Data Processing Agreement (DPA)
Paskutinis redagavimas: 2026-08-21
Informational translation. The binding version of this document is the Lithuanian one. If the two ever differ, the Lithuanian text prevails — see the language clause in §14 of the Terms. Read the Lithuanian original.
These terms apply when Klizai MB processes personal data on the Customer’s behalf — that is, the conversation data SmartChat collects on the Customer’s website. They form an annex to the Terms of Service and meet the requirements of Art. 28 GDPR.
1. Parties and roles
- Controller — the Customer (an online store) that has installed the SmartChat chat window or email channel. The Customer decides the purpose and means of processing its visitors’ data and is responsible for the legal basis and for informing those visitors.
- Processor — Klizai MB, company code 307582652, Melioratorių g. 7, Šventupės k., LT-20362 Ukmergės r., Lithuania.
This DPA does not apply to the Customer’s own account data (email, billing). For that data Klizai MB is an independent controller, and it is governed by the Privacy Policy.
2. Subject matter, duration, nature and purpose
- Subject matter. Processing of personal data in the course of providing the SmartChat AI assistant service.
- Duration. From account creation until the end of the subscription, plus the deletion period under section 9.
- Nature. Collection, storage, structuring (vectorisation), retrieval, transfer to subprocessors and deletion — by automated means.
- Purpose. To answer the Customer’s visitors based on the Customer’s knowledge base; to capture contact details; to give the Customer an overview of conversations and analytics.
3. Categories of data subjects and of data
Data subjects: visitors to the Customer’s website and people writing to it (existing and prospective buyers).
Categories of personal data:
- the content of conversation messages (and anything a visitor writes in them);
- the visitor identifier
visitor_id; - contact details, where a visitor provides them — name, email, message;
visitor_emailand email content, where the email channel is enabled;- technical metadata —
source_url,user_agent, language, timestamps; - the text of unanswered queries.
Special categories of data (Art. 9 GDPR) are not envisaged. The service is not intended for health, biometric or other special data. The chat field is nevertheless free text, and there is no technical filter preventing a visitor from typing such data. The Customer is responsible for not designing a use case that invites it.
4. The Controller’s obligations and rights
Art. 28(3) GDPR requires the agreement to set out the obligations and rights of the Controller as well as the Processor. The Controller:
- determines the purpose and means of processing and ensures it has a legal basis (Art. 6 GDPR) for processing its visitors’ data through SmartChat;
- informs the data subjects (Arts. 13–14) — including that the conversation is handled by artificial intelligence and that data is transferred to the United States (see section 11);
- is responsible for its instructions being lawful, and for the legality and accuracy of the content it uploads to the knowledge base;
- does not upload special categories of data (Art. 9) and does not build use cases that encourage visitors to provide them (see section 3);
- handles data subject requests — the Processor assists (section 8), but the decision and the responsibility are the Controller’s;
- has the right to give documented instructions, to receive information under section 10, to object to subprocessors (section 6) and to choose what happens to the data when the agreement ends (section 9).
5. Processing on instructions
The Processor processes personal data only on documented instructions from the Controller, including instructions regarding transfers to third countries. These terms, the Customer’s account settings and the use of the service constitute such instructions. Where the Processor is required to process data under EU or Member State law, it informs the Controller before processing, unless that law prohibits such notice.
The Processor informs the Controller without delay if, in its opinion, an instruction infringes the GDPR.
Persons with access to the data are bound by confidentiality commitments.
6. Subprocessors
The Controller gives general prior authorisation for the use of subprocessors. The current list:
- Anthropic PBC — Generating AI answers (Claude Sonnet 4.6 and Claude Haiku 4.5) (United States)
- OpenAI, L.L.C. — Turning text into vectors for search (text-embedding-3-small) (United States)
- Supabase, Inc. — Database (PostgreSQL + pgvector), authentication (EU — Frankfurt (eu-central-1))
- Vercel, Inc. — Application hosting and execution (EU — Frankfurt (fra1))
- Upstash, Inc. — Redis — request rate limiting (EU — Ireland (eu-west-1))
- Resend (Plus Five Five, Inc.) — Outbound email (EU — Ireland (eu-west-1))
- Stripe Payments Europe, Ltd. — Subscription payments and billing (EU — Ireland)
- Sentry (Functional Software, Inc.) — Error monitoring (configured with sendDefaultPii: false) (EU — Frankfurt (de.sentry.io))
- Google Ireland Ltd. (Gmail API) — Reply drafts in the customer’s own Gmail mailbox (EU / United States) — only if the Customer enables it
- Shopify International Ltd. — Reading store data (products, orders) (EU / Canada) — only if the Customer enables it
The continuously updated list: /en/subprocessors.
