DPA
Data Processing Agreement (DPA)
Valid for all subscriptions and services of salesbroker gmbh / Frag-Maria™ · As of: July 23, 2026 · Version 4.0
Note: This page shows the currently valid reference version of our Data Processing Agreement according to Art. 28 GDPR. The legally binding DPA between you and salesbroker gmbh / Frag-Maria™ automatically becomes part of every subscription contract and takes effect upon completion of the order in accordance with Art. 28 Para. 9 GDPR (see Section "Validity" below). For questions or a signed copy: maria@frag-maria.ai
maria@frag-maria.ai · +41 41 539 13 73
VAT ID: CHE-267.192.141 MWST
1. General
(1) The processor processes personal data on behalf of the controller within the meaning of Art. 4 No. 8 and Art. 28 of Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR). This contract regulates the rights and obligations of the parties in connection with the processing of personal data.
(2) If the term "data processing" or "processing" (of data) is used in this contract, the definition of "processing" within the meaning of Art. 4 No. 2 GDPR shall apply.
2. Subject matter of the order
The subject matter of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects are set out in Appendix 1 to this contract.
3. Rights and obligations of the controller
(1) The controller is the controller within the meaning of Art. 4 No. 7 GDPR for the processing of data by the processor on its behalf. The processor is entitled, according to Section 4 Para. 3, to inform the controller if, in its opinion, legally impermissible data processing is the subject of the order and/or an instruction.
(2) As the controller, the controller is responsible for safeguarding the rights of data subjects. The processor will inform the controller without delay if data subjects assert their data subject rights against the processor.
(3) The controller has the right to issue supplementary instructions to the processor at any time regarding the nature, scope and procedure of data processing. Instructions must be in text form (e.g. e-mail).
(4) Regulations on any remuneration for additional expenses incurred by the processor due to supplementary instructions from the controller remain unaffected.
(5) The controller may designate authorized persons to issue instructions. If authorized persons are to be designated, they will be named in Appendix 1. In the event that the authorized persons of the controller change, the controller will inform the processor of this in text form.
(6) The controller will inform the processor without delay if it discovers errors or irregularities in connection with the processing of personal data by the processor.
(7) In the event that there is an obligation to inform third parties in accordance with Art. 33, 34 GDPR or any other statutory reporting obligation, the controller is responsible for complying with it.
(8) The controller confirms that it has a suitable legal basis for all personal data processed under this contract, and indemnifies the processor against claims, liabilities and damages of third parties arising from a missing or insufficient legal basis on the part of the controller.
4. General obligations of the processor
(1) The processor processes personal data exclusively within the framework of the agreements made and/or in compliance with any supplementary instructions issued by the controller. Exceptions to this are legal regulations that oblige the processor to process in a different way; in such a case, the processor will inform the controller of these requirements before processing, unless the relevant law prohibits such notification due to an important public interest. Any processing of data deviating from this is prohibited for the processor, unless the controller has given written consent.
(2) The processor will generally carry out data processing on order in member states of the European Union (EU) or the European Economic Area (EEA). The processor is also permitted to process data outside the EU or EEA if appropriate sub-processors in third countries are used in compliance with the requirements of Section 10 and the requirements of Art. 44-48 GDPR are met or an exception within the meaning of Art. 49 GDPR exists.
(3) The processor will inform the controller without delay if, in its opinion, an instruction issued by the controller violates legal regulations. The processor is entitled to suspend the execution of the instruction until it is confirmed or changed by the controller. If the processor can demonstrate that processing according to the controller's instructions can lead to liability of the processor under Art. 82 GDPR, the processor is free to suspend further processing in this respect until liability between the parties is clarified.
(4) The processor may designate the person(s) authorized to receive instructions from the controller. If authorized persons are to be designated, they will be named in Appendix 1. In the event that the authorized persons of the processor change, the processor will inform the controller of this in text form.
(5) The processor and the sub-processors used by it do not use the personal data processed on order for training, improving or evaluating AI models.
