EbaSaiyoBack to EbaSaiyo

Data Processing Addendum (DPA)

Last updated: 8 August 2026

Effective Date: 8 August 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Gabriel Petrozziello, an individual entrepreneur (empresario individual / autónomo) established in Spain and trading as EbaSaiyo ("EbaSaiyo"), and the customer that has accepted the EbaSaiyo Terms of Service or an applicable Order ("Customer").

1. Scope and Roles

This DPA applies where EbaSaiyo processes Personal Data contained in Customer Content on behalf of Customer in connection with the Service.

For such processing:

  • Customer is the Controller (or a Processor acting on behalf of another Controller); and
  • EbaSaiyo is the Processor (or Subprocessor, as applicable).

For account administration, billing, security, service analytics, legal compliance, and EbaSaiyo's own business operations, EbaSaiyo may act as an independent Controller as described in the Privacy Policy; those activities are outside the processor scope of this DPA.

Terms such as "Controller", "Processor", "Personal Data", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in Regulation (EU) 2016/679 (GDPR) where applicable.

2. Customer Instructions

EbaSaiyo will process Personal Data only on documented instructions from Customer, including instructions contained in the agreement, Customer configuration, user actions, API calls, and enabled AI Employee settings, unless EbaSaiyo is required to process the data by applicable law.

If applicable law requires processing outside Customer instructions, EbaSaiyo will inform Customer before processing unless legally prohibited from doing so.

EbaSaiyo will promptly inform Customer if, in EbaSaiyo's reasonable opinion, an instruction infringes applicable data-protection law, without assuming Customer's legal responsibilities as Controller.

3. Nature, Purpose, and Duration

EbaSaiyo processes Personal Data to provide the Service, which may include:

  • authenticating authorized users;
  • synchronizing authorized business email;
  • storing and displaying emails and threads;
  • generating AI-assisted reply drafts;
  • classifying messages;
  • evaluating configured AI rules;
  • sending Customer-authorized communications;
  • maintaining AI decision/audit information;
  • troubleshooting, securing, and supporting the Service; and
  • providing other Customer-enabled features described in the agreement.

Processing continues for the duration of the Customer's use of the Service and for any limited retention period required for deletion, backup cycling, security, or legal obligations.

4. Categories of Data Subjects

Depending on Customer use, Data Subjects may include:

  • Customer employees, contractors, administrators, and users;
  • Customer's customers and prospective customers;
  • email senders and recipients;
  • vendors and business partners;
  • support contacts; and
  • other individuals whose Personal Data is included in Customer Content.

5. Types of Personal Data

Depending on Customer use, Personal Data may include:

  • names;
  • business contact details;
  • email addresses;
  • email message content and metadata;
  • customer-support content;
  • account identifiers;
  • conversation history;
  • customer preferences or requests;
  • AI Employee instructions that contain Personal Data;
  • AI-generated drafts and decisions;
  • human edits and approvals;
  • audit and security metadata; and
  • attachments or knowledge content if enabled.

Customer may submit special-category data only where Customer has a lawful basis and has determined that use of EbaSaiyo is appropriate for that data.

6. Confidentiality

EbaSaiyo will ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations and access the data only as necessary for their duties.

7. Security Measures

EbaSaiyo will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Measures may include, as appropriate to the Service:

  • encrypted transport using industry-standard TLS;
  • encryption of sensitive integration credentials at rest;
  • authentication and access controls;
  • tenant-aware authorization and organization scoping;
  • least-privilege OAuth design where feasible;
  • server-side secret management;
  • logging and monitoring;
  • secure software-development practices;
  • vulnerability and dependency management;
  • backup and recovery measures where configured;
  • incident response procedures; and
  • periodic access review.

A more detailed description appears in Annex II and the Security & Trust Center. EbaSaiyo may update safeguards as technology evolves, provided the overall level of protection is not materially reduced.

8. Subprocessors

Customer gives EbaSaiyo general authorization to engage subprocessors to process Customer Personal Data.

