This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and Escapers GmbH, operating EMA AI, Schönbrunner Straße 222–228 / Stiege 3 / Top A2, 1120 Wien, Austria ("Processor"), and governs the processing of personal data by the Processor on behalf of the Controller in connection with the EMA AI website assistant service ("Service").
The Processor processes personal data solely to provide the Service for the duration of the underlying subscription agreement and until deletion in accordance with Section 9.
Operation of an AI chat assistant embedded on the Controller's website: receiving and answering website-visitor messages, retrieval over the Controller's published content, and related analytics.
| Data subjects | Visitors of the Controller's website; the Controller's authorised users. |
|---|---|
| Categories of data | Conversation content submitted by visitors, technical metadata (session identifiers, timestamps, coarse locale), and any personal data the visitor chooses to include in a message. The Processor applies automatic PII masking before any LLM call or log. |
Personal data is stored within the EU. Where a sub-processor processes data outside the EEA, transfers are safeguarded by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and supplementary measures as appropriate.
The Controller grants general authorisation for the engagement of the following sub-processors. The Processor will inform the Controller of intended changes and give the Controller the opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| OpenAI / Anthropic / Google (via Emergent Universal LLM Proxy) | AI inference (no model training on messages) | EU SCCs |
| MongoDB Atlas | Data storage | EU region |
| Resend Inc. | Transactional email delivery | EU SCCs |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) |
| Emergent Inc. | Hosting platform | EU SCCs |
The Processor provides functionality and reasonable assistance enabling the Controller to fulfil requests for access, rectification, erasure, restriction, portability and objection.
Visitor conversation data is retained for 180 days and then automatically deleted via MongoDB TTL. Upon termination of the Service, the Processor deletes or returns all personal data within 30 days, unless storage is required by Union or Member-State law.
This DPA is governed by Austrian law and the GDPR. In case of conflict between this DPA and the main agreement regarding data protection, this DPA prevails. Place of jurisdiction: Vienna, Austria.
This is a standard template provided for convenience and does not constitute legal advice. Please have it reviewed by your counsel before signing. Questions: privacy@useema.com.