Data Processing Addendum
This Data Processing Addendum (“DPA”) is a template addendum for business customers that use VIALINKER AI as a processor or service provider for personal data processed through VIALINKER software, widgets, workflows, integrations or related services.
1. Parties and roles
This DPA applies between Romas Navasinskas, individual entrepreneur, doing business as VIALINKER AI, and the business customer using the service. The customer is the Controller, Business or equivalent party determining purposes and means of processing customer personal data. VIALINKER is the Processor, Service Provider or equivalent party processing customer personal data on behalf of the customer. VIALINKER may act as Controller for its own business, billing, account, security and website data.
2. Subject matter, duration and data
The subject matter is the provision of AI-assisted communication, sales, lead qualification, follow-up, reactivation, widget and related SaaS services. Processing lasts for the duration of the customer relationship and any legally or operationally required retention period. Data subjects may include website visitors, potential patients, leads, customers, existing patients, customer administrators and staff. Data may include names, phone numbers, emails, messaging handles, chat messages, service interests, language, lead status, qualification data, follow-up status, CRM notes, technical identifiers and voluntarily submitted treatment-related information.
3. Special categories / health-related data
The service is not intended to operate as an Electronic Health Record, diagnostic system, medical device or long-term medical record repository. If health-related information is entered, the customer is responsible for lawful basis, required notices, consents, professional review, retention rules and healthcare compliance. VIALINKER processes such data only to provide the contracted communication and routing service.
4. Instructions and confidentiality
VIALINKER will process customer personal data only on documented instructions from the customer, including instructions in the agreement, service configuration, onboarding settings, support requests and lawful use of the service, unless required by law. VIALINKER will ensure that persons authorized to process customer personal data are subject to confidentiality obligations.
5. Security
VIALINKER will maintain reasonable technical and organizational measures designed to protect customer personal data, including access controls, hosted infrastructure security, logging, reasonable credential controls, limited access based on operational need and measures designed to reduce unauthorized access, loss, alteration or disclosure.
6. Subprocessors and transfers
The customer authorizes VIALINKER to use subprocessors necessary to provide the service. Current categories and examples may be listed at /subprocessors.html. Customer personal data may be transferred to or accessed from jurisdictions outside the customer’s country, including Ukraine, the EEA, the UK or the US. Where required, the parties will rely on appropriate transfer safeguards such as Standard Contractual Clauses, UK transfer mechanisms, contractual safeguards or other legally recognized mechanisms.
7. Data subject requests and compliance assistance
Taking into account the nature of processing, VIALINKER will provide reasonable assistance to the customer for responding to data subject requests, security obligations, breach notifications, data protection impact assessments and supervisory authority consultations, to the extent required by applicable law and reasonably available to VIALINKER.
8. Breach notification
VIALINKER will notify the customer without undue delay after becoming aware of a confirmed personal data breach affecting customer personal data, as required by applicable law. Notification will include available information reasonably necessary for the customer to assess and respond.
9. Deletion, return, audits and liability
Upon termination, VIALINKER will delete or return customer personal data within a reasonable period unless retention is required by law, security, backup, dispute resolution, fraud prevention or legitimate business needs. VIALINKER will make available reasonable information necessary to demonstrate compliance with this DPA. Any audit must be reasonable, limited, pre-scheduled, non-disruptive and confidential. Liability under this DPA is subject to the limitation of liability in the applicable Terms or customer agreement unless mandatory law requires otherwise.