Data Processing Agreement
Version 1.0 of 1 October 2026. Effective from the day it is published on the Website.
Annex 1 to the flowhelp Terms of Service.
This is an English translation of the "Umowa powierzenia przetwarzania danych osobowych". The Polish version is binding and prevails in the event of any discrepancy.
§ 1. Parties and conclusion of the DPA
1.1. This DPA is concluded between:
- the Customer within the meaning of the Terms, as the controller of personal data (the Controller), and
- DOLLABROS sp. z o.o. with its registered office in Poznań, ul. Stanisława Wyspiańskiego 26B/238, 60-751 Poznań, Poland, KRS 0000918078, NIP 7831841993, being the Service Provider within the meaning of the Terms, as the processor (the Processor). In this DPA, DOLLABROS sp. z o.o. is referred to only as the Processor, including where it acts in another capacity.
1.2. This DPA is concluded at the time the Agreement is concluded, by acceptance of the Terms, and forms part of them. It is concluded to comply with Article 28(3) GDPR.
1.3. If the Customer processes data as a processor on behalf of another controller, the Customer warrants that it is authorised to do so, and the Processor acts towards it as a sub-processor on the terms of this DPA.
1.4. For Customers who created a Workspace before the Terms were published on the Website, this DPA binds them from the day they receive the message referred to in § 21.8 of the Terms. Acceptance of this DPA by a User invited to an existing Workspace does not result in the conclusion of a separate DPA (§ 6.5 of the Terms).
§ 2. Definitions
2.1. Capitalised terms have the meanings given to them in the Terms and, in addition:
- Data: personal data processed by the Processor on behalf of the Controller in connection with the provision of the Service, in particular contained in Customer Content, as described in § 4;
- Sub-processor: an entity to which the Processor entrusts the processing of Data, listed in Annex A;
- Data Breach: a personal data breach within the meaning of Article 4(12) GDPR concerning the Data;
- SCC: the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914;
- EEA: the European Economic Area;
- other terms (e.g. processing, controller, processor) have the meanings given to them in the GDPR.
§ 3. Subject matter, nature and purpose of processing
3.1. The Controller entrusts the Processor with the processing of Data to the extent and for the purpose necessary to provide the Service in accordance with the Terms.
3.2. Nature of processing: automated processing, comprising collection of Data through the Widget, recording, organisation, storage, indexing (including conversion of text excerpts into numeric vectors), retrieval, transmission to AI Models to create Answers, making available to Users in the Panel, sending e-mail notifications, export on the Controller's instruction, and erasure.
3.3. Purposes of processing:
- conducting Assistant Conversations with Visitors and creating Answers on the basis of the Materials;
- storing Conversations and making them available to the Controller in the Panel, including for export;
- operating the Contact Form and Handover, including e-mail notifications to the Notification Address;
- collecting Unanswered Questions for analysis by the Controller;
- fetching and indexing Materials indicated by the Controller;
- ensuring the security of processing of the Data (Article 32 GDPR).
3.4. The Processor does not process Data for its own purposes; in particular, it does not use Data to train or fine-tune AI Models, for marketing or for profiling.
§ 4. Types of Data and categories of data subjects
4.1. Categories of data subjects:
- Visitors;
- persons whose data Visitors provide in the content of messages or in the Contact Form;
- users of the Controller's systems, if the Controller passes their identifiers to the Widget;
- persons whose data is contained in the Materials (e.g. employees or associates of the Controller named on the Customer Website).
4.2. Types of Data:
- the content of Visitors' messages and of the Assistant's Answers, together with time, language, answer rating and cited sources (message content may include any data entered by the Visitor);
- a random Visitor identifier stored in the local storage of the Visitor's browser (stored in the database in plain form and as a hash);
- an optional external user identifier passed by the Controller (which may contain an e-mail address if the Controller passes one);
- Contact Form and Handover data within the fields defined by the Controller (e.g. name, e-mail address, telephone number, message content);
- the content of Unanswered Questions;
- the content of e-mail notifications of Contact Form submissions and Handovers (form fields, the last 10 messages of the Conversation) sent to the Notification Address;
- personal data contained in the Materials.
