1. Parties and scope

This Data Processing Agreement ("DPA") is an annex to the BootDesk Terms of Service and forms part of the contract between your organization ("Customer", the controller) and GRUPO OITO OÜ, registry code 17195338, Tartu mnt 67/1-13b, 10115 Tallinn, Estonia ("BootDesk", the processor).

It governs BootDesk's processing of personal data contained in the Customer's service data — conversations, contacts, attachments, transcripts, tickets and notes processed on behalf of the Customer in the course of providing the service. By accepting the Terms of Service (or continuing to use the service after the version date above), the Customer accepts this DPA. A countersigned copy is available on request at suporte@bootdesk.eu.

2. Processing details

Subject matter: omnichannel customer support — unifying conversations from messaging, email, telephony and web channels into ticket threads, with team tooling, automation and AI assistance.

Duration: for the term of the account, plus the deletion periods in section 8.

Nature and purpose: collection, storage, transmission, transcription, indexing and display of Customer communications; provision of automation and AI features over that content.

Categories of data subjects: the Customer's end users (its customers) and the Customer's team members.

Categories of data: identification and contact data (names, handles, phone numbers, email addresses), communication content (messages, audio and its transcripts, attachments), metadata (timestamps, channel identifiers), and account data of team members.

3. Processor obligations

BootDesk processes personal data only on documented instructions from the Customer — including regarding transfers to a third country, unless required by EU or member state law (in which case BootDesk informs the Customer before processing, unless legally prohibited). The Terms of Service and the Customer's product configuration constitute those instructions.

BootDesk ensures that persons authorized to process the data are bound by confidentiality obligations; takes the technical and organizational measures in section 7; assists the Customer, insofar as possible, in fulfilling obligations to respond to data subject requests and to ensure security; makes available the information needed to demonstrate compliance; and, where the Customer so requests, submits to audits as described in the Terms of Service.

4. Subprocessors

BootDesk uses three categories of subprocessors. Platform subprocessors are always active. Channel and integration processors are engaged only when the Customer configures the corresponding integration — the Customer, as controller, decides which apply. AI inference providers are engaged when AI features are enabled, within the region policy of section 5.

Platform subprocessors (always active):

  • Amazon Web Services — cloud infrastructure: compute, database, managed AI services and email delivery. EU regions only. Its Data Processing Addendum (with EU standard contractual clauses) is incorporated into AWS service terms; ISO 27001 and SOC 2 certified; EU–US Data Privacy Framework certified.
  • Scaleway — object storage. Processing entirely within the EU (French entity). ISO 27001 certified; DPA published.
  • BunnyCDN — content delivery, storage edge and DNS. EU edge locations only; EU-based operator (Slovenia); DPA available.
  • Cloudflare — marketing website infrastructure and document rendering. Customer DPA in force with EU standard contractual clauses; ISO 27001 and SOC 2 Type II; EU–US Data Privacy Framework certified.
  • Stripe — payment processing for account billing; EU customers contract with Stripe Payments Europe Ltd. DPA published; PCI DSS Level 1; transfers under standard contractual clauses and Data Privacy Framework.
  • PostHog — product analytics and error tracking, aggregated. EU cloud (Frankfurt); self-serve DPA; SOC 2 Type II.

Channel and integration processors (active only when the Customer enables the integration):

  • Meta — WhatsApp, Messenger, Instagram and Threads messaging channels, under Meta's business platform terms.
  • Telegram — messaging channel. Telegram acts as an independent controller for its users' account data; message content flows to the Customer's workspace through the bot integration.
  • Threema — messaging channel. Swiss provider, Swiss hosting.
  • Slack — team channel and notifications. Slack commits not to train generative AI on customer data without opt-in; regional data residency options available.
  • Microsoft Teams — team channel and notifications. Microsoft's EU Data Boundary keeps customer data within the EU/EFTA for these services.
  • Discord — team channel and notifications, under Discord's own terms.
  • Twilio, Vonage, Telnyx — voice and SMS telephony channels. Telnyx commits not to train AI models on customer content without written opt-in and is Data Privacy Framework certified.
  • Shopify — webstore and order data sync, under Shopify's DPA (transfers via binding corporate rules and standard contractual clauses).
  • GitHub, GitLab — developer connectors for the AI assistants; each governed by its published data protection agreement.

These providers process data to deliver the channel the Customer connected — for example, delivering a WhatsApp reply to the end user who wrote it. Their own privacy terms govern their processing on the Customer's side of the integration.

AI inference providers (active when AI features are enabled): Amazon Web Services (Bedrock), Baseten, Cerebras, Cloudflare (Workers AI), Fireworks AI, Google (Gemini), Groq, Nebius, OpenRouter, Scaleway and Z.ai. Several serve requests from EU datacenters (for example Frankfurt or Paris); others operate from the US or other regions — the region policy of section 5 determines which are used. OpenRouter is a router: the underlying provider varies with the chosen model. These providers are engaged on zero-data-retention or no-training API terms where offered, and requests sent to them are covered by the automated masking described in section 5.

5. Transfers and region policy

The Customer's service data is stored and processed in the European Union — AWS EU regions only, with EU object storage and EU analytics. Content delivery operates exclusively from EU edge locations.

Two categories of processing may route outside the EU, always under the Customer's control:

Channel and integrations process data in the provider's own infrastructure, where that provider operates — this is inherent to delivering the connected channel. Where the provider relies on transfers outside the EEA, transfers occur under standard contractual clauses, binding corporate rules, the EU–US Data Privacy Framework or an equivalent safeguard, as applicable to the provider in question.

AI inference follows the Customer's region policy. Each workspace selects whether AI requests may be served by models in the US, EU, BR or CN regions; by default the region is not locked. Before any request leaves the platform, an automated masking layer removes or pseudonymizes personal identifiers it detects. This layer materially reduces personal data in prompts but is not infallible: if the Customer requires a guarantee that no personal data reaches a given region, the Customer should select a restrictive region policy or disable AI features.

6. Subprocessor changes

BootDesk maintains the current list of subprocessors in this document. New platform subprocessors are announced in advance by email or in-product notice, giving the Customer a reasonable window to object; channel and AI providers become active only through the Customer's own configuration and therefore require no separate notice.

7. Security measures

At a minimum: encryption of data in transit (TLS) and at rest; logical isolation of each workspace's data; role-based access control within the Customer's team; access by BootDesk personnel only on documented support requests, logged, with least privilege; secrets and credentials stored in managed secret systems; infrastructure as code with reviewed changes; centralized logging of access to production systems.

Personal data breaches are notified to the Customer without undue delay and no later than 72 hours after BootDesk becomes aware, with the information reasonably available — nature of the breach, categories and approximate number of data subjects and records, likely consequences and measures taken.

8. Return and deletion

On cancellation, service data is deleted within 30 days and backup copies within 90 days, after which deletion is irreversible. Until deletion, the Customer may export all service data via API or file export at any time. BootDesk disposes of all copies according to this section unless EU or member state law requires storage.

9. Liability and governing law

Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of the Republic of Estonia, and disputes are subject to the venue agreed there.

Questions, signed copies and audit requests: suporte@bootdesk.eu — GRUPO OITO OÜ, Tartu mnt 67/1-13b, 10115 Tallinn, Estonia.

This DPA is drawn up in English. In the event of any discrepancy between the language versions, the English version prevails.