Pēdējo reizi atjaunināts: 2026. gada augusts
This Data Processing Agreement (the “DPA”) forms part of, and is incorporated by reference into, the Terms of Service (the “Agreement”) between:
This DPA governs the processing of personal data carried out by SayPeter on the Customer’s behalf in connection with the SayPeter service (the “Service”), as required by Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”). Capitalised terms not defined here have the meaning given in the Agreement; “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given in the GDPR.
The parties acknowledge that, with respect to the processing of Customer Personal Data (personal data that the Customer, its users, or its own end users or customers submit to, generate within, or instruct Peter to process through the Service):
SayPeter acts as an independent controller for a limited set of data it determines the purposes and means of — namely account, authentication, billing, security, and service-operation data — which is described in the Privacy Policy and is outside the scope of this DPA.
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. SayPeter processes Customer Personal Data for the duration of the Agreement and for the limited retention period thereafter described in Section 11, and solely to provide and support the Service.
SayPeter ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory) and are subject to access controls limiting access to what is necessary for their role (Article 28(3)(b)).
SayPeter implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the processing (Article 32 GDPR). A summary of those measures is set out in Annex 3. SayPeter may update its measures over time provided the level of protection is not materially reduced.
Taking into account the nature of the processing, SayPeter will:
SayPeter will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data (Article 33(2)). The notification will, to the extent then known, describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it, and will be supplemented as further information becomes available. SayPeter does not, by giving such notice, admit fault or liability.
Customer Personal Data is hosted within the European Union (compute and storage, including object storage provisioned in the EU jurisdiction, and managed databases in an EU region). Where the provision of the Service necessarily involves a transfer of Customer Personal Data by SayPeter to a sub-processor located in a third country, SayPeter ensures an appropriate transfer mechanism under Chapter V GDPR is in place, such as an adequacy decision, the Standard Contractual Clauses, or the EU–US Data Privacy Framework, together with any supplementary measures required. The transfer to the AI provider that powers Peter is a separate case, addressed in the paragraph below and in Annex 2.
On SayPeter’s standard plans, Peter operates on SayPeter’s own OpenAI account. The Customer’s prompts and Peter’s responses are transmitted by SayPeter to OpenAI, L.L.C. (United States) under SayPeter’s commercial API agreement, under which that content is not used to train OpenAI’s models. OpenAI is accordingly a sub-processor of SayPeter for this data and is listed in Annex 2, and SayPeter is responsible for the transfer mechanism and safeguards. The Customer needs no AI account of its own; the applicable plan carries a monthly usage allowance instead.
On a bring-your-own-account plan, Peter instead operates using the AI account that the Customer connects, which is either an OpenAI ChatGPT/Codex account or an Anthropic Claude account, at the Customer’s choice. The Customer’s prompts and Peter’s responses are then processed by that provider (OpenAI or Anthropic, both United States) under the provider’s terms applicable to the connected account, and count against that account’s own quota. The provider is in that case the Customer’s own provider for this data rather than a SayPeter sub-processor. The Customer acknowledges that, by connecting that account and instructing Peter, it directs this transfer, and is responsible for the terms, transfer safeguards, and data-handling settings of the account it connects. Where the Customer changes provider, this paragraph applies to whichever account is connected at the time of processing.
SayPeter will make available to the Customer the information necessary to demonstrate compliance with the obligations in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates (Article 28(3)(h)). Audits are conducted on reasonable prior notice, no more than once per year (save where required by a supervisory authority or following a personal data breach), during business hours, and subject to confidentiality; SayPeter may satisfy an audit request by providing relevant third-party certifications or reports where available, so as not to compromise the security or confidentiality of other customers’ data.
On termination of the Service, the Customer’s environment and Customer Personal Data are preserved for 30 days to allow export, after which SayPeter deletes the Customer Personal Data (Article 28(3)(g)), unless Union or Member State law requires continued storage. Back-ups are overwritten in the ordinary course within their retention cycle.
Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Because the Customer determines what Customer Personal Data is processed and on what legal basis, the Customer indemnifies SayPeter against claims, fines, and costs arising from the Customer’s breach of Section 3 (including processing without a valid legal basis or required consents, or submitting personal data it is not entitled to submit), to the extent permitted by applicable law.
In the event of a conflict between this DPA and the Agreement on the subject of data protection, this DPA prevails. This DPA is governed by the laws of the Grand Duchy of Luxembourg, and the courts of Luxembourg have jurisdiction, without prejudice to any mandatory rights a Customer who is a consumer has under the law of their country of residence.
SayPeter engages the following sub-processors to process Customer Personal Data. The list is maintained current; material changes are notified in accordance with Section 6.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Cloudflare | Object storage (EU jurisdiction), edge compute for hosted environments, and secure ingress | EU jurisdiction (US company) | EU jurisdictional storage; SCCs |
| Neon | Managed PostgreSQL database hosting | European Union | EU region; SCCs where applicable |
| Hetzner | Management server and platform infrastructure hosting | European Union (Germany) | EU hosting |
| Tailscale | Private network management between platform and environments (connection metadata) | United States | SCCs |
| Telegram Messenger Inc. | Telegram message transport (where the Customer uses Telegram) | Outside the EEA | SCCs as applicable |
| Composio | Connected third-party app integrations (only for apps the Customer connects) | United States | SCCs |
| OpenAI, L.L.C. | AI inference: prompts and responses, on SayPeter’s own commercial API account (standard plans only — not bring-your-own-account plans, see Section 9) | United States | SCCs; OpenAI data-processing addendum |
On a bring-your-own-account plan, Peter runs on the AI account the Customer connects — OpenAI ChatGPT/Codex or Anthropic Claude (see Section 9) — instead of on SayPeter’s account. In that arrangement the provider processes the Customer’s prompts and Peter’s responses under the Customer’s own account and the provider’s terms for it, and is therefore the Customer’s own provider for that data rather than a sub-processor of SayPeter; the OpenAI row above does not apply to those Customers, and Anthropic is not listed at all. The same applies where the Customer connects other third-party services (e.g. Google, Stripe, an email provider) through Peter: those providers process data under the Customer’s own arrangements with them. Locations and safeguards above are indicative and subject to confirmation against each provider’s current data-processing terms.
SayPeter maintains, at minimum, the following measures (Article 32 GDPR):
For data protection questions or to exercise rights under this DPA:
E-pasts: [email protected]
You also have the right to lodge a complaint with a supervisory authority. SayPeter’s lead supervisory authority is expected to be the Luxembourg Commission nationale pour la protection des données (CNPD).