Data Processing Agreement
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service and any other agreement between you and us governing your use of the Alovibe service (together, the "Agreement"). It sets out the terms on which Alovibe processes personal data on your behalf when you use the Service. This DPA applies where, and to the extent that, Alovibe processes Tenant Personal Data (as defined below) as a processor on your behalf and you are subject to European Data Protection Law, UK Data Protection Law, or other Applicable Data Protection Law.
In this DPA, "Alovibe", "we", "us", and "our" refer to NEXGEN SKYLINEX, S.L., of Paseo Virgen del Puerto 51, 28005 Madrid, Spain, the operator of the Alovibe platform (the "Service"). "You", "your", and the "Customer" refer to the business that has entered into the Agreement and that uses the Service to manage its own end customers.
By entering into the Agreement, or by continuing to use the Service after this DPA takes effect, you agree to this DPA on behalf of yourself and, to the extent required, the controllers on whose behalf you act.
1. Definitions
1.1. The following terms have the meanings set out below. Capitalised terms used but not defined in this DPA have the meaning given to them in the Agreement.
- "Alovibe Account Data" means personal data relating to your relationship with us, including the identity, contact, authentication, billing, security, and usage data of your account owner, team members, and staff that we process to create and administer your account, authenticate users, bill subscriptions, secure the Service, and meet our own legal obligations. We act as a controller of Alovibe Account Data, and its processing is governed by our Privacy Policy, not by this DPA.
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of personal data under the Agreement, including, as applicable: (a) Regulation (EU) 2016/679 (the "GDPR") and its implementing national legislation ("European Data Protection Law"); (b) the GDPR as incorporated into United Kingdom law by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 (the "UK GDPR", and together with the Data Protection Act 2018, "UK Data Protection Law"); (c) the Swiss Federal Act on Data Protection ("Swiss Data Protection Law"); and (d) U.S. state privacy laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA").
- "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Special Category Data", and "Supervisory Authority" have the meanings given to them (or to their functional equivalents, such as "business", "service provider", and "consumer" under the CCPA) in Applicable Data Protection Law. "Process", "Processes", and "Processed" are construed accordingly.
- "Data Subject Request" means a request from a Data Subject to exercise their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection, and equivalent consumer rights under the CCPA (such as the rights to know, delete, correct, and opt out of sale or sharing).
- "EEA" means the European Economic Area.
- "Standard Contractual Clauses" or "SCCs" means: (a) for transfers subject to European Data Protection Law, the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"); and (b) for transfers subject to UK Data Protection Law, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (the "UK Addendum"), in each case as updated, amended, or replaced from time to time.
- "Sub-processor" means any third party engaged by us (including our affiliates) to Process Tenant Personal Data in the course of providing the Service.
- "Tenant Personal Data" means Personal Data that we Process on your behalf, as your Processor, in the course of providing the Service. Tenant Personal Data includes the Personal Data of your end customers and contacts and the conversation, booking, commerce, and related data you bring into, or generate within, the Service, as further described in Annex I. Tenant Personal Data does not include Alovibe Account Data.
1.2. The terms of this DPA apply irrespective of whether Applicable Data Protection Law uses different terminology (for example, "business" and "service provider" under the CCPA). Where such terminology applies, the corresponding role and obligations are read in.
2. Roles of the Parties and Scope
2.1. Three-party model. The Service operates a multi-tenant model involving three distinct categories of party:
(a) You (the Customer) are the Controller of the Personal Data of your own end customers, contacts, and staff. You determine the purposes and means of the Processing of that data — for example, which messaging channels you connect, whether and how the Alo assistant is enabled, what messages you send, and what data you record. You are responsible for establishing and maintaining a valid lawful basis (and, where required, consent) for that Processing and for the relationship with the relevant Data Subjects.
(b) We (Alovibe) act as your Processor with respect to Tenant Personal Data, Processing it only on your documented instructions and on the terms of this DPA. Separately and independently, we act as a Controller of Alovibe Account Data, as described in Section 1 and in our Privacy Policy.
