Data Processing Agreement (DPA)
Version date: 10 September 2026
Effective date: 10 September 2026
Permanent URL: https://findlee.com.ua/dpa/?lang=en
This Data Processing Agreement (“DPA”) forms part of the agreement governing the Findlee platform (“Main Agreement”) between:
- the Customer identified in the Order or account; and
- individual entrepreneur Denis Dmytrovych Apekin, Ukrainian taxpayer registration number 3312916352, country of state registration: Ukraine, email: welcome@nextdoorcoders.com (“Findlee”).
This DPA prevails in the event of a conflict concerning the processing of personal data. Applicable EU Standard Contractual Clauses (“SCCs”) prevail in respect of the relevant international transfer.
1. Definitions and Roles
1.1. Applicable Data Protection Law means the Law of Ukraine “On Personal Data Protection”, the GDPR where applicable, and other mandatory rules governing processing under the Main Agreement.
1.2. Customer Data means personal data processed by Findlee on behalf of the Customer through the Service.
1.3. Personal Data Incident means a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data.
1.4. Subprocessor means a third party engaged by Findlee to process Customer Data on behalf of the Customer.
1.5. For Customer Data, the Customer, including an individual who determines the purposes and means of processing Visitors’ data on their public Resource, is the owner/controller and Findlee is the processor. Where the Customer is itself a processor for another controller, Findlee acts as subprocessor and the Customer confirms that it is authorised to issue these instructions. This DPA applies only to processing governed by data-protection law; the individual’s own account data is governed by the Findlee Privacy Policy.
1.6. Each party is a separate controller of data relating to its own representatives, contracts, payments, security and business communications. Such processing is governed by that party’s privacy policy rather than this DPA.
1.7. Customer Account means the Customer’s segregated environment within the Service to which its settings, users and Customer Data are linked.
2. Subject Matter and Instructions
2.1. The subject matter, duration, nature and purpose of processing, types of data and categories of data subjects are set out in the Main Agreement and Schedule 1.
2.2. Findlee processes Customer Data only:
- on the Customer’s documented instructions;
- to provide, secure, support and terminate the Service;
- for transfers expressly authorised by the Main Agreement, Customer settings, this DPA or a separate written instruction;
- where processing is required by law. In that event, Findlee will notify the Customer of the requirement before processing, unless law prohibits notification for important grounds of public interest.
2.3. The Main Agreement, this DPA, Customer-enabled features and settings constitute documented instructions. An additional instruction must be in writing, lawful, technically feasible and related to the Service. Where it requires material additional work or expense, the parties will first agree the scope, timetable and fee.
2.4. If Findlee reasonably believes an instruction infringes Applicable Data Protection Law, it will promptly notify the Customer and may suspend the relevant operation pending clarification. This is not a definitive legal opinion replacing the Customer’s own assessment.
2.5. Findlee does not sell Customer Data, use it for independent advertising, or use it to train its own general-purpose model or a publicly available third-party model without a separate, specific written instruction and an appropriate legal basis.
3. Customer Obligations
3.1. The Customer is responsible for:
- the lawfulness of collecting and transferring Customer Data and of its instructions;
- an appropriate legal basis, transparent notices and fulfilment of data-subject rights;
- consent for optional cookies and similar technologies where required;
- data quality, accuracy, minimisation and retention settings;
- lawful authority over data received from another controller;
- the lawful selection of a BYOK AI provider, region and processing terms;
- preventing prohibited or excessive data from being submitted.
3.2. Without Findlee’s prior written approval, the Customer must not upload special-category data, medical, biometric or genetic data, criminal-conviction data, precise payment credentials, government identifiers or children’s data unless the Service has been separately assessed and configured for that processing.
3.3. The Customer’s responsibilities do not release Findlee from its own statutory processor obligations.
4. Confidentiality and Personnel
4.1. Customer Data may be accessed only by persons who need it for defined functions and only to the minimum extent required.
4.2. Findlee ensures that such persons are bound by contractual or statutory confidentiality obligations and receive appropriate security and privacy instructions.
