Data Processing Agreement
Effective November 16, 2026
This Data Processing Agreement ("DPA") is concluded between the Customer (as controller, or as processor acting on behalf of its own controllers) and Virbe sp. z o.o., ul. Tomasza Zana 11A, 20-601 Lublin, Poland, KRS 0000780459 ("Virbe", as processor). It forms part of the Agreement under Virbe's Terms of Service (https://virbe.ai/terms) and fulfils the requirements of Article 28(3) GDPR. It is concluded when the Customer accepts the Terms of Service or signs an Order Form or Enterprise Agreement referring to it. A copy signed by Virbe is available on request at [email protected].
1. Definitions
1.1. Capitalised terms not defined in this DPA have the meanings given in the Terms of Service. "Controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
1.2. In this DPA:
- "Customer Personal Data" means personal data contained in Customer Data that Virbe processes on behalf of the Customer in providing the Services.
- "Data Protection Laws" means the GDPR, the Polish Act of 10 May 2018 on the Protection of Personal Data and other data protection laws of the European Union and its Member States that apply to the processing, and, where applicable, the UK GDPR and the Swiss Federal Act on Data Protection.
- "Restricted Transfer" means a transfer of Customer Personal Data to a country outside the European Economic Area (EEA) that is not covered by an adequacy decision of the European Commission.
- "SCCs" means the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914.
- "Sub-processor" means a processor engaged by Virbe to process Customer Personal Data. Third-Party Services connected by the Customer with its own Provider Credentials are not Sub-processors.
- "Support Access" means access by Virbe personnel to a Customer-Hosted deployment at the Customer's request.
2. Scope and roles
2.1. Virbe processes Customer Personal Data as a processor on behalf of the Customer. Where the Customer acts as a processor for its own customers, Virbe acts as its sub-processor, and the Customer is responsible for obtaining the authorisations from its controllers that are required for this DPA.
2.2. The subject matter, nature, purpose and duration of the processing, the types of personal data and the categories of data subjects are described in Annex I.
2.3. The scope of Virbe's processing depends on the Hosting Mode:
- (a) Virbe-Hosted: Virbe processes Customer Personal Data in its cloud infrastructure, in the region selected by the Customer, as described in this DPA.
- (b) Customer-Hosted: Customer Personal Data is stored and processed in the Customer's own infrastructure. Virbe does not have standing access to it and processes it only during Support Access, which takes place only at the Customer's request, is performed by named Virbe administrators and is limited to what is needed for the requested support, maintenance or upgrade. This DPA applies to the processing carried out during Support Access, to services that Virbe operates for Customer-Hosted deployments (such as authentication, e-mail delivery and, under an Enterprise Agreement, AI engines provided by Virbe) as listed in Annex III, and to any Customer Personal Data the Customer otherwise provides to Virbe (for example in support tickets).
- (c) Kiosks: camera images processed by camera-based features of the Kiosk Application are processed locally on the Kiosk and are not transmitted to or stored by Virbe; only statistics are transmitted to the Services. To the extent detection results are transmitted per event or otherwise relate to an identifiable person, they are Customer Personal Data processed under this DPA.
2.4. This DPA does not apply to personal data that Virbe processes as a controller, such as data of the Customer's representatives and Authorized Users for account management, billing, security of the Services and communication. That processing is described in Virbe's Privacy Policy (https://virbe.ai/privacy).
3. Customer's obligations and instructions
3.1. The Customer is responsible for the lawfulness of the processing of Customer Personal Data, including having a lawful basis, providing information to data subjects (including information that End Users interact with an AI system and how their conversations are processed), configuring retention and redaction settings appropriate to its purposes, and ensuring that its instructions comply with Data Protection Laws.
3.2. The Customer instructs Virbe to process Customer Personal Data: (a) to provide, secure and support the Services in accordance with the Agreement and the Documentation; (b) as initiated by the Customer and its Authorized Users through the configuration and use of the Services, including transmitting Customer Personal Data to the Third-Party Services that the Customer configures (such transmissions, including any resulting transfers to third countries, being made on the Customer's documented instruction); (c) to create Aggregated Data by aggregating or de-identifying Customer Personal Data so that it no longer relates to an identified or identifiable person; and (d) as otherwise agreed in documented form. The Agreement and this DPA are the Customer's complete instructions at the time of conclusion. Additional instructions must be consistent with the Agreement; if they require Virbe to incur material costs, Virbe will inform the Customer of the costs before carrying them out.