5. Data Protection Officer of the Processor
(1) The processor confirms that it has appointed a data protection officer in accordance with Art. 37 GDPR. The processor shall ensure that the data protection officer has the necessary qualifications and expertise. The processor will separately inform the controller in text form of the name and contact details of its data protection officer.
(2) The obligation to appoint a data protection officer under paragraph 1 may be waived at the discretion of the controller if the processor can demonstrate that it is not legally obliged to appoint a data protection officer and that operational regulations exist that ensure the processing of personal data in compliance with legal requirements, the provisions of this contract and any further instructions from the controller.
6. Reporting obligations of the Processor
(1) The Processor is obliged to immediately notify the Controller of any violation of data protection regulations or of the contractual agreements made and/or the instructions issued by the Controller, which occurred during the processing by him or other persons involved in the processing. The same applies to any personal data breach.
(2) Furthermore, the Processor will immediately inform the Controller if a supervisory authority in accordance with Art. 58 GDPR takes action and this may affect the control of processing on behalf of the Controller.
(3) The Processor is aware that the Controller may have a reporting obligation according to Art. 33, 34 GDPR, which provides for a report to the supervisory authority within 72 hours of becoming aware. The Processor will assist the Controller in implementing the reporting obligations and immediately report any unauthorized access to personal data upon becoming aware. The report must contain in particular: (a) description of the nature of the breach, including the categories and approximate number of data subjects and data records concerned; (b) description of the measures taken or proposed to address the breach and, where appropriate, measures to mitigate its possible adverse effects.
(4) The Processor will inform the Controller of a confirmed personal data breach no later than 48 hours after becoming aware of it.
7. Cooperation obligations of the Processor
(1) The Processor supports the Controller in its obligation to respond to requests for exercising data subject rights in accordance with Art. 12-23 GDPR. The provisions of Section 12 of this contract apply.
(2) The Processor cooperates in the creation of the records of processing activities by the Controller and must provide the Controller with the necessary information in an appropriate manner.
(3) The Processor supports the Controller, taking into account the nature of the processing and the information available to it, in complying with the obligations specified in Art. 32-36 GDPR.
8. Regulations on mobile workstations
(1) The processor may allow its employees who are entrusted with the processing of personal data for the controller to process data at mobile workstations outside the processor's business premises.
(2) The processor must ensure that compliance with the contractually agreed technical and organizational measures is also guaranteed when using mobile workstations. Deviations must be agreed with the controller in advance and approved by the controller in text form.
(3) In particular, the processor shall ensure that when processing at mobile workstations, the storage locations are configured in such a way that local storage of data is excluded. If this is not possible, the processor must ensure that local storage is exclusively encrypted and that other persons located at the mobile workstation do not gain access to this data.
(4) The processor is obliged to ensure that effective control of processing at mobile workstations by the controller is possible.
(5) If employees are also to be deployed at mobile workstations by sub-processors, the provisions of paragraphs 1 to 4 apply accordingly.
9. Audit rights
(1) The controller has the right to monitor the processor's compliance with data protection laws and/or contractual regulations and/or the controller's instructions to the extent necessary.
(2) The processor is obliged to provide the controller with information to the extent necessary to carry out the audit within the meaning of paragraph 1.
(3) The controller may carry out the audit at the processor's premises during normal business hours after prior notification with reasonable notice. The controller shall ensure that audits are carried out only to the extent necessary so as not to disproportionately disrupt the processor's operations. The parties assume that an audit is necessary at most once a year; further audits must be justified by the controller stating the reason. In the case of on-site audits, the controller will reimburse the processor for the resulting expenses, including personnel costs for supervising and accompanying the auditors, to a reasonable extent; the basis for calculating the costs will be communicated to the controller before the audit is carried out.
(4) At the processor's discretion, proof of compliance with the technical and organizational measures can also be provided, instead of an on-site inspection, by submitting an appropriate, current attestation, reports or report excerpts from independent bodies (e.g. auditors, internal audit, data protection officer, IT security department, data protection auditors or quality auditors) or appropriate certification, if the audit report enables the controller to satisfy itself of compliance with the TOMs as set out in Appendix 3. The controller is aware that an on-site inspection of data centers is not possible or only possible in justified exceptional cases.