4.3. The Service is not intended for processing special categories of data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). The Controller does not configure the Service to collect such data (§ 9.7 of the Terms). If Visitors enter such data on their own initiative, it is processed as part of the Conversation content on the terms of this DPA.
4.4. The following are not Data within the meaning of this DPA:
- the Notification Address and other e-mail addresses to which the Service sends messages;
- web server logs recording requests to the Widget (loading of the Widget scripts, its configuration and requests to the API: IP address, time, request, User-Agent, Referer), kept for 14 days;
- request rate-limit counters based on a hash of the IP address with a secret value (pepper), kept for between 5 minutes and 2 hours.
The Processor processes this data as a separate controller, to send messages and to ensure the security of the Service and prevent abuse (Article 6(1)(f) GDPR), under the Privacy Policy. The content of notifications referred to in clause 4.2 point 6 remains Data.
§ 5. Duration
5.1. This DPA remains in force for the term of the Agreement and, after its termination, until the Data is deleted in accordance with § 15.
§ 6. Obligations of the Controller
6.1. The Controller represents that it processes Data lawfully, in particular that it has a legal basis for processing and entrusting it, and that it has provided data subjects with the information required by Articles 13 and 14 GDPR (including about the Processor and Sub-processors and about transfers of Data outside the EEA).
6.2. The Controller performs the obligations set out in § 9.4 and § 9.7 of the Terms; in particular, it enters the address of its privacy policy in the Panel (Appearance section), selects the Widget consent mode and sets the Conversation retention period.
6.3. The Controller acknowledges that the Widget does not record Visitors' consent and that message content is passed to AI Models and for vector computation without automatic removal of personal data.
§ 7. Documented instructions
7.1. The Processor processes Data only on documented instructions from the Controller, including with regard to transfers of Data to a third country or an international organisation (Article 28(3)(a) GDPR).
7.2. The Controller's instructions are: the Terms, this DPA, the configuration and actions performed by Users in the Panel (including the choice of AI Model, action settings, notification addresses, consent mode, retention period, deletion and export), and instructions sent by e-mail by the owner or an administrator of the Workspace. The Processor may refuse an instruction that goes beyond the scope of the Service; in that case the Controller may terminate the Agreement.
7.3. If the Processor is required to process Data by Union or Member State law, it informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
7.4. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
7.5. The Service sends Data by e-mail: notifications of Contact Form submissions and Handovers, containing the form fields and the last 10 messages of the Conversation, are sent automatically through a Sub-processor (Annex A, item 5) to the Notification Address chosen by the Controller (§ 3.3 point 3). The Controller is responsible for ensuring that the Notification Address belongs to persons authorised to access that Data.
7.6. E-mail correspondence with the Processor takes place through the mailbox indicated in § 2.3 of the Terms, which is operated by an external e-mail provider. The Controller therefore does not send Data in the body or attachments of e-mails addressed to that mailbox; a Conversation, Contact Form submission or Unanswered Question can be identified by its identifier or by its date and time. Apart from the notifications in clause 7.5, the Processor sends Data from that mailbox only when forwarding a data subject's request to the Controller (§ 12.4); it provides exports as described in § 15.1. Any Data that nonetheless reaches that mailbox is deleted from it promptly after the matter has been handled.
§ 8. Confidentiality
8.1. The Processor allows only persons authorised by it, who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, to process Data (Article 28(3)(b) GDPR).
8.2. Such persons have access to Data only to the extent necessary to provide the Service, handle the Controller's requests, remedy failures and Data Breaches, and comply with legal obligations. For technical maintenance and support they may use AI tools of the provider listed in Annex A, item 6; those tools access Data only to the extent necessary for the specific maintenance or support task.
§ 9. Security of processing
9.1. The Processor applies the technical and organisational measures required by Article 32 GDPR, described in Annex B (Article 28(3)(c) GDPR).
9.2. The Controller represents that it has read Annex B, including the limitations described in it, and considers the measures described appropriate for the Data it intends to entrust. If the Controller intends to process in the Service data requiring a higher level of protection, it should not do so without prior agreement with the Processor.
9.3. The Processor may change the measures described in Annex B, provided this does not lower the overall level of protection of the Data.
