Data Processing Addendum
Effective 3 October 2026
TL;DR
- 1.The Customer controls the purpose. Tobira processes Customer Personal Data on documented instructions.
- 2.This Addendum applies when agreed. The Agreement identifies the Customer, enabled services and additional processing terms.
- 3.Providers are specific to the service. Optional integrations are not automatically authorised.
- 4.Return, deletion and safeguards follow the Agreement and law. Session expiry is not permanent erasure.
1. Parties, scope and precedence
This Addendum is between the customer identified in the applicable Tobira order or service agreement ("Customer") and HORIZONTEXUBERANTE, UNIPESSOAL LDA, registered in Portugal ("Tobira"). Tobira privacy contact: [email protected]. It supplements the applicable order and Terms of Service (the "Agreement"). Customer details and authorised contacts are those recorded in the Agreement.
For Customer Personal Data processed to provide the configured site-agent service, Customer is controller and Tobira is processor. If Customer is itself a processor, Customer confirms authority from its controller and Tobira acts as subprocessor on the same documented scope. Roles follow actual purposes. Tobira's separate controller processing for its own account administration, billing, legal obligations and proportionate platform security is covered by its Privacy Policy rather than reclassified by this Addendum.
The paid site-agent offer includes this Addendum when agreed. Free service does not remove the need for a processing agreement where the relationship requires one. Customer shall not assume a price plan itself executes this Addendum.
This Addendum prevails over conflicting provisions of the Agreement concerning Customer Personal Data. Applicable mandatory law and any valid transfer clauses prevail over conflicting terms here. Liability provisions cannot restrict the independent rights of data subjects or regulators.
2. Processing instructions and Customer responsibilities
The parties document the permitted processing in Annex A, the order, configured features and authorised written instructions. Tobira shall use Customer Personal Data only to provide those services on those instructions, including instructions about transfers, unless law requires otherwise. Where legally allowed, Tobira shall notify Customer before legally required additional processing. Tobira shall immediately inform Customer if an instruction appears to breach applicable data-protection law and suspend the affected instruction while it is resolved.
Customer determines the purposes, lawful bases, notices, retention choices and authorised users. Customer shall obtain any required consent, maintain accurate notices, and ensure it may supply the data and instruct the processing. Special-category data requires an expressly documented scope, applicable legal condition and safeguards; enabling a file/chat feature is not blanket authorisation to process such data.
Tobira shall not use Customer Personal Data for advertising, resale or training its own foundation models. Provider training and retention restrictions shall be specified in the approved arrangements for each enabled service and route. An optional provider or connection is not authorised merely because the platform supports it.
3. Confidentiality, access and security
Tobira shall limit access to authorised persons who need it to perform the agreed service and are bound by appropriate confidentiality obligations. It shall implement and maintain risk-appropriate technical and organisational measures, with the agreed baseline in Annex B. Customer remains responsible for its users, content and selected integrations, without reducing Tobira's processor obligations.
Changes to security measures must not materially reduce the agreed protection. Tobira shall make relevant information available to Customer and address identified material shortcomings. Annex B describes the baseline and service-specific measures; it does not represent a certification or encryption of every field.
4. Subprocessors and Customer-selected recipients
Customer gives general written authorisation for the subprocessors specifically identified for its service under Annex C for its enabled services. An optional provider listed as a candidate is not automatically authorised. Before use, Tobira shall verify appropriate written obligations, security and transfer arrangements. Subprocessor obligations shall provide the relevant protection required of Tobira, and Tobira remains responsible to Customer for performance of those obligations.
Tobira shall notify Customer in advance of adding or replacing a subprocessor, describing its function and processing location and allowing a reasonable opportunity to object on data-protection grounds. Any specific notice period is set out in the Agreement. The parties shall seek a suitable alternative; if the concern cannot be resolved, the affected processing shall not proceed and Customer may terminate that part of the service with a remedy for unused prepaid service under the Agreement and applicable law. Necessary emergency changes require prompt notice and a documented protective response.
Customer-selected Cal.com accounts, notification destinations, webhooks, CRMs or own-AI services may be Customer's own processors or independent recipients. Their roles must be recorded, not assumed. Such selection does not exempt Tobira from its duties when Tobira actually appoints a provider as subprocessor. The visitor's own external assistant is generally a visitor-authorised recipient, not automatically Tobira's subprocessor.
5. Data-subject requests and regulatory assistance
Tobira shall assist Customer, using appropriate technical and organisational measures, with access, correction, deletion, restriction, objection and portability requests. If Tobira receives a request about Customer-controlled data, it shall promptly notify Customer and coordinate handling, unless law requires a direct response. It shall not disclose another person's data while verifying a request.
Tobira shall provide information and reasonable assistance for Customer's security obligations, breach response, impact assessments and regulatory consultations, taking account of the processing and available information. Costs for exceptional additional work may be agreed in advance; charges or commercial limits shall not be used to obstruct mandatory assistance.
6. Personal data breaches
Tobira shall notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, including available facts even if investigation continues.
