Data Processing Agreement
pursuant to Art. 28 of Regulation (EU) 2016/679 ("GDPR")
Permanent text of this version: plutonios.com/en/data-processing-agreement/v1-0
This is a translation. In case of discrepancy, the Italian version prevails.
This agreement ("Agreement") forms an integral part of the contract for the supply of the Plutonios services, consisting of the commercial offer ("Offer") and the General Terms and Conditions for the Supply of Services ("GTC") (jointly, the "Contract"), and is accepted by signing the Offer. The parties to the Agreement are:
- the Company indicated in the Offer, as data controller ("Controller");
- Plutonios S.r.l., with registered office at Via Giuseppe Frua 15, 20146 Milan, Italy, tax code/VAT 13788200965, as data processor ("Processor").
Terms not defined in this Agreement have the meaning given to them by the GDPR.
1. Subject matter and duration
The Controller entrusts the Processor with the processing of the personal data necessary to provide the Services described in the Contract. This Agreement supplements and, in case of conflict, prevails over the GTC.
The Agreement has the same duration as the Contract and remains in effect until the data are returned or erased under Art. 10.
2. Nature and purposes of the processing
The Processor processes personal data exclusively to:
- a)manage, through the artificial intelligence assistant, conversations with guests and prospective guests on the activated channels (web widget, WhatsApp, email and, if activated, telephone), including translation, summaries and escalation to the Controller’s staff;
- b)generate quotes and check availability through the connection to the Controller’s booking engine and PMS;
- c)synchronise bookings from the PMS or channel manager and provide the inbox, back office, conversation history and dashboards;
- d)run the automations configured by the Controller (pre-stay, stay, post-stay) and, where requested by the Controller, guest analysis and segmentation;
- e)provide technical support, maintenance, security and the quality checks provided for in Art. 9.3 of the GTC.
Processing is carried out by electronic means, including through artificial intelligence models made available by the sub-processors listed in Annex 1.
3. Categories of data subjects and data
Data subjects: guests, prospective guests and users who contact the Controller through the channels of the Services; persons named in bookings, including companions and minors limited to their number and age; the Controller’s staff using the back office.
Data: identification and contact data (name, telephone, email, language, nationality); booking and stay data (dates, rooms, rates, quotes, number and age of guests, requests); content of conversations (messages, voice messages and their transcripts, call recordings where activated); technical identifiers (WhatsApp identifier, browser identifier, IP address); preferences and attributes inferred from conversations; data transmitted by the Controller’s PMS or channel manager.
The Services are not intended for processing special categories of personal data (Art. 9 GDPR) or identity document data. The Processor limits the data acquired from the PMS to those necessary to provide the Services and does not use health data for segmentation or promotional purposes. Where such data are spontaneously provided by guests in conversations, they are processed solely to handle the related request.
4. Controller’s instructions
The Processor processes personal data only on documented instructions from the Controller, consisting of the Contract, this Agreement and the settings configured by the Controller in the back office, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in such a case the Processor informs the Controller before processing, unless the law prohibits it.
The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
The Processor keeps the Controller’s data logically separate from data processed on behalf of other customers and does not combine them.
5. Authorised persons
The Processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, have received instructions under Art. 29 GDPR and access the data only to the extent necessary for support, maintenance, security and quality control of the Services.
6. Security
The Processor implements appropriate technical and organisational measures under Art. 32 GDPR, taking into account the state of the art, the costs of implementation and the risks, including: (a) encryption of data in transit; (b) encryption of credentials for access to third-party systems; (c) role-based access control and individual credentials; (d) logging of access and relevant events; (e) periodic backups; (f) storage of the main data on servers located in the European Union; (g) incident management procedures; (h) periodic review and update of the measures.
The Processor assists the Controller in ensuring compliance with Arts. 32-36 GDPR, including data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to it.
7. Sub-processors
The Controller grants general written authorisation to engage the sub-processors listed in Annex 1.
The Processor notifies the Controller in writing, including by email, of any intended addition or replacement of sub-processors at least 15 (fifteen) days in advance. The Controller may object on reasonable and documented data protection grounds within 10 (ten) days of the notice. In case of objection the Parties seek a solution in good faith; failing that, the Controller may withdraw from the affected Services without penalty, including the penalty under Art. 6.3 of the GTC, with a refund of the unused portion of the fee.
The Processor imposes on sub-processors, by contract, data protection obligations substantially equivalent to those in this Agreement and remains liable to the Controller for the performance of their obligations (Art. 28(4) GDPR).
Where the WhatsApp channel is activated on a WhatsApp Business account in the Controller’s name, Meta processes the data under the direct contractual relationship between the Controller and Meta; the Processor accesses it as a technology provider authorised by the Controller.
8. Transfers to third countries
Transfers of personal data outside the European Economic Area take place only to the sub-processors listed in Annex 1 and on the basis of the safeguards under Chapter V GDPR: an adequacy decision, including the EU-U.S. Data Privacy Framework for certified recipients, or standard contractual clauses adopted by the European Commission.
9. Data subject rights and personal data breaches
The Processor informs the Controller without undue delay, and in any case within 5 (five) working days, of requests received directly from data subjects and does not respond to them without the Controller’s instructions. At the Controller’s request, it carries out within 15 (fifteen) days the operations needed to handle requests for access, rectification, erasure, restriction and portability.