(5) The processor is obliged, in the event of measures taken by the supervisory authority against the controller within the meaning of Art. 58 GDPR, to provide the necessary information and to enable the competent supervisory authority to carry out an on-site inspection. The controller must be informed by the processor of such planned measures.
(6) The parties agree that control measures for processing at mobile workstations are primarily carried out by checking the assurance of the measures to be taken by the processor in accordance with Section 8 Paragraphs 2 and 3.
10. Subcontracting relationships
(1) The Processor is entitled to use the sub-processors specified in Appendix 2 to this contract for the processing of data on order. The change of sub-processors or the appointment of additional sub-processors is permissible under the conditions mentioned in paragraph 2.
(2) The Contractor shall carefully select the Subcontractor and, before commissioning, verify that the Subcontractor can comply with the agreements made between the Principal and the Contractor. In the event of a planned change or planned new commission, the Contractor shall inform the Principal in text form in good time, but no later than 10 days before the change or new commission ("Information"). The Principal has the right to object to the change or new commission, stating reasons in text form, within 10 days of receipt of the "Information". The objection can be withdrawn in text form at any time. In the event of an objection, the Contractor may terminate the contractual relationship with a notice period of at least 14 days to the end of a calendar month, whereby the Contractor will reasonably consider the interests of the Principal. If no objection is raised by the Principal within 10 days of receipt of the "Information", this shall be deemed consent to the change or new commission.
(3) The Contractor is obliged to obtain confirmation from the Subcontractor that the latter has appointed a data protection officer in accordance with Art. 37 GDPR, if legally obliged to do so.
(4) The Contractor shall ensure that the regulations agreed in this contract and, if applicable, supplementary instructions from the Principal also apply to the Subcontractor.
(5) The Contractor shall conclude a DPA with the Subcontractor that complies with the requirements of Art. 28 GDPR. The DPA shall be provided to the Principal in copy upon request.
(6) The Contractor is particularly obliged to ensure, through contractual arrangements, that the control rights (Clause 9 of this contract) of the Principal and supervisory authorities also apply to the Subcontractor.
(7) Services that the Contractor obtains from third parties as a pure ancillary service (e.g., cleaning services, telecommunication services, postal and courier services) are not considered subcontracting relationships within the meaning of paragraphs 1 to 6. The maintenance and care of IT systems or applications constitute a subcontracting relationship requiring consent if personal data processed on behalf of the Principal can be accessed during maintenance.
11. Confidentiality Obligation
(1) When processing data for the Principal, the Contractor is obliged to maintain confidentiality regarding data that it receives or becomes aware of in connection with the order.
(2) The Contractor has informed its employees about the relevant data protection provisions and obliged them to maintain confidentiality.
(3) The obligations of the employees according to paragraph 2 must be demonstrated to the Principal upon request.
12. Safeguarding Data Subject Rights
(1) The Principal is solely responsible for safeguarding the rights of data subjects. The Contractor is obliged to support the Principal in its duty to process requests from data subjects according to Art. 12-23 GDPR. In particular, the Contractor must ensure that the necessary information is provided to the Principal without delay so that the Principal can comply with its obligations under Art. 12 para. 3 GDPR.
(2) Insofar as the Contractor's cooperation is required for safeguarding data subject rights – in particular to information, rectification, restriction of processing, or erasure – the Contractor shall take the respective necessary measures as instructed by the Principal.
(3) Regulations regarding any remuneration for additional efforts arising for the Contractor from cooperation services in connection with the assertion of data subject rights against the Principal remain unaffected.
13. Confidentiality Obligations
(1) Both parties undertake to treat all information they receive in connection with the performance of this contract as confidential indefinitely and to use it only for the performance of the contract. Neither party is entitled to make this information accessible to third parties.
(2) The foregoing obligation does not apply to information that one of the parties demonstrably received from third parties without being obliged to maintain confidentiality, or that is publicly known.
14. Remuneration
Any regulations regarding remuneration for separate services must be agreed upon separately between the parties.
15. Technical and Organizational Measures for Data Security
(1) The Contractor undertakes to comply with the technical and organizational measures required to comply with the applicable data protection regulations. This includes, in particular, the requirements of Art. 32 GDPR.
