Data Processing Agreement
Version 1.0 | Effective date: 12 March 2026
§ 1. Parties to the Agreement
This Data Processing Agreement (hereinafter: the “Agreement” or “DPA”) is concluded between:
- The Data Controller: the User of the BetterCX Platform who has registered an account and accepted the Platform’s Terms of Service (hereinafter: the “Controller” or the “User”),
- The Data Processor: AppWave Sp. z o.o. with its registered office in Łódź, ul. Kolumny 147E/1, 93-611 Łódź, KRS: 0001193213, NIP: 9820394623, REGON: 542683999 (hereinafter: the “Processor” or “AppWave”).
This Agreement constitutes an integral part of the BetterCX Platform Terms of Service and enters into force upon the creation of an account on the Platform by the Controller.
§ 2. Definitions
The terms used in this Agreement shall have the meanings assigned to them in Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the BetterCX Platform Terms of Service and the Platform Privacy Policy. In addition:
- Personal Data – personal data of End Users (the Controller’s customers) processed through the Platform;
- End User – a natural person whose data is processed as part of the communication conducted by the Controller through the Platform;
- Platform – the BetterCX application available at https://app.bettercx.ai/;
- Sub-processor (further data processor) – a third party to whom the Processor entrusts the processing of Personal Data for the purpose of providing the Platform’s services;
- Data Breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
§ 3. Subject Matter and Scope of the Agreement
- The Controller entrusts the Processor with the processing of End Users’ Personal Data in connection with the use of the BetterCX Platform, under the conditions set out in this Agreement.
- The Processor shall process Personal Data solely on behalf of the Controller and in accordance with the Controller’s documented instructions, unless processing is required under European Union law or the law of the Member State to which the Processor is subject.
- A detailed description of the processing is set out in Appendix 1 to this Agreement.
§ 4. Duration of the Agreement
- The Agreement shall remain in force for the entire period during which the Controller uses the BetterCX Platform.
- The Agreement shall expire upon the deletion of the Controller’s account on the Platform, subject to the obligations regarding the deletion or return of data set out in § 12.
§ 5. Obligations of the Processor
The Processor undertakes to:
- process Personal Data solely within the scope and for the purpose specified by the Controller, in accordance with this Agreement, the Platform Terms of Service and the Controller’s documented instructions;
- ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR;
- comply with the conditions for engaging a further data processor (sub-processor) set out in § 7;
- taking into account the nature of the processing, assist the Controller, insofar as possible, in fulfilling the obligation to respond to requests by data subjects for the exercise of their rights as set out in Chapter III of the GDPR;
- taking into account the nature of the processing and the information available, assist the Controller in fulfilling the obligations set out in Articles 32–36 of the GDPR;
- upon termination of the provision of services, at the Controller’s choice, delete or return all Personal Data and delete existing copies, unless European Union law or the law of a Member State requires the retention of the data;
- make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits and inspections in accordance with § 9.
§ 6. Technical and Organisational Measures
- The Processor applies the following technical and organisational measures to protect Personal Data:
- encryption of data in transit (TLS 1.2+) and at rest;
- storage of data on Amazon Web Services (AWS) servers located within the European Economic Area (EEA);
- access control based on the principle of least privilege;
- hashing of user passwords;
- regular security reviews and log monitoring;
- security incident response procedures;
- regular data backups performed at least every 7 days;
- multi-factor authentication (MFA) for administrative access to data processing systems.
- The Processor regularly tests, assesses and evaluates the effectiveness of technical and organisational measures for ensuring the security of processing.
- A detailed list of technical and organisational measures is set out in Appendix 2 to this Agreement.
§ 7. Further Entrustment of Processing (Sub-processors)
- The Controller grants general authorisation for the Processor to engage the further data processors (sub-processors) listed in Appendix 3 to this Agreement.
- The Processor shall inform the Controller of any intended changes regarding the addition or replacement of sub-processors with at least 14 days’ notice, by publishing an updated list of sub-processors on the Platform’s website and sending a notification to the Controller’s email address.
- The Controller has the right to raise a reasoned objection to a new sub-processor within 14 days of receiving the notification. In the event of an objection, the Parties shall negotiate to find a solution. If no solution is reached within 30 days, the Controller has the right to terminate the Platform usage agreement.
- The Processor shall ensure that each sub-processor is bound by data protection obligations at least equivalent to those set out in this Agreement, in accordance with Article 28(4) of the GDPR.
- The Processor shall bear full liability toward the Controller for the acts and omissions of sub-processors.
