This EU / UK Data Protection Addendum (“EU / UK Addendum”) forms part of the Data Processing Agreement (“DPA”) between FOP Kushnir Denis Olehovych (“Helveris”, “Processor”, “we”, “us”) and the Customer (“Controller”).

This EU / UK Addendum applies only to the extent that Helveris processes Personal Data subject to:

  • Regulation (EU) 2016/679 (“EU GDPR”);
  • the UK GDPR; and/or
  • the UK Data Protection Act 2018.

1. Scope

Where Customer Personal Data is subject to EU GDPR or UK GDPR, this EU / UK Addendum supplements the DPA and governs the processing of such Personal Data by Helveris in connection with the Services.

If there is any conflict between this EU / UK Addendum and the DPA with respect to Personal Data subject to EU GDPR or UK GDPR, this EU / UK Addendum will prevail to the extent of that conflict.

2. Roles of the Parties

For the purposes of Personal Data subject to EU GDPR or UK GDPR:

  • the Customer acts as Controller;
  • Helveris acts as Processor.

The Customer is responsible for ensuring that it has an appropriate legal basis for the processing of Personal Data and for providing any required notices to data subjects.

3. Processor Obligations

To the extent required by EU GDPR or UK GDPR, Helveris will:

  • process Personal Data only on documented instructions from the Customer, unless otherwise required by applicable law;
  • ensure that persons authorized to process Personal Data are subject to confidentiality obligations;
  • implement appropriate technical and organizational measures designed to protect Personal Data;
  • assist the Customer, taking into account the nature of the processing, in responding to data subject requests;
  • assist the Customer, where required, with data protection impact assessments, security incident handling, and consultations with supervisory authorities;
  • notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data;
  • delete or return Personal Data at the end of the Services, subject to applicable legal retention obligations; and
  • make available information reasonably necessary to demonstrate compliance with this EU / UK Addendum and the DPA.
Controlled Environment

Helveris is designed for business website workflows and operates within a controlled service environment rather than as a public AI system. Customers remain responsible for determining whether their use of the Service is appropriate for the Personal Data they choose to process.

4. Subprocessors

The Customer authorizes Helveris to engage subprocessors in accordance with the DPA.

Helveris will ensure that any subprocessor processing Customer Personal Data is bound by written obligations providing a level of protection for Personal Data that is no less protective than the obligations applicable to Helveris under the DPA and this EU / UK Addendum, to the extent relevant to the services provided by such subprocessor.

5. International Transfers

Where Customer Personal Data subject to EU GDPR or UK GDPR is transferred to a country that does not provide an adequate level of protection under applicable data protection law, the parties will implement an appropriate lawful transfer mechanism, including, where applicable:

  • the European Commission’s Standard Contractual Clauses;
  • the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; or
  • another lawful transfer mechanism recognized under applicable law.

6. Sensitive Data

Unless otherwise expressly agreed in writing, the Customer must not intentionally submit to the Service any special categories of personal data or other sensitive data subject to heightened protection under EU GDPR or UK GDPR.

If the Customer chooses to process such data through the Service, the Customer remains solely responsible for ensuring that it has a valid legal basis and that any additional legal requirements are satisfied.

7. Security and Data Handling

Helveris applies technical and organizational safeguards appropriate to the nature of the Services and the risks presented by the processing of Customer Personal Data. The Customer remains responsible for configuring its own workflows, ensuring data minimization, and avoiding submission of data types that are not appropriate for the Service.

Where the Service is used for website assistance, lead routing, customer support workflows, or CRM handoff, the Customer is responsible for ensuring that its website notices, internal procedures, and downstream systems remain compliant with applicable law.

8. Liability

The liability of each party under this EU / UK Addendum is subject to the liability limitations set out in the Agreement and the DPA, except to the extent such limitations are prohibited by applicable law.

9. Governing Law

This EU / UK Addendum is governed in accordance with the governing law provisions of the Agreement, unless applicable data protection law requires otherwise with respect to a particular transfer mechanism or mandatory legal rule.

10. Contact

If you have questions about this EU / UK Addendum, our DPA, or the way Helveris supports privacy-aware website operations, please contact us at:

support@helveris.com