본문으로 건너뛰기
Namiru.ai

Data Processing Agreement

Effective date: 30 September 2026. This agreement is provided in English.

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Crowie s. r. o., Lipovník 187, 049 42 Lipovník, Slovakia, IČO 53 098 391 ("Namiru", "we") and the customer using Namiru ("you"). It applies whenever we process personal data on your behalf while providing the Service. By accepting the Terms of Service you accept this DPA.

You are the controller of that personal data, or a processor acting for your own client. We are your processor, or your sub-processor. Terms such as "personal data", "processing", "controller", "processor" and "personal data breach" have the meaning given in the General Data Protection Regulation (EU) 2016/679 ("GDPR").

2. Instructions

We process personal data only on your documented instructions: the Terms of Service, this DPA, and the settings and features you use in the Service. We do not process it for our own purposes, except where EU or Member State law requires it, in which case we inform you first unless that law forbids it.

We tell you straight away if we believe an instruction infringes data protection law.

3. Confidentiality

Everyone we authorise to process personal data is bound by confidentiality, by contract or by law, and has access only as far as their task requires.

4. Security

We implement the technical and organisational measures in Annex 2, which are appropriate to the risk under Art. 32 GDPR. We may improve these measures over time, but never below the level described.

5. Sub-processors

You give us general authorisation to engage the sub-processors listed on namiru.ai/trust, in the section "Who processes data for us". We inform you of any intended addition or replacement at least 30 days in advance, by email or in the Service. You may object on reasonable data protection grounds within that period; if we cannot address the objection, you may end the affected part of the Service.

We bind every sub-processor to data protection obligations equivalent to this DPA and remain responsible to you for its performance.

6. Transfers outside the EEA

We transfer personal data outside the European Economic Area only with safeguards under Chapter V GDPR. Where a recipient is not covered by an adequacy decision, including certification under the EU-US Data Privacy Framework, we rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 with that recipient.

7. Requests from data subjects

The Service lets you view, export and delete conversations and leads, which covers most requests you receive. Where you need more, we help you answer requests to exercise data subject rights, taking into account the nature of the processing. If a data subject contacts us directly about your data, we forward the request to you and do not answer it on your behalf unless you ask us to.

8. Assistance

Taking into account the nature of the processing and the information available to us, we help you meet your obligations on security, personal data breach notification, data protection impact assessments and prior consultation under Arts. 32 to 36 GDPR.

9. Personal data breaches

We notify you without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting your data. The notice includes, as far as available, the information in Art. 33(3) GDPR, and we update it as we learn more. We take reasonable steps to contain the breach and limit its effects.

10. Deletion and return

While you use the Service you can export and delete your data at any time. When you delete your account, we delete your personal data from our live systems immediately, unless EU or Member State law requires us to keep it. Copies in backups are removed when those backups are deleted.

11. Information and audits

We make available the information needed to demonstrate compliance with this DPA. We allow audits, including inspections, by you or an independent auditor you mandate, with at least 30 days' notice, during business hours, no more than once a year unless a supervisory authority requires it or a personal data breach occurred, and under confidentiality. You bear the costs of your audit.

12. Your obligations

  • Have a lawful basis for the processing you instruct.
  • Inform the people concerned, for example in your privacy policy, including that Namiru and the AI providers we use process their chat messages.
  • Do not use the Service to collect special categories of personal data unless that is lawful and necessary.
  • Configure the Service appropriately, for example keeping the chat off pages where it is not needed, such as login, account or payment pages.

13. Term, liability and precedence

This DPA applies for as long as we process personal data on your behalf. Liability is governed by the Terms of Service. If this DPA conflicts with the Terms of Service on the protection of personal data, this DPA prevails. This DPA is governed by the laws of the Slovak Republic.

Annex 1: Details of processing

Data subjects
Visitors who use the chat on your website; your users of the Service; people named in the content you add.
Personal data
Chat messages; contact details visitors choose to share, such as name, email and phone; booking details; a random visitor ID and session IDs; the IP address, used transiently and stored only as a keyed hash; approximate country; timezone; browser details; feedback; content you upload or let us read.
Special categories
None intended. Do not configure the Service to collect them.
Nature and purpose
Hosting and running your AI chat assistant: generating replies with AI, summarising conversations, capturing leads, handling bookings, sending the notifications you enable and showing you analytics.
Duration
For the term of the Terms of Service, then until deletion as set out in clause 10.
Retention
As published in the Privacy Policy: for example, chat message logs are deleted after 90 days, and conversations stay until you delete them.

Annex 2: Technical and organisational measures

  • Hosting in Hetzner data centres in Germany.
  • Encryption in transit with TLS for all connections to the Service.
  • Credentials you give us for data feeds, webhooks and notification channels are encrypted with AES-256-GCM.
  • Access to production systems limited to authorised personnel.
  • Separation of customer data by account, with authorisation checks on every request.
  • IP addresses in chat and analytics records stored only as a hash made with a secret key; country lookups run on our own servers.
  • Nothing is stored in a visitor's browser before the visitor opens or starts using the chat.
  • Automatic deletion: chat message logs after 90 days, security events after 180 days, website analytics after 13 months.
  • Rate limiting, abuse protection and security event monitoring.
  • Automated tests and dependency vulnerability checks, and review of security-relevant changes.

Annex 3: Sub-processors

The current list, with each provider's purpose and location, is published on namiru.ai/trust. For a signed copy of this DPA, write to patrik@namiru.ai.