Back to home

Data Processing Agreement

Last updated: July 2026

Draft pending legal review. This Data Processing Agreement is provided for review. SayPeter SARL-S is in the process of formation under the laws of Luxembourg; company registration details are completed on execution. The English text is the authoritative version.

This Data Processing Agreement (the “DPA”) forms part of, and is incorporated by reference into, the Terms of Service (the “Agreement”) between:

  • SayPeter SARL-S, a société à responsabilité limitée simplifiée in formation under the laws of the Grand Duchy of Luxembourg, with registered office at [registered address to be completed], registered with the Luxembourg Trade and Companies Register (RCS) under number [RCS number to be completed] (“SayPeter”, “we”, “us”), acting as processor; and
  • the customer identified in the Agreement (“Customer”, “you”), acting as controller.

This DPA governs the processing of personal data carried out by SayPeter on the Customer’s behalf in connection with the SayPeter service (the “Service”), as required by Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”). Capitalised terms not defined here have the meaning given in the Agreement; “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given in the GDPR.

1. Roles of the Parties

The parties acknowledge that, with respect to the processing of Customer Personal Data (personal data that the Customer, its users, or its own end users or customers submit to, generate within, or instruct Peter to process through the Service):

  • the Customer is the controller (or, where the Customer itself acts as a processor for a third party, the Customer is the relevant processor and SayPeter is the sub-processor); and
  • SayPeter is the processor, processing Customer Personal Data only on the Customer’s documented instructions.

SayPeter acts as an independent controller for a limited set of data it determines the purposes and means of — namely account, authentication, billing, security, and service-operation data — which is described in the Privacy Policy and is outside the scope of this DPA.

2. Subject Matter, Duration, Nature and Purpose

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. SayPeter processes Customer Personal Data for the duration of the Agreement and for the limited retention period thereafter described in Section 11, and solely to provide and support the Service.

3. Customer Instructions and Responsibilities

  • The Customer’s complete and final instructions for the processing of Customer Personal Data are this DPA and the Agreement, together with the Customer’s configuration and use of the Service (including the instructions the Customer gives Peter). SayPeter will process Customer Personal Data only on those documented instructions, including with regard to transfers, unless required to do otherwise by Union or Member State law to which SayPeter is subject; in that case SayPeter will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
  • The Customer is solely responsible for establishing and maintaining a valid legal basis under Article 6 GDPR (and, where applicable, a condition under Article 9 GDPR for special categories of data) for all Customer Personal Data it processes through the Service, and for providing all notices to, and obtaining all consents from, data subjects that the law requires.
  • The Customer warrants that it is entitled to transfer Customer Personal Data to SayPeter so that SayPeter may lawfully process it as contemplated by the Agreement, and that its instructions will not cause SayPeter to breach applicable data protection law.
  • SayPeter will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions (Article 28(3), final paragraph).

4. Confidentiality

SayPeter ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory) and are subject to access controls limiting access to what is necessary for their role (Article 28(3)(b)).

5. Security of Processing

SayPeter implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the processing (Article 32 GDPR). A summary of those measures is set out in Annex 3. SayPeter may update its measures over time provided the level of protection is not materially reduced.

6. Sub-processors

  • The Customer grants SayPeter general written authorisation to engage sub-processors to process Customer Personal Data. The sub-processors engaged as at the date of this DPA are listed in Annex 2.
  • SayPeter will impose on each sub-processor, by contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor’s obligations (Article 28(4)).
  • SayPeter will inform the Customer of any intended addition or replacement of a sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds within 30 days. If the Customer objects, the parties will work in good faith to resolve the concern; if it cannot be resolved, the Customer may terminate the affected part of the Service.

7. Assistance to the Customer

Taking into account the nature of the processing, SayPeter will:

  • assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR (Articles 15–22). If a data subject contacts SayPeter directly, SayPeter will, where it can identify the relevant Customer, refer the request to that Customer (Article 28(3)(e)); and
  • assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to SayPeter (Article 28(3)(f)).

8. Personal Data Breaches

SayPeter will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data (Article 33(2)). The notification will, to the extent then known, describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it, and will be supplemented as further information becomes available. SayPeter does not, by giving such notice, admit fault or liability.

9. International Transfers

Customer Personal Data is hosted within the European Union (compute and storage, including object storage provisioned in the EU jurisdiction, and managed databases in an EU region). Where the provision of the Service necessarily involves a transfer of Customer Personal Data by SayPeter to a sub-processor located in a third country, SayPeter ensures an appropriate transfer mechanism under Chapter V GDPR is in place, such as an adequacy decision, the Standard Contractual Clauses, or the EU–US Data Privacy Framework, together with any supplementary measures required. The transfer to the AI provider that powers Peter is a separate case, addressed in the paragraph below and in Annex 2.

Peter operates using the OpenAI ChatGPT/Codex account that the Customer connects. The Customer’s prompts and Peter’s responses are processed by OpenAI (United States) under OpenAI’s terms applicable to the connected account, and count against that account’s own quota. OpenAI is therefore the Customer’s own provider for this data rather than a SayPeter sub-processor. The Customer acknowledges that, by connecting that account and instructing Peter, it directs this transfer, and is responsible for the terms, transfer safeguards, and data-handling settings of the account it connects.

