Last updated: July 2026
This Data Processing Agreement (the “DPA”) forms part of, and is incorporated by reference into, the Terms of Service (the “Agreement”) between:
This DPA governs the processing of personal data carried out by SayPeter on the Customer’s behalf in connection with the SayPeter service (the “Service”), as required by Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”). Capitalised terms not defined here have the meaning given in the Agreement; “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given in the GDPR.
The parties acknowledge that, with respect to the processing of Customer Personal Data (personal data that the Customer, its users, or its own end users or customers submit to, generate within, or instruct Peter to process through the Service):
SayPeter acts as an independent controller for a limited set of data it determines the purposes and means of — namely account, authentication, billing, security, and service-operation data — which is described in the Privacy Policy and is outside the scope of this DPA.
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. SayPeter processes Customer Personal Data for the duration of the Agreement and for the limited retention period thereafter described in Section 11, and solely to provide and support the Service.
SayPeter ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory) and are subject to access controls limiting access to what is necessary for their role (Article 28(3)(b)).
SayPeter implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the processing (Article 32 GDPR). A summary of those measures is set out in Annex 3. SayPeter may update its measures over time provided the level of protection is not materially reduced.
Taking into account the nature of the processing, SayPeter will:
SayPeter will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data (Article 33(2)). The notification will, to the extent then known, describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it, and will be supplemented as further information becomes available. SayPeter does not, by giving such notice, admit fault or liability.
Customer Personal Data is hosted within the European Union (compute and storage, including object storage provisioned in the EU jurisdiction, and managed databases in an EU region). Where the provision of the Service necessarily involves a transfer of Customer Personal Data by SayPeter to a sub-processor located in a third country, SayPeter ensures an appropriate transfer mechanism under Chapter V GDPR is in place, such as an adequacy decision, the Standard Contractual Clauses, or the EU–US Data Privacy Framework, together with any supplementary measures required. The transfer to the AI provider that powers Peter is a separate case, addressed in the paragraph below and in Annex 2.
Peter operates using the OpenAI ChatGPT/Codex account that the Customer connects. The Customer’s prompts and Peter’s responses are processed by OpenAI (United States) under OpenAI’s terms applicable to the connected account, and count against that account’s own quota. OpenAI is therefore the Customer’s own provider for this data rather than a SayPeter sub-processor. The Customer acknowledges that, by connecting that account and instructing Peter, it directs this transfer, and is responsible for the terms, transfer safeguards, and data-handling settings of the account it connects.
SayPeter will make available to the Customer the information necessary to demonstrate compliance with the obligations in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates (Article 28(3)(h)). Audits are conducted on reasonable prior notice, no more than once per year (save where required by a supervisory authority or following a personal data breach), during business hours, and subject to confidentiality; SayPeter may satisfy an audit request by providing relevant third-party certifications or reports where available, so as not to compromise the security or confidentiality of other customers’ data.
On termination of the Service, the Customer’s environment and Customer Personal Data are preserved for 30 days to allow export, after which SayPeter deletes the Customer Personal Data (Article 28(3)(g)), unless Union or Member State law requires continued storage. Back-ups are overwritten in the ordinary course within their retention cycle.
Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Because the Customer determines what Customer Personal Data is processed and on what legal basis, the Customer indemnifies SayPeter against claims, fines, and costs arising from the Customer’s breach of Section 3 (including processing without a valid legal basis or required consents, or submitting personal data it is not entitled to submit), to the extent permitted by applicable law.
In the event of a conflict between this DPA and the Agreement on the subject of data protection, this DPA prevails. This DPA is governed by the laws of the Grand Duchy of Luxembourg, and the courts of Luxembourg have jurisdiction, without prejudice to any mandatory rights a Customer who is a consumer has under the law of their country of residence.
SayPeter engages the following sub-processors to process Customer Personal Data. The list is maintained current; material changes are notified in accordance with Section 6.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Cloudflare | Object storage (EU jurisdiction), edge compute for hosted environments, and secure ingress | EU jurisdiction (US company) | EU jurisdictional storage; SCCs |
| Neon | Managed PostgreSQL database hosting | European Union | EU region; SCCs where applicable |
| Hetzner | Management server and platform infrastructure hosting | European Union (Germany) | EU hosting |
| Tailscale | Private network management between platform and environments (connection metadata) | United States | SCCs |
| Meta Platforms Ireland | WhatsApp message transport (where the Customer uses WhatsApp) | EU / United States | SCCs as applicable |
| Composio | Connected third-party app integrations (only for apps the Customer connects) | United States | SCCs |
Peter runs on the OpenAI ChatGPT/Codex account the Customer connects (see Section 9). OpenAI processes the Customer’s prompts and Peter’s responses under the Customer’s own account and OpenAI’s terms for it, and is therefore the Customer’s own provider for that data rather than a sub-processor of SayPeter, which is why it is not listed in the table above. The same applies where the Customer connects other third-party services (e.g. Google, Stripe, an email provider) through Peter: those providers process data under the Customer’s own arrangements with them. Locations and safeguards above are indicative and subject to confirmation against each provider’s current data-processing terms.
SayPeter maintains, at minimum, the following measures (Article 32 GDPR):
For data protection questions or to exercise rights under this DPA:
Email: [email protected]
You also have the right to lodge a complaint with a supervisory authority. SayPeter’s lead supervisory authority is expected to be the Luxembourg Commission nationale pour la protection des données (CNPD).