EPAV DESK · DATA PROCESSING AGREEMENT

Version 1.0 · Effective from 9 October 2026

Processor: NeriusCognitaren OÜ, registry code 17503018, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia ("EPAV", "we", "us")
Data protection: privacy@epavdesk.com · Support: support@epavdesk.com · Legal: legal@epavdesk.com
Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), https://www.aki.ee


1. What this agreement is

1.1 This Data Processing Agreement ("DPA") is part of the EPAV Desk Terms of Service (the "Terms"). It sets out how we process personal data on your behalf when you use EPAV Desk, as Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") requires.

1.2 How it is concluded. You accept this DPA when you create a cabinet at my.epavdesk.com and accept the Terms. It is concluded in electronic form (Article 28(9) GDPR) and needs no separate signature. The person who accepts it confirms that they may bind the company named in the cabinet. We record which version was accepted, by which account and when. A copy of the version in force is always available at https://epavdesk.com/legal/dpa and, on request, as a PDF from privacy@epavdesk.com.

1.3 Order of precedence. On the processing of personal data, this DPA prevails over the Terms. Where Standard Contractual Clauses apply under Section 12, they prevail over this DPA.

1.4 Words used here. Words defined in the GDPR (such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach") have the GDPR meaning. In addition:


2. Roles

2.1 For Customer Personal Data you are the controller and we are your processor. If you use EPAV Desk to serve your own clients and act as their processor, we are your sub-processor, and you confirm that your clients have authorised this.

2.2 For your cabinet account, billing, our own support conversations with you and the security of our service, we are an independent controller, and our Privacy Policy applies. This does not cover the content of your Site: conversations, contacts, files and knowledge base remain Customer Personal Data.

2.3 Services you choose yourself are not our Sub-processors. When you connect a service to your Site, that service works for you under its own terms, and we only pass data to it on your instruction. This includes: your own AI provider and API key, your own mail server or mailbox, Telegram, Meta (WhatsApp), Atlassian Confluence, Shopify, WooCommerce, Cal.com, your webhooks and the custom tools of your assistant, and the push services of the browsers your agents use.


3. Your instructions

3.1 We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms, this DPA, and the settings you choose in your Site and your cabinet (for example the channels you connect, whether the AI assistant answers, which AI provider it uses, and what you delete). Other instructions need our written agreement. You also instruct us to compute anonymous, aggregated statistics from usage figures, which no longer identify anyone, to improve EPAV Desk.

3.2 We do not process Customer Personal Data for our own purposes. In particular, we do not use it to train or fine-tune AI models, and we do not sell it or use it for advertising.

3.3 If we believe an instruction infringes data protection law, we tell you immediately, unless the law forbids it, and we may suspend the affected processing until you confirm, change or withdraw the instruction.

3.4 If the law of the EU or an EU Member State requires us to process Customer Personal Data in another way, we tell you before we do so, unless that law forbids it.


4. Your responsibilities

4.1 You are responsible for having a lawful basis for the processing, for informing your Visitors and Agents, and for the content you put into your Site. Annex 4 of this DPA gives you text you can adapt for your own privacy notice.

4.2 Do not use EPAV Desk to collect special categories of personal data (Article 9 GDPR), data on criminal convictions, or payment card numbers, unless you have assessed this yourself and have a lawful basis. Visitors may write such data into a chat without being asked; you decide how to handle it, and you can delete it in your Site.

4.3 Keep the access to your Site secure: choose who your Agents are, give them the roles they need, and protect their passwords and the keys you create.


5. Confidentiality and our people

5.1 Only people who need access to operate, support or secure the service may access Customer Personal Data, and only as far as needed. They are bound by a duty of confidentiality that continues after their work for us ends.