§ 10. Sub-processors
10.1. The Controller grants the Processor a general written authorisation to engage Sub-processors (Article 28(2) GDPR). On the date this DPA enters into force, they are the entities listed in Annex A.
10.2. The Processor informs the Controller of any intended addition or replacement of a Sub-processor by e-mail to the addresses indicated in § 21.5 of the Terms (the Workspace owners and administrators and the Workspace notification address, if one is set) and additionally, where the Panel allows, by a notice in the Panel, at least 14 days in advance, stating the entity, the scope of processing and the place of processing.
10.3. Within that period the Controller may raise a reasoned objection by e-mail. The parties seek a solution in good faith. If they do not find one, the Controller may terminate the Agreement with effect before the date of the change and receives a refund of a proportional part of the fee for the unused period. Absence of an objection within the time limit constitutes consent to the change.
10.4. If the replacement of a Sub-processor is urgently needed for the continuity or security of the Service (e.g. due to a failure or a provider ceasing operations), the Processor may make it before the period in clause 10.2 expires, informing the Controller without delay; the Controller then has the rights set out in clause 10.3.
10.5. The Processor entrusts Data to Sub-processors on the basis of agreements concluded with those entities, including standard contractual clauses where data leaves the EEA, imposing data protection obligations substantially the same as those in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures (Article 28(4) GDPR). With respect to AI Model providers (item 3 of Annex A), the Processor ensures these obligations through its contract with OpenRouter, Inc., which engages them under its own contracts with those providers.
10.6. The Processor is liable to the Controller for the performance of a Sub-processor's obligations as for its own acts, on the terms of § 17.
§ 11. Transfers of Data outside the EEA
11.1. The Processor transfers Data outside the EEA only to the Sub-processors listed in Annex A, to the extent described there, on the basis of a Commission adequacy decision or SCC or other safeguards provided for in Chapter V GDPR.
11.2. The Controller acknowledges that:
- OpenRouter, Inc., Resend, Inc. and Anthropic, PBC are established in the USA;
- AI Model providers selected by OpenRouter may process Data in the USA and other countries;
- CoinAxe Ltd (deAPI) uses a distributed network of GPU servers that may be located outside the EEA.
11.3. At the Controller's request, the Processor will provide information on the safeguards applied to transfers of Data, omitting confidential information.
§ 12. Assistance with data subject rights
12.1. The Processor assists the Controller in fulfilling its obligation to respond to requests from data subjects (Articles 15 to 22 GDPR), primarily through the tools available in the Panel (Article 28(3)(e) GDPR):
- viewing Conversations, all Contact Form submissions (a list split into pages) and open Unanswered Questions (up to 100 at a time, in the Insights section);
- deleting individual Conversations and any Contact Form submission (owner and administrator) and individual open Unanswered Questions shown in the Panel (owner, administrator and editor); other Unanswered Questions, including those marked as ignored or resolved, are deleted by the Processor at the Controller's request under clause 12.3. Deleting an Unanswered Question does not delete a question-answer pair that the Controller created from it (the "Save as Q&A" function): its text forms part of the Materials and is deleted by deleting that source in the Panel, and its copy in the Assistant's internal quality test set is deleted by the Processor at the Controller's request under clause 12.3 or together with the Workspace;
- exporting Conversations in CSV or JSON format (owner and administrator);
- setting the Conversation retention period (30, 90 or 365 days or unlimited);
- deleting the Workspace.
12.2. The Controller acknowledges that the Visitor identifier is random, so locating a given person's Conversations may require obtaining additional information from that person (e.g. a date or an excerpt of the Conversation, or an external user identifier), and that the export in the Panel covers Conversations only; the Processor provides an export of Contact Form submissions and Unanswered Questions at the Controller's request under clause 12.3, through a secure download link as described in § 15.1 point 1.
12.3. If a request cannot be fulfilled using the Panel, the Processor, at the Controller's request sent by e-mail, assists it within a time that allows the time limits in Article 12(3) GDPR to be met.
12.4. If a data subject addresses a request directly to the Processor, the Processor forwards it to the Controller without delay, provided it can identify the Controller, and does not respond to it on the merits, except to inform that person that the request has been forwarded to the controller or should be addressed to the controller.
