Data Processing Agreement
Effective date: October 9, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sapiura Systems LLC, a Wyoming limited liability company doing business as Pronvi ("Provider"), and the client that accepts them ("Client"). If this DPA conflicts with the Terms, this DPA controls on data protection matters. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control.
1. Definitions
Terms such as "controller", "processor", "personal data", "processing", "data subject", "personal data breach", "business", "service provider", "sell" and "share" have the meanings given in Applicable Data Protection Laws. "Applicable Data Protection Laws" means all laws that apply to the processing of Client Personal Data, including the EU GDPR, the UK GDPR, the Swiss FADP, the California Consumer Privacy Act as amended (CCPA) and other U.S. state privacy laws. "Client Personal Data" means personal data in Client Data that Provider processes on Client's behalf. "Sub-processor" means any third party Provider engages to process Client Personal Data.
2. Roles
2.1 Client is the controller (or business) of Client Personal Data, and Provider is its processor (or service provider).
2.2 Where Client itself processes Client Personal Data on behalf of another controller (for example, its own customers), Client is a processor and Provider is Client's sub-processor. Client confirms it has the authority of that controller to appoint Provider.
3. Client's instructions and obligations
3.1 Provider processes Client Personal Data only on Client's documented instructions. The Agreement, Client's configuration and use of the Platform, and any written instructions agreed by the parties are Client's complete instructions. Client authorizes Provider and its Sub-processors to de-identify or aggregate data and to provide AI features as part of the Services.
3.2 Provider will inform Client if it believes an instruction infringes Applicable Data Protection Laws.
3.3 Client is responsible for: the lawfulness of the processing; giving all notices and obtaining all consents required; the accuracy of Client Personal Data; responding to data subject requests; setting retention periods; and making any breach notifications required of Client. Client will not upload special categories of data, health data, payment card data or government ID numbers unless expressly agreed in writing.
4. Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Platform and Services under the Agreement |
| Nature and purpose | Hosting, storing, organizing, sending communications, automating marketing and sales workflows, analytics, support and AI features, as configured by Client |
| Data subjects | Client's customers, prospects, contacts, website visitors, employees and users |
| Categories of data | Contact details, communications content, appointment and transaction details, form responses, usage and device data, and any other data Client chooses to submit |
| Special categories | None, unless agreed in writing |
| Duration | For the term of the Agreement and until deletion under Section 10 |
| Frequency | Continuous |
5. Confidentiality and security
5.1 Provider ensures that persons authorized to access Client Personal Data are bound by confidentiality and access it only as needed.
5.2 Provider implements, directly and through its Sub-processors, appropriate technical and organizational measures, which may be updated over time as long as overall protection is not materially reduced, such as: encryption in transit (TLS 1.2 or higher) and at rest (AES-256); role-based access controls; two-factor authentication options; logging and monitoring; backups; regular vulnerability scans and penetration testing; and patch management.
6. Sub-processors
6.1 Client gives Provider general authorization to engage Sub-processors, including its platform technology provider and that provider's own sub-processors (hosting, communications, email, payments and AI). A current list is available to Client on request at hola@pronvi.com and is confidential.
6.2 Provider will notify Client of new Sub-processors at least 10 days before they begin processing Client Personal Data, or as soon as Provider receives notice from its technology provider if that is later. Client may object in writing within 10 days of the notice on reasonable data protection grounds. The parties will discuss in good faith. If no solution is found, Client may terminate the affected Services and receive a refund of prepaid fees for the unused period, as its sole remedy.
6.3 Provider imposes on each Sub-processor data protection obligations that give at least the same level of protection as this DPA, and remains responsible for their performance as required by Applicable Data Protection Laws.
7. Data subject requests
Provider will promptly forward to Client any request it receives from a data subject regarding Client Personal Data and will not respond except on Client's instructions or as required by law. Taking into account the nature of the processing, Provider will assist Client, mainly through the Platform's self-service features, in responding to such requests.
8. Personal data breaches
8.1 Provider will notify Client without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Client Personal Data. When the breach occurs at a Sub-processor, Provider becomes aware when the Sub-processor notifies it.
8.2 The notice will describe, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Provider will supplement it as more information becomes available.
8.3 Provider will take reasonable steps to contain and remediate the breach and will reasonably assist Client with notifications Client must make. A notice is not an admission of fault.
9. Assistance, records and audits
9.1 Provider will give Client reasonable information and assistance for data protection impact assessments and prior consultations, limited to Provider's processing.
9.2 On written request, no more than once a year (unless required by a regulator or after a breach), Provider will make available information reasonably needed to demonstrate compliance with this DPA, including Sub-processors' security documentation and certifications. If that information is not sufficient, Client may conduct an audit, including remotely, with 30 days' notice, during business hours, under confidentiality, and at Client's cost, including Provider's reasonable time at its standard rates.
10. Deletion and return
After the Agreement ends, Client may export Client Personal Data for 30 days. After that period, Provider will delete it, and instruct its Sub-processors to delete it, within 90 days, except where retention is required by law. Data in backups will be isolated and deleted on regular backup cycles.
11. International transfers
11.1 Client Personal Data may be processed in the United States and other countries where Provider or its Sub-processors operate.
11.2 For transfers of personal data protected by the GDPR from the EEA to countries without an adequacy decision, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914: Module Two (controller to processor) where Client is a controller, and Module Three (processor to processor) where Client is a processor. For those clauses: Clause 7 (docking) applies; under Clause 9(a), Option 2 (general authorization) applies with the notice period in Section 6.2; the optional wording in Clause 11 does not apply; Clauses 17 and 18 select the law and courts of Ireland; Annex I is Section 4 of this DPA and Annex II is Section 5.2. Where a Sub-processor is certified under the EU–U.S. Data Privacy Framework, that framework may also be relied on.
11.3 For transfers from the UK, the UK International Data Transfer Addendum applies to the clauses above. For transfers from Switzerland, the clauses apply with references adapted to the Swiss FADP and the competent authority is the Swiss FDPIC.
12. U.S. state privacy laws
Where Provider processes Client Personal Data subject to the CCPA or similar U.S. state laws, Provider acts as a service provider or processor and will not: (a) sell or share Client Personal Data; (b) retain, use or disclose it for any purpose other than providing the Services or as permitted by law; (c) retain, use or disclose it outside the direct business relationship with Client; or (d) combine it with personal data from other sources, except as permitted by law. Provider will notify Client if it can no longer meet these obligations, and Client may take reasonable steps to stop unauthorized use. Provider certifies that it understands and will comply with these restrictions.
13. Liability and term
13.1 Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms, except where Applicable Data Protection Laws do not allow it. All claims under this DPA and the Terms together are subject to a single aggregate cap, which this DPA does not increase.
13.2 This DPA lasts as long as Provider processes Client Personal Data. Provider may update this DPA to reflect changes in law or in its Sub-processors' terms, with 14 days' notice for material changes.
13.3 Client will indemnify Provider for any fines, claims, damages and costs arising from Client's instructions, from processing Client Personal Data without a lawful basis, required notice or consent, or from Client's breach of this DPA or of Applicable Data Protection Laws.
13.4 Provider is not responsible for processing that Client performs itself, or that is performed by third-party services Client chooses to enable.
14. Contact
Data protection contact for Provider: hola@pronvi.com, 7345 W Sand Lake Rd, Ste 210, Office 3330, Orlando, FL 32819, USA. Data protection contact for Client: the contact listed in Client's account.