5.2 How we access your Site. Your Site has built-in service accounts that we use to set it up, change its address and collect the usage figures shown in your cabinet. These accounts must not be edited or deleted. The usage figures include, for each handover to a human and each question the assistant could not answer, the type, reason, time and the Visitor's last message before it, shortened to 300 characters, so that you can see in your cabinet which questions the assistant did not answer. Our staff can see these figures too. We look at the content of your Site beyond that only when you ask for help, when it is needed to fix a fault or a security problem, or when the law requires. Our hosting account also gives the people who operate the service access to the Site's database and storage; we use it only for these purposes and to carry out exports you ask for.


6. Security

6.1 We implement the technical and organisational measures described in Annex 2. We may improve or replace them, but not in a way that lowers the overall level of protection.

6.2 You are responsible for the security measures that are in your hands, described in Section 4.3 and Annex 2, part B.


7. Sub-processors

7.1 General authorisation. You authorise us to engage the Sub-processors listed in the EPAV Desk Sub-processor List (https://epavdesk.com/legal/subprocessors) as it stands when you accept this DPA. The list states for each Sub-processor what it does, which data it receives, where it processes the data and on what basis data leaves the EEA. It is Annex 3 of this DPA.

7.2 Our duties toward Sub-processors. We engage a Sub-processor only under a written contract (which may be its standard terms accepted electronically) that imposes data protection obligations no less protective than those in this DPA as far as they apply to its service. We remain liable to you for our Sub-processors as for ourselves. On request we give you a copy of the relevant terms, without commercial details.

7.3 Changes. Before we add or replace a Sub-processor, we email the owner of your cabinet at least 30 days before the new Sub-processor starts processing Customer Personal Data. The email names the Sub-processor, what it will do, where, and on what transfer basis. We also update the list and keep a dated record of changes. For a model listed under OpenRouter, the hosts that OpenRouter chooses for each request are named as seen in use and may change without prior notice from OpenRouter; the notice in this Section applies to OpenRouter itself, to the models and to the settings named in the List.

7.4 Objection. You may object within 14 days after our email, by writing to privacy@epavdesk.com with reasonable grounds relating to data protection. We will then try in good faith to offer an alternative, for example a setting that keeps your data away from that Sub-processor, or the use of your own AI provider. If we cannot offer one before the change takes effect, you may cancel your subscription with effect from that date, and we refund the part of any fee you prepaid for the time after it. If you do not object in time, the change is treated as authorised.

7.5 Urgent replacement. If a Sub-processor fails, stops its service or becomes a security risk, we may replace it with another provider of the same kind without the 30-day notice where waiting would interrupt your service or put data at risk. We then tell you without undue delay, and Section 7.4 applies from that email.

7.6 AI routing. Requests to cloud AI models go from our AI gateway to OpenRouter, Inc., which passes each request to a model host, and, for ordering search results, to Voyage AI directly. For each function the Sub-processor List names the model and the hosts used with it, and the settings we apply (no use of requests for training, and zero data retention where stated). During a trial, when the cloud AI budget of your plan is used up, after 14 days of a failed payment, after the paid period of a cancelled plan, and as a backup when our cloud AI does not answer or its overall limit is reached, the assistant uses EPAV's own model on hardware that EPAV operates itself in the EU, which is not a Sub-processor. If you connect your own AI provider in your Site and place it first, it answers instead; when it cannot answer, the next provider in your list takes over, which may be our cloud AI or our own model. Your provider settings decide this, and our documentation explains them.


8. Requests from data subjects

8.1 If a Visitor or Agent asks us to exercise their rights over Customer Personal Data, we forward the request to you without undue delay and tell the person that we have done so. We do not answer it ourselves unless you authorise us.

8.2 Your Site lets you do most of the work yourself: Agents with the right permissions can find a contact, export the data of one contact, download the transcript of a conversation, and delete a contact together with their conversations and files. Where you need more help, we provide it as far as is reasonable given the nature of the processing.


9. Other assistance

9.1 We help you, as far as is reasonable given the information available to us, with security (Article 32 GDPR), with notifying personal data breaches (Articles 33 and 34), with data protection impact assessments and with prior consultation of a supervisory authority (Articles 35 and 36).