3.3. The Customer must not design Customer Agents to request special categories of personal data or data relating to criminal convictions unless this is agreed in an Enterprise Agreement, together with the appropriate measures.
4. Virbe's obligations
4.1. Virbe will:
- (a) process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which Virbe is subject; in such a case, Virbe will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
- (b) immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the execution of that instruction until it is confirmed or changed;
- (c) ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and receive appropriate data protection training;
- (d) take all measures required pursuant to Article 32 GDPR, as described in Section 5;
- (e) respect the conditions for engaging Sub-processors in Section 7;
- (f) assist the Customer as described in Section 6;
- (g) delete or return Customer Personal Data as described in Section 12;
- (h) make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as described in Section 11; and
- (i) maintain a record of processing activities carried out on behalf of the Customer in accordance with Article 30(2) GDPR.
4.2. Virbe will not: (a) use Customer Personal Data to train, fine-tune or improve any AI model, whether its own or a third party's; (b) sell Customer Personal Data or use it for advertising; or (c) process Customer Personal Data for its own purposes, except to create Aggregated Data under Section 3.2(c) and as required by law.
5. Security
5.1. Virbe implements and maintains the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks for the rights and freedoms of natural persons.
5.2. Virbe may update these measures, provided that the updates do not reduce the overall level of protection.
5.3. The Customer is responsible for the security of its accounts, credentials, Kiosks and devices, for the configuration of the security features of the Services (such as user roles, authorised domains, Profile Secrets, Security PIN, PII redaction and retention settings) and, for Customer-Hosted deployments, for the security of its infrastructure.
6. Assistance
6.1. Data subject requests. Taking into account the nature of the processing, Virbe assists the Customer by appropriate technical and organisational measures in responding to requests of data subjects exercising their rights under Chapter III GDPR. The Services include functions to find, export and delete conversations and other Customer Data. If Virbe receives a request directly from a data subject relating to Customer Personal Data, it will forward it to the Customer without undue delay and will not respond to it except to direct the data subject to the Customer or as instructed by the Customer.
6.2. Other assistance. Virbe assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, personal data breaches, data protection impact assessments and prior consultations), taking into account the nature of the processing and the information available to Virbe, including by providing information about the Services, their AI components and the measures in Annex II.
6.3. Costs. Assistance through the self-service functions of the Services, notifications under Section 10 and assistance required because of Virbe's breach of this DPA are free of charge. For other assistance requiring significant effort, Virbe may charge its professional services rates communicated to the Customer in advance. Virbe will never make the notification of a personal data breach, or the provision of the information required under Section 10, conditional on payment.
7. Sub-processors
7.1. The Customer gives Virbe a general authorisation to engage Sub-processors. The current list of Sub-processors, with their location, the purpose of processing and the Hosting Modes in which they are used, is available at https://virbe.ai/legal/subprocessors (Annex III). The list also shows which Sub-processors are used only when the Customer selects a particular region, uses Virbe-provided AI engines or uses an Enterprise proxy.
7.2. Virbe will inform the Customer of any intended addition or replacement of a Sub-processor at least 30 days in advance by e-mail to the Customer's account contact address or to subscribers of change notices (subscriptions are available at [email protected]), and by updating the list. Where an urgent replacement is needed for security or business-continuity reasons, Virbe will inform the Customer in advance where feasible and otherwise as soon as possible; Section 7.3 applies from that notice.
7.3. The Customer may object to a new Sub-processor on reasonable grounds relating to data protection by notice to [email protected] within the notice period. The parties will discuss the objection in good faith; Virbe may propose a change in configuration or the use of the Services that avoids processing by the Sub-processor. If the objection is not resolved within 30 days of its receipt, the Customer may terminate the affected Services by notice, and Virbe will refund prepaid Fees for the remaining Subscription Term of those Services.
7.4. Virbe imposes on each Sub-processor, by written contract, data protection obligations providing the same level of protection as this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Virbe remains fully liable to the Customer for the performance of its Sub-processors' obligations in accordance with Article 28(4) GDPR. On request, Virbe provides the Customer with information about the processors engaged by its Sub-processors to the extent available to Virbe, and copies of the relevant data protection terms (commercial terms may be redacted).
7.5. Third-Party Services. When the Customer connects Third-Party Services with its own Provider Credentials, the provider processes data under its own contract with the Customer. Virbe transmits Customer Personal Data to such providers solely on the Customer's instruction (Section 3.2(b)) and is not responsible for their processing. Third-Party Services provided by Virbe itself, including under an Enterprise proxy, are Sub-processors.