4.3. Confidentiality obligations survive termination of access or engagement.
5. Security of Processing
5.1. Findlee implements and maintains appropriate technical and organisational measures, taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as risks to individuals. The current minimum measures are described in Schedule 2.
5.2. Findlee may improve those measures provided that the overall level of protection is not materially reduced. Material changes that reduce protection of Customer Data require advance notice and, where required by law, agreement.
5.3. The Customer is responsible for secure use of the Service, its devices, role management, integration settings and protection of its BYOK account. Findlee is responsible for components under its control. Two-factor authentication is not available in the current version of the Service, and this DPA does not require the Customer to use an unavailable feature.
6. Subprocessors
6.1. The Customer gives general written authorisation for Findlee to engage the following Subprocessors:
| Subprocessor | Function | Data | Processing location |
|---|---|---|---|
| Contabo GmbH | server infrastructure, database, search system and file storage | Customer Data hosted in the Service | EU region |
| OpenAI, L.L.C. and/or OpenAI Ireland Limited, depending on the account and applicable terms | generation of AI responses in Casual mode | query, instructions and required knowledge-base or catalogue context | EEA, United States and other regions according to the product and settings |
| Anthropic, PBC and/or the applicable affiliate | generation of AI responses in Casual mode | query, instructions and required knowledge-base or catalogue context | EEA, United States and other regions according to the product and settings |
| Google LLC and/or Google Ireland Limited, depending on the account and applicable terms | generation of Gemini AI responses in Casual mode | query, instructions and required knowledge-base or catalogue context | EEA, United States and other regions according to the product and settings |
Providers connected directly by the Customer through BYOK or the Customer’s own Meta, Telegram, eSputnik, SMTP or webhook accounts are Customer-selected recipients acting on its documented instruction, rather than Subprocessors independently added by Findlee to Casual mode.
6.2. Findlee enters into written terms with each Subprocessor that impose data-protection obligations no less protective than the applicable obligations in this DPA. Findlee remains responsible to the Customer for the Subprocessor’s performance to the extent required by law and the Main Agreement.
6.3. Findlee keeps this list current. Where the GDPR applies or other law requires an opportunity to object, Findlee will notify the Customer by email and/or through the dashboard of an intended addition or replacement at least 15 calendar days before the Subprocessor begins processing Customer Data.
6.4. During that period, the Customer may object on documented and reasonable data-protection grounds. The parties will seek a reasonable solution in good faith, such as an alternative configuration. If no solution is available and the Subprocessor is objectively required for a feature, the Customer may discontinue that feature before processing begins or, where the Service would otherwise lose its principal value, terminate the Main Agreement and receive a pro-rata refund of prepaid fees for the unused post-termination period. This does not apply to a provider selected by the Customer through BYOK.
7. BYOK and AI Providers
7.1. In Casual mode, an AI provider selected by Findlee is a Findlee Subprocessor and is governed by Section 6.
7.2. In BYOK mode, the Customer selects the provider, creates an account and accepts its terms. To the extent Findlee merely routes data to that provider according to the Customer’s configuration, the transfer is made on the Customer’s instruction. The Customer reviews the legal basis, region, transfer mechanism, retention and provider data-use settings.
7.3. Findlee does not conceal available settings that materially affect privacy and provides reasonable information about the technical data flow. Findlee is not responsible for independent actions of a BYOK provider beyond its control, but remains responsible for secure storage and use of the key within Findlee systems.
8. Assistance with Data-Subject Rights
8.1. Taking into account the nature of processing, Findlee will assist the Customer through available technical and organisational measures with lawful requests for access, rectification, erasure, restriction, objection, portability and automated-decision rights.
8.2. If Findlee receives a request directly concerning Customer Data, it will notify the Customer without undue delay and will not respond substantively except to direct the person to the Customer or where otherwise required by law.