(2) The state of the technical and organizational measures existing at the time of concluding the contract is attached as Appendix 3 to this contract. The Contractor shall agree on significant changes that could impair the integrity, confidentiality, or availability of personal data with the Principal in advance. The Contractor may implement minor changes without negative effects without consultation. The Principal may request an updated version of the TOMs once a year or on justified occasions.
16. Duration of the Order
(1) The contract begins with the conclusion of the subscription and runs for the duration of the main contract existing between the parties regarding the Principal's use of the Contractor's services.
(2) The Principal may terminate the contract at any time without notice if there is a serious breach by the Contractor of the applicable data protection regulations or obligations under this contract, if the Contractor cannot or will not execute an instruction from the Principal, or if the Contractor unlawfully denies the Principal or the competent supervisory authority access.
17. Termination
(1) Upon termination of the contract, the Contractor shall, at the Principal's option, return or delete all documents, data, and created processing or usage results that have come into its possession in connection with the contractual relationship. The deletion must be documented appropriately. If the Principal does not state the desired procedure within 90 days after the termination of the contract, the data will be automatically deleted after this period, provided there is no legal retention obligation to the contrary.
(2) The Contractor may store personal data beyond the termination of the contract if and to the extent that a legal obligation to retain it applies. In these cases, the data may only be processed for the purposes of fulfilling the respective legal retention obligations. After the retention period has expired, the data must be deleted without delay.
18. Right of Retention
The parties agree that any right of retention of the Contractor regarding the processed data and associated data carriers under the law applicable at its place of business is excluded.
19. Final Provisions
(1) Should the Principal's property with the Contractor be endangered by measures of third parties (e.g., seizure or confiscation), by insolvency proceedings, or by other events, the Contractor must inform the Principal immediately. The Contractor will immediately inform the creditors that the data is processed on behalf of the Principal.
(2) Ancillary agreements require written form.
(3) Should individual parts of this contract be invalid, this shall not affect the validity of the remaining provisions.
(4) Applicable Law: For EU Principals, this contract is governed by the GDPR. For Swiss Principals, the Swiss Data Protection Act (nDSG) additionally applies. For UK Principals, the UK GDPR applies.
1. Subject Matter and Purpose of Processing
The Contractor (salesbroker gmbh / Frag-Maria™) provides digital AI services to the Principal based on the booked subscription. Depending on the booked product, the order includes one or more of the following service areas:
- Chat AI: Operation of an AI-powered text chat assistant on the Principal's website or digital channels — including conversation management, dialogue control, appointment management, and email escalation to the Principal's support (Human-in-the-Loop).
- Voice AI: Operation of an AI-powered voice assistant for incoming and/or outgoing calls — including speech recognition (STT), speech synthesis (TTS), conversation management, and forwarding to human employees.
- Face AI: Operation of an AI-powered video avatar assistant (Facebot) — including visual representation, conversation management, and integration into the Principal's digital channels.
- Commerce AI: Setup and operation of a professional, conversion-oriented e-commerce store (Shopify) with an integrated AI assistant (Chat, Voice, and/or Face AI) for digital purchase assistance, product advice, service inquiries, and order support.
- Workflow Automation & Integration: Automated processing and forwarding of conversation data, leads, and inquiries to the Principal's internal systems (CRM, calendar, email, etc.) via defined interfaces.
Purpose of processing: Digital customer communication on behalf of the Principal — in particular, answering inquiries, providing information, appointment management, lead qualification, purchase assistance, and structured handover of concerns to the responsible departments at the Principal.
2. Type of Personal Data
- Communication data: Chat messages and conversation histories (text), voice recordings and transcripts (Voice AI), video session metadata (Face AI)
- Contact data (if voluntarily submitted by the user): First name, last name, email address, phone number, company
- Technical data: IP address, session ID, browser and device information, operating system, timestamps, connection data
- Inquiry content: Specific concerns, questions, wishes, and other information transmitted by the user during the conversation
- Appointment-related data (if appointment module active): Desired appointments, availabilities, if applicable, reason for conversation
Further processing of special categories of personal data within the meaning of Art. 9 GDPR is not intended and not permitted to the Contractor, unless there is an express written instruction from the Principal.