§ 8. Data Processing Using Artificial Intelligence
- In the course of providing the Platform’s services, the Processor uses artificial intelligence models provided by OpenAI, L.L.C. (hereinafter: “OpenAI”) via the API interface, for the purpose of text analysis and response generation.
- Personal Data may be transmitted to OpenAI solely to the extent necessary for the Platform functionalities configured by the Controller.
- According to OpenAI’s declarations regarding the API platform:
- OpenAI does not use data submitted via the API to train its models (by default);
- input and output data is retained in OpenAI’s logs for a period of up to 30 days for the purpose of abuse monitoring;
- data is encrypted at rest (AES-256) and in transit (TLS 1.2+);
- OpenAI is a certified participant in the EU-US Data Privacy Framework.
- The Processor shall make best efforts to ensure that the processing of data by OpenAI complies with the requirements of the GDPR, including by concluding an appropriate agreement (Data Processing Addendum) with OpenAI.
- The Controller acknowledges that the use of the Platform involves the transfer of Personal Data to OpenAI as a sub-processor, which includes the transfer of data to the United States on the basis of the mechanisms described in § 10.
§ 9. Audits and Inspections
- The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations arising from Article 28 of the GDPR.
- The Controller or a Controller-appointed auditor shall have the right to carry out an audit of compliance with this Agreement no more than once per calendar year, subject to 30 days’ prior notice.
- The audit shall be carried out at the Controller’s expense, in a manner that does not cause undue disruption to the Processor’s operations.
- The Processor may, instead of allowing an on-site audit, provide the Controller with current security certificates, reports from audits carried out by independent third parties (e.g. SOC 2) or other documents confirming compliance.
§ 10. Transfer of Data to Third Countries
- Personal Data is stored on AWS servers located within the EEA.
- In connection with the use of OpenAI and Stripe services, Personal Data may be transferred to the United States. Such transfers are carried out on the basis of:
- the European Commission’s implementing decision (EU) 2023/1795 (EU-US Data Privacy Framework) – with respect to certified entities;
- Standard Contractual Clauses (SCC) approved by the European Commission.
- The Processor shall ensure that transfers of data to third countries are carried out solely in accordance with the safeguards provided for in Chapter V of the GDPR.
§ 11. Personal Data Breach
- The Processor shall notify the Controller of a Personal Data Breach without undue delay, and no later than within 48 hours of becoming aware of the breach.
- The notification shall contain at a minimum:
- a description of the nature of the breach, including the categories and approximate number of data subjects affected;
- the name and contact details of the person from whom more information can be obtained;
- a description of the likely consequences of the breach;
- a description of the measures taken or proposed to remedy the breach.
- The Processor shall assist the Controller in fulfilling the obligations under Articles 33 and 34 of the GDPR (notification of the breach to the supervisory authority and communication to the data subjects).
- The Processor shall document all Data Breaches, including the circumstances, effects and remedial actions taken.
§ 12. Deletion and Return of Personal Data
- Upon termination of the provision of services (deletion of the account on the Platform), the Processor shall – at the Controller’s choice – delete or return all Personal Data to the Controller and delete existing copies, unless European Union law or the law of a Member State requires the retention of such data.
- In the absence of the Controller’s instructions, the Processor shall delete the Personal Data within 30 days of the account deletion.
- The Controller may submit a request for export of Personal Data prior to account deletion. The Processor shall make the data available in a commonly used format (e.g. CSV, JSON) within 14 days of receiving the request.
- Deletion of data from OpenAI’s logs shall take place in accordance with OpenAI’s retention policy (up to 30 days from the time of processing).
§ 13. Liability
- The Processor shall be liable for damage caused by processing that is not in compliance with this Agreement or the GDPR, on the terms set out in Article 82 of the GDPR.
- The Processor’s liability shall be limited to damage arising directly from the failure to perform the obligations imposed on it by the GDPR or this Agreement, and in any event shall not exceed PLN 20,000.
§ 14. Obligations of the Controller
The Controller undertakes to:
- have a valid legal basis for the processing of End Users’ Personal Data;
- fulfil the information obligation towards End Users in accordance with Article 13 or 14 of the GDPR, including informing them of the use of an AI system in communication;
- configure the AI system in a manner consistent with the principle of data minimisation (Article 5(1)(c) of the GDPR);
- refrain from processing special categories of personal data (Article 9 of the GDPR) through the Platform, unless in possession of a valid legal basis and having obtained the explicit consent of the data subjects;
- provide the Processor solely with documented, lawful instructions regarding processing;
- promptly inform the Processor of any requests from End Users relating to their rights under the GDPR.
§ 15. Final Provisions
- In matters not regulated by this Agreement, the provisions of the GDPR and Polish law shall apply.