(c) Your end customers and your staff are the Data Subjects whose Personal Data is Processed under this DPA.
2.2. CCPA roles. To the extent the CCPA applies, you are a "business" and we are a "service provider" with respect to Tenant Personal Data. We will Process Tenant Personal Data only to perform the Service and the business purposes specified in the Agreement and this DPA, and we will not: (a) sell or share Tenant Personal Data; (b) retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship between you and us; or (d) combine it with Personal Data received from other sources, except as permitted by the CCPA. We certify that we understand and will comply with these restrictions.
2.3. Connected channels and your own provider accounts. Where you connect a third-party channel or service using your own account with that provider — for example, your own Meta/WhatsApp Business account, your own Telegram bot, your own Stripe Connect account, or your own Google Workspace — that provider Processes Personal Data as your provider or sub-processor under your own agreement with it, and any messaging, transaction, or service fees are billed by that provider directly to you. Those providers are not our Sub-processors with respect to your direct relationship with them, and your contract with each such provider governs that Processing. This Section 2.3 does not affect our engagement of the providers listed in Section 6.2 to the extent they Process Tenant Personal Data on our infrastructure to deliver the Service.
2.4. No independent purposes. We will not Process Tenant Personal Data for our own independent purposes, and will never sell Tenant Personal Data. We do not use Tenant Personal Data to train, fine-tune, or develop any general-purpose or foundation artificial-intelligence model of our own.
3. Processing of Tenant Personal Data
3.1. Subject matter, duration, nature, and purpose. The subject matter, duration, nature, and purpose of the Processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I. In summary, we Process Tenant Personal Data by automated means to operate, secure, and support the Service — including receiving and sending messages across the channels you connect; managing services, staff, resources, and availability; taking and managing bookings; processing commerce, deposits, refunds, gift cards, loyalty, and related payment metadata; sending transactional and (where you direct) marketing communications; and powering the Alo assistant and web-voice features where you enable them — for the duration of your account, plus the limited wind-down period described in Section 11.
3.2. Documented instructions. We will Process Tenant Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law to which we are subject. Where the law requires us to Process Tenant Personal Data other than on your instructions, we will inform you of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.
3.3. What constitutes your instructions. Your instructions are constituted by: (a) the Agreement and this DPA; (b) your configuration and use of the Service through its features and settings — including the channels you connect, whether the Alo assistant and web-voice are enabled, the campaigns you run, the messages and offers you send, and the data you enter, import, or instruct the assistant to act upon; and (c) any further written instructions you give that are agreed by us. You may give additional reasonable instructions consistent with the Service; we may charge for, or decline, instructions that fall outside the scope of the Service or that we cannot lawfully or technically accommodate.
3.4. Lawfulness of instructions. We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law, save where we are prohibited from doing so by law. We are not obliged to, and do not, monitor your compliance with Applicable Data Protection Law.
3.5. Your responsibilities. You warrant that: (a) you have provided all required notices and have a valid lawful basis (and, where required, consent) to collect and share Tenant Personal Data with us and to instruct the Processing described in this DPA; (b) your instructions comply with Applicable Data Protection Law; and (c) you will not place Special Category Data, government identifiers, payment card numbers, or other unusually sensitive data into free-text fields, notes, attachments, or knowledge-base content beyond what is necessary, and that you accept responsibility where you do so.
4. Confidentiality
4.1. We will treat Tenant Personal Data as confidential. We ensure that personnel authorised to Process Tenant Personal Data are bound by appropriate, written or statutory, confidentiality obligations, are made aware of the confidential nature of the data, and access it only as needed to provide, secure, and support the Service. These obligations survive termination of their engagement.
4.2. Access to Tenant Personal Data within our organisation is limited to authorised personnel on a least-privilege, need-to-know basis, subject to the access controls described in Annex II.
5. Security
5.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects, we implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. A description of those measures is set out in Annex II.
5.2. You are responsible for the security of credentials, devices, and access used to reach the Service on your side, for configuring the Service appropriately (including roles and access for your team members and staff), and for the security practices of any of your own third-party provider accounts you connect.