3. Categories of Data Subjects
- Website visitors and users of the Principal's digital channels
- Customers, prospective customers, and business partners of the Principal
- Persons who contact the AI assistant via embedded widgets, direct links, or telephone lines
4. Persons Entitled to Issue Instructions and Persons Authorized to Receive Instructions
| Party | Function | Contact |
|---|---|---|
| Principal | Person(s) authorized to issue instructions | As specified in the customer account or separately designated by email |
| Contractor | Person authorized to receive instructions | salesbroker gmbh | Frag-Maria™ maria@frag-maria.ai · +41 41 539 13 73 |
Changes to the persons authorized to issue or receive instructions must be communicated to the other party immediately in text form.
The Contractor (salesbroker gmbh / Frag-Maria™) uses the services of the following third-party companies for the processing of data on behalf of the Principal:
← Table horizontally scrollable on small screens →
| Provider (Name & Address) | Service / Function | Legal Basis Third Country | Server Location | Special Notes |
|---|---|---|---|---|
|
Twilio Ireland Limited 25–28 North Wall Quay, D01 H104 Dublin, IE |
Telephony / Carrier Routing | EU-US DPF, BCR, EU SCC | Ireland Region (EU) | Data remains in EU region according to provider. |
|
OpenAI Ireland Ltd. The Liffey Trust Centre, 117–126 Sheriff St Upper, Dublin 1, IE |
LLM, Speech-to-Text, Text-to-Speech | EU-US DPF, EU SCC | Processing in EU, Zero Retention | Enterprise Tenants / Azure EU. |
|
Eleven Labs Inc. (optional) 169 Madison Ave #2484, New York, NY, USA |
Text-to-Speech / Speech-to-Text — via Voiceflow | EU-US DPF, EU SCC | Belgium (EU) | Zero Retention after audio generation. Only for activated module. Concerns exclusively Chat-Voice functions via Voiceflow. |
|
Microsoft Ireland Operations Ltd. One Microsoft Place, D18 P521 Dublin, IE |
Speech-to-Text, LLM, Text-to-Speech | EU-US DPF, EU SCC | EU Data Protection Zone | Azure OpenAI / EU Tenants. |
|
Google Ireland Ltd. Gordon House, Barrow Street, Dublin 4, IE |
STT, LLM, TTS | EU-US DPF, SCC, Adequacy Decision | Europe Deployments | Only EU regions active. |
|
Perplexity AI, Inc. (optional) 575 Market St Fl 4, San Francisco, CA, USA |
Knowledge/Search Engine | EU-US DPF, EU SCC | EU Region | Only for activated function. |
|
Voiceflow Inc. 260 Carleton Ave, Suite 100, Ottawa, ON K1S 2C3, Canada |
Dialog Design and Bot Management Platform | Adequacy Decision CH/EU–Canada | Canada / EU Region | Storage of Bot Flows / Prompts; no customer dialogues. |
|
Zapier Inc. 548 Market St #62411, San Francisco, CA, USA |
Workflow Automation / MCP Client Integration | EU-US DPF, EU SCC | EU Region (where available) | Data transfer minimized / Task-based. |
|
n8n GmbH Gerichtstr. 23, 13347 Berlin, Germany |
Workflow Automation / Data Flows | n/a (no third country) | Germany / EU | Self-hosted / EU-Cloud Option; no third countries. |
|
Brevo (SeedRocket SAS) 106 Boulevard Haussmann, 75008 Paris, France |
Email / Transactional & Marketing Communication | n/a (no third country) | France / EU | GDPR-compliant processing (EU servers). |
|
Telephony/Voice Agent Infrastructure Provider EU/Austria |
Real-time voice agent orchestration, call routing and telephony infrastructure | n/a — provider based in the EU/EEA | Austria / EU | Data Processing Agreement according to Art. 28 GDPR is in place. The AI model providers used by this infrastructure are listed individually as separate sub-processors in this annex. |
|
Theai, Inc. dba Inworld AI (optional) USA |
Text-to-Speech — via Telephony/Voice Agent Infrastructure | EU-US DPF, EU SCC | EU Region | EU Data Residency, Zero Data Retention. Only when module is activated. |
|
Deepgram, Inc. (optional) 548 Market St Suite 25104, San Francisco, CA 94104-5401, USA |