8.3. The Customer may use available interface functions to delete individual conversations, leads, orders, the catalogue, keys or integrations. Complete deletion of a Customer Account is performed by Findlee following a request to welcome@nextdoorcoders.com and verification of identity and authority. Material additional manual assistance for other requests may be charged at a rate agreed in advance unless the need arises from Findlee’s breach or a mandatory legal obligation.
9. Personal Data Incidents
9.1. Findlee will notify the Customer of a confirmed Personal Data Incident without undue delay after becoming aware of it and aims to provide the initial notification within 48 hours where reasonably possible on the available information.
9.2. Initial or subsequent notifications will, to the extent available, describe:
- the nature of the incident and known categories and approximate numbers of data subjects and records;
- the name and contact details of the responsible contact;
- likely consequences;
- measures taken or planned to contain, remedy and mitigate harm.
Information may be provided in phases without further undue delay.
9.3. Findlee takes reasonable measures to contain, investigate, remedy and document the incident and cooperates with the Customer regarding its notifications to authorities and data subjects.
9.4. A notification is not an admission of fault or liability. Findlee will not notify an authority or data subject on the Customer’s behalf without instruction unless directly required by law.
9.5. The GDPR’s 72-hour period for a controller’s notification to a supervisory authority does not replace the processor’s duty to notify the controller without undue delay.
10. Impact Assessments and Consultations
Taking into account the nature of processing and information available to it, Findlee provides reasonable assistance with:
- data protection impact assessments;
- prior consultation with a supervisory authority;
- security and breach-notification obligations.
Material assistance beyond standard information may be charged by prior agreement unless required due to Findlee’s breach.
11. International Transfers
11.1. Findlee does not transfer Customer Data across national borders unless authorised by the Main Agreement, this DPA, the Subprocessor list, Customer settings or a separate instruction, and unless the mechanism required by law is in place.
11.2. Transfers governed by Ukrainian law are handled in accordance with Article 29 of the Law of Ukraine “On Personal Data Protection”.
11.3. Where the GDPR applies and Customer Data is transferred from the EEA to Findlee or a Subprocessor in a country without an adequacy decision, the parties will execute the SCCs approved by European Commission Implementing Decision (EU) 2021/914 before that transfer in accordance with Schedule 3:
- Module 2 where the Customer is controller and Findlee is processor;
- Module 3 where the Customer is processor and Findlee is subprocessor;
- Module 1 or 4 only where the actual roles of a particular transfer require it and the parties complete the relevant terms.
11.4. Where necessary, the parties document a transfer impact assessment and implement supplementary technical, contractual or organisational measures. Findlee will provide reasonably available information required for that assessment.
11.5. If a transfer mechanism becomes invalid, the parties will in good faith implement a lawful replacement. Until then, Findlee may suspend the relevant transfer or feature where it cannot operate lawfully.
12. Public Authority Requests
12.1. Findlee verifies the formal validity of a binding request and discloses only the minimum necessary data.
12.2. Unless prohibited, Findlee will notify the Customer before disclosure. Where notification is prohibited, Findlee will make reasonable efforts to obtain permission to notify.
12.3. Where a request is manifestly unlawful or disproportionate and reasonable means of challenge are available, Findlee will assess such challenge having regard to law and associated risks.
13. Retention and Deletion
13.1. The Service does not provide a general Customer Data export feature. Findlee does not provide standard exports of conversations, catalogues, leads, orders or the Customer’s entire database. Where Article 28(3)(g) GDPR or another mandatory obligation to return personal data applies to the processing, the Customer may contact welcome@nextdoorcoders.com before deletion and choose deletion or return of the relevant personal data. The parties agree the scope, format and technically available return method before such processing begins. After return, Findlee deletes existing copies unless applicable law requires their continued storage. This clause does not create a general data export feature in the Service.
13.2. Following expiry of the most recent access term provided, Findlee may make the Customer Account inactive and retain its associated Customer Data in the active environment for up to 180 calendar days solely to permit renewed use. Conversations and related files may be deleted earlier under the separate 60-day inactivity period.