The Processor notifies the Controller of any personal data breach without undue delay and in any case within 48 (forty-eight) hours of becoming aware of it, providing, to the extent available, the information referred to in Art. 33(3) GDPR, and cooperates with the Controller for the obligations under Arts. 33 and 34 GDPR.
10. Retention, return and erasure
Data are retained for the duration of the Contract. The Controller may at any time request the early erasure of individual conversations or of the data of individual guests.
Technical logs, which may contain conversation data, are retained for no more than 120 (one hundred and twenty) days. Call recordings, where the telephone channel is activated, are retained for the period set by the Controller and in any case for no more than 90 (ninety) days.
Upon termination of the Contract the Processor, at the Controller’s choice, returns the data as provided by Art. 6.3 of the GTC and erases them within 30 (thirty) days; backup copies are erased within 90 (ninety) days of termination, unless Union or Member State law requires their retention. On request, the Processor confirms the erasure in writing.
11. Information and audits
The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or by an auditor mandated by it and bound by confidentiality.
Except in case of a personal data breach or a request from a supervisory authority, audits are agreed with at least 30 (thirty) days’ notice, no more than once a year, during business hours, in a manner that does not compromise the security of other customers’ data, and at the Controller’s expense.
12. Further obligations
The Processor keeps the record of processing activities under Art. 30(2) GDPR.
The Controller guarantees the lawfulness of the processing entrusted, including the existence of an appropriate legal basis, the information provided to data subjects and, where necessary, the collection of consent, as well as the lawfulness of the instructions given.
The liability of the Parties towards data subjects is governed by Art. 82 GDPR.
Annex 1. Authorised sub-processors
- Sub-processor
- Hetzner Online GmbH
- Activity
- Hosting of application servers, databases, backups, logs and system services
- Location
- Germany
- Transfer safeguards
- No transfer outside the EEA
- Sub-processor
- Google Ireland Ltd / Google LLC
- Activity
- Firebase (widget hosting and file storage), Gemini API (speech synthesis), Cloud Translation, Google Workspace (email channel), Cloud Run (technical web page reading services)
- Location
- EU / USA
- Transfer safeguards
- Data Privacy Framework; standard contractual clauses
- Sub-processor
- OpenAI Ireland Ltd / OpenAI, L.L.C.
- Activity
- Language models for replies, translation, summaries, classification and knowledge base indexing
- Location
- USA
- Transfer safeguards
- Standard contractual clauses; Data Privacy Framework where certified
- Sub-processor
- Groq, Inc.
- Activity
- Language models for information extraction and conversation classification
- Location
- USA
- Transfer safeguards
- Standard contractual clauses; Data Privacy Framework where certified
- Sub-processor
- Anthropic Ireland Ltd / Anthropic, PBC
- Activity
- Artificial intelligence tools for technical support, analysis and quality control
- Location
- USA
- Transfer safeguards
- Standard contractual clauses; Data Privacy Framework where certified
- Sub-processor
- Meta Platforms Ireland Ltd
- Activity
- WhatsApp Business Platform, for numbers provided by Plutonios (Art. 9.4(b) of the GTC)
- Location
- EU / USA
- Transfer safeguards
- Data Privacy Framework; standard contractual clauses
- Sub-processor
- Qdrant Solutions GmbH
- Activity
- Vector database for the knowledge base
- Location
- Germany
- Transfer safeguards
- No transfer outside the EEA
- Sub-processor
- Langfuse GmbH
- Activity
- Technical monitoring of calls to artificial intelligence models
- Location
- EU
- Transfer safeguards
- No transfer outside the EEA
- Sub-processor
- Soniox, Inc.
- Activity
- Speech transcription, only if the telephone channel is activated
- Location
- USA
- Transfer safeguards
- Standard contractual clauses
| Sub-processor | Activity | Location | Transfer safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of application servers, databases, backups, logs and system services | Germany | No transfer outside the EEA |
| Google Ireland Ltd / Google LLC | Firebase (widget hosting and file storage), Gemini API (speech synthesis), Cloud Translation, Google Workspace (email channel), Cloud Run (technical web page reading services) | EU / USA | Data Privacy Framework; standard contractual clauses |
| OpenAI Ireland Ltd / OpenAI, L.L.C. | Language models for replies, translation, summaries, classification and knowledge base indexing | USA | Standard contractual clauses; Data Privacy Framework where certified |
| Groq, Inc. | Language models for information extraction and conversation classification | USA | Standard contractual clauses; Data Privacy Framework where certified |
| Anthropic Ireland Ltd / Anthropic, PBC | Artificial intelligence tools for technical support, analysis and quality control | USA | Standard contractual clauses; Data Privacy Framework where certified |
| Meta Platforms Ireland Ltd | WhatsApp Business Platform, for numbers provided by Plutonios (Art. 9.4(b) of the GTC) | EU / USA | Data Privacy Framework; standard contractual clauses |
| Qdrant Solutions GmbH | Vector database for the knowledge base | Germany | No transfer outside the EEA |
| Langfuse GmbH | Technical monitoring of calls to artificial intelligence models | EU | No transfer outside the EEA |
| Soniox, Inc. | Speech transcription, only if the telephone channel is activated | USA | Standard contractual clauses |