Speech-to-Text (Speech Recognition) | EU-US DPF, EU SCC | EU Region (where available) | Zero-data-retention agreement in place. Only used when this module is activated. |
|
HubSpot Ireland Limited HubSpot House, 1 Sir John Rogerson's Quay, Dublin 2, D02 CR67, Ireland |
CRM / Marketing Cloud Infrastructure | n/a (no third country) | Ireland / EU | GDPR-compliant processing (EU servers). |
|
PostHog, Inc. 2261 Market Street #4008, San Francisco, CA 94114, USA |
Product Usage Analysis | EU-US DPF, EU SCC | EU Region (EU-hosted instance) | Exclusively aggregated technical usage data; no conversation content. |
|
New Relic, Inc. 188 Spear Street, Suite 1200, San Francisco, CA 94105, USA |
Application Logging / Performance Monitoring | EU-US DPF, EU SCC | EU Region (where available) | Exclusively technical infrastructure monitoring; no conversation content. |
|
Meta Platforms Ireland Ltd. (optional) 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland |
WhatsApp Business Platform — Sending notifications, callback and confirmation messages | EU-US DPF, EU SCC | EU Region (where available) | Only used when WhatsApp module is activated. |
|
Anthropic, PBC 548 Market St, PMB 90375, San Francisco, CA 94105, USA |
LLM / Language Model (Claude) | EU-US DPF, EU SCC | USA (API access) | Processing via API; no data storage by Anthropic for API requests according to Anthropic API Terms of Use (Zero Retention Policy). |
Legend: EU-US DPF = EU-US Data Privacy Framework · SCC = Standard Contractual Clauses · BCR = Binding Corporate Rules
Optional = Only used if the corresponding module/feature is contractually booked and activated.
The Contractor (salesbroker gmbh / Frag-Maria™) implements the following technical and organizational measures for data security in accordance with Art. 32 GDPR (as of: July 2026):
General Measures
The protection of personal data is considered during the development and selection of hardware, software, and procedures, taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risks to the rights and freedoms of natural persons (Art. 25 GDPR).
1. Access Control
- Chip card/transponder locking system
- Security locks
- Access rules for external personnel
2. Entry Control / User Access Control
- Always up-to-date virus protection and current software versions
- Authorization/authentication concepts with access regulations limited to the necessary minimum
- Minimum password lengths, password managers, and multi-factor authentication for increased protection requirements
- Encryption of mobile data carriers, devices, and hard drives (FileVault, BitLocker)
- Logging of data access
- Encryption of data at rest according to AES-256 standard
3. Transmission Control
- Encryption of data carriers and connections
- Encryption of data connections (in transit) according to TLS 1.2 or higher
- Dedicated transmission authorizations, definition and documentation of recipients
- Email encryption (S/MIME), pseudonymization
4. Input Control
- Assignment of rights for entering, modifying, and deleting data based on an authorization concept following the four-eyes principle
- Logging of data entries, modifications, and deletions
5. Order Control
- Careful selection of sub-contractors, written definition of instructions
- Monitoring of compliance, ensuring data destruction after contract termination
6. Availability Control / Integrity
- Continuously monitored backup and recovery concept
7. Ensuring Purpose Limitation / Separation Requirement
- Logical client separation, separation of production and test systems
- For pseudonymized data: separation of the assignment file and storage on a separate, secured system
Status of TOMs: July 2026 — salesbroker gmbh / Frag-Maria™. Significant changes will be communicated to the client in advance according to Section 15 Para. 2 of this DPA.
DPA v4.0 · salesbroker gmbh | Frag-Maria™ · frag-maria.ai · Legal basis: Art. 28 GDPR · Status: 23.07.2026
Inquiries or signed copy: maria@frag-maria.ai