Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between the customer (a merchant or agency, the "Controller") and Praevidens.ai, operated by BOYAKOV PROPERTY INVESTMENTS LTD (the "Processor"), for the processing of personal data under Article 28 of the GDPR. By using the platform to process personal data, the Controller accepts this DPA. A countersigned copy is available on request for enterprise customers.
Company reg. no.: HE 459562 (Cyprus)
Tax ID (TIN / VAT): 60085668O
Registered office: Erifylis 16, Mouttalos, 8049, Paphos, Cyprus
Contact: privacy@praevidens.ai
1. Roles
The Controller determines the purposes and means of processing the personal data of its own customers (shoppers). The Processor processes that data only on the Controller's documented instructions, which include this DPA and the Controller's use of the platform's features and settings.
2. Subject-matter, nature & purpose
The Processor processes personal data to provide e-commerce retention analytics, an AI-driven memory of shopping patterns, personalised offer generation, and retention communications, for the duration of the customer's subscription.
3. Categories of data & data subjects
- Data subjects: the Controller's customers and website visitors.
- Categories: contact details (name, email), order and purchase history, product preferences, behavioural/engagement signals, and aggregated traffic/campaign metrics.
- No special-category data (Art. 9) is required or intended to be processed.
4. Processor obligations
- Process personal data only on the Controller's documented instructions, including for international transfers, unless required by law.
- Ensure persons authorised to process data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see §7).
- Assist the Controller, taking into account the nature of processing, in responding to data-subject requests and in meeting its obligations under Articles 32–36 GDPR.
- At the Controller's choice, delete or return personal data at the end of the service, and delete existing copies unless retention is legally required.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits, subject to reasonable notice and confidentiality.
5. Sub-processors
The Controller grants general authorisation for the Processor to engage sub-processors. The current list is published in our Privacy Policy and includes hosting, database, AI, analytics, advertising and email providers. The Processor will inform the Controller of intended changes and give the Controller the opportunity to object. The Processor remains liable for its sub-processors' performance of their data-protection obligations.
6. International transfers
Where personal data is transferred outside the EEA/UK, the Processor relies on the European Commission's Standard Contractual Clauses or another valid transfer mechanism, together with supplementary measures where required.
7. Security measures
- Encryption of data in transit; access limited on a least-privilege, role-based basis.
- Tenant isolation, credential rotation, and monitoring of critical processing jobs.
- Procedures to restore availability and to regularly test the effectiveness of measures.
8. Personal data breaches
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably necessary for the Controller to meet its notification obligations.
9. Deletion & return
On termination or on the Controller's instruction (for example, an app uninstall), the Processor will delete or return the relevant personal data within a reasonable period, subject to any legal retention requirement. Default retention limits are set out in the Privacy Policy.
10. Liability & order of precedence
Liability under this DPA is subject to the limitations in the main agreement. In case of conflict between this DPA and the main agreement on data-protection matters, this DPA prevails.
Need a signed copy or a bespoke DPA for enterprise procurement? Email privacy@praevidens.ai.