
§ 3 Categories of Data and Data Subjects
(1) Categories of personal data:
a) Content data: visitor message content; content supplied by the Controller (documents, knowledge snippets, crawled pages).
b) Contact data: email addresses, phone numbers, names, where provided by visitors.
c) Usage data: conversation IDs, timestamps, IP addresses, user agents, the URL of the page where the widget was loaded.
d) Media data: images uploaded by visitors (only where the feature is enabled by the Controller).
e) Authentication and billing data of the Controller's administrative users.
f) Technical access logs (HTTP request logs): timestamp, HTTP method and path, status code, response time, requester IP address and user agent, and — for authenticated requests — tenant ID and user ID. Live database retention: 30 days. Encrypted off-site backups may retain a record for up to 90 additional days; during this period the data is not actively processed. Legal basis: Article 6(1)(f) GDPR (legitimate interest in IT security and abuse detection).
(2) Categories of data subjects:
a) Visitors to the Controller's website(s) who interact with the chat widget.
b) Natural persons whose personal data is contained in the Controller's knowledge base (e.g., staff, contacts).
c) Users of the administration interface on behalf of the Controller.
§ 4 Obligations of the Processor
(1) The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such notification on important grounds of public interest.
(2) The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions or any provision of this Agreement.
(3) The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(4) Taking into account the nature of the processing and the information available to it, the Processor shall assist the Controller in complying with the obligations set out in Articles 32 to 36 GDPR.
(5) The Processor shall assist the Controller, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III GDPR. This includes, in particular, the rights to information, rectification, erasure, restriction of processing, and data portability.
(6) On request, the Processor shall make available to the Controller a structured, commonly used, and machine-readable export of the data (JSON format).
(7) The Processor designates the following point of contact for data-protection matters: info@werila.com.
(8) No use for AI model training. The Processor warrants that personal data transferred under this Agreement to the AI sub-processors listed in § 6 and Annex 2 (in particular Anthropic, Voyage AI, Google [Gemini], OpenAI, OpenRouter) is used by those sub-processors exclusively to deliver the respective API service (model inference / embedding computation) and is not used to train or improve those providers' models. This is ensured by using the API tiers with "zero data retention" / "no training" configuration in line with each provider's terms in force at the time of processing (as of issuance: Anthropic API — no training by default; OpenAI API — no training since March 2023; Google AI for Developers / Vertex AI — no training for paying API customers; Voyage AI — inference-only service, no training use; OpenRouter — routes only to the foregoing providers with their "no training" configuration enabled, with training and logging pass-through disabled in the OpenRouter account settings). Any change to this configuration shall be deemed a material change within the meaning of § 6(2) and shall be notified to the Controller in advance.
(9) Third-country transfer assessment (TIA). For the sub-processors located in the United States listed in Annex 2, the Processor has carried out a Transfer Impact Assessment in accordance with EDPB Recommendations 01/2020. The assessment is made available to the Controller on request.
§ 5 Obligations of the Controller
(1) The Controller is solely responsible for assessing the lawfulness of the processing and for safeguarding the rights of data subjects.
(2) In particular, the Controller shall ensure that:
a) a legal basis exists for the processing of personal data transmitted through the widget (e.g., consent, legitimate interest);
b) the Controller's privacy policy transparently names the use of the chat widget, the processing of submitted message content by generative AI models, and the sub-processors listed in Annex 2 (including the transfer to the United States on the basis of Standard Contractual Clauses), and that data subjects are informed accordingly before they first interact with the widget;
c) content uploaded to the knowledge base does not contain personal data of third parties without a legal basis. In particular, no special categories of personal data within the meaning of Art. 9 GDPR (health data, biometric data, etc.) and no content with disproportionate reference to identifiable natural persons may be uploaded to the knowledge base without the affected person's consent;
d) a legal basis exists for the capture of any lead data (email addresses, phone numbers, names) and that data subjects are informed accordingly before submission.
(3) The Controller shall as a rule communicate instructions to the Processor in writing, by electronic means, or via the dedicated functions of the administration interface. Oral instructions shall be confirmed in writing or by electronic means without undue delay.
§ 6 Sub-processors
(1) The Controller hereby grants general written authorisation, within the meaning of Article 28(2) GDPR, for the engagement of the sub-processors listed below:
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Anthropic, PBC | Large-language-model inference for chat replies and intent classification | United States (Standard Contractual Clauses) |
| Voyage AI, Inc. | Vector embeddings for retrieval-augmented generation over tenant content | United States (Standard Contractual Clauses) |
| Resend, Inc. | Transactional email delivery (onboarding, lead notifications, data-export links) | European Union |
| Stripe Payments Europe, Ltd. | Subscription billing and payment processing | Ireland (contracting entity), with onward transfer to its US parent under Standard Contractual Clauses |
| Hetzner Online GmbH | Hosting (database, application servers, file storage) in Falkenstein, Germany | Germany |
| Cloudflare, Inc. | Reverse proxy and TLS termination for all application traffic (transient processing, no content storage), and off-site backup storage (Cloudflare R2); backups are encrypted client-side with age before upload, the decryption private key is held only by the operator | United States (data stored in an EU region; Standard Contractual Clauses) |
| PostHog, Inc. (PostHog Cloud EU) | Error tracking only (exception events with key-based scrubbing of credentials and contact data); no analytics, no session capture, no widget-visitor telemetry | European Union (Frankfurt, Germany) |
| Google LLC (Gemini API) | Failover large-language-model provider (used only when Anthropic is unavailable) | United States (Standard Contractual Clauses) |
| OpenAI, L.L.C. | Failover content-extraction model (used only when the primary provider is unavailable) | United States (Standard Contractual Clauses) |
(2) The Processor shall inform the Controller of any intended changes regarding the addition or replacement of sub-processors at least 60 days in advance, in text form (e.g. by email to the point of contact designated in the header of this Agreement). The Controller may object to such changes within that period on substantive data-protection grounds. In the event of a justified objection, both Parties shall have the right to terminate the main contract extraordinarily.