13.3. The Customer Account owner may request earlier complete deletion by emailing welcome@nextdoorcoders.com from the associated email address. Findlee may verify identity, authority and acknowledgement of irreversible consequences. After 180 days without renewal, Findlee deletes the Customer Account and its associated data from active systems following the warnings described in the Main Agreement, except where law requires specific records to be kept longer.
13.4. Findlee may retain the minimum data expressly required by law. Such data will be isolated, not used for other purposes and deleted after the mandatory period.
13.5. On written request, Findlee will confirm completion of deletion where technically and legally possible.
14. Information, Audits and Evidence of Compliance
14.1. Findlee provides information reasonably necessary to demonstrate compliance with this DPA, initially through current policies, security questionnaires, independent-review reports or certifications where available.
14.2. If those materials are insufficient for a justified requirement, the Customer may conduct a documentary audit no more than once in any 12-month period through an independent auditor bound by confidentiality, on at least 30 days’ written notice, during working hours and without access to other customers’ data or secrets unnecessary for the audit.
14.3. A more frequent or on-site audit is permitted following a material incident, where required by an authority, or where earlier materials objectively do not permit verification.
14.4. The Customer bears its own and Findlee’s reasonable additional audit costs unless the audit establishes a material Findlee breach, in which case Findlee bears its own costs and reimburses reasonable verification costs subject to the Main Agreement.
14.5. Audit results are confidential except for disclosure to a competent authority or professional adviser subject to confidentiality.
15. Liability
15.1. In dealings with a Business Customer, all claims against Findlee arising under this DPA or in connection with the processing of Customer Data are included within Findlee’s general liability limit under clause 18.5 of the Main Agreement and do not create a separate or additional liability limit. Exclusions and limitations apply subject to clauses 18.3 to 18.8 of the Main Agreement. For a consumer Customer, they apply only to the extent they do not restrict mandatory rights.
15.2. Nothing limits a data subject’s or consumer’s rights, a supervisory authority’s powers, or liability that cannot lawfully be limited, nor does it alter the parties’ liability to data subjects under the GDPR.
15.3. As between the parties, liability is allocated according to each party’s contribution to the harm, breach and applicable law.
16. Term and Termination
16.1. This DPA applies from the time Findlee begins processing Customer Data until it is returned, deleted or anonymised.
16.2. A DPA amendment that materially affects Customer rights or instructions will be notified directly in advance. Merely posting a new version on the website is not sufficient notice of a material change to mandatory processing terms.
16.3. Confidentiality, deletion, audit, transfer and liability provisions survive to the extent necessary after termination.
17. Governing Law and Priority
17.1. The governing law and dispute process of the Main Agreement apply to this DPA unless the SCCs or a mandatory rule provide otherwise.
17.2. In the event of conflict, the following priority applies: (1) the SCCs for the relevant transfer; (2) this DPA; (3) the Main Agreement; and (4) other documents.
SCHEDULE 1. DESCRIPTION OF PROCESSING
| Item | Description |
|---|---|
| Subject matter | provision of an AI assistant for search and navigation, knowledge-base answers, consultations, comparisons, recommendations, collection of enquiries and interaction with Customer content and, where applicable, catalogue data, together with integrations, analytics and support |
| Duration | term of the Main Agreement plus the retention and deletion period under Section 13 |
| Nature of operations | collection, recording, organisation, structuring, storage, retrieval, analysis, transmission to properly engaged providers, display, restriction, deletion and anonymisation |
| Purpose | provision, security, support and improvement of Customer functionality without training a general-purpose model on Customer Data |
| Data subjects | Visitors and users of the Customer’s website, application or other digital resource; applicants, leads, buyers, Dashboard Users, Customer employees and contractors; other categories only under an agreed configuration |
| Data | request and conversation text, responses, images for search, random widget session identifier, hashed technical fingerprint, clicks, page and material views, search and navigation actions, comparisons, conversions, lead contact details, pages, documents, knowledge-base content, other context and, where applicable, catalogue, cart and order data, logs and metadata; a Visitor’s IP address and User-Agent are used to generate the fingerprint but are not stored in plain text in the conversation history |
| Special categories | not intended and prohibited without prior written approval and separate safeguards |
| Frequency | continuously or in response to requests during use of the Service |
| Processing locations | Contabo infrastructure in the EU region; Ukraine; for AI features, the relevant provider regions described in Sections 6, 7 and 11 |
| Customer contact | Customer Account administrator email or another contact stated in the Order |
| Findlee contact | welcome@nextdoorcoders.com |
SCHEDULE 2. TECHNICAL AND ORGANISATIONAL MEASURES
The following measures describe the current version of the Service. They may be improved without materially reducing the overall level of protection.
