Data Processing Agreement
This agreement forms part of the Terms of Service between the business using Neaion (the Controller) and Rawly OÜ (the Processor). It applies whenever the Processor processes personal data on the Controller's behalf.
1. Subject matter and instructions
The Processor processes personal data only to provide Neaion as described in Annex I, and only on the Controller's documented instructions — which are the Terms, this agreement, and the Controller's configuration of the service (its playbook, policies, connected channels and answers). If the Processor believes an instruction breaks data protection law, it will tell the Controller.
2. Confidentiality
Everyone the Processor authorises to process the data is bound by confidentiality. Access to message content by the Processor's staff is limited to what is needed to operate, secure or support the service.
3. Security
The Processor implements the technical and organisational measures in Annex II, and keeps them appropriate to the risk (Art. 32 GDPR).
4. Sub-processors
The Controller authorises the sub-processors listed on the Sub-processors page. The Processor will announce any addition or replacement at least 30 days in advance, giving the Controller the chance to object; if an objection cannot be resolved, the Controller may terminate the affected service. The Processor imposes data protection obligations on each sub-processor equivalent to this agreement and remains responsible for them.
5. International transfers
Where personal data leaves the European Economic Area, the transfer relies on an adequacy decision (such as the EU–US Data Privacy Framework for certified recipients) or the European Commission's Standard Contractual Clauses.
6. Assistance
The Processor helps the Controller, taking into account the nature of the processing, to respond to data subjects exercising their rights, and with data protection impact assessments and prior consultations where relevant. The service itself lets the Controller find everything held about one of its customers, hand it over as one file, and erase it — except what the Controller must keep by law, such as invoices.
7. Personal data breaches
The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information the Controller needs to meet its own obligations.
8. End of processing
When the service ends, the Processor deletes the Controller's personal data within 30 days of the Controller's written request (or returns it first, if asked), unless the law requires it to be kept. Backups containing it expire within a further 30 days.
9. Audits and information
The Processor makes available the information needed to demonstrate compliance with this agreement, and allows for audits by the Controller or an auditor it mandates, on reasonable notice and at reasonable intervals.
10. United States: service provider terms (CCPA and other state laws)
Where the Controller is a "business" under the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 and following, and its regulations, Cal. Code Regs. tit. 11, § 7000 and following — the "CCPA"), the Processor is its "service provider"; where another US state's consumer privacy law applies, the Processor is its "processor". Words in quotation marks have the meaning those laws give them. In addition to sections 1 to 9:
- Limited purposes. The Controller discloses personal information to the Processor only for the limited and specified business purposes described in Annex I — providing Neaion to the Controller.
- No selling or sharing. The Processor does not sell or share the personal information (as "sell" and "share" are defined in the CCPA). The parties agree that the Processor gives nothing of value for it: the Controller pays the Processor for the service, not the other way round.
- No other use. The Processor does not retain, use or disclose the personal information for any purpose — including any commercial purpose — other than the business purposes in Annex I, or as the CCPA and its regulations otherwise permit a service provider; and not outside the direct business relationship between the Processor and the Controller. In particular, it does not use it to train AI models.
- No combining. The Processor does not combine the personal information it receives from or on behalf of the Controller with personal information it receives from or on behalf of anyone else, or collects from its own interaction with the consumer, except as the CCPA's regulations permit a service provider.
- Same protection. The Processor complies with the obligations the CCPA places on service providers and gives the personal information the same level of privacy protection the CCPA requires of the Controller, including reasonable security (Annex II).
- Consumer requests. The Processor helps the Controller answer consumers' requests (section 6). When the Controller tells it of a request to delete, to correct or to opt out, the Processor carries it out for the data it holds, and passes it on to its sub-processors where they hold the data.
- The Controller's checks. The Controller may take reasonable and appropriate steps to make sure the Processor uses the personal information in a manner consistent with the Controller's obligations under the CCPA — including the information and audits in section 9.
- Notice, and stopping misuse. The Processor tells the Controller if it determines that it can no longer meet its obligations under the CCPA. The Controller may then, on notice, take reasonable and appropriate steps to stop and remediate any unauthorised use of the personal information.
- Sub-processors. Each sub-processor (section 4) is bound by a written contract with the same restrictions as this section.
- Deidentified information. If the Processor ever receives deidentified information from the Controller, it does not try to reidentify it.
The Processor certifies that it understands the restrictions in this section and will comply with them. For the other states' laws, sections 2 (confidentiality), 4 (sub-processors), 6 (assistance), 8 (deletion or return at the end) and 9 (information and audits) are the processor's duties those laws require.
11. No health information (HIPAA)
Neaion is not built or offered to create, receive, maintain or transmit protected health information under the US Health Insurance Portability and Accountability Act ("HIPAA"), and the Processor does not enter into business associate agreements. A Controller that is a HIPAA "covered entity" or "business associate" must not use Neaion for its patients' information (see the Terms, section 14).
Annex I — Details of processing
| Nature and purpose | Receiving and answering the Controller's customer messages with AI, grounded in the Controller's playbook, on the channels it connects; booking, moving and cancelling appointments in its calendar; reading one order's status for that order's own customer; drafting review replies and content for the Controller to approve and publish; sending the Controller's emails to its subscribers; reading the receipts and invoices it sends in — and the e-invoices that reach it by mail or at its e-invoice integrator — into a ledger, and following the invoices it issued, with the reminders it asks for; gathering problem reports; briefing the Controller on its own mail and drafting replies for it to send; escalating questions to the Controller; recording what was done. |
|---|---|
| Categories of data subjects | The Controller's customers and prospects who contact it; its subscribers; its suppliers and the other contacts whose documents or mail it passes to the service; the Controller's own staff who use the service. |
| Categories of personal data | Names, email addresses, phone numbers and other contact details; the content of messages, replies and notes; conversation history and what each conversation is about; ratings of answers; appointment times; order status; invoice and purchase details (numbers, amounts, dates); review texts; problem reports; anything else data subjects choose to write. |
| Special categories | None intended — and no protected health information under HIPAA (section 11). Customers may volunteer them in free text; the Controller should not configure the service to request them. |
| Duration | The term of the agreement, plus the deletion period in section 8. |
| Frequency | Continuous. |
Annex II — Technical and organisational measures
- Tenant isolation enforced by the database (row-level security keyed to the company, with no data returned when no company is in scope), backed by foreign keys that tie every record to its company; automated tests attempt cross-tenant access and must fail.
- Least privilege: the internet-facing service and the AI worker use separate database roles with narrow, separate grants; neither is a superuser; the audit trail of AI calls cannot be modified or deleted by either.
- Encryption: TLS for traffic from the internet; connected-account credentials encrypted with AES-256-GCM under a per-company key, with the master key held outside the database.
- Network isolation: the AI layer has no route from the internet.
- Action control: every action the AI proposes is evaluated by a rule engine — recipient pinned to the conversation's own counterpart, marketing blocked without consent, spending capped — and every decision is recorded.
- Data minimisation in AI routing: customer content is sent only to AI providers approved for it; this is enforced in code.
- Access control: passwords stored as bcrypt hashes; sign-in rate-limited and locked after repeated failures; administrative access to servers by key only.
- Resilience: daily backups stored off the server; restores rehearsed against a scratch database, including a check that tenant isolation survives the restore.
- Monitoring: automated alarms for provider failures, queue backlogs, unanswered escalations and unusual spend.