§ 13. Data Breaches
13.1. The Processor notifies the Controller of a Data Breach without undue delay and no later than 48 hours after becoming aware of it, by e-mail to the addresses of the Workspace owners and administrators and to the Workspace notification address, if one is set (§ 21.5 of the Terms).
13.2. The notification contains, as far as available, the information listed in Article 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and records concerned, contact details, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Information that cannot be provided at once is provided in phases without undue further delay.
13.3. The Processor documents Data Breaches, takes prompt measures to limit their effects and cooperates with the Controller in notifying the supervisory authority and data subjects.
§ 14. Assistance with impact assessments and consultations
14.1. Taking into account the nature of processing and the information available to it, the Processor assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (Article 28(3)(f) GDPR); in particular, it provides on request the information on processing, security measures and Sub-processors needed for a data protection impact assessment and for prior consultation with the supervisory authority.
14.2. The Processor informs the Controller of inspections and proceedings of the supervisory authority concerning the Data, unless prohibited by law.
§ 15. Deletion or return of Data
15.1. After the end of the provision of the Service, the Processor, at the choice of the Controller, returns or deletes the Data (Article 28(3)(g) GDPR):
- return: before deleting the Workspace, the Controller may itself export Conversations in the Panel (CSV or JSON). In addition, at the Controller's request made by e-mail before the Workspace is deleted or within 14 days of deletion of the Workspace or termination of the Agreement, the Processor will provide, within 14 days of the request, an export of Conversations, Contact Form submissions and Unanswered Questions (CSV or JSON) through a secure download link, not as an e-mail attachment. The link is valid for 7 days and the export file is deleted when it expires (§ 18.1 and 18.3 of the Terms);
- deletion: deleting the Workspace results in its immediate deactivation, and all Workspace Data (Conversations, Contact Form submissions, Unanswered Questions, Materials, configuration) is permanently deleted no later than 30 days after deletion. Data disappears from backups within the following 14 days, as the backups rotate. An export request made within the period in point 1 is fulfilled before those 30 days expire.
15.2. Auxiliary data expires automatically: query vectors in the cache after 7 days, queue jobs after 24 hours (completed) or 7 days (failed). Application logs do not contain Conversation content. Database diagnostic logs (slow queries) may exceptionally contain fragments of Data in query parameters; they are overwritten in line with container log rotation (3 files of 10 MB per service). Data transmitted to Sub-processors is deleted in accordance with those entities' terms; in particular, Resend, Inc. keeps sending logs, including the content of sent messages, for the retention period set out in its terms.
15.3. The deletion obligation does not apply to Data whose storage is required by Union or Member State law.
15.4. At the Controller's request, the Processor confirms deletion of the Data by e-mail.
§ 16. Information and audits
16.1. The Processor makes available to the Controller, at its request sent by e-mail, all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, within 30 days (Article 28(3)(h) GDPR).
16.2. The Controller, or an independent auditor mandated by it who is bound by confidentiality and is not a competitor of the Processor, may carry out an audit, including an inspection, no more than once every 12 months, at the Controller's cost, after notifying the Processor at least 30 days in advance. The audit takes place on business days, between 9:00 and 17:00 Polish time, in a manner that does not disrupt the Service and without access to other customers' data or to the Processor's trade secrets beyond the purpose of the audit.
16.3. An additional audit is permitted if required by a supervisory authority or following a Data Breach concerning the Controller.
16.4. Audits of the premises and systems of Sub-processors (including the data centre) are conducted by making available information, certifications and reports published or provided by those entities.
16.5. The Controller bears the costs of the audit, including the Processor's documented labour costs exceeding one business day; the costs of an audit under clause 16.3 are borne by each party itself. The Processor promptly informs the Controller of any non-compliance identified in the audit and how it will be remedied.
§ 17. Liability
17.1. The parties' liability under this DPA is governed by § 14 of the Terms, including the total liability cap common to the Agreement and this DPA.
17.2. This DPA does not limit the parties' liability towards data subjects (Article 82 GDPR) or administrative liability. Settlements between the parties in respect of compensation paid to a data subject take place in accordance with Article 82(5) GDPR, taking into account § 14 of the Terms.