8. Location of processing and international transfers
8.1. In the Virbe-Hosted mode, Customer Personal Data stored in the Services is hosted in the region selected by the Customer, or, if no region is selected, in the European Union, in the data centre locations stated in Annex III. Virbe will not move Customer Personal Data stored in the Services out of that region or location without the Customer's prior consent in documentary form. If the Customer selects a region outside the EEA, it instructs Virbe to process Customer Personal Data in that region and is responsible for any authorisations it needs for such processing.
8.2. Sub-processors may process Customer Personal Data outside the EEA (for example, for transactional e-mails or AI processing) as indicated in Annex III. Virbe ensures that any transfer of Customer Personal Data outside the EEA complies with Chapter V GDPR, relying on: (a) an adequacy decision, including the EU–US Data Privacy Framework for recipients certified under it; or (b) for Restricted Transfers, the SCCs (Module 3, processor to processor) concluded between Virbe and the Sub-processor, together with supplementary measures where needed following a transfer impact assessment.
8.3. If the Customer is established outside the EEA in a country without an adequacy decision and Virbe transfers Customer Personal Data to the Customer, the SCCs (Module 4, processor to controller) are incorporated into this DPA by reference, with Virbe as data exporter and the Customer as data importer.
8.4. For the purposes of the SCCs, where they apply: Clause 7 (docking clause) applies; under Clause 9(a), Option 2 (general written authorisation) applies with the notice period in Section 7.2; the optional wording in Clause 11 does not apply; under Clause 13, the competent supervisory authority is the President of the Personal Data Protection Office (UODO), Poland; under Clauses 17 and 18, the SCCs are governed by Polish law and disputes are resolved by the courts of Poland; Annexes I and II of the SCCs are completed with the information in Annexes I and II of this DPA, and Annex III of the SCCs with the list of Sub-processors.
8.5. Where the UK GDPR or the Swiss Federal Act on Data Protection applies to a transfer, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the UK Information Commissioner or with the adaptations required by the Swiss Federal Data Protection and Information Commissioner, respectively.
8.6. If a transfer mechanism relied on under this Section is invalidated or suspended (for example, if the EU–US Data Privacy Framework ceases to apply), Virbe will rely on an alternative mechanism, such as the SCCs, inform the Customer without undue delay and take the measures needed to continue the transfer lawfully or to stop it.
9. Requests from public authorities
9.1. If Virbe receives a legally binding request from a public authority for access to Customer Personal Data, it will, unless legally prohibited: (a) notify the Customer promptly and provide a copy of the request; (b) review the legality of the request and challenge it where there are reasonable grounds to consider it unlawful; and (c) disclose only the minimum data necessary to comply with the request.
9.2. Information on the jurisdiction of Virbe's infrastructure and the safeguards against unlawful governmental access is published at https://virbe.ai/legal/trust-and-data-location.
10. Personal data breaches
10.1. Virbe will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it.
10.2. The notification will describe, to the extent then known: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information. Where it is not possible to provide all information at the same time, Virbe will provide it in phases without undue further delay.
10.3. Virbe will take reasonable steps to contain and remedy the breach, will cooperate with the Customer and provide the information reasonably needed for the Customer to meet its obligations under Articles 33 and 34 GDPR, and will document the breach.
10.4. Notification of a breach is not an acknowledgement of fault or liability by Virbe. Notifications are sent to the Customer's account contact address and, if provided, to the security or privacy contact designated by the Customer.
11. Information and audits
11.1. Virbe makes available to the Customer, on request, the information necessary to demonstrate compliance with this DPA, including: (a) this DPA and Annex II; (b) a completed security questionnaire, once per 12 months; (c) summaries of third-party penetration tests and, once obtained, certificates and audit reports (for example ISO/IEC 27001), under a confidentiality agreement; and (d) relevant certifications and reports of Sub-processors made available to Virbe.