9.2 For a data protection impact assessment, we provide on request a document pack: this DPA with its annexes, the Sub-processor List, and a description of how the AI assistant processes conversations. Custom work beyond that may be charged at cost, which we will tell you in advance.

9.3 If we become aware that Customer Personal Data in our systems is inaccurate or outdated, we tell you without undue delay.


10. Personal data breaches

10.1 If we become aware of a personal data breach affecting Customer Personal Data, we notify you without undue delay and in any case within 48 hours, by email to the owner of your cabinet. Unsuccessful attempts that do not compromise data, such as failed log-ins, port scans or blocked attacks, are not breaches for this purpose.

10.2 The notification describes, as far as known: the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we do not have all of this at once, we send it in stages as we learn it.

10.3 We take reasonable steps to contain the breach and limit its effects. A notification is not an admission of fault.


11. When the service ends: return and deletion

11.1 Export during the subscription. You can take your data out at any time: the knowledge base through your own AI assistant connected over MCP, a conversation with "Download transcript", the data of one contact with "Export data", and conversations, messages and contacts in bulk through the REST API of your Site.

11.2 After cancellation. Your Site works until the end of the paid period. From the next day the AI assistant is paused, and the panel keeps working for 30 days so that you can export your data. If you ask us at support@epavdesk.com before the deletion date, we export the knowledge base and the contacts for you and send them to the email address of your cabinet. 30 days after the pause we remove the Site.

11.3 Account deletion on request. If you ask for your account to be deleted (in your cabinet or at support@epavdesk.com), we cancel the subscription and remove the Site with its data within 7 days.

11.4 Trial without payment. A trial Site whose owner has not paid is removed on day 14 of the trial, counting the day the email was confirmed as day 1. A Site whose email was never confirmed is removed 7 days after sign-up.

11.5 What removal means. Removing a Site deletes its hosting project with its database, files and knowledge base, takes its addresses out of service, and deletes the encrypted secrets of the Site that our cabinet holds. We ask our hosting provider to delete the project; it is deleted 48 hours later, and until then we can still cancel the deletion. After that the Site cannot be restored. When the hosting provider erases the project's volumes and their backups follows its own rules. The usage figures of the Site in our cabinet are deleted at the same time, and backups of our cabinet's database are replaced as they expire. A removed Site is never given to another customer.

11.6 We may keep Customer Personal Data longer only where EU or Member State law requires it, and then only for that purpose.


12. Transfers outside the EEA

12.1 We are established in Estonia, and your Site runs in the EU West region (Amsterdam, the Netherlands) of our hosting provider. Some Sub-processors are established or process data outside the EEA. You authorise those transfers as described in the Sub-processor List.

12.2 We transfer Customer Personal Data outside the EEA only on one of these bases: an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework, for recipients certified under it), or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, included in the Sub-processor's data processing terms. Where a Sub-processor passes data on to its own providers outside the EEA, it does so under its own terms with them, as the Sub-processor List describes. Where a basis is no longer valid, we move to another valid basis or stop the transfer and tell you.

12.3 If you are established outside the EEA in a country without an adequacy decision, the Standard Contractual Clauses of Decision (EU) 2021/914, Module 4 (processor to controller), are incorporated into this DPA for transfers from us to you, with Estonian law and the courts of Estonia chosen under their Clauses 17 and 18.

12.4 Requests from public authorities. If a public authority asks us for Customer Personal Data, we refer it to you where the law allows, tell you about the request unless the law forbids it, and disclose only what we are legally obliged to disclose.


13. Information and audits

13.1 We make available to you the information needed to show that we meet Article 28 GDPR. First by documents: this DPA, its annexes and written answers to a reasonable security questionnaire.