5.3. We may update the measures in Annex II from time to time provided that the updated measures do not materially reduce the overall level of security of the Service.
6. Sub-processors
6.1. General authorisation. You give general written authorisation for us to engage Sub-processors to Process Tenant Personal Data in order to provide the Service, subject to this Section 6.
6.2. Current Sub-processors. As at the effective date of this DPA, we engage the Sub-processors listed below. Each Processes Tenant Personal Data only as necessary to perform the function described.
| Sub-processor | Function | Nature of data Processed | Where applicable |
|---|---|---|---|
| OpenAI | Powers the Alo assistant (chat completions), knowledge-base text embeddings, and the optional web-voice feature (cascaded STT, Alo, and TTS). | Conversation context, business knowledge-base content, and — for web-voice — audio turns and generated speech, sent to transcribe and generate replies. | Where the assistant and/or web-voice are active (both enabled by default; the Account Owner can turn either off in settings). |
| Stripe | (1) Billing of your Alovibe subscription via our own Stripe account; and (2) Stripe Connect — processing payments from your end customers (booking deposits and balances, product orders, gift-card purchases, no-show fees) directly into your own connected Stripe account. | Payment and order metadata and Stripe identifiers. We store Stripe identifiers and metadata only and never store full payment card numbers. | Always for subscription billing; the Connect flow only where you connect your own Stripe account. |
| Resend | Transactional and marketing email delivery (login links, verification, password reset, booking confirmations and reminders, order and gift-card emails, and marketing campaigns). | Recipient email addresses, names, and message content. | Always (for transactional email); marketing email only where you run campaigns. |
| Meta (WhatsApp, Instagram, Facebook) | Inbound and outbound messaging on the Meta-owned channels you connect, using your own Meta/WhatsApp Business account. | Messaging handles, message content, and related identifiers. | Only where you connect a Meta channel. Meta Processes that data as your own provider under its terms; see Section 2.3. |
| Telegram | Inbound and outbound messaging via your own Telegram bot. | Messaging handles, message content, and related identifiers. | Only where you connect Telegram. See Section 2.3. |
| Google (Calendar, Gmail) | Optional. One-way Calendar sync that pushes booking events to your connected calendar; and a send-only Gmail connector for support-inbox replies. | Booking event details (Calendar); outbound email content and recipients (Gmail). | Only where you connect Google (off unless configured). |
| Sentry | Optional error and exception monitoring for our application and infrastructure. | Error context and diagnostic data, which may incidentally include Personal Data present in error details. | Only where error monitoring is enabled. |
| Operator-run hosting infrastructure | The application is self-hosted by us on dedicated server infrastructure (including the primary database, cache, reverse proxy/TLS, application services, a backup process, and a file store). We do not use a managed third-party cloud database. | All Tenant Personal Data, as the underlying hosting and storage layer. | Always. Where configured, encrypted backups may be uploaded to an operator-controlled off-host backup location. |
6.3. Sub-processor obligations. Before engaging a Sub-processor to Process Tenant Personal Data, we impose data protection obligations on it by written contract that are no less protective than those in this DPA, to the extent applicable to the nature of the Service provided by that Sub-processor, including, where the Sub-processor Processes Tenant Personal Data outside the country of collection, an appropriate international-transfer mechanism as described in Section 9. We remain fully responsible to you for the performance of each Sub-processor's obligations.
6.4. Change notification and objection. We will give you a means of becoming aware of additions to, or replacements of, our Sub-processors — for example, by maintaining an up-to-date list and notifying you of changes through the Service, by email to your account owner, or by another reasonable mechanism, before the new Sub-processor begins Processing Tenant Personal Data. You may object to a new Sub-processor on reasonable grounds relating to data protection by notifying us within thirty (30) days of being notified. If you object, we will use reasonable efforts to make available a change in the Service, or recommend a commercially reasonable configuration, that avoids Processing by the objected-to Sub-processor without unreasonably burdening you. If we cannot do so within a reasonable period, you may, as your sole and exclusive remedy, terminate the affected part of the Service that cannot be provided without the Sub-processor by giving written notice, and you will receive a pro-rata refund of any prepaid fees for the terminated portion covering the period after termination.