- Any disputes arising from this Agreement shall be settled by the court having jurisdiction over the Processor’s registered office.
- Amendments to this Agreement shall require documentary form to be valid. The Processor may amend the Agreement with 14 days’ notice, informing the Controller by electronic means.
- This Agreement has been drawn up in the Polish language. In the event of any discrepancy with a version in another language, the Polish version shall prevail.
Appendix 1 – Description of Personal Data Processing
| Subject of processing | Processing of personal data of End Users within the framework of automating communication with the Controller’s customers through the BetterCX Platform. |
| Duration | For the period during which the Controller uses the BetterCX Platform. |
| Nature and purpose of processing | Analysis of message content, generation of responses using AI, collection and storage of contact data, handling of communication via email, chat, social media, handling of bookings and payments. |
| Types of personal data | Identification data (first name, last name), contact data (email, phone), correspondence content, transaction data, and other data voluntarily provided by End Users in the course of communication (scope dependent on the Controller’s configuration). |
| Categories of data subjects | End Users – customers and prospective customers of the Controller, persons communicating through channels supported by the Platform. |
| Processing operations | Collection, recording, storage, organisation, retrieval, use (AI analysis), transmission, erasure. |
Appendix 2 – Technical and Organisational Measures (Article 32 GDPR)
| Category | Description of measures |
|---|---|
| Encryption | TLS 1.2+ in transit, encryption at rest on AWS servers. AES-256 encryption on OpenAI’s side. |
| Access control | Data access based on the principle of least privilege. Multi-factor authentication for Processor personnel. |
| Infrastructure security | Hosting on AWS in the EU region, AWS certifications: ISO 27001, SOC 2 Type II, CSA STAR. |
| Password hashing | User passwords stored exclusively in hashed form. |
| Monitoring and logs | Continuous log monitoring, anomaly detection, security alerts. |
| Backups | Systems processing data are subject to a regular backup process. Backups are performed automatically every 7 days and stored in secured cloud infrastructure. Access to backups is restricted to authorised technical personnel. Backups are encrypted and retained for a limited time in accordance with the data retention policy. Data restoration tests are conducted regularly to verify the correctness of backup procedures. |
| Incident management | The Controller has implemented procedures for detecting, analysing and responding to security incidents related to the processing of personal data. In the event of an incident being detected, actions are taken to contain it, secure the systems and analyse the causes. Incidents are documented and, where necessary, remedial and preventive actions are taken. In the event of a personal data breach, the Controller takes actions in accordance with applicable laws, including – if required – notifying the competent supervisory authority and informing the affected data subjects. |
| Personnel training | Persons having access to personal data are required to maintain confidentiality and participate in training on data protection and information security. Training covers, among other things, data processing principles, identification of security threats, incident response procedures and best practices in information protection. Training is provided upon obtaining access to data processing systems and periodically during the course of cooperation. |
Appendix 3 – List of Approved Sub-processors
The following list contains the entities to which the Processor entrusts the processing of Personal Data as part of the provision of Platform services:
| Sub-processor | Location | Purpose of processing | Transfer mechanism |
|---|---|---|---|
| OpenAI, L.L.C. | USA | Text analysis and AI response generation | EU-US DPF, SCC |
| Amazon Web Services (AWS) | EEA (EU) | Infrastructure and database hosting | Processing in the EEA |
| Stripe, Inc. | USA / Ireland | Payment processing and Stripe Connect | EU-US DPF, SCC |
| Meta Platforms | USA / Ireland | Integration with Facebook Messenger, Instagram, WhatsApp | EU-US DPF, SCC |
| Google LLC | USA / Ireland | Integration with Gmail, Google Calendar | EU-US DPF, SCC |
| Microsoft Corp. | USA / Ireland | Integration with Outlook, Outlook Calendar | EU-US DPF, SCC |
| PrestaShop S.A. | France (EEA) | Integration with e-commerce platform for browsing products and checking order statuses | Processing in the EEA |
| Shopify Inc. | Canada / USA / Ireland | Integration with e-commerce platform for browsing products and checking order statuses | SCC |
| WooCommerce (Automattic Inc.) | USA / Ireland | Integration with e-commerce platform (WordPress) for browsing products and checking order statuses | EU-US DPF, SCC |
| Pipedrive OÜ | Estonia (EEA) / USA | Integration with CRM system for transmitting and synchronising customer data | SCC |
| HubSpot, Inc. | USA / Ireland | Integration with CRM and marketing automation system for transmitting customer data | EU-US DPF, SCC |
| SendGrid, Inc. | USA | Email sending and delivery | EU-US DPF, SCC |
The current list of sub-processors is available on the BetterCX Platform website.