BOTYARD

Legal

Data Processing Agreement

Last updated: August 27, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Botyard ApS ("Botyard", "we", "us") and the customer identified in the applicable order form, or, where no separate order form or signed agreement exists, the entity or individual that accepts our Terms of Service ("Customer", "you"), and applies to the extent Botyard processes Personal Data on Customer's behalf in connection with the Service.

This DPA is incorporated by reference into the Terms of Service (see Section 5, "Your Content and Data"), or, where applicable, into the separate written agreement between the parties governing use of the Service. It applies automatically once Customer submits Personal Data to the Service — no separate signature is required — but Customer may request a signed copy at any time by contacting legal@botyard.io.

1. Definitions

Terms such as "controller", "processor", "personal data", "personal data breach", "processing", and "data subject" have the meanings given in the GDPR. In addition:

  • "GDPR" means Regulation (EU) 2016/679 (the "EU GDPR") and, to the extent applicable to Customer's processing, the UK General Data Protection Regulation as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the "UK GDPR"), together with any other data protection legislation implementing, supplementing, or replacing either of them.
  • "Customer Data" means any Personal Data that Botyard processes on Customer's behalf in the course of providing the Service, including content submitted to AI agents hosted on the platform.
  • "Sub-processor" means any processor engaged by Botyard to process Customer Data on Customer's behalf.
  • "Service" has the meaning given in the Terms of Service.

2. Roles of the Parties

As between the parties, Customer is the controller (or, where Customer processes Customer Data on behalf of a third party, processor) and Botyard is the processor of Customer Data. Botyard shall process Customer Data only as necessary to provide the Service and shall not process Customer Data for any other purpose. The subject matter, duration, nature and purpose of processing, and the categories of data subjects and types of Personal Data are set out in Schedule 1.

This DPA does not apply to personal data for which Botyard is itself a controller — for example, account, billing, and administrative contact data — which is governed by our Privacy Policy.

3. Processing Instructions

Botyard shall process Customer Data only on Customer's documented instructions, including with regard to transfers of Customer Data to a third country, unless required to do otherwise by applicable law. Customer's use and configuration of the Service, together with this DPA, constitute Customer's documented instructions.

Botyard shall promptly inform Customer if, in Botyard's opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Confidentiality

Botyard shall ensure that persons authorized to process Customer Data are subject to appropriate confidentiality obligations, whether contractual or statutory.

5. Security Measures

Botyard shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, in accordance with Article 32 GDPR. Further detail on Botyard's security practices is available on our Security page.

Customer may request reasonable additional documentation concerning Botyard's security measures, sub-processors, and hosting locations by contacting legal@botyard.io.

6. Sub-processors

Customer gives general written authorization for Botyard to engage the sub-processors listed at botyard.io/legal/subprocessors (the "Sub-processor List"), which forms part of this DPA by reference.

  • Botyard shall provide at least 30 days' prior notice of any intended addition or replacement of a sub-processor, where reasonably practicable, by updating the Sub-processor List and its change log. Customers may request to be notified of changes by contacting legal@botyard.io.
  • Customer may object to a new or replacement sub-processor on reasonable data-protection or security grounds by notifying Botyard in writing within 14 days of the notice. The parties shall discuss the objection in good faith. If the parties cannot resolve the objection, Customer may terminate the affected part of the Service without penalty.
  • Where required to address an urgent security, confidentiality, or legal-compliance need, Botyard may engage a new or replacement sub-processor on shorter notice, provided Botyard notifies Customer without undue delay and gives Customer the objection right above.
  • Botyard shall impose data-protection obligations on each sub-processor that are no less protective than those imposed on Botyard under this DPA, to the extent applicable to the sub-processor's processing, and remains fully responsible to Customer for each sub-processor's performance of those obligations.

7. International Transfers

Where Customer Data is transferred outside the European Economic Area (or, as applicable, the United Kingdom) to a country not subject to an applicable adequacy decision, Botyard shall ensure the transfer is subject to an appropriate safeguard under applicable data protection law, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable), through Botyard's agreement with the relevant recipient or sub-processor. The Sub-processor List identifies the contractual framework relied on where a restricted transfer occurs.

8. Assistance with Data Subject Rights

Taking into account the nature of the processing, Botyard shall provide reasonable assistance to Customer, by appropriate technical and organizational measures, to fulfil Customer's obligations to respond to requests from data subjects exercising their rights under the GDPR. Taking into account the nature of processing and the information available to Botyard, Botyard shall also provide reasonable assistance with Customer's obligations under Articles 32 to 36 GDPR, including security, personal-data-breach notifications, data protection impact assessments, and prior consultation with a supervisory authority. Botyard shall promptly notify Customer if it receives a request from a data subject directly and shall not respond to such request itself, other than to confirm receipt and direct the data subject to Customer, unless legally required to do otherwise.

9. Personal Data Breach Notification

Botyard shall notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and shall provide reasonable information to assist Customer in meeting its own notification obligations under applicable data protection law.

10. Audits and Information

Botyard shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable advance notice, confidentiality, and no more than once per year (unless required by a supervisory authority or following a personal data breach). Botyard may satisfy this obligation by providing a summary of a recent third-party audit report, where available and sufficient for Customer's purposes.

11. Return or Deletion of Customer Data

Upon termination or expiration of the Service, and at Customer's election, Botyard shall delete or return all Customer Data, and delete existing copies, unless applicable law requires storage of the Customer Data, consistent with the deletion terms in our Terms of Service.

12. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service (or, where applicable, the separate written agreement between the parties).

13. Term

This DPA takes effect when Customer Data is first submitted to the Service and remains in effect for as long as Botyard processes Customer Data on Customer's behalf.

14. Precedence and Governing Law

In the event of a conflict between this DPA and the Terms of Service (or a separate written agreement between the parties) regarding the processing of Personal Data, this DPA shall prevail. In all other respects, the Terms of Service (or separate written agreement) continue to apply.

This DPA is governed by the same governing law as the Terms of Service (or, where applicable, the separate written agreement between the parties).

Schedule 1

Description of Processing

This Schedule sets out the information required by Article 28(3) GDPR for the generic, self-service use of the Service. Where Customer's use of the Service is governed by a separate written agreement, that agreement's statement-of-work or order form takes precedence over this Schedule to the extent it addresses the same subject matter.

Subject matter of processing: Provision of the Botyard AI agent hosting platform (the "Service") to Customer.

Duration of processing: For the duration of the agreement between the parties governing use of the Service, plus any post-termination retention period described in Section 11 (Return or Deletion of Customer Data) of this DPA.

Nature and purpose of processing: Hosting, storage, transmission, and processing of Customer Data submitted to or generated by AI agents on the Service, including LLM inference, embedding generation, retrieval, analytics, and the underlying infrastructure operations described in the Sub-processor List, all as necessary to provide the Service.

Categories of data subjects: Customer's end users, employees, contractors, and other individuals whose personal data Customer or its end users submit to or process through the Service.

Types of personal data: Personal data contained within content that Customer or its end users submit to or generate through AI agents on the Service. Because the Service is a general-purpose platform, Customer determines the specific types of personal data processed based on its own configuration and use of the Service.

Special categories of data: Customer shall not submit special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions or offences (Article 10 GDPR) to the Service unless the parties have agreed additional safeguards in writing.

15. Contact Us

If you have questions about this DPA, need a signed copy, or want to discuss a customer-specific data processing arrangement, contact us at:

Botyard ApS

CVR 46303040

Email: legal@botyard.io