The notice shall provide available information about the incident, affected data/individuals, likely effects, mitigation and a contact for coordination. Missing information may follow in stages. Tobira shall investigate, contain and remediate the incident and preserve appropriate evidence. Customer determines its own regulator and individual notices; Tobira's notice is not delayed until every fact is established and is not itself an admission of liability.
7. Return, retention and deletion
Processing continues for the service term and the agreed return/deletion period, subject to lawful retention. At Customer's choice, Tobira shall return Customer Personal Data in an available commonly used format or delete it after the affected service ends, and delete remaining copies unless law requires retention. If both return and deletion are requested, deletion follows return. Legally retained records shall be identified, restricted to the retention purpose and deleted when no longer required.
The Agreement and documented instructions specify the return and deletion arrangements, including any agreed periods for active records and residual backup copies. Tobira shall comply with applicable deadlines and valid data-subject instructions. Session expiry or a restoration window does not establish a universal deletion deadline.
Backups awaiting expiry shall remain protected and unused except for necessary recovery; recovered copies shall remain subject to the original deletion instruction. Tobira shall require relevant subprocessors to apply deletion/return terms and confirm completion to Customer on request. Data held independently by a Customer-selected recipient follows that recipient's documented arrangement.
Session expiry, subscription cancellation, soft deletion and permanent erasure are different. Current seven-day session validity does not establish seven-day erasure of transcripts, saved visitor accounts or leads. The 30-day agent restoration window is not proof of complete deletion after that window. Annex A records these implementation limits.
8. Audits and information
Tobira shall provide information necessary to demonstrate its obligations and allow and contribute to Customer audits, including inspections by Customer or its mandated auditor. Parties should first use relevant documentation and available independent reports where sufficient, without replacing the right to inspect when necessary.
Audits shall protect other customers' data, security secrets and confidentiality and use reasonable coordination. Routine frequency, notice and reasonable cost arrangements may be agreed; they shall not bar justified incident/regulator audits or statutory rights. Tobira shall address substantiated material findings. No SOC 2 or ISO certification is represented by this Addendum.
9. International transfers
Customer Personal Data is stored and processed in the United States: the application and PostgreSQL database are hosted on Railway in region us-west2. Files and attachments use Cloudflare R2 with region auto; this does not guarantee a fixed country or EU-only storage. Other recipient countries are listed in Annex C. Transfers from the EEA rely on the European Commission's Standard Contractual Clauses (SCCs) and, where the provider participates and the transfer is covered, the EU-US Data Privacy Framework. The service-specific register must identify the applicable mechanism for each relevant recipient. Tobira shall not perform a restricted transfer without a lawful basis and necessary safeguards. Where standard contractual clauses are needed, execute the correct modules and complete their parties, description, security and competent-authority annexes, with transfer assessments and supplementary measures where required. An adequacy or Data Privacy Framework basis may be used only when it actually covers the recipient and transfer.
This Addendum does not itself execute transfer clauses or establish EU-only hosting or a universal transfer basis. Any applicable transfer clauses or other local safeguards shall be agreed before restricted processing begins.
10. Duration, execution and governing law
This Addendum takes effect when validly agreed and continues for as long as Tobira processes Customer Personal Data under the Agreement. Return/deletion, confidentiality, assistance and other necessary obligations survive termination. Portuguese law and the Agreement's valid dispute provisions apply, subject to mandatory data-protection law and superior transfer clauses.
Acceptance is recorded in the applicable Agreement or another documented acceptance between authorised representatives. That record identifies the Customer, enabled features, service-specific provider inventory and any additional agreed processing terms.
Annex A. Processing description and retention
| Element | Agreed description |
|---|---|
| Subject matter | Configured site-agent chat, company-scoped visitor accounts, relevant knowledge, leads, bookings and enabled integrations |
| Duration | Agreement term plus the agreed return and deletion period, subject to applicable legal duties |
| Nature of processing | Receipt, storage, retrieval, AI inference, transcription/extraction, summarisation, routing, authorised disclosure, export and deletion |
| Purposes | Answer visitor questions; maintain their company-scoped conversations and preferences; deliver requested leads/support; organise bookings; apply purchased access and usage; secure the service |
| Individuals | Company website visitors and customers, prospective customers, Company contacts/staff, and persons whose data Customer lawfully includes in knowledge or messages |
| Data categories | Identity/contact and sign-in data, message/transcript content, files and extracted evidence, saved visitor memory/preferences, booking/contact records, visit-source information, usage and permitted technical metadata |
| Sensitive data | Excluded from a general authorisation; document any necessary additional scope, basis and controls before processing |
| Frequency | Continuous while configured services are used; inference/routing follows enabled features |
| Customer instructions | Identify Company, agents, permitted knowledge scopes, private-chat settings, integrations, regions and retention in the order |
Service-specific retention instructions shall identify periods for visitor accounts, chats and memory; leads and bookings; knowledge documents, originals and revisions; file-derived evidence; logs; operational records; backups; and attribution copied into other services. Guest files default to a 24-hour object expiry, configurable up to seven days, with deletion attempts and retries; derived evidence has a separate lifetime. Visitor verification codes expire in five minutes; expiry does not itself erase related records. Tobira's own billing and tax records follow its controller retention duties.