10. Audits

SayPeter will make available to the Customer the information necessary to demonstrate compliance with the obligations in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates (Article 28(3)(h)). Audits are conducted on reasonable prior notice, no more than once per year (save where required by a supervisory authority or following a personal data breach), during business hours, and subject to confidentiality; SayPeter may satisfy an audit request by providing relevant third-party certifications or reports where available, so as not to compromise the security or confidentiality of other customers’ data.

11. Return or Deletion of Data

On termination of the Service, the Customer’s environment and Customer Personal Data are preserved for 30 days to allow export, after which SayPeter deletes the Customer Personal Data (Article 28(3)(g)), unless Union or Member State law requires continued storage. Back-ups are overwritten in the ordinary course within their retention cycle.

12. Liability and Indemnity

Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Because the Customer determines what Customer Personal Data is processed and on what legal basis, the Customer indemnifies SayPeter against claims, fines, and costs arising from the Customer’s breach of Section 3 (including processing without a valid legal basis or required consents, or submitting personal data it is not entitled to submit), to the extent permitted by applicable law.

13. Order of Precedence, Governing Law

In the event of a conflict between this DPA and the Agreement on the subject of data protection, this DPA prevails. This DPA is governed by the laws of the Grand Duchy of Luxembourg, and the courts of Luxembourg have jurisdiction, without prejudice to any mandatory rights a Customer who is a consumer has under the law of their country of residence.


Annex 1 — Details of Processing

  • Subject matter: provision of the SayPeter service (a hosted AI assistant with messaging, workspace, and integration tooling).
  • Duration: the term of the Agreement, plus the post-termination retention period in Section 11.
  • Nature and purpose: hosting, storage, transmission, organisation, retrieval, and AI-assisted processing of Customer Personal Data in order to operate the Service as instructed by the Customer through Peter.
  • Types of personal data: determined by the Customer. Typically includes the Customer’s and its contacts’ identifiers (names, phone numbers, email addresses), message and conversation content, business records (e.g. CRM, finance, scheduling data), files the Customer stores in its workspace, and any other personal data the Customer chooses to submit. The Customer is responsible for not submitting special categories of data (Article 9 GDPR) unless it has a valid condition for doing so.
  • Categories of data subjects: determined by the Customer. Typically the Customer’s personnel and the Customer’s own contacts, customers, suppliers, and counterparties.

Annex 2 — Sub-processors

SayPeter engages the following sub-processors to process Customer Personal Data. The list is maintained current; material changes are notified in accordance with Section 6.

Sub-processor Purpose Location Transfer safeguard
Cloudflare Object storage (EU jurisdiction), edge compute for hosted environments, and secure ingress EU jurisdiction (US company) EU jurisdictional storage; SCCs
Neon Managed PostgreSQL database hosting European Union EU region; SCCs where applicable
Hetzner Management server and platform infrastructure hosting European Union (Germany) EU hosting
Tailscale Private network management between platform and environments (connection metadata) United States SCCs
Meta Platforms Ireland WhatsApp message transport (where the Customer uses WhatsApp) EU / United States SCCs as applicable
Composio Connected third-party app integrations (only for apps the Customer connects) United States SCCs

Peter runs on the OpenAI ChatGPT/Codex account the Customer connects (see Section 9). OpenAI processes the Customer’s prompts and Peter’s responses under the Customer’s own account and OpenAI’s terms for it, and is therefore the Customer’s own provider for that data rather than a sub-processor of SayPeter, which is why it is not listed in the table above. The same applies where the Customer connects other third-party services (e.g. Google, Stripe, an email provider) through Peter: those providers process data under the Customer’s own arrangements with them. Locations and safeguards above are indicative and subject to confirmation against each provider’s current data-processing terms.

Annex 3 — Technical and Organisational Measures

SayPeter maintains, at minimum, the following measures (Article 32 GDPR):

  • Tenant isolation: each customer’s compute environment is isolated from other customers, and credentials are scoped so that one environment cannot access another’s data or storage.
  • Encryption in transit: data in transit between components and to sub-processors is protected with TLS.
  • Encryption at rest: object storage and databases are encrypted at rest; connected third-party credentials are additionally encrypted in the management database.
  • Conversation confidentiality: conversation transcripts stored in a customer environment are sealed with per-tenant public-key encryption so that they cannot be read in the environment; decryption is possible only on the management side, is limited to defined operational purposes, and every such access is logged to an access-audit record.
  • Access control: administrative access is restricted to authorised personnel over a private network, on a least-privilege basis, and is logged.
  • Data residency: Customer Personal Data is stored within the European Union (including object storage provisioned in the EU jurisdiction and databases in an EU region).
  • Data minimisation: the management platform does not store customer conversation content in clear text; operational analytics are limited to metadata (counts, timestamps, tool names, outcomes) and are retention-limited and purged on a schedule.
  • Resilience and recovery: data is backed up and environments can be restored; security updates are applied to the platform on an ongoing basis.

Contact

For data protection questions or to exercise rights under this DPA:

Email: [email protected]

You also have the right to lodge a complaint with a supervisory authority. SayPeter’s lead supervisory authority is expected to be the Luxembourg Commission nationale pour la protection des données (CNPD).