7. Assistance to You
7.1. Data Subject Requests. Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, to fulfil your obligation to respond to Data Subject Requests. The Service provides self-service tooling that enables your account owner to export and to delete account data directly from Settings, and to correct end-customer, staff, booking, and related records directly in the product; it also lets you record an end customer's marketing opt-out, and every marketing email carries a one-click unsubscribe link. Where a Data Subject Request reaches us directly in respect of Tenant Personal Data, we will, unless legally prohibited, promptly inform you and direct the Data Subject to you, and will not respond to the request ourselves except on your documented instructions or as required by law.
7.2. Compliance assistance. Taking into account the nature of Processing and the information available to us, we will provide reasonable assistance to help you comply with your obligations under Articles 32 to 36 of the GDPR (and equivalent provisions of other Applicable Data Protection Law), namely: security of Processing; notification of Personal Data Breaches to Supervisory Authorities and Data Subjects; data protection impact assessments; and prior consultation with Supervisory Authorities. We may make available documentation about the Service's security and Processing to support these activities.
7.3. Cost. Assistance under this Section that goes materially beyond the self-service tooling and standard documentation we make available, or that recurs frequently, may be provided on a reasonable, cost-reimbursement basis, save where Applicable Data Protection Law requires otherwise.
8. Personal Data Breaches
8.1. We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Tenant Personal Data. The notification will, to the extent then known and available to us, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Where we cannot provide all of this information at once, we may provide it in phases without undue further delay.
8.2. We will take reasonable steps to mitigate the effects of, and to minimise any damage resulting from, a Personal Data Breach, and will provide you with information reasonably available to us to enable you to meet your own obligations to notify Supervisory Authorities and Data Subjects.
8.3. Our notification of, or response to, a Personal Data Breach under this Section is not an acknowledgement of fault or liability.
9. International Transfers
9.1. You authorise us, and our Sub-processors, to transfer and Process Tenant Personal Data outside the country in which it was collected, including to and from the EEA, the United Kingdom, Switzerland, and the United States, where necessary to provide the Service.
9.2. Where a transfer of Tenant Personal Data subject to European Data Protection Law, UK Data Protection Law, or Swiss Data Protection Law is made to a country that has not been the subject of an adequacy decision, we will ensure that an appropriate transfer mechanism is in place, including, as applicable, the Standard Contractual Clauses. For such transfers:
(a) the EU SCCs are incorporated into and form part of this DPA by reference, with Module Two (controller-to-processor) applying as between you and us, and Module Three (processor-to-processor) applying as between us and our Sub-processors;
(b) the UK Addendum applies to transfers subject to UK Data Protection Law, and the EU SCCs are read with the amendments required by the Swiss Federal Data Protection and Information Commissioner (including treating references to the GDPR as references to Swiss Data Protection Law and the competent authority as the FDPIC) for transfers subject to Swiss Data Protection Law;
(c) for the purposes of the SCCs: the data exporter is you (and the relevant controllers on whose behalf you act) and the data importer is us; in respect of onward transfers to our Sub-processors, we act as data exporter and the Sub-processor as data importer; the clause-level options, optional language, and the docking clause are deemed selected as set out in this DPA and the Agreement; for Clause 9, Option 2 (general written authorisation) applies with the notice period set out in Section 6.4; for Clause 11, the optional independent dispute-resolution body does not apply; for Clauses 17 and 18, the governing law and forum are as specified at Spain to the extent the SCCs permit a choice; Annex I and Annex II to this DPA populate the corresponding annexes of the SCCs; and any blanks or options not addressed here are completed so as to give the broadest protection to Data Subjects consistent with the SCCs.
9.3. If the chosen transfer mechanism is invalidated, superseded, or amended, we will, without undue delay, implement an alternative lawful transfer mechanism and take additional safeguards as required by Applicable Data Protection Law.
10. Audits and Information
10.1. We will make available to you all information reasonably necessary to demonstrate compliance with this DPA and with the obligations of a Processor under Applicable Data Protection Law, and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you.
