Data Processing Agreement
Permalink: /legal/dpa/v1
Last updated: 2026-06-09 · Version v1
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions between Aya, operated by Velts Pitronot (Solutions), a licensed business (osek murshe) no. 317637791 (“Aya”, “Processor”, “we”) and the business customer accepting them (“Customer”, “Controller”, “you”). It applies whenever Aya processes personal data on your behalf in the course of providing the Aya app and related services (the “Service”).
1. Roles and scope
- For the personal data you put into Aya about other people — your clients, their contact details, invoices, receipts, calendar attendees, email correspondents — you are the controller and Aya is your processor under Article 28 GDPR (and equivalent provisions of other applicable data-protection laws).
- For your own account data (your email, sign-in, subscription, device and usage data), Aya is an independent controller; that processing is governed by the Privacy Policy, not this DPA.
2. Subject matter, duration, nature and purpose
- Subject matter: the customer content you store and process through the Service — chat messages and attachments, client records and notes, receipts and invoices, calendar events, and (where you connect them) email messages from your mailbox.
- Duration: the term of your agreement with Aya, until your account data is deleted under Section 9.
- Nature and purpose: hosting and storage; AI-assisted organisation, extraction, classification and summarisation; calendar and email synchronisation; document generation; notification delivery — all solely to provide the Service to you.
3. Categories of data subjects and data
- Data subjects: your clients and prospective clients; correspondents in email threads you connect; attendees of calendar events you sync; your employees or collaborators you invite.
- Data categories: names, email addresses, phone numbers, postal addresses; business and billing details (bank details appearing on invoices or receipts); message and document content; calendar event details. Aya is not designed for and must not be used to process special categories of data (Art. 9 GDPR) or data about minors.
4. Your instructions
Aya processes customer content only:
- to provide, maintain and secure the Service as described in its documentation;
- as configured by you through the Service’s features and settings (for example, connecting a calendar or mailbox, sending a client reminder); and
- as otherwise documented in written instructions you give us, where technically feasible.
Aya will inform you if, in our opinion, an instruction infringes applicable data-protection law. We do not sell customer content or use it to train generalised AI models.
5. Confidentiality
Persons authorised by Aya to process customer content are bound by contractual or statutory confidentiality obligations.
6. Security measures (Art. 32 GDPR)
Aya implements appropriate technical and organisational measures, including:
- Encryption in transit: TLS for all connections between the app, the API and downstream services.
- Encryption at rest: infrastructure-level encryption on all databases and object storage; additional application-layer AES-256-GCM encryption for high-sensitivity fields (for example phone numbers and OAuth tokens). The mobile app’s local cache is an encrypted database on the device.
- Access control: role-based access control with least-privilege database roles; per-tenant scoping enforced at the application and, for AI-agent data, the database row level.
- Auditability: append-only audit logs for changes to sensitive records, protected against modification and deletion.
- Data lifecycle tooling: automated erasure and export pipelines (Section 9), retention sweeps, and a breach-incident register with notification workflows.
- Operational security: isolated staging and production environments, secrets management via the hosting platform, and continuous error monitoring.
7. Sub-processors
You authorise Aya to engage the sub-processors listed below. We will give you at least 30 days’ notice (via the app or email) before adding or replacing a sub-processor that processes customer content; if you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected service and receive a pro-rata refund of prepaid fees.
| Sub-processor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| DigitalOcean, LLC | Application and database hosting; object storage for file attachments | US, EU | EU SCCs (Module 2) |
| Google (Gemini API) | AI assistant — orchestration, classification, transcription, embeddings | US | EU–US Data Privacy Framework |
| Google LLC | Google Calendar sync and Gmail ingestion (only for accounts you connect) | US | EU–US Data Privacy Framework |
| Sendinblue SAS (Brevo) | Transactional email delivery (sign-in links) | EU | EEA-internal processing |
| Meta Platforms Ireland Ltd | WhatsApp OTP delivery for sign-up / sign-in | EU, US | EU SCCs (Module 2) |
| OneSignal Inc. | Push-notification delivery (pseudonymous identifiers and routing data only) | US | EU SCCs (Module 2) |
| RevenueCat, Inc. | Subscription entitlement management and receipt validation | US | EU SCCs (Module 2) |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | US | EU SCCs (Module 2) |
Each sub-processor is bound by a data-processing agreement imposing obligations materially equivalent to this DPA. The live register, including data categories per sub-processor, is also surfaced in the Privacy Policy.
8. International transfers
Where customer content is transferred outside the EEA/UK, Aya relies on the transfer mechanisms listed in the table above (EU Standard Contractual Clauses, Module 2, or an adequacy mechanism such as the EU–US Data Privacy Framework), together with supplementary technical measures described in Section 6.
9. Erasure, return and retention
- You can delete individual records (clients, messages, files) in-app at any time; deletion propagates to backups on the standard backup-rotation cycle.
- On verified request, or when your account is closed, Aya erases or irreversibly pseudonymises customer content through audited erasure tooling — except financial records (invoices, receipts and related accounting data) which are retained for up to 7 years where statutory accounting and tax law requires, then deleted.
- You may export your data at any time via the in-app data-export tooling or by written request.
10. Assistance and audits
- Aya provides reasonable assistance with data-subject requests (access, rectification, erasure, portability) that reach you for data held in the Service — most are self-service in-app.
- Aya assists with your Art. 32–36 obligations (security, breach notification, DPIAs) with information reasonably available to us.
- Aya will make available information necessary to demonstrate compliance with this DPA and, no more than once per year (unless required by a supervisory authority), allow an audit by you or your independent auditor under reasonable confidentiality terms. We may first satisfy an audit request with current third-party documentation of our hosting providers and our own compliance records.
11. Personal data breaches
Aya notifies you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting customer content, with the information required by Art. 33(3) GDPR as it becomes available, and cooperates in your notification obligations.
12. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms & Conditions. If this DPA conflicts with the Terms, this DPA prevails for data-protection matters. If a court or authority finds any part of this DPA invalid, the remainder stays in force.
13. Contact
Data-protection questions and notices under this DPA: contact@velts.co (subject line: “DPA”) · Velts Pitronot (Solutions), Margolin 1, Rishon LeZion, Israel.