1Parties, object and duration
This Data Processing Addendum (“DPA”) applies when a customer (“Controller”) uses Amevia, a product of Dioartis Grup SRL (“Processor”), to process personal data of website visitors (conversations, leads and, where enabled, visitor monitoring). The Processor is registered in the Republic of Moldova under IDNO 1011600003727, registered office MD-2020, mun. Chișinău, sector Rîșcani, Calea Orheiului 109/3, ap. (of.) 211.
Processing lasts for the term of the service and any documented retention period, then until deletion or return as described below.
2Nature, purpose and categories
- Purpose: provide website-agent chat, optional lead capture, optional visitor analytics with consent, knowledge search and customer workspace tools.
- Data subjects: visitors of the customer website; customer staff accounts are generally a separate controller relationship with Dioartis Grup SRL.
- Data: messages, conversation identifiers, source page URL, optional host identity, lead form fields, technical IP/user-agent as needed for security, and Monitor session data when analytics consent is granted.
3Instructions
The Processor processes visitor data only on documented instructions of the Controller, including configuration in the Amevia workspace (features enabled, retention days, anonymize visitors) and this DPA. Unlawful instructions may be refused.
4Confidentiality
Persons authorised to process personal data are bound by confidentiality and access is limited to what is needed to operate the service.
5Security measures
Technical and organisational measures include TLS in transit, access control for the workspace, hashed passwords (Argon2id), optional passkeys, secret management via environment configuration, rate limiting on public widget APIs, and backup/restore according to hosting practice (retention period to be confirmed).
6Sub-processors
The Controller authorises the sub-processors listed at /subprocessors. The Processor will post updates on that page. Customers who object in writing within 14 days of a material addition may stop using the affected feature or terminate the service as provided in the Terms.
7Assistance, incidents and DSAR
The Processor will assist the Controller with data-subject requests relating to visitor data in the product, taking into account the nature of processing. Personal data breaches will be handled under the internal incident procedure, including notification to the Controller without undue delay when required, and CNPDCP within 72 hours where Dioartis Grup SRL is controller.
8Deletion, return and audit
On end of service the Controller may delete the website in the workspace (cascading visitor, conversation and lead rows). Export of conversations and leads is available in the product where the plan allows. The Processor will make available information reasonably necessary to demonstrate this DPA and allow audits with reasonable notice, without revealing other customers’ data or security secrets.
9International transfers
Where a sub-processor processes data outside the Republic of Moldova / EEA, the legal transfer tool (adequacy or standard contractual clauses) must be confirmed before being relied upon in a signed contract. See docs/REQUIRED_LEGAL_INPUTS.md internally.
10After termination
After deletion from the live database, residual copies may remain in backups until those backups expire. That period is not yet a verified public number.