EbaSaiyo will:

  • maintain a current list of subprocessors;
  • impose data-protection obligations on subprocessors that are materially consistent with EbaSaiyo's obligations under this DPA for the services they perform; and
  • remain responsible for its subprocessors' performance of those obligations to the extent required by applicable law.

EbaSaiyo will provide reasonable notice of a new subprocessor where required by GDPR Article 28. Customer may object on reasonable data-protection grounds within the stated notice period. The parties will work in good faith to address the objection. If no reasonable alternative is available, either party may terminate the affected Service component subject to the agreement and applicable law.

9. Assistance with Data Subject Requests

Taking into account the nature of processing, EbaSaiyo will provide reasonable assistance to Customer through appropriate technical and organizational measures, insofar as possible, to enable Customer to respond to requests from Data Subjects exercising rights under applicable data-protection law.

If EbaSaiyo receives a request directly relating to Customer Content for which Customer is Controller, EbaSaiyo will generally direct the requester to Customer and will not independently respond on the merits unless legally required or authorized by Customer.

10. Assistance with Compliance

Taking into account the nature of processing and information available to EbaSaiyo, EbaSaiyo will provide reasonable assistance regarding Customer's obligations under GDPR Articles 32-36 where applicable, including security, breach response, data-protection impact assessments, and prior consultation.

Customer remains responsible for determining whether a DPIA or other assessment is required for its particular deployment, including its use of autonomous AI communications.

11. Personal Data Breach

EbaSaiyo will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

The notice will include information reasonably available to EbaSaiyo that Customer needs to comply with applicable breach-notification obligations, such as:

  • the nature of the incident;
  • categories of data or Data Subjects affected, where known;
  • likely consequences, where reasonably assessable;
  • containment or remediation measures taken; and
  • a contact for follow-up.

EbaSaiyo's notification of an incident is not an admission of fault or liability.

12. Return and Deletion

Upon termination or at Customer's documented request, EbaSaiyo will delete or return Customer Personal Data within the scope of the Service, unless retention is required by law.

Deletion from backups may occur according to normal backup lifecycle schedules, provided retained backup data remains protected and is not restored for ordinary business use except disaster recovery or legal necessity.

Specific self-service export or deletion functionality may depend on the applicable plan and product feature set.

13. Audits and Information

EbaSaiyo will make available information reasonably necessary to demonstrate compliance with this DPA.

Where Customer reasonably requires additional verification, EbaSaiyo may provide relevant security documentation, third-party audit reports if available, questionnaires, or other evidence before agreeing to an on-site audit.

If an on-site or bespoke audit is legally required and cannot reasonably be satisfied through existing information, the parties will agree on scope, timing, confidentiality, and cost allocation. Audits must not compromise other customers' confidentiality or EbaSaiyo's security.

14. International Transfers

Customer authorizes EbaSaiyo and its authorized subprocessors to transfer Customer Personal Data internationally as necessary to provide the Service, provided appropriate safeguards are used where required.

14.1 EEA transfers

Where GDPR Chapter V applies and data is transferred to a recipient in a country without an applicable adequacy decision, the parties agree to use a lawful transfer mechanism, which may include the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("EU SCCs").

Where the EU SCCs are required between Customer and EbaSaiyo, the parties intend that:

  • Module Two (Controller to Processor) applies where Customer is Controller and EbaSaiyo is Processor;
  • Module Three (Processor to Processor) applies where Customer is Processor and EbaSaiyo is Subprocessor;
  • the optional docking clause may apply;
  • the competent supervisory authority and governing member-state law are determined according to the Customer/EbaSaiyo establishment and SCC requirements; and
  • Annexes I-III of this DPA provide the corresponding description of processing, security measures, and subprocessor information to the extent applicable.

Where the parties rely on the EU SCCs, Clause 17 and Clause 18 elections will follow the Customer's establishment and the SCC requirements applicable to that transfer, unless otherwise agreed in writing.

14.2 UK transfers

Where UK restricted-transfer rules apply, the parties will use an appropriate UK transfer mechanism, such as the UK International Data Transfer Addendum to the EU SCCs, where required.