§ 18. Final provisions
18.1. In matters concerning the processing of Data, this DPA prevails over the other provisions of the Terms.
18.2. This DPA may be amended under § 20 of the Terms, and the list of Sub-processors also under § 10.
18.3. This DPA is governed by Polish law. The Polish version is binding.
18.4. Annex A "List of sub-processors" and Annex B "Technical and organisational measures" form an integral part of this DPA.
Annex A. List of sub-processors
As at 1 October 2026. Items 1 to 5 follow the flow of Data in the Service; item 6 concerns technical maintenance and support. Sub-processors act on the basis of agreements concluded with them by the Processor (for item 3: by OpenRouter, Inc.), including standard contractual clauses where data leaves the EEA.
| No. | Entity | Scope of service | Data | Location | Transfer safeguard |
|---|---|---|---|---|---|
| 1 | OVH SAS, 2 rue Kellermann, 59100 Roubaix, France | hosting of the whole Service (server, database, backups) | all Service Data | data centre in Germany (EU) | not applicable (EEA) |
| 2 | OpenRouter, Inc., USA | gateway to AI Models (writing chat answers, "Suggest an answer" in the Panel, welcome message suggestion during initial setup) | Visitors' questions, the last messages of the Conversation, matching excerpts of the Customer's knowledge, public text of the Customer Website (initial setup) | USA | SCC |
| 3 | AI Model providers selected by OpenRouter for a given request (default model: Google Gemini; depending on the AI Model selected by the Customer also OpenAI, Anthropic or other providers available in OpenRouter); routing restricted to providers that, according to OpenRouter's classification, do not collect data from requests (OpenRouter setting data_collection: deny) | creating Answers | as in item 2 | USA and other countries | SCC or the provider's equivalent safeguards under Chapter V GDPR |
| 4 | CoinAxe Ltd (deAPI), Dragonara Business Centre, 5th Floor, Dragonara Road, St. Julians STJ 3141, Malta | computing embeddings (numeric vectors) used to search the knowledge base | excerpts of the Customer's content, Visitors' questions | EU (Malta) and a distributed network of GPU servers that may be located outside the EEA | SCC where Data leaves the EEA |
| 5 | Resend, Inc., USA | sending e-mail notifications of Contact Form submissions and Handovers | content of notifications (form fields, the last 10 messages of a Conversation); Resend keeps sending logs, including message content, for the period set out in its terms | sending infrastructure in the EU (Ireland, AWS), company in the USA | SCC |
| 6 | Anthropic, PBC, San Francisco, USA | AI tools supporting technical maintenance and support of the Service (diagnostics, server administration) | access to Service data only to the extent necessary for a specific maintenance or support task | USA | SCC (the provider's data processing terms) |
Annex B. Technical and organisational measures
This description reflects the state of the Service as at 1 October 2026.
B.1. Infrastructure
- The Service runs on an OVH server in a data centre in Germany (EU).
- A network firewall blocks incoming traffic by default; only traffic necessary for the operation of the Service is allowed.
- Application services listen only on the server's local interface and are reachable from outside only through the web server (nginx).
- Application secrets (provider keys, database passwords) are stored in environment variables, outside the code repository.
B.2. Encryption in transit
- Connections to the Panel, the Website, the Widget and the Widget file server are encrypted with TLS 1.2 or 1.3 (Let's Encrypt certificates).
- The Website and the Panel use the HSTS header, which enforces encrypted connections.
B.3. Authentication and access control to the Panel
- Registration only with an invitation code or on the basis of a valid team invitation.
- Passwords of at least 8 characters, stored only as a scrypt hash with a random salt.
- Login sessions valid for 7 days; expired sessions are deleted automatically no later than 2 days after expiry. The session cookie has the HttpOnly, Secure and SameSite=Lax attributes.
- Password reset and e-mail verification links are valid for 1 hour.
- Login attempt limit: 5 per minute from one IP address.
- Workspace roles (owner, administrator, editor, viewer); export and deletion of Conversations and submissions only for the owner and administrator; deletion of Unanswered Questions also for the editor.
- Security headers of the Panel and the Website: framing prohibited (X-Frame-Options DENY, frame-ancestors 'none'), X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin.
