Data Processing Agreement
Version 1.0 · 27 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and AXONLUMIA S.R.L. ("we", "us"), and applies whenever we process personal data on your behalf. It is accepted when you accept the Terms; no signature is required. If your organization requires a countersigned copy, contact us.
It gives effect to Article 28(3) of Regulation (EU) 2016/679 (GDPR).
1. Parties and roles
You are the controller. When visitors chat with an agent you have deployed, you decide why their messages are collected and what the agent does. That makes you the controller for that personal data.
We are your processor for it. We process it only to provide the service, on your instructions.
Separately, we are a controller in our own right for your account, billing and security data — that is not covered by this DPA; our Privacy Policy governs it.
PayPro Global is neither. Our Merchant of Record is an independent controller for payment and order data, not our sub-processor. See the Privacy Policy §5.
2. Subject matter and duration
Subject matter: provision of the LumiaChatFlow AI chat-assistant platform — indexing the content you supply, and generating agent responses to end-user messages.
Duration: for as long as your account is active, plus the deletion periods in section 8.
3. Nature and purpose of processing
Collection, storage, structuring, indexing, retrieval, generation of responses, transmission, and deletion — solely to operate the service for you and to meter your usage.
4. Categories of personal data
- End-visitor conversation content — whatever a visitor types, and the agent's responses.
- Technical data — the visitor's IP address, timestamps, and session identifiers.
- Personal data inside the content you index — anything present in the pages and files you supply.
Your own team's account data — names, emails, workspace roles — is not covered by this DPA. We are the controller for it, and our Privacy Policy governs it. It falls under this DPA only where your team members' details appear inside content you index or inside a conversation.
We do not require or request special-category data. Do not configure agents to solicit it — see the Acceptable Use Policy §5.
5. Categories of data subjects
Visitors to the websites where you deploy an agent, and any individuals identifiable within the content you index or within conversations — which may include your own staff where they appear in that content.
As above, your team's account records are not processed under this DPA; we are the controller for those.
6. Our obligations
We will:
(a) Process only on your instructions. Your instructions are these Terms, this DPA, and your configuration of the service. If we believe an instruction breaches data-protection law we will tell you. If law requires us to process otherwise, we will inform you first unless that law forbids it.
(b) Ensure confidentiality. Everyone we authorize to process the data is bound by confidentiality obligations.
(c) Apply appropriate security measures under Art. 32 — set out in Annex II.
(d) Engage sub-processors only under section 7.
(e) Assist you with data-subject requests. The service provides export and deletion directly; where a request cannot be met through the product, we will help you within a reasonable time, taking into account the nature of the processing.
(f) Assist you with data-protection impact assessments and prior consultation, and with your Art. 32–36 obligations, taking into account the information available to us.
(g) Notify you of a personal data breach without undue delay after becoming aware of it, with the information we hold, so you can meet your own notification duties.
(h) Delete or return the data in line with section 8.
(i) Make available the information needed to demonstrate compliance with Art. 28, and allow audits under section 10.
7. Sub-processors
You give general authorization for us to engage sub-processors. Our current list, with the role of each, is published at /sub-processors.
We will give at least 30 days' notice before adding a sub-processor with material access to personal data processed on your behalf. You may object on reasonable data-protection grounds within that period; if we cannot resolve your objection, you may terminate the affected part of the service without penalty for the remainder of the paid term.
We impose data-protection obligations on each sub-processor equivalent to those in this DPA, and we remain fully liable to you for their performance.
8. Deletion and return
You can delete content, agents, and your whole account from within the service at any time.
On account deletion, a 30-day grace period applies during which restoration is possible. After it, we delete the tenant's data and its encryption keys, which renders any remaining encrypted material unreadable, and we purge the search index built from your content. We retain a minimal deletion record as proof of erasure, and any data we are required by law to keep.
Export is available from Settings → Privacy & GDPR before deletion.
9. International transfers
Our own infrastructure is in the European Union (Google Cloud europe-west1).
The AI search and generation layer is provided by Google, which does not offer a regional storage guarantee for that service; its terms permit storage in any country where Google or its agents maintain facilities. Transfers to Google are covered by Google's data-processing terms and its transfer mechanisms, including Standard Contractual Clauses where applicable.
Where we transfer personal data outside the EEA, we rely on an adequacy decision or on appropriate safeguards under Chapter V GDPR.
10. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA, including our published security documentation.
Where you require more, you may request an audit once per twelve months, on reasonable notice, at your cost, subject to confidentiality, and conducted so as not to disrupt the service or compromise other customers' data. We may satisfy an audit request by providing a completed security questionnaire, or an independent report where one is available.
11. Liability
Liability between you and us under this DPA is subject to the limitations in the Terms of Service §12.
This does not affect either party's liability to data subjects or to supervisory authorities under applicable data protection law, which cannot be limited by agreement between us.
12. Changes
We may update this DPA to reflect changes in law or in the service. Material changes will be notified in line with the Terms of Service. The current version and its date are shown at the top.
Annex I — Processing details
| Controller | You, the Customer |
| Processor | AXONLUMIA S.R.L., Ilfov, Romania |
| Subject matter | Section 2 |
| Duration | Term of the account, plus deletion periods (section 8) |
| Nature and purpose | Section 3 |
| Personal data | Section 4 |
| Data subjects | Section 5 |
| Sub-processors | /sub-processors |
Annex II — Technical and organizational measures
| Measure | What we do |
|---|---|
| Encryption in transit | TLS on all endpoints |
| Encryption at rest | Per-tenant envelope encryption; AES-256-GCM data keys wrapped by Google Cloud KMS |
| Tenant isolation | Data partitioned per tenant; cross-tenant access treated as a hard constraint |
| Access control | Role-based access within a workspace; platform-admin operations gated on a separate, non-self-serviceable claim |
| Authentication | Mandatory email verification; two-factor authentication and session controls available; no social login |
| Logging | Security and compliance events recorded, with high-severity events published for alerting |
| Deletion | Self-service deletion with grace period; erasure of tenant data and encryption keys; deletion records retained as proof |
| Model training | No training or fine-tuning on customer data; AI providers contractually bound not to use paid-tier content to improve their models |
| Availability | Managed cloud infrastructure with provider-level redundancy |