10.2. To the extent permitted by Applicable Data Protection Law, you agree that you will exercise the audit right under Section 10.1 primarily by reviewing the documentation, security descriptions, and other information we make available. Where this is insufficient to demonstrate compliance, or where a Supervisory Authority requires it, you may conduct, or mandate an independent auditor to conduct, an inspection, subject to: (a) reasonable prior written notice of at least thirty (30) days, except where a Personal Data Breach or a regulator's requirement makes shorter notice necessary; (b) being conducted during normal business hours, no more than once in any twelve-month period (unless required by a Supervisory Authority or following a Personal Data Breach); (c) the auditor being bound by appropriate confidentiality obligations and not being a competitor of ours; and (d) reasonable measures to avoid disruption to our operations and to protect the security, confidentiality, and Personal Data of our other customers. You bear your own and the auditor's costs.
11. Deletion or Return of Tenant Personal Data
11.1. On termination or expiry of the Agreement, or otherwise on your written request, we will, at your choice, delete or return the Tenant Personal Data we Process on your behalf, and delete existing copies, unless applicable law requires continued storage.
11.2. Self-service. The account owner may, at any time, export account data as a downloadable bundle and may request deletion of the account from Settings. Deletion is subject to re-authentication and owner-only controls. On a verified deletion request, we cancel the related subscription, mark the account for deletion, and revoke active sessions; a scheduled process then hard-deletes the account's data after a fixed wind-down period (currently thirty (30) days), after which the data is permanently removed from the live systems.
11.3. Operational and security deletion. Independent of account deletion, the Service applies routine data-minimisation processes that delete time-bounded operational records on their normal cycle — for example, raw inbound webhook payloads and expired one-time tokens and verification records are deleted on a short rolling schedule, and abandoned, never-charged checkouts are released and removed.
11.4. Backups. Backups containing Tenant Personal Data are retained on a rolling rotation and are overwritten in the ordinary course on their normal rotation cycle following deletion. Until a backup is overwritten, the data within it remains subject to the security and confidentiality terms of this DPA and is not restored to live systems except as part of disaster recovery.
11.5. Certain limited records (such as audit-log entries recording that a deletion occurred, and records we are required to retain for legal, tax, accounting, or security purposes) may be retained for the period required, after which they are deleted or anonymised.
12. Liability and Indemnity
12.1. Each party's liability arising out of or related to this DPA, whether in contract, tort, or any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together.
12.2. Nothing in this DPA or the Agreement limits or excludes either party's liability to a Data Subject or a Supervisory Authority to the extent such limitation or exclusion is not permitted by Applicable Data Protection Law, including under the SCCs.
12.3. You are responsible for, and will indemnify us against, claims, losses, and liabilities arising from your failure to comply with your obligations as a Controller under this DPA and Applicable Data Protection Law, including your failure to establish a lawful basis or provide required notices, and your entry of prohibited data contrary to Section 3.5, except to the extent caused by our breach of this DPA.
13. General
13.1. Order of precedence. This DPA forms part of the Agreement. In the event of a conflict between this DPA and any other part of the Agreement with respect to the Processing of Tenant Personal Data, this DPA prevails. Where the SCCs apply and conflict with this DPA, the SCCs prevail with respect to the transfers they govern. Matters not addressed in this DPA are governed by the Privacy Policy and the Agreement.
13.2. Changes. We may update this DPA from time to time to reflect changes in the Service, our Sub-processors, or Applicable Data Protection Law. We will post the updated version with a new "Last updated" date and, where the change is material, provide reasonable notice through the Service or by email. Your continued use of the Service after the update takes effect constitutes acceptance, except where additional consent is required by law.
13.3. Governing law and jurisdiction. This DPA is governed by, and construed in accordance with, the laws of Spain, and the parties submit to the exclusive jurisdiction of its courts, except to the extent Applicable Data Protection Law or the SCCs require otherwise.
13.4. Severability. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions continue in full force, and the invalid provision is replaced by a valid provision that most closely reflects the original intent.
