Skip to content

DATA PROCESSING ADDENDUM

Data Processing Addendum

This addendum describes how Dioartis Grup SRL processes visitor data for Amevia customers. It is a product-aligned draft and needs legal validation before it is treated as a signed contract.

Draft for legal review — 19 August 2026

1Parties, object and duration

This Data Processing Addendum (“DPA”) applies when a customer (“Controller”) uses Amevia, a product of Dioartis Grup SRL (“Processor”), to process personal data of website visitors (conversations, leads and, where enabled, visitor monitoring). The Processor is registered in the Republic of Moldova under IDNO 1011600003727, registered office MD-2020, mun. Chișinău, sector Rîșcani, Calea Orheiului 109/3, ap. (of.) 211.

Processing lasts for the term of the service and any documented retention period, then until deletion or return as described below.

2Nature, purpose and categories

  • Purpose: provide website-agent chat, optional lead capture, optional visitor analytics with consent, knowledge search and customer workspace tools.
  • Data subjects: visitors of the customer website; customer staff accounts are generally a separate controller relationship with Dioartis Grup SRL.
  • Data: messages, conversation identifiers, source page URL, optional host identity, lead form fields, technical IP/user-agent as needed for security, and Monitor session data when analytics consent is granted.

3Instructions

The Processor processes visitor data only on documented instructions of the Controller, including configuration in the Amevia workspace (features enabled, retention days, anonymize visitors) and this DPA. Unlawful instructions may be refused.

4Confidentiality

Persons authorised to process personal data are bound by confidentiality and access is limited to what is needed to operate the service.

5Security measures

Technical and organisational measures include TLS in transit, access control for the workspace, hashed passwords (Argon2id), optional passkeys, secret management via environment configuration, rate limiting on public widget APIs, and backup/restore according to hosting practice (retention period to be confirmed).

6Sub-processors

The Controller authorises the sub-processors listed at /subprocessors. The Processor will post updates on that page. Customers who object in writing within 14 days of a material addition may stop using the affected feature or terminate the service as provided in the Terms.

7Assistance, incidents and DSAR

The Processor will assist the Controller with data-subject requests relating to visitor data in the product, taking into account the nature of processing. Personal data breaches will be handled under the internal incident procedure, including notification to the Controller without undue delay when required, and CNPDCP within 72 hours where Dioartis Grup SRL is controller.

8Deletion, return and audit

On end of service the Controller may delete the website in the workspace (cascading visitor, conversation and lead rows). Export of conversations and leads is available in the product where the plan allows. The Processor will make available information reasonably necessary to demonstrate this DPA and allow audits with reasonable notice, without revealing other customers’ data or security secrets.

9International transfers

Where a sub-processor processes data outside the Republic of Moldova / EEA, the legal transfer tool (adequacy or standard contractual clauses) must be confirmed before being relied upon in a signed contract. See docs/REQUIRED_LEGAL_INPUTS.md internally.

10After termination

After deletion from the live database, residual copies may remain in backups until those backups expire. That period is not yet a verified public number.

Data Processing Addendum — Amevia