How we process data on the customer’s behalf.
This Addendum applies where SOVRAS processes Customer Data on a company’s behalf. It forms part of the Terms of Service and of the contract entered into with the customer.
Updated September 16, 2026Scope and roles of the parties
This Data Processing Addendum (“Addendum” or “DPA”) applies to the processing of personal data contained in Customer Data that SOVRAS IO SpA (“SOVRAS”) carries out on behalf of a business customer (“Customer”) when delivering the Services described in the Terms of Service.
In respect of that data, the Customer acts as controller — or, where applicable, as processor for a third-party controller — and SOVRAS acts as processor or service provider, under the terminology of the applicable law.
Processing for which SOVRAS is the controller — accounts, billing, security, the commercial relationship — is governed by the Privacy Policy and not by this Addendum.
This Addendum is incorporated into the contract between the parties. Where this Addendum conflicts with the Terms of Service in respect of the processing of personal data, this Addendum prevails, unless a signed enterprise agreement expressly provides otherwise.
Customer instructions
SOVRAS will process Customer Data only on the Customer’s documented instructions, which include the contract, this Addendum, the order forms, and the configuration the Customer defines in the platform: agents, prompts, permissions, channels, integrations, escalation rules and knowledge bases.
SOVRAS may depart from those instructions only where applicable law requires it; in that case it will inform the Customer before processing, unless the law itself prohibits doing so.
SOVRAS will inform the Customer if, in its reasonable opinion, an instruction infringes applicable data protection law.
The Customer is responsible for the lawfulness of the instructions it gives, for holding the necessary legal bases, notices and consents, and for not instructing the processing of data categories for which no specific safeguards have been agreed.
Personnel confidentiality
SOVRAS limits access to Customer Data to personnel who need it to deliver the Services, meet legal obligations or handle the Customer’s own support requests.
That personnel is bound by contractual or statutory confidentiality obligations that survive the end of the relationship.
Security measures
SOVRAS implements and maintains the technical and organizational measures described in Annex II, designed to ensure a level of security appropriate to the risk.
SOVRAS may update those measures provided this does not materially reduce the agreed level of protection.
The Customer is responsible for the security configuration under its control: user and permission management, protecting its credentials, defining what actions each agent may execute, and which operations require human approval.
Subprocessors
The Customer grants SOVRAS general authorization to engage subprocessors in delivering the Services.
The current subprocessor list, organized by function, is published at sovras.io/en/subprocesadores. SOVRAS will provide any Customer that requests it with the register naming each subprocessor, subject to confidentiality. SOVRAS will give reasonable advance notice of the addition or replacement of a subprocessor to customers who subscribe to change notifications by writing to contacto@sovras.io.
The Customer may object on reasonable data protection grounds within the period stated in the notice. If the parties cannot reach a solution, the Customer may terminate the affected service without penalty.
SOVRAS enters into data protection obligations with each subprocessor that are substantially equivalent to those in this Addendum, and remains liable to the Customer for their performance to the same extent as for its own.
Assistance with data subject rights
Taking into account the nature of the processing, SOVRAS will assist the Customer with appropriate technical and organizational measures so that it can handle access, rectification, deletion, objection, restriction or portability requests it receives from data subjects.
If SOVRAS receives a data subject request relating to Customer Data directly, it will not respond on the merits and will refer it to the Customer, unless the law provides otherwise.
SOVRAS will also reasonably assist the Customer with impact assessments and prior consultations with authorities, where applicable and in relation to the Services.
Security incidents
SOVRAS will notify the Customer without undue delay after becoming aware of a security breach affecting Customer Data.
The notification will describe, to the extent the information is available, the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed.
SOVRAS will cooperate reasonably with the Customer so it can meet its own notification obligations to authorities and data subjects. A notification by SOVRAS is not an acknowledgement of fault or liability.
Return and deletion
During the term of the Service, the Customer may access, export, correct and delete Customer Data using the features available in the platform, its APIs, or a request to SOVRAS.
On termination of the Service, and at the Customer’s election, SOVRAS will return or delete Customer Data within a reasonable period, unless applicable law requires it to be retained.
Copies held in backups are deleted in line with normal rotation cycles. Until deleted, they remain subject to this Addendum.
Detailed instructions are at Data deletion.
Audit and demonstration of compliance
SOVRAS will make available to the Customer the information reasonably necessary to demonstrate compliance with this Addendum, including documentation of the measures in Annex II and, where they exist, third-party reports or certifications.
Where that information is not sufficient, the Customer may request an audit on reasonable notice, during business hours, without disrupting operations, no more than once a year unless required by an authority or following a security incident, subject to confidentiality and at the Customer’s cost.
International transfers
SOVRAS and its subprocessors may process Customer Data in Chile and in other countries where the providers needed to deliver the Service operate. The location of each subcontracted function is stated in the published list.
Where the law applicable to a processing activity requires a specific mechanism for international transfer — standard contractual clauses, an adequacy decision or another — the parties will enter into it, or SOVRAS will evidence that the mechanism is in place for the relevant provider.
Annex I · Description of the processing
| Subject matter | Delivery of the SOVRAS Services: operation of artificial intelligence agents over the channels, systems and information the Customer connects and configures. |
|---|---|
| Duration | The term of the contract, plus the return or deletion period set out in this Addendum. |
| Nature and purpose | Receipt, storage, structuring, retrieval, transmission, transformation, response generation, execution of authorized actions, and recording of evidence and traceability, in line with the Customer’s configuration. |
| Categories of data subjects | Customers, prospects, end users, suppliers, patients or guests depending on the Customer’s industry, and the Customer’s own employees or authorized users. |
| Categories of data | Identification and contact data; message and conversation content; audio, recordings and transcripts where the voice channel is enabled; documents and files; operational records such as orders, quotes, cases, bookings, payments, statuses and dates; technical and platform identifiers. |
| Special categories | Not contemplated by default. Processing them requires a prior specific agreement defining the additional safeguards that apply. |
| Frequency | Continuous, while the Service is active. |
Annex II · Technical and organizational measures
Access control
- Logical segregation of information by organization.
- User authentication and role- and permission-based access control.
- Least privilege for SOVRAS personnel.
- Revocation of access at the end of the relationship or the role.
Protecting the information
- Encryption in transit over TLS across web surfaces, APIs and webhooks.
- Encryption at rest supported by the infrastructure used.
- Integration credentials and secrets stored in encrypted stores, separate from code and from visible configuration.
- Secrets are not written to logs or exposed in the interfaces.
Operations and continuity
- Backup and recovery of platform information.
- Monitoring of availability, errors and security signals.
- Change and release management with the ability to roll back.
- Audit records of the actions executed by agents and by users.
Agent governance
- Explicit definition of what actions each agent may execute.
- Configurable human approval for the operations the Customer determines.
- Evidence and traceability for every action executed.
- Testing and evaluation of agents before they go into production.
Organization
- Confidentiality obligations for personnel with access.
- Incident response procedure and notification to the Customer.
- Vendor assessment before engaging them as subprocessors.
- Periodic review of access and permissions.
Signing this Addendum and contact
This Addendum is deemed incorporated into the Customer’s contract. If your organization needs a signed copy, the subprocessor register, the detail of the security measures, or a specific international transfer mechanism, write to contacto@sovras.io stating the organization and the requirement.
SOVRAS IO SpA
Email: contacto@sovras.io
Website: sovras.io
