Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between Corveria ehf., kt. 590526-1260 ("Processor", "we") and the customer that accepts it ("Controller", "you") for use of the Anna service ("Service"). It governs our processing of personal data on your behalf under Article 28 GDPR. By accepting our Terms of Service or using the Service, you accept this DPA; acceptance in electronic form is valid under Article 28(9) GDPR. If the Terms and this DPA conflict on the processing of personal data, this DPA prevails.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", and "personal data breach" have the meanings given in the GDPR (Regulation (EU) 2016/679), as it applies in Iceland through the EEA Agreement and the Act nr. 90/2018. "Customer Personal Data" means personal data we process on your behalf through the Service, described in Annex 1. "SCCs" means the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914.
2. Roles and scope
You are the controller and we are the processor of the Customer Personal Data. You remain responsible for the lawfulness of the data that you and your end users put into the Service and for any notices and legal bases required towards your end users. Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects.
3. Our obligations
We will:
(a) Documented instructions. Process Customer Personal Data only on your documented instructions, including as to transfers, unless required otherwise by EEA or Icelandic law (in which case we will inform you, unless that law prohibits it). Your instructions are this DPA, the Terms, your configuration of the Service, and your use of it. We will inform you if, in our opinion, an instruction infringes the GDPR or Act nr. 90/2018.
(b) Confidentiality. Ensure that persons authorised to process the data are bound by confidentiality.
(c) Security. Implement appropriate technical and organisational measures under Article 32. Our current measures are described in Annex 2.
(d) Sub-processors. Engage sub-processors only as set out in clause 4.
(e) Data-subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects under Chapter III GDPR.
(f) Assistance. Assist you in ensuring compliance with Articles 32 to 36 (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to us. We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
(g) Return or deletion. At the end of the Service, at your choice, delete or return all Customer Personal Data and delete existing copies, unless EEA or Icelandic law requires storage. Our default is deletion within 30 days of termination, subject to any legal retention.
(h) Audits. Make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Such audits take place on reasonable prior written notice, no more than once per year (unless a supervisory authority requires otherwise or following a personal data breach), during business hours, under confidentiality, and in a manner that does not disrupt the Service; we may satisfy an audit request by providing a written self-assessment and any relevant certifications or third-party reports we hold, and each party bears its own costs.
4. Sub-processors
You give general authorisation for us to engage sub-processors. Our current sub-processors, what they do, where they process data, and the transfer safeguard for each, are listed in our Sub-processor list, which forms Annex 3. We impose data protection obligations on each sub-processor that are equivalent to those in this DPA, and we remain fully liable to you for each sub-processor's performance (Article 28(4)).
We will give you prior notice of any intended addition or replacement of a sub-processor, with at least 30 days to object on reasonable data protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the Service.
5. International transfers
Where a sub-processor processes Customer Personal Data outside the EEA, we ensure an appropriate Chapter V safeguard is in place: an adequacy decision, the EU-US Data Privacy Framework, or the SCCs with supplementary measures. The safeguard for each sub-processor is identified in the Sub-processor list. The relationship between you (in the EEA) and us (in Iceland, an EEA state) is intra-EEA and does not itself require the SCCs.
6. Your obligations
You warrant that you have a lawful basis for the Customer Personal Data processed through the Service, that you have given your end users the privacy information required by Articles 13 and 14, and that your instructions will comply with applicable data protection law. We provide an end-user privacy notice template to help, but you remain the controller responsible for it.
7. Liability and term
Liability under this DPA is subject to the limitations of liability in the Terms. This DPA takes effect when you accept it and continues for as long as we process Customer Personal Data.
8. Governing law
This DPA is governed by Icelandic law. If this DPA is provided in more than one language and there is a conflict, the Icelandic version prevails.
Annex 1: Description of the processing
- Subject matter: provision of the Anna AI customer-service assistant.
- Duration: for the term of the Service agreement.
- Nature and purpose: receiving end-user messages, generating replies using AI models, retrieving relevant knowledge, routing conversations to your team, and related support functions.
- Types of personal data: end-user chat messages and any content within them, received through the website widget or a connected messaging channel (such as Messenger or Instagram); contact details provided on escalation (name, email, phone) and any display name provided by a connected channel; your account users' data needed to operate the Service.
- Categories of data subjects: your website visitors and customers who message you through Anna (end users), and your own staff users of the Service.
Annex 2: Technical and organisational measures
Our current technical and organisational measures are described in our Technical and Organisational Measures document, which forms part of this DPA.
Annex 3: Sub-processors
Our current sub-processors are listed in our Sub-processor list, which forms part of this DPA.
Version 1.0.0. Last updated 2026-06-23.