Data Processing Agreement (DPA)
Data Processing Agreement (DPA)
Last updated: 27.8.2026
This Data Processing Agreement (“Agreement” or “DPA”) forms part of the Terms of Service (“Principal Agreement”) between the customer (“Data Controller”) and Showdini (“Data Processor”).
It governs the processing of personal data that takes place when the Data Controller uses the Showdini platform.
Subject and Duration
1.1. This DPA applies to all processing of personal data that the Data Processor carries out on behalf of the Data Controller while providing the Service.
1.2. Processing begins when the Data Controller starts using the Service and continues for as long as the Data Processor provides access to it.
Nature and Purpose of Processing
2.1. The Data Processor provides a software platform that enables interactive, AI-powered product demos for website visitors.
2.2. Personal data processed may include:
• Interaction data (e.g., chat messages, inferred insights, voice input, session logs)
• Technical data (e.g., browser type, IP address, device info)
• Optional contact data (e.g., name or email if provided by the visitor)
2.3. The Data Processor processes this data only to:
• Deliver and maintain the demo experience
• Provide analytics, session information and sales insights to the Data Controller
• Improve and secure the Service
2.4. Aggregated data. Notwithstanding clause 2.3, the Data Processor may process personal data to create aggregated and anonymised data about the performance and use of the Service, including for research that the Data Processor publishes. Such data will be irreversibly anonymised, will not identify the Data Controller, any end user, or any individual, and will not be presented in a way that permits any of them to be identified. The Data Processor acts as a controller in respect of this processing, and may retain and use such aggregated data after the Principal Agreement ends.
Roles and Responsibilities
3.1. The Data Controller determines the purpose and means of personal data processing.
3.2. The Data Processor acts only on the Data Controller’s documented instructions, except as set out in clause 2.4 and where otherwise required by applicable law.
3.3. The Data Controller is responsible for ensuring that personal data is collected lawfully.
Obligations of the Data Processor
The Data Processor shall:
• Process personal data only as instructed by the Data Controller, except as set out in clause 2.4.
• Ensure that persons authorized to process the data have committed to confidentiality.
• Implement appropriate technical and organizational measures to protect personal data.
• Assist the Data Controller, where possible, in fulfilling obligations related to data subjects’ rights.
• Notify the Data Controller without undue delay after becoming aware of any personal data breach.
• Delete or return all personal data at the end of the service relationship, unless required by law to retain it or permitted under clause 2.4.
Sub-Processors
5.1. The Data Controller authorizes the Data Processor to engage sub-processors necessary for operating the Service.
5.2. The Data Processor shall ensure that sub-processors are bound by equivalent data-protection obligations.
5.3. Current sub-processors include:
LiveKit, Inc. for real-time voice and streaming infrastructure. Data transfers outside the EU are protected under Standard Contractual Clauses (SCCs).
OpenAI for AI language-model processing. Data transfers outside the EU are protected under Standard Contractual Clauses (SCCs).
Microsoft Azure for text-to-speech (TTS) services for Slovenian language. Data may be processed within Azure EU regions, and any transfers outside the EU are protected under Standard Contractual Clauses (SCCs).
Soniox for speech-to-text (STT) processing. Data transfers outside the EU are protected under Standard Contractual Clauses (SCCs).
International Data Transfers
If personal data is transferred outside the European Economic Area (EEA), the Data Processor shall ensure adequate protection by relying on the European Commission’s Standard Contractual Clauses (SCCs) or other approved safeguards.
Security Measures
The Data Processor shall maintain appropriate security measures, including:
Encryption in transit and at rest
Access control and authentication
Regular data deletion and system monitoring
Limiting data access to authorized personnel only
Data Subject Rights
Where applicable, the Data Processor shall assist the Data Controller in responding to requests from data subjects, including access, correction, deletion, or restriction of processing.
Data Retention and Deletion
The Data Processor stores personal data for as long as necessary to provide the Service.
Unless otherwise instructed by the Data Controller, demo session data is automatically deleted or anonymized within 30 days of collection.
10. Audit Rights
The Data Controller has the right to request documentation reasonably necessary to demonstrate the Data Processor’s compliance with this DPA.
Audits may be conducted no more than once per year, upon reasonable notice, and without disrupting service operations.
11. Liability
Each party’s liability under this DPA shall be subject to the limitations of liability set forth in the Principal Agreement.
12. Termination
Upon termination or expiry of the Principal Agreement, the Data Processor shall delete or return all personal data processed on behalf of the Data Controller, unless retention is required by law or permitted under clause 2.4.
13. Governing Law and Jurisdiction
This agreement is governed by the laws of Slovenia.
Any disputes arising out of or related to this DPA shall be resolved in the courts of Ljubljana, Slovenia.
14. Contact
For all data-protection inquiries, please contact:
[email protected]