11.2. If the information under Section 11.1 is not sufficient to demonstrate compliance, or if a supervisory authority requires it, or after a personal data breach affecting Customer Personal Data, the Customer may carry out an audit, including an inspection, itself or through an independent auditor bound by confidentiality who is not a competitor of Virbe, subject to the following: (a) the Customer gives at least 30 days' notice (or shorter notice where required by a supervisory authority or after a breach) and the parties agree on the scope and date; (b) audits take place during business hours, without unreasonably disrupting Virbe's operations and in compliance with its security policies, last no more than 2 business days, and do not take place more than once in 12 months, except after a personal data breach or where required by a supervisory authority; (c) audits do not give access to data of other customers, to Virbe's trade secrets beyond what is necessary, or to the facilities of Sub-processors, for which Virbe relies on their reports and certifications; and (d) the Customer bears its own costs and reimburses Virbe's reasonable costs at its professional services rates communicated in advance, unless the audit reveals a material breach of this DPA by Virbe.
11.3. Nothing in this DPA limits the rights of a supervisory authority or of any other public authority with supervisory powers over the Customer. Audit rights of regulators of Customers in regulated sectors (such as financial institutions) are set out in the relevant Enterprise Agreement.
12. Return and deletion
12.1. During the Agreement, the Customer can export and delete Customer Data using the functions of the Services, and can configure retention and automatic clean-up of conversations as described in the Documentation.
12.2. After the Agreement ends, Virbe makes Customer Data available for retrieval for 30 days (or the longer retrieval period applicable under Section 18.5 of the Terms of Service). Virbe then deletes Customer Personal Data from its production systems within 30 days, and from backups through the regular backup rotation within a further 35 days, unless Union or Member State law requires its storage, in which case Virbe protects it and processes it only for the purposes of that legal requirement. Virbe confirms the deletion on request.
12.3. In the Customer-Hosted mode, the Customer controls the return and deletion of Customer Data in its infrastructure; Virbe deletes any copies obtained during Support Access when they are no longer needed for the support request.
13. Liability
13.1. Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions in Section 17 of the Terms of Service, including the cap applicable to data obligations, unless an Enterprise Agreement provides otherwise.
13.2. This Section does not limit either party's liability to data subjects under Article 82 GDPR or the liability of either party under the SCCs to the extent the SCCs prohibit such limitation.
14. Term, precedence and changes
14.1. This DPA applies for as long as Virbe processes Customer Personal Data on behalf of the Customer.
14.2. In case of conflict: the SCCs (where they apply) prevail over this DPA; this DPA prevails over the Terms of Service and other documents of the Agreement with regard to the processing of personal data; an Enterprise Agreement prevails over this DPA (but not over the SCCs).
14.3. Virbe may change this DPA in accordance with Section 20 of the Terms of Service, provided that changes do not reduce the overall level of protection of Customer Personal Data, except where required by Data Protection Laws or a supervisory authority.
14.4. This DPA is governed by Polish law, and disputes are resolved by the courts specified in the Terms of Service, without prejudice to Clauses 17 and 18 of the SCCs.
Annex I — Details of the processing
A. Parties. Controller: the Customer, as identified in its account or Order Form; contact: the Customer's account owner or designated privacy contact. Processor: Virbe sp. z o.o., ul. Tomasza Zana 11A, 20-601 Lublin, Poland; contact: [email protected]. Where the SCCs apply, the data exporter and data importer are as described in Sections 8.2 and 8.3.
B. Categories of data subjects:
- End Users interacting with Customer Agents (for example, the Customer's customers, prospects, visitors and, where the Customer deploys Customer Agents internally, its employees);
- Authorized Users, to the extent their data appears in Customer Data (for example, operators taking over conversations or authors of configuration changes);
- persons whose personal data is contained in Knowledge Base content, prompts, configuration or assets provided by the Customer (for example, the Customer's employees or contact persons);
- persons whose voice, image or likeness is used in custom assets provided by the Customer.
Camera images captured by Kiosks are processed locally on the Kiosk and are not processed by Virbe. Statistics derived from them are processed by Virbe only in aggregated form, unless they are transmitted per event, in which case they are Customer Personal Data (Section 2.3(c)).
C. Categories of personal data:
- conversation content: text messages, transcripts of voice messages, Outputs, conversation variables, form inputs and attachments provided in conversations;
- voice data: audio of End Users' spoken messages transmitted for speech recognition and, where audio storage is enabled by the Customer, stored recordings;
- identification and contact data that End Users provide in conversations or forms (for example name, e-mail address, telephone number);
- technical data: IP address, browser and device information, language, session and device identifiers, Kiosk identifiers, timestamps, approximate location derived from the IP address;
- content of Knowledge Base documents, prompts, system instructions and webhook payloads, to the extent they contain personal data;
- custom assets (images, avatars, audio) provided by the Customer, to the extent they contain personal data;
- data relating to Authorized Users contained in Customer Data (name, e-mail, actions performed).
