Last updated: 8 August 2026
Effective Date: 8 August 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Gabriel Petrozziello, an individual entrepreneur (empresario individual / autónomo) established in Spain and trading as EbaSaiyo ("EbaSaiyo"), and the customer that has accepted the EbaSaiyo Terms of Service or an applicable Order ("Customer").
This DPA applies where EbaSaiyo processes Personal Data contained in Customer Content on behalf of Customer in connection with the Service.
For such processing:
For account administration, billing, security, service analytics, legal compliance, and EbaSaiyo's own business operations, EbaSaiyo may act as an independent Controller as described in the Privacy Policy; those activities are outside the processor scope of this DPA.
Terms such as "Controller", "Processor", "Personal Data", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in Regulation (EU) 2016/679 (GDPR) where applicable.
EbaSaiyo will process Personal Data only on documented instructions from Customer, including instructions contained in the agreement, Customer configuration, user actions, API calls, and enabled AI Employee settings, unless EbaSaiyo is required to process the data by applicable law.
If applicable law requires processing outside Customer instructions, EbaSaiyo will inform Customer before processing unless legally prohibited from doing so.
EbaSaiyo will promptly inform Customer if, in EbaSaiyo's reasonable opinion, an instruction infringes applicable data-protection law, without assuming Customer's legal responsibilities as Controller.
EbaSaiyo processes Personal Data to provide the Service, which may include:
Processing continues for the duration of the Customer's use of the Service and for any limited retention period required for deletion, backup cycling, security, or legal obligations.
Depending on Customer use, Data Subjects may include:
Depending on Customer use, Personal Data may include:
Customer may submit special-category data only where Customer has a lawful basis and has determined that use of EbaSaiyo is appropriate for that data.
EbaSaiyo will ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations and access the data only as necessary for their duties.
EbaSaiyo will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Measures may include, as appropriate to the Service:
A more detailed description appears in Annex II and the Security & Trust Center. EbaSaiyo may update safeguards as technology evolves, provided the overall level of protection is not materially reduced.
Customer gives EbaSaiyo general authorization to engage subprocessors to process Customer Personal Data.
EbaSaiyo will:
EbaSaiyo will provide reasonable notice of a new subprocessor where required by GDPR Article 28. Customer may object on reasonable data-protection grounds within the stated notice period. The parties will work in good faith to address the objection. If no reasonable alternative is available, either party may terminate the affected Service component subject to the agreement and applicable law.
Taking into account the nature of processing, EbaSaiyo will provide reasonable assistance to Customer through appropriate technical and organizational measures, insofar as possible, to enable Customer to respond to requests from Data Subjects exercising rights under applicable data-protection law.
If EbaSaiyo receives a request directly relating to Customer Content for which Customer is Controller, EbaSaiyo will generally direct the requester to Customer and will not independently respond on the merits unless legally required or authorized by Customer.
Taking into account the nature of processing and information available to EbaSaiyo, EbaSaiyo will provide reasonable assistance regarding Customer's obligations under GDPR Articles 32-36 where applicable, including security, breach response, data-protection impact assessments, and prior consultation.
Customer remains responsible for determining whether a DPIA or other assessment is required for its particular deployment, including its use of autonomous AI communications.
EbaSaiyo will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
The notice will include information reasonably available to EbaSaiyo that Customer needs to comply with applicable breach-notification obligations, such as:
EbaSaiyo's notification of an incident is not an admission of fault or liability.
Upon termination or at Customer's documented request, EbaSaiyo will delete or return Customer Personal Data within the scope of the Service, unless retention is required by law.
Deletion from backups may occur according to normal backup lifecycle schedules, provided retained backup data remains protected and is not restored for ordinary business use except disaster recovery or legal necessity.
Specific self-service export or deletion functionality may depend on the applicable plan and product feature set.
EbaSaiyo will make available information reasonably necessary to demonstrate compliance with this DPA.
Where Customer reasonably requires additional verification, EbaSaiyo may provide relevant security documentation, third-party audit reports if available, questionnaires, or other evidence before agreeing to an on-site audit.
If an on-site or bespoke audit is legally required and cannot reasonably be satisfied through existing information, the parties will agree on scope, timing, confidentiality, and cost allocation. Audits must not compromise other customers' confidentiality or EbaSaiyo's security.
Customer authorizes EbaSaiyo and its authorized subprocessors to transfer Customer Personal Data internationally as necessary to provide the Service, provided appropriate safeguards are used where required.
Where GDPR Chapter V applies and data is transferred to a recipient in a country without an applicable adequacy decision, the parties agree to use a lawful transfer mechanism, which may include the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("EU SCCs").
Where the EU SCCs are required between Customer and EbaSaiyo, the parties intend that:
Where the parties rely on the EU SCCs, Clause 17 and Clause 18 elections will follow the Customer's establishment and the SCC requirements applicable to that transfer, unless otherwise agreed in writing.
Where UK restricted-transfer rules apply, the parties will use an appropriate UK transfer mechanism, such as the UK International Data Transfer Addendum to the EU SCCs, where required.
EbaSaiyo will use supplementary technical, contractual, or organizational measures where reasonably appropriate based on transfer risk and applicable law.
Where Customer enables AI features, relevant Customer Content may be sent to an authorized AI service provider as a subprocessor.
EbaSaiyo will configure business/API services so that Customer Content is not intentionally opted into general model training unless Customer has expressly agreed and the arrangement complies with applicable law and contract.
Current provider-specific data retention and abuse-monitoring practices remain subject to the provider's terms and EbaSaiyo's contractual configuration.
Google and Microsoft may process data in their own capacity when Customer uses their underlying email services and authorizes EbaSaiyo through OAuth. EbaSaiyo's role is limited to processing data retrieved from or submitted to those platforms under Customer's instructions and the permissions granted.
Customer remains responsible for its contractual relationship with its email provider.
Liability arising under this DPA is subject to the limitation-of-liability provisions in the Terms or applicable Order, except to the extent applicable data-protection law prohibits such limitation.
If this DPA conflicts with the Terms regarding processing of Customer Personal Data, this DPA controls for that subject matter. The EU SCCs or other mandatory transfer terms control where they expressly require a different result.
Data exporter: Customer identified in the EbaSaiyo Workspace, Order, or account.
Role: Controller or Processor, as applicable.
Data importer: Gabriel Petrozziello, an individual entrepreneur (empresario individual / autónomo) established in Spain and trading as EbaSaiyo, NIF Y9325381-E, Calle Encarna Albarracin, 6, 46025 Valencia, Spain.
Role: Processor or Subprocessor, as applicable.
Subject matter: Provision of EbaSaiyo AI Employee SaaS functionality.
Duration: Subscription term plus limited deletion, backup, security, and legal-retention periods.
Nature of processing: Collection, retrieval, transmission, organization, storage, analysis, generation, classification, display, modification at Customer instruction, and deletion.
Purpose: Email-support workflows, AI-assisted drafting, Customer-configured automation, workspace operation, troubleshooting, security, and related Service functions.
Data subjects: As described in Section 4.
Personal data: As described in Section 5.
Sensitive data: Not required by default; may be incidentally included by Customer. Customer is responsible for lawful use and minimization.
Frequency: Continuous or event-driven during Customer use.
Retention: According to Section 12, product settings, and documented retention schedule.
The following describes EbaSaiyo's baseline technical and organizational measures:
See the current EbaSaiyo Subprocessors page at /legal/subprocessors. EbaSaiyo will keep that list current as providers change.