---
Annex I — Description of the Processing
A. Parties
- Data exporter (Controller): You, the Customer, being the business that has entered into the Agreement and that uses the Service to manage its end customers. Your identity and contact details are those associated with your Alovibe account.
- Data importer (Processor): NEXGEN SKYLINEX, S.L., of Paseo Virgen del Puerto 51, 28005 Madrid, Spain, operator of the Alovibe platform. Contact: privacy@alovibe.com.
B. Roles
The Customer is the Controller and Alovibe is the Processor of the Tenant Personal Data described in this Annex. Where Tenant Personal Data is transferred internationally, the Customer is the data exporter and Alovibe is the data importer for the purposes of the Standard Contractual Clauses.
C. Subject matter and duration of the Processing
The subject matter is the provision of the Alovibe service: a multi-tenant AI booking, CRM, and commerce platform that receives and sends messages across connected channels, manages services, staff, and availability, takes and manages bookings, processes commerce and payment metadata, sends communications, and powers the Alo assistant and web-voice features where enabled. The Processing continues for the duration of the Agreement, plus the wind-down and backup-rotation periods described in Section 11.
D. Nature and purpose of the Processing
Processing is carried out by automated means in order to operate, provide, secure, and support the Service on your instructions, including: receiving, storing, generating, and sending messages and attachments; recording and managing customer, staff, booking, and commerce data; generating AI-assisted replies and, where enabled, voice interactions; sending transactional and marketing communications; processing payment and order metadata; and maintaining the security, integrity, and availability of the Service.
E. Categories of Data Subjects
- Your end customers and contacts (including prospective customers).
- Your staff and team members whose details you record in the Service.
- Recipients of communications you send (including gift-card recipients and campaign audiences).
- Individuals who interact with your connected channels or your booking and storefront pages.
F. Categories of Personal Data
- Identity and contact data: names; business names; phone numbers; email addresses; messaging handles and per-channel external identifiers and display names (WhatsApp, Telegram, Instagram, Facebook); preferred channel and language; tags and free-text notes; and customer history indicators.
- Address and delivery data: recipient name, phone, street, city, state, postal code, and country for shipping and delivery.
- Conversation data: full inbound and outbound message content across all channels (WhatsApp, Telegram, Instagram, Facebook, website/web-chat, and voice), including direction, author, language, and channel message identifiers; message attachments (customer-provided photos and documents, and owner-reply images), with their filenames, types, and sizes.
- AI and voice metadata: per-reply model and token usage, duration, reply language, and a record of the tools the assistant invoked with their inputs and outputs; assistant cross-turn state; and, for the web-voice feature, an anonymous visitor identifier, conversation linkage, and usage/duration metering.
- Booking and scheduling data: appointment customer, staff, resource, times, party size, price, paid status, notes, recurrence, and connected-calendar event identifiers; and verification records used to confirm a customer controls an email or phone (email, phone, hashed one-time codes, expiry, and attempts).
- Payment, order, and commerce data: Stripe customer, subscription, Connect, payment-intent, and checkout-session identifiers; deposit, balance, and no-show amounts and paid flags; product orders, line items, quantities, totals, discount codes, gift cards (including recipient name and email, sender name, and message for online gift cards), loyalty cards and stamps, and refunds with reasons and internal notes. Full payment card numbers are not Processed by us.
- CRM and growth data: memberships, service packages, waitlist entries (with preference and channel), reviews (rating and text), campaign audiences, and marketing opt-out status.
- Business knowledge-base content you provide, which may contain Personal Data in free text.
- Connected-channel credentials and OAuth tokens for the providers you connect (stored encrypted at rest).
- Notification and technical data: web-push subscription endpoints and keys and user-agent strings; IP addresses, device and browser information, server and audit logs, and system alerts; and raw inbound webhook payloads retained for a short period for crash recovery (which may contain message text, phone numbers, and names).
- Plan-interest capture: email, plan, and locale submitted to register interest in features.
