1. Parties, application and duration
This agreement applies between the business customer accepting the Axentrio offer, as controller, and Achraf Lamrani Makhloufi CommV, trading as Axentrio, Passtraat 248/B, 9100 Sint-Niklaas, Belgium, VAT BE0789355217, as processor. It forms part of the service when agreed together with the offer. Publication alone does not replace an earlier agreement.
Processing lasts while Axentrio provides the relevant service for the customer and thereafter only for necessary return, deletion or statutory duties. Axentrio may be an independent controller for its own billing, business account administration and statutory purposes; the privacy notice applies to those activities.
2. Subject matter, nature and data subjects
The subject matter is digital customer assistance: receiving, storing, understanding and answering messages, capturing context and leads, supporting human handover, processing appointments and producing insights under the selected plan and instructions. This may involve accessing, organising, disclosing to engaged processors, exporting and deleting data.
Data subjects are the customer’s visitors, prospects, customers and contacts, and customer workspace users. Data may include names, contact and address details, channel and session identifiers, message content, supplied files, timestamps, notes, service enquiries, appointment details and related metadata. Actual scope depends on the functions used and data the customer has processed.
Special-category and criminal-offence data are not covered by ordinary service delivery without suitable separate instructions, legal basis and security arrangements. The customer limits data to what is necessary.
3. Documented instructions
Axentrio processes personal data only on the customer’s documented instructions, including the agreed service, configured channels, calendar, knowledge base, instructions and authorised support requests. This also applies to transfers outside the EEA. If law requires other processing, Axentrio informs the customer beforehand unless the law prohibits this on important grounds.
If an instruction appears to breach data protection law, Axentrio immediately informs the customer and seeks a lawful solution. Axentrio does not use customer conversations or data for its own AI model training or fine-tuning, and does not sell data processed on instructions for its own purposes.
The customer determines purposes and legal basis, properly informs data subjects and ensures lawful instructions and disclosure of data. Axentrio retains its own obligations as processor.
4. Confidentiality and security
Axentrio ensures that people authorised to process data under its authority are bound to confidentiality or an appropriate statutory duty of confidentiality. Access is restricted to what their task requires and removed when no longer needed.
The parties implement appropriate technical and organisational measures proportionate to the nature, scope, context, purposes and risks. These include access management, secure connections, recovery provisions, incident handling and assessment of measures. A measure is not a promise of absolute security.
The confirmed setup includes application, database and database backup hosting with Hetzner in Germany, mandatory two-factor authentication for superadmin accounts, logging of superadmin access and changes, recovery backups and configured retention periods. Superadmins and direct technical support operate from Belgium. This list does not state that every external service operates only in Germany.
5. Services and subprocessors
The customer gives general written authorisation for subprocessors necessary for the agreed service, subject to the information and objection rights below. The current functional list includes Hetzner for hosting and backups, OpenAI for AI processing and Resend for booking emails. Clerk supports account emails and Combell support mailboxes; their role depends on the actual processing.
Meta, Google and Microsoft provide the channel and calendar connections directly selected by the customer. They may be independent controllers for their own services. Connecting a channel does not authorise unrestricted disclosure to every provider. ChatGPT Sites hosts the separate marketing website, not the customer database.
Axentrio makes relevant subprocessor identity, role and processing location available. Before a proposed addition or replacement, Axentrio informs the customer, allowing reasonable data protection objections before the change takes effect. The parties seek a suitable solution; if none is available, appropriate termination options for the affected service apply without restricting the customer’s statutory rights.
Axentrio imposes equivalent data protection obligations on a subprocessor and remains responsible to the customer for that subprocessor’s performance of those obligations. Actual access by external technical support personnel must also be appropriately governed; technical work does not place a supplier outside these obligations.
6. Transfers and OpenAI
For transfers outside the EEA, Axentrio ensures a valid instruction and the required Chapter V GDPR safeguards, such as an applicable adequacy decision or standard contractual clauses with necessary supplementary measures. A general reference to a supplier does not replace that assessment. The customer may request relevant information and evidence of safeguards.
Axentrio uses the OpenAI API directly and has approved active Zero Data Retention for the project. No specific OpenAI data region is configured. Feature-specific limitations and exceptions in OpenAI’s documentation remain relevant. The service must not be presented as a universal guarantee of zero storage or exclusively European processing.
7. Data subject rights and assistance
Taking account of the nature of processing, Axentrio assists the customer through appropriate measures in handling data subject requests. A directly received request about data controlled by the customer is passed to the customer without undue delay, unless law requires otherwise. Axentrio responds substantively under the customer’s instructions and does not disclose data without appropriate checks.
Support requests about export and deletion are currently handled manually through support@axentrio.com. For account requests, we seek prior confirmation through the linked email address and check relevant authority. These checks must not unnecessarily impede statutory rights.
Manual export support is free. Timing depends on the request and volume, subject to applicable statutory deadlines. Axentrio also assists with security obligations, data protection impact assessments and prior consultation, considering the nature of processing and information available.
8. Personal data breaches
Axentrio notifies the customer of a breach involving data processed on its instructions without undue delay after becoming aware of it. To the extent available, the notice describes the incident, affected data and people, likely consequences, measures taken or proposed and a contact point. Missing information may follow in phases without unnecessary delay.
Axentrio limits consequences, carefully preserves necessary investigation material and helps the customer assess and make any notifications to authorities or data subjects. The controller’s statutory notification deadline is not replaced by a waiting period chosen by Axentrio. External communications are coordinated where law permits.
9. Information and audits
Axentrio makes available the information necessary to demonstrate compliance with this agreement and allows and contributes to audits, including inspections by the customer or its mandated auditor. Appropriate arrangements protect other customers, security information and confidential material without excluding statutory audit rights.
The parties reasonably coordinate practical arrangements according to risk, the reason for the audit and existing relevant documentation. Supervisory authorities’ powers are not restricted.
10. Return, deletion and retention
After processing ends, Axentrio returns or deletes data processed on instructions, at the customer’s choice, and deletes existing copies unless applicable law requires retention. Statutory switching and retrieval rules continue to apply. The export register in the general terms describes existing .txt, CSV and Excel exports and the route for additional account data; it does not limit rights to those standard buttons.
Ordinary periods: conversations twelve months from the last message; prospects without a relationship twelve months without genuine interaction; completed appointments twelve months from the appointment date and cancelled appointments twelve months from cancellation. A business’s automated message does not restart a prospect period. Data needed for an ongoing quote, relationship, order or warranty is retained only while that purpose exists, then reviewed.
Recovery backups last at most thirty days from creation. Data remaining there after active-system deletion is not reused for normal service delivery; deletion instructions must be reapplied on restoration. Superadmin logs have a twelve-month period per action. Only necessary evidence for a specific incident, dispute or legal duty is retained separately with restricted access and review.
Deleting operational platform data does not cancel already-booked future appointments in the customer’s external calendar. The planned self-service function with a thirty-day waiting period is still in development and does not restrict these processor obligations.
11. Priority and contact
For conflicts about personal data processing, this agreement takes priority over general commercial terms, subject to applicable law and valid transfer provisions. Restrictions on commercial functionality or a free account do not remove statutory rights or these obligations. Data assistance: support@axentrio.com. Privacy enquiries to Axentrio: info@axentrio.com.
