Version 2026-09-23
Data Processing Agreement
Version 2026-09-23, under Article 28 of Regulation (EU) 2016/679 ("GDPR"). It forms part of the Terms and is accepted with them, in electronic form (Article 28(9) GDPR). This is a translation: if it differs from the Italian version, the Italian version prevails.
1. Parties and roles
1.1 Controller: the Customer, identified by the data entered at registration.
1.2 Processor: Federico De Cillia, sole proprietorship GPT Chatbot di Federico De Cillia, Via Ernesto Teodoro Moneta 50, 20161 Milan, Italy, VAT IT13990330964, email info@flylabs.ai, certified email (PEC) federico.decillia@spidmail.it (the "Processor").
1.3 Reviews are published by data subjects on third-party platforms (Google, TripAdvisor, Booking.com and others), which are independent controllers. This Agreement covers the collection, storage and processing of that content on the Controller's behalf.
1.4 If this Agreement conflicts with the Terms on data protection, this Agreement prevails.
2. Subject matter, duration, instructions
2.1 The Processor processes personal data on the Controller's behalf only to provide the service described in Annex A, for the term of the contract and until the deletion set out in section 10.
2.2 The Terms, the account configuration and this Agreement are the Controller's documented instructions. Further instructions are given by email to info@flylabs.ai.
2.3 The Processor promptly informs the Controller if it believes an instruction infringes the law, and may suspend it until clarified.
3. Categories of data
3.1 Data subjects, data and operations are described in Annex A.
3.2 The Processor does not knowingly process special categories of data (Article 9 GDPR). The freely written text of a review may incidentally contain them (health, diet, family). The Processor does not extract them, does not use them as a processing criterion and applies the same security measures to them.
4. Processor obligations
The Processor:
- a) processes the data only on the Controller's documented instructions, including for transfers to third countries, unless required by law, in which case it informs the Controller where the law allows;
- b) ensures that persons processing the data are bound by confidentiality;
- c) takes the measures under Article 32 GDPR described in Annex B;
- d) engages sub-processors only under the conditions of section 7;
- e) assists the Controller in responding to data subject requests (section 6);
- f) assists the Controller with the obligations under Articles 32-36 GDPR, taking into account the nature of the processing and the information available;
- g) at the end of the service deletes or returns the data under section 10;
- h) makes available to the Controller the information needed to demonstrate compliance with Article 28 GDPR and allows the audits in section 11.
5. Personal data breaches
5.1 The Processor notifies the Controller of any personal data breach without undue delay and, where possible, within 48 hours of becoming aware of it, stating the nature of the breach, categories and approximate number of data subjects and records, likely consequences and measures taken or proposed. If not all information is available at once, it may be provided in phases.
5.2 Notification to the supervisory authority and to data subjects remains with the Controller; the Processor assists.
6. Data subject rights
6.1 If a data subject contacts the Processor, the Processor forwards the request to the Controller without undue delay and does not answer it on the merits by itself.
6.2 At the Controller's request, within 30 days, the Processor extracts, rectifies or deletes a data subject's data in its systems and, for deleted reviews, prevents their re-collection in later synchronisations (exclusion list).
6.3 The Processor does not control the platforms: deleting a review from its systems does not remove it from the original platform.
7. Sub-processors
7.1 The Controller gives general authorisation to engage the sub-processors listed in Annex C, also published on this page.
7.2 The Processor binds sub-processors by contract to data protection obligations no less strict than this Agreement and remains liable to the Controller for their performance.
7.3 The Processor gives at least 30 days' notice by email of any addition or replacement of a sub-processor. The Controller may object on data protection grounds within the same period; if no solution is found, it may withdraw at no cost, with a refund through Link of the unused part of the Plan.
8. Transfers outside the European Economic Area
Transfers to third countries take place only on the basis of an adequacy decision (including the EU-US Data Privacy Framework for certified providers) or of the Commission's Standard Contractual Clauses, as indicated for each sub-processor in Annex C.
9. Processing by the Processor as an independent controller
For transparency, the Processor is an independent controller, and does not act on the Controller's behalf, for:
- a) account and User data, security and logs, as described in the Privacy Notice;
- b) the register of generated drafts and their non-reversible fingerprints, kept to comply with Article 50 of Regulation (EU) 2024/1689 (AI Act): they contain only codes computed from the text, the model used and the date, not the text or readable guest data, and are kept for 5 years, also after the end of the contract;
- c) aggregate statistics about the service that do not relate to identified or identifiable individuals.