14.3 Supplementary measures

EbaSaiyo will use supplementary technical, contractual, or organizational measures where reasonably appropriate based on transfer risk and applicable law.

15. AI Providers and Customer Content

Where Customer enables AI features, relevant Customer Content may be sent to an authorized AI service provider as a subprocessor.

EbaSaiyo will configure business/API services so that Customer Content is not intentionally opted into general model training unless Customer has expressly agreed and the arrangement complies with applicable law and contract.

Current provider-specific data retention and abuse-monitoring practices remain subject to the provider's terms and EbaSaiyo's contractual configuration.

16. Connected Email Providers

Google and Microsoft may process data in their own capacity when Customer uses their underlying email services and authorizes EbaSaiyo through OAuth. EbaSaiyo's role is limited to processing data retrieved from or submitted to those platforms under Customer's instructions and the permissions granted.

Customer remains responsible for its contractual relationship with its email provider.

17. Liability

Liability arising under this DPA is subject to the limitation-of-liability provisions in the Terms or applicable Order, except to the extent applicable data-protection law prohibits such limitation.

18. Precedence

If this DPA conflicts with the Terms regarding processing of Customer Personal Data, this DPA controls for that subject matter. The EU SCCs or other mandatory transfer terms control where they expressly require a different result.


A. Parties

Data exporter: Customer identified in the EbaSaiyo Workspace, Order, or account.
Role: Controller or Processor, as applicable.

Data importer: Gabriel Petrozziello, an individual entrepreneur (empresario individual / autónomo) established in Spain and trading as EbaSaiyo, NIF Y9325381-E, Calle Encarna Albarracin, 6, 46025 Valencia, Spain.
Role: Processor or Subprocessor, as applicable.

B. Processing Operations

Subject matter: Provision of EbaSaiyo AI Employee SaaS functionality.

Duration: Subscription term plus limited deletion, backup, security, and legal-retention periods.

Nature of processing: Collection, retrieval, transmission, organization, storage, analysis, generation, classification, display, modification at Customer instruction, and deletion.

Purpose: Email-support workflows, AI-assisted drafting, Customer-configured automation, workspace operation, troubleshooting, security, and related Service functions.

Data subjects: As described in Section 4.

Personal data: As described in Section 5.

Sensitive data: Not required by default; may be incidentally included by Customer. Customer is responsible for lawful use and minimization.

Frequency: Continuous or event-driven during Customer use.

Retention: According to Section 12, product settings, and documented retention schedule.


The following describes EbaSaiyo's baseline technical and organizational measures:

  1. Access control: authenticated access; organization/tenant authorization; least privilege for administrative access.
  2. Authentication: external identity/authentication provider; secure session management; MFA capabilities subject to provider/customer plan.
  3. Integration credentials: OAuth access/refresh credentials stored server-side and encrypted at rest using authenticated encryption or a managed secret/key mechanism.
  4. Transport security: HTTPS/TLS for application and API traffic.
  5. Application authorization: tenant scoping for Customer data; employee-resource scoping where applicable.
  6. Logging: operational and security logging designed to avoid unnecessary exposure of secrets; AI decision logs for applicable automation events.
  7. Secrets: production secrets stored outside source control and restricted to required runtime environments.
  8. Software development: code review/testing practices, dependency management, and separation of development/production configuration as appropriate.
  9. Incident response: procedures for investigation, containment, remediation, and Customer notice for confirmed Personal Data Breaches.
  10. Availability: cloud-hosted architecture with provider-level redundancy and backup measures as configured; no unstated uptime guarantee.
  11. Data minimization: request only integration permissions and data reasonably required for enabled functions.
  12. Deletion: logical deletion and backup expiry according to documented retention lifecycle.
  13. Subprocessor management: contractual data-protection obligations and vendor review appropriate to the provider's role.
  14. AI safety: human-configurable autonomy, business rules, escalation, audit logging, and ability to disable autonomous behavior.

See the current EbaSaiyo Subprocessors page at /legal/subprocessors. EbaSaiyo will keep that list current as providers change.