B.4. Customer data isolation
- The data of each Workspace is separated by the Row-Level Security mechanism of the PostgreSQL database, enforced on tables containing customer data; the application's database roles cannot bypass this mechanism.
- Isolation is verified by an automated test in the continuous integration process, run on every change to the main code branch and on every proposed change; a failure of this test stops the run.
B.5. Widget security and abuse protection
- The Widget works only on domains on the Workspace's list of allowed domains (Origin header verification).
- Optional identity verification of the Controller's logged-in users with an HMAC-SHA256 signature.
- Answer content is displayed without injecting raw HTML, which reduces the risk of XSS attacks.
- Excerpts of the Materials are passed to the AI Model as data marked as untrusted, which limits the effects of manipulation attempts.
- Limits: at the web server (chat 20 requests per minute per IP address), in the application (20 messages per 5 minutes per Visitor, 200 per 5 minutes per IP address, a daily usage cap per Assistant) and limits on Contact Form submissions (per Visitor, IP address and Assistant).
- The Crawler respects the robots.txt file and is protected against fetching addresses in internal networks (SSRF protection).
B.6. Data minimisation
- Only the Assistant's instructions, matching excerpts of the Materials, the question and the latest messages of the Conversation are passed to the AI Model; without the Visitor identifier, IP address, page address or Contact Form data.
- The Visitor identifier is random and not derived from personal data; the Widget does not use cookies.
- The Visitor's IP address is not stored in the database; request rate limits use only its hash with a secret value, kept for between 5 minutes and 2 hours.
- Application logs contain identifiers and counters, without Conversation content and without IP addresses; e-mail addresses in them are masked. Database diagnostic logs (slow queries) may exceptionally contain fragments of Data in query parameters; all these logs are overwritten in line with container log rotation (3 files of 10 MB per service).
- The Workspace event log records Users' actions (e.g. changes of roles and membership) without Conversation content, with masked e-mail addresses.
B.7. AI Models
- Requests to AI Models are routed only to providers that, according to OpenRouter's classification, do not collect data from requests (setting
data_collection: deny); providers may process requests for a limited time on the terms of their own agreements, e.g. to detect abuse. - The Processor does not train or fine-tune AI Models on the Data.
- The Widget always marks the conversation as conducted with AI (an "AI" badge that cannot be switched off and an information sentence that cannot be removed).
B.8. Retention and deletion
- Conversation retention period set by the Controller (30, 90 or 365 days or unlimited; 90 days by default), with daily automatic deletion.
- Deletion in the Panel of individual Conversations, any Contact Form submission and open Unanswered Questions shown in the Panel (up to 100 at a time); other Unanswered Questions at the Controller's request. Deleting an Unanswered Question does not delete a question-answer pair created from it, which is deleted together with that source of Materials (clause 12.1 point 2).
- Workspace deletion: immediate deactivation, permanent deletion of Data no later than after 30 days, deletion from backups within the following 14 days.
- Web server logs: 14 days. Query vectors in the cache: 7 days.
B.9. Backups
- A full database backup is made daily at 03:00 UTC and kept for 14 days.
- Backups are stored on the same server as the Service.
B.10. Organisational measures
- Administrative access to the server and the database is limited to persons authorised by the Processor and bound by confidentiality.
- Server administration is supported by AI tools (Annex A, item 6), used by authorised persons and under their supervision; those tools access Data only to the extent necessary for a specific maintenance or support task.
- Handling of Data Breaches in accordance with § 13 of this DPA.
- The Service code is covered by automated tests, including the customer data isolation test, run on every change to the main code branch and on every proposed change.
B.11. Limitations the Controller should be aware of
For a fair risk assessment (Article 32 GDPR), the Processor states that it currently:
- does not apply encryption at rest (the database and backups are not additionally encrypted);
- does not store backups in any location other than the Service server;
- does not offer two-factor authentication, and verification of a User's e-mail address is not required;
- does not automatically remove or mask personal data in Conversation content, so data entered by a Visitor reaches AI Models and the vector computation unchanged;
- gives all Workspace roles, including the viewer role, access to the full content of Conversations;
- uses, for technical maintenance and support, AI tools of a provider established in the USA (Annex A, item 6), which may access Data in the course of a specific task.