The Processor does not use guest data for other purposes of its own, does not disclose it and does not use it to train third-party models. Examples of the Controller's replies are used to improve the service only after documented anonymisation that removes names and stay details.
10. End of contract
10.1 At the end of the contract the Controller may request, within 30 days, the return of the data in a structured, commonly used format (CSV or JSON).
10.2 After 30 days from the end of the contract the Processor deletes the data, including copies, except for retention required by law and except as set out in section 9. Backups managed by the database provider are overwritten in their cycle, and in any case within 90 days.
11. Audits
11.1 The Processor answers the Controller's requests for information about compliance with this Agreement, including by providing documentation and sub-processors' certifications.
11.2 If documentation is not enough, the Controller may carry out an audit, also through an auditor bound by confidentiality, no more than once a year unless a breach has been established or an authority requests it, with 30 days' notice, during business hours and at its own cost.
12. Liability, law and jurisdiction
Liability follows Article 82 GDPR and the Terms. Law and jurisdiction are those of the Terms.
Annex A: description of the processing
| Item | Content |
|---|---|
| Purposes | Collect the reviews published on the Controller's listings; show and translate them; prepare replies in the Controller's tone; recognise published replies; statistics for the Controller |
| Operations | Collection, recording, organisation, storage, consultation, automated processing (draft generation), erasure |
| Data subjects | Authors of reviews on the Controller's listings; people named in reviews or replies |
| Data | Public name or pseudonym, location if any, review text and its translation, rating, publication and stay dates, language, trip type, public link, manager's reply and related draft |
| Source | Public platforms, through a data extraction service |
| Automated decisions | None with effects on data subjects: drafts are proposals and publishing is done by the Controller |
| Duration | For the term of the contract, then section 10. The raw content returned by extraction is kept for the term of the contract |
| Minors | Not addressed; possible incidental mention by an adult |
Annex B: technical and organisational measures
Measures in place at the date of this version.
Access and separation between customers
- Access to the service through a single-use link sent by email; signed sessions.
- Every query is limited to the user's customer; integrity constraints in the database (composite customer and record keys) prevent associating data with a different customer.
- Application and engine use a database role without ownership privileges and without the ability to change the schema; administration credentials are held only by the Processor.
- Internal endpoints (engine, scheduled jobs) protected by a secret; preview environments protected by authentication.
Encryption and location
- TLS on all communications, including to the database.
- Encryption at rest of the managed database.
- Database and application functions in the European Union (Frankfurt).
Continuity
- Point-in-time database recovery, within the window offered by the provider.
- Persistent work queue with retries: a temporary provider failure does not lose data.
Control and monitoring
- Spending caps and an emergency switch on the engine.
- Automatic daily anomaly check, with email alerts to the Processor.
- Secrets kept only in the providers' configuration systems, never in the code.
Minimisation
- No guest emails, phone numbers or payment data are collected.
- AI models receive only the review and the property context needed for the draft; the model provider does not use them for training.
Organisational
- A single operator of the Processor with access to the data, bound by confidentiality.
- Record of processing activities; breach handling procedure.
Planned (before public registration opens; this annex will be updated when they are in place): row-level isolation in the database (RLS), log of sensitive actions, export and deletion from the app, periodic deletion of raw content.
Annex C: sub-processors
| Provider | Service | Data location | Transfer safeguard |
|---|---|---|---|
| Apify Technologies s.r.o. (Czech Republic) | Extraction of reviews from platforms | EU | No transfer |
| Anthropic Ireland Ltd (Ireland) | AI model for drafts and translations | EU and USA | Standard Contractual Clauses; data kept 30 days, not used for training |
| Neon Inc. (USA) | Managed database | EU (Frankfurt, AWS) | Standard Contractual Clauses |
| Vercel Inc. (USA) | Hosting of the application and engine | Functions in the EU (Frankfurt); global delivery network | Data Privacy Framework and Standard Contractual Clauses |
| Plus Five Five Inc., "Resend" (USA) | Sign-in and notification emails | USA | Data Privacy Framework and Standard Contractual Clauses |