Annex B. Security baseline
The following baseline applies to the relevant enabled features. Customer-specific configuration and additional measures are documented in the Agreement. These measures do not represent an independent security certification.
| Area | Baseline and scope |
|---|---|
| Content protection | AES-256-GCM protects designated messages, private profile/setup fields, memory, knowledge and integration secrets. Owner-knowledge originals are encrypted separately. Identifiers, email, public profiles and some operational/payment metadata are outside this application encryption layer. |
| File storage | Owner-knowledge originals are encrypted before object storage. Guest-file bytes rely on storage-provider protections, without additional application encryption. Cloudflare R2 provides object storage with region auto; additional measures are documented for the enabled service. |
| Tenant and account isolation | Agent/company/account access checks, knowledge-scope filtering, owner-only exclusion, visitor private-chat controls and visitor MCP keys scoped to the Company's visitor account. |
| Authentication | Owner Clerk integration; visitor passwordless email or Google sign-in; hashed visitor verification codes and MCP keys; revocation and abuse limits. |
| Transmission and integrations | Secure transport, time-limited signed file links, authenticated software access and applicable integration validation and external-request protections. A signed-link recipient can access the file until link expiry. |
| Operations | Relevant error records, transactional access/payment updates and file cleanup/retry mechanisms. Service-specific backup, recovery and retention arrangements follow the Agreement and documented instructions. |
Tobira shall maintain appropriate confidentiality and access authorisation, least-privilege access, access review and revocation, incident response contacts, vulnerability management, recovery procedures, deletion-request handling and a maintained provider and transfer inventory. These obligations do not constitute a claim of certification.
Annex C. Service-specific providers
The following list identifies infrastructure providers and recipients for the configured service, including optional integrations. The service-specific register agreed with Customer identifies the enabled providers, contracting entities, functions, processing locations, roles and transfer safeguards. Provider countries are not exclusive storage-location guarantees; global services and downstream vendors may process elsewhere. This list does not authorise every optional provider. Tobira shall identify the relevant provider and establish the required arrangements before it processes Customer Personal Data.
| Provider / recipient | Function and scope | Country / processing location |
|---|---|---|
| Railway | Application and PostgreSQL database hosting, including service records, stored content and technical logs. | United States; configured region us-west2. |
| Cloudflare | CDN, DNS and Turnstile bot protection; Cloudflare R2 object storage for uploaded guest files and encrypted owner-knowledge originals. | United States; global network. R2 region is auto, with no fixed country specified. |
| OpenAI | Agent replies through connected ChatGPT/Codex services; API speech recognition and realtime voice; configured file processing. Contract and retention terms differ by route. | United States. |
| Google Gemini | Enabled AI inference, file or audio processing, separate from Google sign-in or font loading. | United States; global services. |
| OpenRouter and selected model vendors | Requested inference context and routing metadata. Selected downstream vendors may include Anthropic, Google or DeepSeek and are identified for the enabled route. | OpenRouter: United States. Downstream vendor countries depend on the selected model. |
| Z.ai (GLM) | AI inference for enabled test or experimental routes, including the context supplied to that route. | Processing outside the EU; location depends on the enabled service. |
| Other selected AI providers | Optional providers used only when selected and specifically identified for the service, with appropriate processing and transfer arrangements. | Countries depend on the selected provider and are identified in the service-specific register. |
| Resend | Email addresses, verification codes, purchase confirmations and enabled notifications, which may include permitted lead summaries. | United States. |
| Telegram | Chat identifiers and enabled Company/owner notifications, including permitted lead or conversation summaries. | British Virgin Islands and United Arab Emirates; international infrastructure. Telegram states that UK/EEA user data is stored in the Netherlands. |
| Cal.com | Requested scheduling through the Company's connected account and owner-supplied key: attendee/contact details, appointments, booking answers and permitted source metadata. | United States; some subprocessors may process elsewhere. |
| Clerk | Owner-account identity, email and session/authentication information, separate from visitor passwordless authentication. | United States. |
| Stripe | Checkout/customer, subscription, tax, invoice, refund and payment-related data; independent compliance and fraud-prevention processing where applicable. | United States; international payment processing. |
| Google OAuth and Google Fonts | Optional visitor sign-in and remote fonts on Chinese/Japanese landing pages, separate from Gemini inference. | United States; global services. |
| Jina Reader | Public URLs/content where this website-fetching integration is used during agent setup. | Germany; international processing under the applicable provider terms. |
Separate-role recipients: Clerk primarily serves owner identity; Stripe processes purchases/payment administration and may have independent purposes; optional Google sign-in and Google Fonts serve different activities from Gemini; Company webhooks/CRMs and visitor-chosen assistants may be independently selected recipients. Document the processing role for each relevant activity. Include any of these in the subprocessor register only to the extent Tobira appoints it to process this Customer's data; do not omit it from the overall disclosure merely because it has another role.