D. Special categories of data. The Services are not intended for processing special categories of personal data. Such data may, however, be included incidentally in free-text or voice messages of End Users. The measures in Annex II apply to all Customer Personal Data; in addition, the Customer can enable PII detection and redaction and short retention periods. Any intended processing of special categories of data must be agreed in an Enterprise Agreement.
E. Frequency of processing. Continuous, for the duration of the Agreement.
F. Nature of the processing. Hosting and storage; operation of the conversation engine and Customer Agents; transmission of Inputs to the AI models, speech-to-text and text-to-speech engines and other services configured by the Customer or provided by Virbe; indexing of Knowledge Base content (including creation of vector embeddings); generation of analytics; optional PII detection and redaction; support, maintenance and Support Access; backup and recovery; aggregation and de-identification; deletion.
G. Purpose of the processing. Providing, securing and supporting the Services in accordance with the Agreement, and creating Aggregated Data on the Customer's instruction.
H. Duration and retention. For the duration of the Agreement and the retrieval and deletion periods in Section 12. Within that period: conversations are retained for 12 months by default in the Virbe-Hosted mode, unless the Customer configures a shorter or longer retention period or deletes them earlier; technical logs containing personal data are retained for up to 90 days; backups are overwritten within 35 days.
I. Sub-processors. As listed in Annex III, for the purposes, locations and Hosting Modes indicated there.
J. Competent supervisory authority. The President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, without prejudice to the competence of the supervisory authority of the Customer's establishment.
Annex II — Technical and organisational measures
1. Governance and organisation
- Information security policies approved by management, reviewed at least annually; an information security management system based on ISO/IEC 27001 is being implemented.
- Designated responsibility for information security and data protection; contact: [email protected] and [email protected].
- Confidentiality obligations and data protection and security training for all personnel with access to Customer Data; access rights revoked promptly on termination.
- Risk assessment of new features and of Sub-processors before engagement, including review of their security and data protection commitments and of AI providers' data use and retention terms.
2. Access control
- Access to production systems and Customer Data restricted to authorised personnel on a need-to-know and least-privilege basis, with individual accounts and multi-factor authentication.
- Access to Customer-Hosted deployments only at the Customer's request, by named administrators, and logged.
- Role-based access control for Authorized Users in the Dashboard; obfuscation of Provider Credentials stored in the Dashboard; Profile Secrets for Widget and Kiosk connections; authorised domain lists for the Widget; Security PIN for Kiosk settings.
3. Encryption and data protection
- Encryption of data in transit over public networks using TLS 1.2 or higher.
- Encryption of stored data at rest using the encryption mechanisms of the hosting infrastructure.
- Secure storage of secrets and credentials, separated from application code.
4. Separation and minimisation
- Logical separation of Customer Data between customers; separate environments for development, testing and production; no use of Customer Personal Data in development or testing without the Customer's consent.
- Data minimisation functions available to the Customer: configurable conversation retention, scheduled automatic clean-up, manual deletion, optional PII detection and redaction of incoming text before storage and before transmission to AI models, and local (on-device) processing of Kiosk camera images.
- No use of Customer Data to train AI models; AI providers engaged by Virbe are bound by terms excluding training on Customer Data.
5. Integrity, logging and monitoring
- Logging of administrative access and security-relevant events, with logs protected against unauthorised modification and retained for up to 90 days.
- Monitoring of the availability and performance of the Services and alerting on anomalies.
6. Secure development and vulnerability management
- Version control, peer code review and automated testing before deployment.
- Regular updating of dependencies and timely patching of known vulnerabilities according to their severity.
- Penetration testing by an independent third party at least annually and after significant changes, with remediation of findings.
- Coordinated vulnerability disclosure through [email protected].
7. Availability and resilience
- Hosting in professional data centres of providers holding recognised security certifications (such as ISO/IEC 27001).
- Regular backups of production data with restricted access, stored separately from the primary systems and overwritten within 35 days; tested restoration procedures.
- Incident response procedures, including notification of personal data breaches in accordance with Section 10.
8. Physical security
- Physical security of the data centres is provided by the hosting Sub-processors under their certified controls. Virbe's offices apply access control and clean-desk rules; Virbe personnel use encrypted, centrally managed devices.
Annex III — Sub-processors
The current list of Sub-processors is available at https://virbe.ai/legal/subprocessors.