Before changing or adding a subprocessor, the Processor informs the Controller 30 days in advance. The Controller may reasonably object; if the objection cannot be resolved, the Controller may terminate the service without penalty. The Processor concludes an agreement with each subprocessor imposing obligations no less protective than those in this DPA, and remains fully liable to the Controller for the subprocessor’s acts.
7. Security measures (Art. 32 GDPR)
Measures implemented, and verifiable in the code:
- Tenant isolation — each Customer’s data is separated at the database level through PostgreSQL Row Level Security policies.
- Encryption — TLS in transit; encryption at rest (Supabase); application level encryption of sensitive access tokens (for example the Gmail refresh token).
- Access control — authentication through Supabase Auth, role-based access to the Customer’s account.
- Abuse resistance — request rate limiting per IP and per Customer; domain allowlist checks for the chat window.
- Automatic deletion — a configurable retention window with a nightly purge process.
- Monitoring — error monitoring without personal data (
sendDefaultPii: false).
The Processor commits only to the measures listed in this section. The Processor does not hold ISO 27001 or SOC 2 certification and does not carry out periodic independent penetration testing; where the Controller requires such measures, they are agreed separately in writing.
8. Assistance to the Controller
- Data subject requests (Arts. 12–23). Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures. Implemented: deletion and data export by email address; automatic handling of the Shopify
customers/redact,customers/data_requestandshop/redactwebhooks. Where a request reaches the Processor directly, it does not act on it independently but forwards it to the Controller.
A limit worth knowing: a data subject is identified by email address. A conversation with no email is linked only to avisitor_id, so it can be deleted only if that identifier is provided. - Personal data breaches (Arts. 33–34). The Processor notifies the Controller without undue delay after becoming aware, and in any event within 48 hours, and provides the information available to it that the Controller needs to meet its own obligations.
- DPIAs and prior consultation (Arts. 35–36). The Processor provides reasonable assistance, taking into account the information available to it.
9. Deletion or return
On the end of the provision of services, at the Controller’s choice the Processor deletes or returns all personal data and deletes existing copies, unless EU or Member State law requires retention. The Controller must state its choice within 30 days of the end of the agreement; failing that, the data is deleted within 90 days.
During the term the Controller may at any time set an automatic conversation retention window or trigger deletion itself.
No restorable backups are kept at present — the database service plan in use does not include them. The practical consequence for the Controller cuts both ways: deleted data cannot be recovered from a backup, so deletion is immediately final, but for the same reason the Processor cannot guarantee recovery after an infrastructure failure.
10. Audit and information
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations in Art. 28 GDPR, and allows for and contributes to audits conducted by the Controller or an auditor it mandates.
The Processor maintains, and on request provides, records of processing activities under Art. 30(2) GDPR — the categories of processing, subprocessors, transfers to third countries and a general description of the security measures.
Practical terms: an audit is carried out no more than once a year, on 30 days’ notice, during working hours, without disrupting operations and subject to confidentiality. The Controller covers the Processor’s reasonable costs, except where the audit reveals a material breach. The Processor holds no ISO 27001 or SOC 2 certificate that could stand in place of an audit.
11. International transfers
Data is stored and processed in the EU: the database and application execution in Frankfurt, rate limiting in Ireland, error monitoring in Frankfurt.
For the service to work, however, conversation content is transferred to the United States — to Anthropic (generating answers) and OpenAI (vectorisation). These two transfers are continuous and unavoidable: without them the service does not function.
Separately: some providers operating in the EU region have US parent companies that may access data for support purposes, and optional channels (Gmail, Shopify) may process data outside the EEA. The exact location and transfer basis for each provider is set out in the subprocessor list.
By entering into this DPA, the Controller instructs the Processor to carry out these transfers. Without them the service does not work. A Controller that cannot accept transfers to the United States should not use the service.
Transfers are governed by the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914, Module 3 (processor to processor), concluded with each US-established subprocessor and forming part of its data processing agreement. Those clauses are incorporated into this DPA by reference; their text is set out in the relevant subprocessor’s data processing agreement. In the event of a conflict between this DPA and the standard contractual clauses, the standard contractual clauses prevail.
12. Conflicts and liability
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails on matters of personal data processing. The limitation of liability is set out in the Terms of Service; it does not apply to the extent Art. 82 GDPR does not permit it.