G. Special Category Data
The Service is not designed to Process Special Category Data, and you are instructed not to submit it except where strictly necessary (see Section 3.5). Any Special Category Data that nonetheless appears in free-text fields, notes, attachments, or knowledge-base content is Processed only as an incidental part of providing the Service, under your responsibility and instructions, with the safeguards in Annex II.
H. Frequency of the Processing
Continuous, for the duration of the Agreement.
I. Sub-processors
As listed in Section 6.2, which forms part of this Annex.
J. Competent Supervisory Authority
The competent Supervisory Authority for the purposes of the SCCs is determined in accordance with Clause 13 of the EU SCCs and Applicable Data Protection Law, by reference to Spain and the location of the relevant Data Subjects.
---
Annex II — Technical and Organisational Security Measures
We implement and maintain the following technical and organisational measures to protect Tenant Personal Data, appropriate to the risk in accordance with Article 32 of the GDPR. We may update these measures provided the overall level of security is not materially reduced.
1. Encryption of secrets at rest. Sensitive secrets are encrypted at rest using AES-256-GCM, including connected-channel credentials and OAuth refresh tokens, the platform AI provider key, two-factor authentication secrets, and other platform secrets.
2. Encryption in transit. All connections to the Service are served over TLS, with certificates issued and renewed automatically, HTTP Strict Transport Security (one-year max-age, including subdomains), and security headers including X-Content-Type-Options, X-Frame-Options, a strict Referrer-Policy, and a per-route Permissions-Policy that restricts the microphone to the booking page only.
3. Password and credential protection. Account passwords are hashed with bcrypt (work factor 12). One-time codes and tokens (login links, password reset, verification, order-portal, and loyalty codes) are stored only as SHA-256 hashes — the raw value is never persisted — are generated with a cryptographically secure random source, and are compared in constant time.
4. Session security. Sessions use an opaque, randomly generated identifier stored in an HTTP-only, SameSite=Lax, Secure (in production) cookie, backed by a cache store with an expiry (30 days by default, or shorter when "remember me" is not selected) and a sliding-expiry, per-user revocation index. Sessions are revoked on logout, password change, and account deletion.
5. Access control and tenant isolation. The Service enforces strict multi-tenant isolation: every data query is tenant-scoped, reinforced at the database layer by composite tenant foreign keys (a child record's tenant must match its parent's) and partial unique indexes that prevent cross-tenant access to channel assets, so one business cannot access another's data. Role-based access control (owner, manager, front-desk) is enforced server-side, with an optional platform-administration IP allowlist and re-authentication required before irreversible or sensitive actions.
6. Integrity and abuse protection. Inbound webhooks are verified by HMAC signature (Meta, Stripe, Telegram), and the Service applies rate limiting and a deterministic abuse-cooldown ("spam-shield") ladder to protect against floods and misuse.
7. Confidentiality. Personnel authorised to Process Tenant Personal Data are bound by confidentiality obligations and access data on a least-privilege, need-to-know basis.
8. Backups and resilience. Daily database backups are produced in a compressed format, verified for restorability before being counted as valid, and rotated on a count-based schedule that retains the most recent verified backups. Where configured, encrypted backups are uploaded off-host to an operator-controlled location, and backup failures raise a loud alert.
9. Logging, monitoring, and alerting. The Service maintains audit logs of significant actions and a system-alerting facility, exposes a deep health endpoint for external monitoring, and supports optional error and exception monitoring. These support the detection of, and response to, security and availability events.
10. Data minimisation and retention controls. Routine processes delete time-bounded operational data on a short rolling schedule (raw webhook payloads, expired tokens and verification records, and abandoned checkouts) and a scheduled purge permanently deletes account data after the wind-down period, as described in Section 11.
11. Restoration and availability. The measures above — verified backups, monitoring, health checks, and the ability to restore from backup — support the restoration of availability and access to Personal Data in a timely manner in the event of a physical or technical incident.
---
Contact
For questions about this DPA, to exercise audit rights, or to raise a data protection matter, contact us at privacy@alovibe.com or support@alovibe.com, addressed to the Data Protection contact at NEXGEN SKYLINEX, S.L., Paseo Virgen del Puerto 51, 28005 Madrid, Spain.