13.2 If that is not enough, or a supervisory authority requires it, or after a personal data breach, you may audit our compliance, yourself or through an independent auditor bound by confidentiality, once a year and additionally when there are indications of non-compliance. Audits are held remotely where possible, with at least 14 days' notice, during business hours, and without access to other customers' data. You bear your own costs and your auditor's. Our hosting provider and other Sub-processors are audited through the reports and certifications they publish.


14. Liability

14.1 Each party's liability under this DPA is subject to the limits in the Terms. Nothing in this DPA limits the rights of data subjects under the GDPR, including under Article 82, or liability that the law does not allow to be limited.


15. Duration, changes, law

15.1 This DPA applies for as long as we process Customer Personal Data for you, including the period after the end of the Terms until deletion under Section 11 is complete.

15.2 Changes. We may change this DPA to reflect changes in the law, in guidance of supervisory authorities, or in our service. We email the owner of your cabinet a summary of the changes at least 30 days before they take effect. If a change reduces your protection, you may cancel your subscription before it takes effect and we refund the part of any fee you prepaid for the time after cancellation. A change required by law or a supervisory authority may take effect sooner, as that requires. If you do not cancel before a change takes effect, you approve it. Changes to the Sub-processor List follow Section 7, not this Section. Earlier versions of this DPA remain available with their dates at https://epavdesk.com/legal/dpa.

15.3 Law and courts. This DPA is governed by Estonian law, and disputes go to Harju County Court (Harju Maakohus), Tallinn.

15.4 Contact. Questions about this DPA and objections under Section 7: privacy@epavdesk.com. Data protection notices to us: privacy@epavdesk.com, or by post to Sepapaja tn 6, 15551 Tallinn, Estonia.


Annex 1 · Details of the processing

Parties. Controller: the customer named in the cabinet, contact: the owner of the cabinet. Processor: NeriusCognitaren OÜ, see the header. Competent supervisory authority for the processor: Andmekaitse Inspektsioon (Estonia).

Subject matter and purpose. Providing EPAV Desk to the customer: receiving and storing conversations from the customer's channels, letting the customer's Agents answer them, answering Visitors automatically with an AI assistant from the customer's knowledge base, searching the knowledge base, transcribing voice messages, describing images sent by Visitors, sending email notifications to Agents, keeping a help center, reporting usage in the cabinet, and operating, securing and updating the Site.

Nature of the processing. Collection, storage, retrieval, transmission, organisation, automated generation of replies by large language models, semantic search, speech to text, image to text, email delivery, export and erasure.

Duration. The term of the subscription and the periods in Section 11. Frequency: continuous.

Categories of data subjects.

Categories of personal data.

Special categories. Not intended. Visitors may disclose them in free text; see Section 4.2. Voice messages are stored as attachments and transcribed; they are not used to identify anyone by their voice.

AI processing. When the AI assistant answers, the conversation text and the relevant pieces of the knowledge base go to the AI model. Images in the conversation are first turned into text by an image model. Voice messages are transcribed by a speech model. When articles are added or changed, their text goes to the search model. The Visitor's question goes to the search model and to the model that orders the results by relevance. For answers in Estonian, Latvian and Lithuanian, the answer goes to the model a second time for a spelling check. Agents' requests to the AI helpers in the panel go to the same models. The AI assistant tells people that they are chatting with an AI assistant in its first message in the chat, the mobile app, Telegram and WhatsApp. When a conversation is resolved, the assistant may draft a question and answer for the knowledge base from it; a draft becomes an article only if the customer approves it, and the customer can switch this off.

Retention in the Site. Conversations, contacts and files are kept until the customer deletes the contact (which deletes the contact's conversations and files) or the Site is removed. Shorter periods apply to: notifications in the panel (30 days), help center search queries (90 days), the list of visited pages (24 hours), anonymous chat sessions (180 days, extended on each use), the change journal of the knowledge server (30 days). Usage figures in the cabinet are deleted when the Site is removed. Deleting a contact does not reach copies of the database taken before updates, records of proactive messages, activity logs of Agents or the usage figures in the cabinet: these are kept until the Site is removed, and on request we delete a Visitor's entries in the usage figures earlier.