(3) The Processor undertakes to enter into written agreements with each sub-processor that meet the requirements of Article 28 GDPR, in particular with regard to appropriate technical and organisational measures.
(4) Where sub-processors process personal data outside the European Union or the European Economic Area, the Processor shall ensure an adequate level of data protection by entering into the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) or by means of other appropriate safeguards under Article 46 GDPR.
§ 7 Technical and Organisational Measures (TOMs)
(1) The Processor shall implement the technical and organisational measures described in Annex 1 to this Agreement to ensure the security of the processing in accordance with Article 32 GDPR.
(2) The TOMs shall be reviewed regularly, and at least annually, and adapted to the state of the art. Material reductions in the level of protection are not permitted.
(3) The Processor shall demonstrate compliance with the TOMs on request by providing appropriate evidence (e.g., self-disclosure, certificates, external audit reports where available).
§ 8 Notification of Personal Data Breaches
(1) The Processor shall notify the Controller without undue delay, and in any case within 48 hours of becoming aware of it, of any personal data breach occurring within the Processor's or a sub-processor's area of responsibility.
(2) The notification shall, where available at the time of notification, include at least the following information:
a) a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and records concerned;
b) the name and contact details of the data-protection officer or other contact point;
c) a description of the likely consequences of the breach;
d) a description of the measures taken or proposed by the Processor to address the breach and mitigate its possible adverse effects.
(3) The Controller remains solely responsible for notifying the competent supervisory authority pursuant to Article 33 GDPR and, where applicable, the affected data subjects pursuant to Article 34 GDPR.
§ 9 Erasure and Return of Data
(1) Upon termination of the processing services, the Processor shall, at the Controller's choice, either delete or return all personal data processed on behalf of the Controller, unless Union or Member State law requires storage of the personal data.
(2) Erasure shall take place no later than 30 days after termination of the main contract. A data-export request from the Controller shall be fulfilled within 14 days.
(3) Local backup copies on the production system are overwritten daily and deleted from the production server after 30 days. Off-site backups on Cloudflare R2 are deleted automatically by an object-storage lifecycle rule after 90 days. This applies cumulatively to every category of data listed in § 3 — backups capture the state of the production database at the time of the backup, so a record deleted from the live database may persist in an encrypted off-site backup for up to 90 days after deletion. During this period the backed-up data is not actively processed; access is restricted to recovery scenarios. Off-site backups are encrypted client-side with asymmetric public-key cryptography (age) before they leave the production environment; the decryption private key is held exclusively by the Processor. The sub-processor that stores the backups has no technical access to the cleartext data.
§ 10 Inspection and Audit Rights
(1) The Controller has the right to verify the Processor's compliance with the obligations set out in this Agreement and in the GDPR. The Processor shall make available to the Controller all information necessary to demonstrate compliance.
(2) On-site inspections shall be carried out with reasonable advance notice of at least 14 days, during normal business hours, and no more than once per calendar year, unless there is a specific incident giving rise to an extraordinary inspection. Where an inspection exceeds the Processor's usual effort, the Processor may request reasonable reimbursement of expenses from the Controller.
(3) The Controller may exercise its inspection rights through authorised third parties. The Processor may object to a specific third party on important grounds (e.g., a competing relationship). Such third parties shall be bound to confidentiality before the inspection begins.
§ 11 Liability
The Parties' liability is governed by Article 82 GDPR and by the liability provisions of the main contract. Any liability limitation in the main contract shall not affect liability arising under this Agreement where the GDPR does not permit such limitation.
§ 12 Final Provisions
(1) If any provision of this Agreement is or becomes invalid in whole or in part, the validity of the remaining provisions shall not be affected. The invalid provision shall be replaced by an effective provision that comes closest to the economic purpose of the invalid one.
(2) Amendments and supplements to this Agreement require text form. This also applies to any amendment of this text-form requirement itself.
(3) In the event of any conflict between this Agreement and the main contract, the provisions of this Agreement shall prevail to the extent they concern data-protection matters.
(4) This Agreement is governed exclusively by the laws of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods.
(5) The exclusive place of jurisdiction for all disputes arising out of or in connection with this Agreement is, to the extent permitted by law, Augsburg, Germany.
