
Version 1.0 — in force since 10 August 2026
Dotika S.à r.l. · 9, rue du Laboratoire, L-1911 Luxembourg · RCS Luxembourg B296675 · TVA LU36653351
Document exported on 10 August 2026 — Source: http://127.0.0.1:4173/en/dpa
This agreement governs the processing of personal data that Dotika S.à r.l. (the "Processor") carries out on behalf of its client (the "Controller"), under an Assignment governed by Dotika's General Terms and Conditions or through use of the Bryf platform.
It is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and forms an integral part of the main contract. It applies automatically wherever the Assignment involves processing personal data on the Client's behalf, without the need for a separate signature; the Client may nonetheless request a signed copy at privacy@dotika.ai.
In the event of a conflict between this agreement and the main contract on a data protection matter, this agreement prevails.
The Client determines the purposes and means of the processing: it acts as controller. Dotika processes the data on its behalf: it acts as processor.
Where Dotika processes data for its own purposes — managing the commercial relationship, invoicing, measuring its website audience — it acts as controller. Those activities are described in its privacy policy and fall outside the scope of this agreement.
The Client warrants that it has a valid legal basis for the processing it entrusts to Dotika, that it has informed the data subjects, and that the data transmitted is adequate, relevant and limited to what is necessary.
Dotika processes the data only on the Client's documented instructions. The following constitute documented instructions: the main contract, the accepted Offer, Annex 1 to this agreement, and any subsequent instruction sent in writing to privacy@dotika.ai.
Dotika immediately informs the Client if an instruction appears to infringe the GDPR or another Union or Member State data protection provision. It may suspend performance of the instruction concerned until the matter is clarified.
If Union or Member State law requires Dotika to carry out processing, it informs the Client beforehand, unless that law prohibits such information on important grounds of public interest.
Dotika ensures that persons authorised to process the data are bound by an appropriate contractual or statutory confidentiality obligation, and that they receive the necessary data protection training.
Access to the Client's data is limited to those staff and practitioners whose involvement is necessary to perform the Assignment, on a least-privilege basis.
Dotika implements the appropriate technical and organisational measures required by Article 32 GDPR, set out in Annex 2. It may update them, provided the level of security is not degraded.
The Client gives Dotika general authorisation to engage the sub-processors listed in Annex 3, which constitutes the prior written authorisation required by Article 28(2) GDPR.
Dotika informs the Client of any addition or replacement of a sub-processor at least thirty (30) days before it goes live. The Client has that period to object in writing, giving reasons. If it objects, the parties will seek an alternative in good faith; failing agreement, either party may terminate the Assignment concerned without indemnity, the Client paying for services performed.
Dotika imposes on each sub-processor, by contract, data protection obligations equivalent to those in this agreement. It remains fully liable to the Client for those sub-processors' performance of their obligations.
Taking into account the nature of the processing, Dotika assists the Client through appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection).
If a data subject contacts Dotika directly, Dotika does not respond on the substance and forwards the request to the Client within five (5) business days, unless the Client instructs otherwise.
Dotika notifies the Client of any personal data breach without undue delay and no later than forty-eight (48) hours after becoming aware of it, so as to allow the Client to meet its own seventy-two (72) hour deadline under Article 33 GDPR.
The notification describes, to the extent information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects.
Dotika documents every breach and provides the Client with the reasonable assistance needed to notify the supervisory authority and, where applicable, to communicate with the data subjects. It makes no notification to the authority or to data subjects on the Client's behalf without the Client's written instruction.
Dotika assists the Client, taking into account the nature of the processing and the information available to it, in carrying out data protection impact assessments (Article 35) and, where applicable, in conducting prior consultation of the supervisory authority (Article 36).
This assistance is provided within reasonable limits; beyond that, it may be invoiced on terms agreed between the parties.
Data is processed and stored within the European Union, subject to the sub-processors listed in Annex 3 whose location is indicated there.
Any transfer to a third country is governed by the Standard Contractual Clauses adopted by the European Commission and, where required, by supplementary measures resulting from a transfer impact assessment.
Dotika informs the Client of any binding request from a third-country authority concerning the Client's data, unless legally prohibited, and endeavours to challenge it where there are reasonable grounds to do so.
Where the Assignment involves the use of artificial intelligence models supplied by third parties, data transmitted to those providers is sent solely to produce the requested output.
Dotika contracts with those providers so that the Client's data is not used to train or improve their models. Any exception would be subject to prior notice and the Client's written agreement.
The Client remains responsible for the lawfulness of the data it submits and for its use of the outputs produced, which must be subject to human verification before any decision producing effects concerning individuals.
At the end of the Assignment, Dotika will, at the Client's written election, return the data in a structured, commonly used format, or delete it.
Failing an instruction from the Client within thirty (30) days of the end date, Dotika deletes the data within ninety (90) days, except for data whose retention is required by Union or Member State law, which then remains protected by this agreement until it is actually deleted.
Dotika certifies deletion in writing at the Client's request. Encrypted backups are purged in line with their rotation cycle, within a maximum of six (6) months.
Dotika makes available to the Client all information necessary to demonstrate compliance with the obligations of Article 28 GDPR.
The Client may carry out an audit, including an inspection, once in any twelve (12) month period, subject to thirty (30) days' written notice, during business hours, without disrupting Dotika's activity and subject to confidentiality. An additional audit may be carried out following a confirmed data breach or at the reasoned request of a supervisory authority.
Dotika may satisfy this obligation by providing the audit reports, certifications or security questionnaires available to it, where these reasonably answer the Client's questions.
Audit costs are borne by the Client, unless the audit reveals a material failure by Dotika to meet its obligations.
This agreement takes effect when the Assignment begins and ends on completion of the processing operations and deletion or return of the data.
Each party is liable for damage caused by processing which infringes the GDPR, under the conditions set out in Article 82. The limitations of liability stipulated in the main contract apply to this agreement to the extent permitted by law.
This agreement is governed by Luxembourg law. The supervisory authority competent for Dotika is the Commission nationale pour la protection des données (CNPD), Luxembourg.
Where the Assignment warrants it, this annex is refined in the Offer or in an attached document signed by both parties, which then prevails over this general description.
| Sub-processor | Role | Data location | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database, server functions and file storage | European Union | Data processing agreement, Art. 28 GDPR |
| Netlify, Inc. | Hosting and delivery of the website pages | United States | Standard Contractual Clauses |
| Anthropic PBC | Language model behind the conversational assistant | United States | Standard Contractual Clauses — no training on the data |
| Resend, Inc. | Delivery of transactional and confirmation e-mails | United States | Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Payment processing for the Bryf platform | European Union (Ireland) | Data processing agreement, Art. 28 GDPR |
Sub-processors specific to a particular Assignment (the Client's own tools, infrastructure it mandates, specialist providers) are added to this list in the corresponding Offer. The current version of this annex is available at this address; any change is notified in accordance with Article 5.
This agreement is accepted by the Client when it accepts the Offer. A named copy, ready to sign and completed with the details specific to your Assignment, is available on request at privacy@dotika.ai.