Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement (“DPA”) applies where Ninjabot processes personal data on behalf of a customer in connection with the Ninjabot service, and forms part of the service agreement. A countersigned copy is available on request: privacy@ninjabot.eu.
1. Roles & scope
The customer is the data controller of the personal data in its lists, conversations, and CRM records; Ninjabot is the data processor. Processing covers contact and conversation data needed to respond to, qualify, and book the customer’s leads.
2. Processor obligations
- Process personal data only on documented instructions from the customer.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational measures (encryption in transit and at rest, role-based access, logging).
- Assist the customer with data subject requests and with obligations under Articles 32–36 GDPR.
- Delete or return personal data at the end of the engagement, at the customer’s choice.
- Make available information necessary to demonstrate compliance and allow audits.
3. Sub-processors
Ninjabot uses vetted sub-processors (hosting, telephony, email delivery, AI model providers) under written agreements imposing equivalent obligations. The current sub-processor list is available on request; customers are notified of changes with an opportunity to object.
4. International transfers
Data is stored in the EU. Where a sub-processor processes data outside the EU/EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
5. Security incidents
Ninjabot notifies the customer without undue delay after becoming aware of a personal data breach affecting customer data, with information reasonably needed for the customer’s own notification obligations.
For the signable version of this DPA, required by many clinics, brokers, and legal buyers, contact privacy@ninjabot.eu.