Annex 1: Technical and Organisational Measures (TOMs)
The Processor implements the following measures pursuant to Article 32 GDPR:
1. Confidentiality (Art. 32(1)(b) GDPR)
Physical Access Control
- Production infrastructure is operated in the data centre of Hetzner Online GmbH (Falkenstein, Germany). Hetzner employs multi-layered physical access controls (man-traps, video surveillance, 24/7 security personnel, biometric access controls).
- The data centre holds ISO/IEC 27001 certification.
Logical Access Control
- Administrative interfaces are accessible only via SSH with key-based authentication (password login disabled).
- All staff with production access use a password manager with two-factor authentication.
- Access to the administration interface is encrypted via HTTPS (TLS 1.3) with individual user authentication.
Authorisation Control
- Role-based permission model within the application (Owner, Admin, Viewer with fine-grained permissions).
- Strict tenant isolation: all database queries are tenant-scoped; cross-tenant access is prevented by database constraints and application-layer checks.
- Complete audit logs for administrative actions, retained for at least 12 months.
Separation Control
- Multi-tenant architecture with logical separation at the database and application layer.
- Production, staging, and development environments are strictly separated and use different data stores.
Pseudonymisation
- IP addresses are not persistently stored where not strictly required for operation. Where storage is required (e.g., rate limiting), it is time-limited.
- Optional PII redaction in conversation logs (enabled by default).
2. Integrity (Art. 32(1)(b) GDPR)
Transmission Control
- All data transmission between browser and server uses TLS 1.3.
- Data transmission to sub-processors (LLM, embedding, email providers) uses TLS-encrypted API connections exclusively.
- Tenant-specific API keys with origin allowlists restrict widget embedding to authorised domains.
Input Control
- Audit logs capture administrative actions with timestamp, user ID, and affected resource (retained for at least 12 months).
- Access logs (HTTP requests to the API) are recorded for IT security and abuse detection purposes under Article 6(1)(f) GDPR and automatically deleted from the production database after 30 days; encrypted off-site backups may retain a record for up to 90 additional days. Captured fields: timestamp, HTTP method and path, status code, latency, requester IP address, user agent, and — where authenticated — tenant ID and user ID. Request bodies and message content are not persisted.
- Conversation history is immutable after completion; subsequent corrections are versioned as separate entries.
3. Availability and Resilience (Art. 32(1)(b) GDPR)
Availability Control
- Regular automated database and file-system backups (daily, retained 30 days).
- Off-site backups are stored on Cloudflare R2 (EU region); before leaving the production environment they are encrypted client-side using asymmetric public-key cryptography (age). Cloudflare has no technical access to the cleartext backup data. The decryption private key is held exclusively by the Processor.
- External availability monitoring with alerts on outages and anomalies.
Recoverability
- Recovery Time Objective (RTO): 24 hours.
- Recovery Point Objective (RPO): 24 hours.
- Recovery procedures are tested regularly.
4. Regular Review (Art. 32(1)(d) GDPR)
- TOMs are reviewed at least annually by management.
- Security-relevant incidents trigger an ad-hoc review of the affected measures.
- TOMs are adapted to changes in the threat landscape and to the state of the art.
- Established open-source and commercial off-the-shelf components are used; security-relevant updates are applied promptly.
5. Sub-processor Management
- All sub-processors are named individually in Annex 2 of this Agreement.
- Each sub-processor is bound by an agreement meeting the requirements of Article 28 GDPR.
Annex 2: List of Sub-processors
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Anthropic, PBC | Large-language-model inference for chat replies and intent classification | United States (Standard Contractual Clauses) |
| Voyage AI, Inc. | Vector embeddings for retrieval-augmented generation over tenant content | United States (Standard Contractual Clauses) |
| Resend, Inc. | Transactional email delivery (onboarding, lead notifications, data-export links) | European Union |
| Stripe Payments Europe, Ltd. | Subscription billing and payment processing | Ireland (contracting entity), with onward transfer to its US parent under Standard Contractual Clauses |
| Hetzner Online GmbH | Hosting (database, application servers, file storage) in Falkenstein, Germany | Germany |
| Cloudflare, Inc. | Reverse proxy and TLS termination for all application traffic (transient processing, no content storage), and off-site backup storage (Cloudflare R2); backups are encrypted client-side with age before upload, the decryption private key is held only by the operator | United States (data stored in an EU region; Standard Contractual Clauses) |
| PostHog, Inc. (PostHog Cloud EU) | Error tracking only (exception events with key-based scrubbing of credentials and contact data); no analytics, no session capture, no widget-visitor telemetry | European Union (Frankfurt, Germany) |
| Google LLC (Gemini API) | Failover large-language-model provider (used only when Anthropic is unavailable) | United States (Standard Contractual Clauses) |
| OpenAI, L.L.C. | Failover content-extraction model (used only when the primary provider is unavailable) | United States (Standard Contractual Clauses) |
As of: [completed on signing]
Signatures
Controller
[Your company]
Represented by: [Signing contact]
Processor
Renner & Schneider GbR
Represented by: the partners authorised to represent the company (Daniel Renner / Tim Schneider)