- Access management: access to administrative and production components is restricted to authorised roles; Customer access is segregated by Customer Account; unnecessary access is revoked. Two-factor authentication is not implemented in the current version.
- Transmission security: public web interfaces and data transfers to them use HTTPS/TLS. The specific protocol version depends on current server and client configuration.
- Passwords and secrets: passwords are stored as irreversible hashes. BYOK keys and integration credentials are encrypted at application level.
- BYOK: after saving, the full key is not returned to the browser; only a masked value is displayed. A key can be replaced or deleted. Full keys are excluded from the permitted context of payment and application logs.
- Segregation: access is checked by user, role and Customer Account; requests are restricted by the applicable Customer Account identifier.
- Images: new conversation images are stored privately and served through an authorised route to the relevant Customer or Visitor session. A foreign or empty identifier does not grant access.
- Logging: application logs are retained for 14 days; web-server logs rotate by volume. Full LiqPay payloads, payment signatures, card data and complete BYOK keys are intentionally excluded from logs. There is no separate complete log of login and privileged actions.
- Monitoring and restrictions: emergency technical failures are monitored with automatic team notification; suspicious requests and rate-limit violations are blocked. There is no separate notification system for every suspicious login attempt.
- Environments and development: production access is limited to persons with a technical need; production debug is disabled; testing should not use real data unless necessary and authorised.
- Deletion: conversations and related files are automatically deleted after 60 days of inactivity; manual conversation deletion removes its images immediately. Complete Customer Account deletion covers the primary database, search data, catalogue and associated files.
- Sessions: a dashboard login session remains active for up to 12 hours of inactivity. A Visitor session identifier is stored in a cookie for 30 days and may be renewed, and in localStorage until cleared by the browser or user; after server history is deleted it is no longer linked to a conversation.
- Incidents: confirmed incidents are contained, investigated and reported to the Customer in accordance with Section 9.
- Subprocessors: providers are engaged for defined functions and changes to the list are controlled in accordance with Section 6.
- Physical infrastructure: data-centre physical security is provided by Contabo; Findlee manages logical access to the rented server infrastructure.
This DPA does not guarantee a separate backup system, a particular RPO/RTO, ISO/SOC 2 certification or full-disk encryption unless and until the relevant measure has actually been implemented and verified.
SCHEDULE 3. INTERNATIONAL TRANSFERS AND SCCs
- This DPA does not itself complete the variable provisions of the SCCs and does not represent that SCCs have already been executed for every Customer or data route.
- Before the first transfer requiring SCCs under the GDPR, the parties will determine the actual roles, Module 2 or 3, parties and contacts, transfer description and frequency, competent supervisory authority, applicable law of an EU Member State, courts, Subprocessors and supplementary measures.
- Once completed, the SCCs approved by European Commission Implementing Decision (EU) 2021/914 apply and prevail for the relevant transfer in the event of conflict.
- If an appropriate mechanism has not been completed, Findlee may decline to activate or may suspend the relevant feature or transfer route until it is lawfully established.
Electronic Acceptance
This DPA forms an integral part of the Main Agreement and is accepted together with it through an Order, payment interface, other electronic confirmation or signature by the parties. Unless otherwise agreed in writing, the version published at the permanent URL at the time the Main Agreement is accepted applies.