Ce document est disponible en espagnol (version qui prévaut) et en anglais.
Data processing agreement
How Dona processes the data of your customers when it serves your business: Dona is the processor, you are the controller.
1. Parties and purpose
This agreement is part of the Terms of service and governs the processing of personal data that Dona IA ("Dona", processor) performs on behalf of the Customer (controller) when providing the Service, under sec. 25 of Argentine Law 25,326 and, where applicable, Article 28 of the GDPR.
2. Data and data subjects
Data subjects: people who contact the Customer through the channels Dona handles (its customers and prospects) and the Customer's users.
Data: name, phone, email, message content, audio and calls (and their transcripts), bookings, orders, notes and any other data the Customer chooses to record in the CRM. The Customer must not configure the Service to collect sensitive data (health, racial or ethnic origin, political opinions, religious beliefs, sex life) unless it has a legal basis and has agreed it with Dona in advance.
Purpose: handling the Customer's communications, managing bookings, orders and sales follow-up, and the other Service features the Customer enables.
3. Dona's obligations
Process the data only on the Customer's documented instructions (the Service configuration and this agreement), never for its own purposes.
Not use the data to train AI models.
Ensure the confidentiality of staff with access, limited to those who need it.
Apply the measures described in the Security policy.
Assist the Customer in responding to data subject requests and with impact assessments where applicable.
Notify the Customer of any security incident affecting its data without undue delay and, where possible, within 48 hours of becoming aware of it.
When the Service ends, allow data export for 30 days and then delete it (and from backups as they rotate), except where the law requires retention.
Make available the information needed to demonstrate compliance with this agreement.
4. Customer's obligations
Have a legal basis for the processing and inform data subjects, including that they may be served by an AI assistant and that the listed providers may process their data.
Obtain the consent required for promotional messages and honor opt-outs.
Give lawful instructions and configure the Service in line with applicable law.
5. Sub-processors
The Customer authorizes Dona to engage the following sub-processors, which assume equivalent protection obligations:
DigitalOcean, LLC (USA): server hosting and backups.
Anthropic, PBC (USA): AI models that generate the agents' responses.
OpenAI, L.L.C. (USA): audio transcription, if enabled.
Meta Platforms, Inc. / WhatsApp LLC: WhatsApp Business channel.
Twilio Inc. (USA): phone calls, if enabled.
Resend (USA): transactional email.
Mercado Pago and Stripe: subscription payments (Customer data only).
Integrations the Customer connects (for example Google Calendar, HubSpot, Kommo), under the Customer's account and responsibility.
Dona will give 30 days' notice before adding a new sub-processor; the Customer may object on reasonable grounds and, if no agreement is reached, cancel without penalty.
6. International transfers
Transfers to sub-processors outside Argentina rely on the safeguards required by law (model clauses approved by AAIP Disposition 60-E/2016 and, for EU data, the European Commission's Standard Contractual Clauses) or equivalent mechanisms.
Dernière mise à jour: 2026-09-28