Annex 2 · Technical and organisational measures

A. Measures we take

  1. Separation. Every customer gets a separate installation: its own application, database, cache and knowledge server in a separate hosting project. Conversations, contacts, files and the knowledge base are kept only in the Site's own database. Our cabinet's database, shared by all customers, holds the usage figures described in Section 5.2, including the shortened Visitor messages.
  2. Location. Sites and the AI gateway run in the EU West region (Amsterdam, the Netherlands) of our hosting provider. EPAV's own AI model runs on hardware that EPAV operates in the EU.
  3. Encryption in transit. The panel, the chat, the help center, the cabinet and the widget are served over HTTPS. Requests to AI providers use HTTPS, and our email is sent to the delivery service over an encrypted connection (STARTTLS).
  4. Secrets. The Site's encryption key, the password of its System account, the secret of its knowledge server and its keys to the AI gateway are stored in our cabinet encrypted, with the key kept only in the cabinet's environment. In the Site, connector tokens (such as Confluence), webhook secrets and the headers of assistant tools are stored encrypted with the Site's key. Cabinet passwords are stored only as salted hashes.
  5. Sessions. Panel sessions expire after 9 hours by default. The session cookies of the panel and the cabinet are HttpOnly, SameSite=Lax and Secure. Cabinet sessions last 30 days and are stored only as hashes.
  6. Limits on abuse. The Site limits the rate of requests to the chat, sign-in, public pages and files, and the number of chat conversations per contact per day. Outgoing requests made for you (webhooks, assistant tools, import of web pages) are blocked from reaching internal network addresses.
  7. Minimal logging. The AI gateway does not write the content of requests to its logs. The cabinet and the widget server log requests without the body and without the Visitor's IP address; the cabinet's log also names the recipients of emails it relays for the EPAV mailbox.
  8. AI settings. For our cloud AI we set OpenRouter to use only hosts that do not use requests for training, and only zero-retention hosts where the Sub-processor List says so. For voice transcription no such setting can be sent, and we rely on the policies of the hosts, as the List says. Our own account with Voyage AI is opted out of data use.
  9. Updates and recovery. We update the software of Sites centrally. Before an update we take a copy of the Site's database, and if the new version does not start, the Site returns to the previous version by itself.
  10. Access. Access to our hosting, the cabinet console and production secrets is limited to the people who operate the service. Day to day, our access to a Site goes through its service accounts; hosting-level access is used only as Section 5.2 describes.
  11. AI disclosure. The assistant identifies itself as an AI assistant in its first message in chat channels, and this cannot be switched off.
  12. Sub-processors. We choose Sub-processors that offer data processing terms and a valid transfer basis, and we list them publicly.
  13. Incidents. We follow the breach procedure in Section 10.
  14. Open source. The panel of each Site is based on open-source software under the GNU AGPL v3, and its source code is available from the Site itself, so its behaviour can be inspected.

B. Measures in your hands

  1. Decide who your Agents are, give them only the roles they need, and remove them when they leave.
  2. Keep passwords, API keys and access tokens secret, and rotate them if they may have leaked.
  3. Set the list of trusted domains for your chat, so that it can be embedded only on your own websites.
  4. Delete contacts you no longer need; this also deletes their conversations and files.
  5. Tell your Visitors how their data is processed (see Annex 4).

Annex 3 · Sub-processors

The Sub-processor List published at https://epavdesk.com/legal/subprocessors on the date you accept this DPA, as updated under Section 7.


Annex 4 · Text for your own privacy notice

The EPAV Desk Privacy Notice Template (https://epavdesk.com/legal/privacy-notice-template) gives wording you can adapt for your own privacy notice. It is provided for convenience and is not legal advice; you remain responsible for your notice.