Data processing agreement
Last updated 10 October 2026
Draft: this text has not yet been reviewed by a lawyer, and the parts marked [REVIEW] are still open.
This agreement applies when [Company legal name] (“processor”) processes personal data on behalf of a business that uses LovaAI (“controller”), as required by Art. 28 GDPR. It forms part of our terms of service and applies for as long as the controller uses the service.
Subject matter and purpose
The processor provides the assistant, the chat window and the panel. In doing so it processes personal data to answer the controller’s website visitors by voice or text, to show products and pages, to collect contact details and to present conversations and leads to the controller.
Types of data and data subjects
- Website visitors of the controller: messages, voice audio processed in real time and not recorded, pages viewed during the visit, contact details given by the visitor, the record of their consent in the contact form (time, text shown, privacy link and page), a random visitor ID kept in the browser, a keyed hash of the IP address, ratings of answers.
- The controller’s staff using the panel: name, email address, login and activity data.
Instructions
The processor processes personal data only on the controller’s documented instructions. These consist of this agreement, the terms of service and the settings the controller makes in the panel. If the processor believes an instruction breaks data protection law, it will tell the controller.
Confidentiality
Everyone at the processor who has access to personal data is bound to confidentiality.
Security
The processor takes the technical and organisational measures described in the annex below and keeps them up to date.
Subprocessors
The controller authorises the processor to use the subprocessors listed on the subprocessors page. The processor will announce new subprocessors at least 30 days in advance by email; the controller may object for important data protection reasons and, if no solution is found, cancel the service. The processor imposes the same data protection obligations on its subprocessors.
Transfers outside the EEA
Where a subprocessor processes data outside the European Economic Area, the transfer relies on an adequacy decision or on the EU standard contractual clauses. ElevenLabs processes data in the United States; it is certified under the EU-U.S. Data Privacy Framework, and its data processing agreement also incorporates the EU standard contractual clauses (Commission Implementing Decision 2021/914). [REVIEW: basis for the other providers]
Assistance
The processor helps the controller to respond to requests from data subjects, with security, with data protection impact assessments and with consulting the supervisory authority, as far as this concerns the service.
Personal data breaches
The processor informs the controller without undue delay, and within [REVIEW: 48] hours of becoming aware, of a personal data breach that affects the controller’s data, and gives the information the controller needs to meet its own obligations.
Deletion and return
While using the service, the controller can delete single conversations and leads, and all data of one data subject, in the panel. Conversations, visits and leads older than the retention period the controller sets (3 to 36 months, 12 by default) are deleted automatically. Copies at the speech provider expire after 90 days; data the controller deletes in the panel is deleted there as well. When the controller closes its account in the panel, the processor deletes its personal data at once. When the service ends in another way, the processor deletes the controller’s personal data within [REVIEW: 30] days, unless the law requires it to be kept. The controller can export its leads as a CSV file at any time; conversations can be read in the panel but not yet exported as a file.
Information and audits
The processor makes available the information needed to show that it meets this agreement and allows audits, including inspections, by the controller or an auditor it appoints, with reasonable notice and during business hours.
Annex: technical and organisational measures
- Encryption: traffic to the website, the panel and the chat window is encrypted with TLS. [REVIEW: encryption of databases at rest] Stored secrets such as Slack addresses and webhook keys are encrypted with AES-256-GCM. Passwords are stored as salted hashes.
- Data minimisation: voice calls are not recorded; IP addresses are stored only as keyed hashes; files uploaded as knowledge are not kept on our servers; conversations, visits and leads are deleted automatically after the retention period the controller sets.
- Access control: each business can only access its own data in the panel; each business has its own assistant and knowledge folder at the speech provider. Panel sign-in uses session cookies that page scripts can’t read, session tokens are stored only as hashes, and sign-in pauses after repeated failed attempts.
- Protection of the chat window: it loads only on the controller’s allowed domains (its website’s domain and subdomains) and in the panel, nowhere else; each text chat opens through a single-use signed link and each call through its own token; the provider’s keys never reach the browser.
- Integrity: incoming and outgoing webhooks are signed; outgoing webhooks go only to public HTTPS addresses.
- Availability and resilience: rate limits per visitor and per IP address on all public endpoints. [REVIEW: hosting, backups and recovery]