Data Processing Agreement
Last updated: July 21, 2026
1. Purpose and roles
This Data Processing Agreement (“DPA”) forms part of the service agreement between you (the “Customer”, acting as data controller) and Nativx (acting as data processor) for the provision of the Aria AI sales assistant. It sets out how we process personal data on your behalf under Article 28 of the GDPR.
Processor: [Legal entity to be added once Nativx is formally registered — currently operated as an unregistered project based in Romania]. Data protection contact: adrian@nativextech.com.
2. Subject matter, nature and duration
We process personal data only to provide the Aria service — that is, to power AI-assisted conversations, product recommendations and related analytics for your store. Processing lasts for the term of the service agreement and the limited wind-down period described in Section 8.
- Categories of data subjects: your store’s visitors and customers who interact with the assistant
- Categories of personal data: contact details, conversation content, order and browsing context, and technical identifiers strictly needed to run the service
- Special-category data: not requested; you agree not to route it through the assistant
3. Processing on documented instructions
We process personal data only on your documented instructions, including for international transfers, unless required to do otherwise by law — in which case we will inform you first, unless the law forbids it. This DPA and your configuration of the service are your complete and final instructions. If we believe an instruction breaches data protection law, we will tell you.
4. Confidentiality
We ensure that anyone authorised to process your personal data is bound by an appropriate duty of confidentiality and processes the data only as needed to deliver the service.
5. Security measures
We take appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the costs involved and the risks to individuals. These include:
- Encryption of data in transit and, where practical, at rest
- Access controls limiting data to those who need it
- Reputable, security-vetted infrastructure and sub-processors
- Logging and monitoring proportionate to the service
6. Sub-processors
You give general authorisation for us to engage sub-processors to deliver the service. We currently rely on providers such as our CRM, analytics, hosting and AI-model vendors. We impose data protection obligations on each sub-processor no less protective than this DPA, and we remain responsible for their performance.
We will give you reasonable notice of any intended addition or replacement of a sub-processor so you can object on reasonable data protection grounds. A current list is available on request at adrian@nativextech.com.
7. Assisting you
Taking into account the nature of the processing, we assist you with appropriate measures in responding to data-subject requests (access, rectification, erasure and so on), and in meeting your obligations around security, breach notification, impact assessments and prior consultation with a supervisory authority. Where we receive a request directly from a data subject, we forward it to you rather than acting on it ourselves.
8. Return and deletion
On termination of the service, and at your choice, we delete or return all personal data and delete existing copies, unless retention is required by law. We will do this within a reasonable wind-down period after the service ends.
9. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own notification duties under the GDPR.
10. Audits
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality and frequency limits so as not to disrupt the service.
11. International transfers
Where personal data is transferred outside the European Economic Area, we ensure an appropriate safeguard is in place — such as the European Commission’s Standard Contractual Clauses — so the transfer meets GDPR requirements.
12. Contact and execution
To request the sub-processor list, raise a data protection question, or arrange a signed copy of this DPA alongside your service agreement, email adrian@nativextech.com.