Legal

Data Processing Agreement

Last updated: 1 August 2026

This document is provided in English, which is the legally authoritative version.

This Data Processing Agreement ("DPA") is incorporated into and forms part of the Terms of Service between you ("Controller") and Semplo B.V. ("Processor"). By using the Semplo Service, you agree to the terms of this DPA. This DPA takes effect on the date you first accept our Terms of Service or otherwise begin using the Service.

1. Definitions

In this DPA, the following terms have the meanings given to them in the GDPR:

  • "Personal Data" — any information relating to an identified or identifiable natural person.
  • "Processing" — any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and deletion.
  • "Controller" — the entity that determines the purposes and means of Processing Personal Data. In this DPA, you (the Semplo customer) are the Controller.
  • "Processor" — the entity that processes Personal Data on behalf of the Controller. In this DPA, Semplo B.V. is the Processor.
  • "Sub-processor" — any third party engaged by the Processor to assist in Processing Personal Data.
  • "GDPR" — the General Data Protection Regulation (EU) 2016/679.
  • "Supervisory Authority" — the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or any other competent data protection authority.

2. Scope of processing

Subject matter. Semplo processes Personal Data on your behalf to provide the Service, including operating the AI employee chat widget on your website, storing customer conversation transcripts, sending automated messages, and managing appointment bookings.

CategoryDetail
Categories of data subjectsYour customers, website visitors, and leads who interact with your AI employee widget
Types of Personal DataNames, email addresses, phone numbers, appointment details, message content, and any other data subjects voluntarily share in conversation
Purpose of ProcessingProviding the Semplo Service as described in the Terms of Service
DurationFor the term of your subscription, plus any retention period required by law or agreed in writing

3. Processor obligations

Semplo agrees to:

  • Process Personal Data only on your documented instructions, unless required to do so by applicable law, in which case we will notify you in advance unless prohibited by law.
  • Ensure that all personnel authorised to process Personal Data are subject to appropriate confidentiality obligations.
  • Implement appropriate technical and organisational security measures as described in Article 32 GDPR, including encryption at rest and in transit, access controls, and regular security testing.
  • Not engage sub-processors without your prior general written authorisation. Our current list of sub-processors is maintained in Annex A below and on our website. We will give at least 30 days notice of any changes.
  • Assist you in fulfilling your obligations to respond to requests from data subjects exercising their rights under Chapter III GDPR.
  • Assist you in ensuring compliance with Articles 32–36 GDPR (security, data breach notification, DPIAs, and prior consultation).
  • At your choice, delete or return all Personal Data upon termination of the Service and delete existing copies unless required to retain them by law.
  • Make available to you all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by you or a mandated auditor, with reasonable notice and at your cost.

4. Controller obligations

You agree to:

  • Have a lawful basis for all Personal Data you instruct us to process on your behalf.
  • Provide adequate privacy notice to your customers regarding the use of the Semplo chat widget and the processing of their data.
  • Ensure the Personal Data you provide to us is accurate and kept up to date.
  • Notify us promptly of any changes to your instructions that may affect our processing activities.

5. Security and data breaches

Semplo maintains appropriate technical and organisational measures to protect Personal Data, including:

  • Encryption of Personal Data at rest (AES-256) and in transit (TLS 1.2+)
  • Role-based access controls limiting data access to authorised personnel only
  • Regular security reviews and vulnerability assessments
  • Incident response procedures

In the event of a Personal Data breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware, providing sufficient information for you to meet your own notification obligations under Article 33 GDPR.

6. International transfers

Some of our sub-processors are located outside the European Economic Area (EEA). Where Personal Data is transferred outside the EEA, we ensure appropriate safeguards are in place in accordance with Chapter V GDPR, including Standard Contractual Clauses approved by the European Commission (Commission Decision 2021/914).

By using the Service, you authorise Semplo to make such transfers on your behalf under the conditions described in this DPA.

7. Sub-processors

Annex A — Current sub-processors

Sub-processorPurposeLocationTransfer mechanism
Supabase Inc.Database, authentication, file storageEU (AWS Frankfurt)EU-hosted, no transfer
Anthropic PBCAI language model — processes message content to generate responsesUSAStandard Contractual Clauses
Stripe Inc.Payment processing — processes billing dataUSAStandard Contractual Clauses
Resend Inc.Email delivery — processes recipient email addresses and message contentUSAStandard Contractual Clauses
Twilio Inc.SMS delivery — processes recipient phone numbers and message content, and carries WhatsApp messagesUSAStandard Contractual Clauses
Vercel Inc.Application hosting and CDNUSA/EUStandard Contractual Clauses
Vapi Labs Inc.Voice call orchestration — processes call audio and transcriptsUSAStandard Contractual Clauses
Deepgram Inc.Speech-to-text — transcribes the caller’s speech during voice callsUSAStandard Contractual Clauses
ElevenLabs Inc.Text-to-speech — synthesises the spoken replyUSAStandard Contractual Clauses
Google Ireland Ltd.Calendar synchronisation, where the customer connects Google Calendar — processes appointment detailsEU/USAStandard Contractual Clauses
Microsoft Ireland Operations Ltd.Calendar synchronisation, where the customer connects Outlook — processes appointment detailsEU/USAStandard Contractual Clauses
Booking.com B.V.Reservation synchronisation, where the accommodation connects its Booking.com accountEU (Netherlands)EU-hosted, no transfer

You may object to a new or replacement sub-processor within 14 days of receiving notice. If you object and we cannot accommodate your objection without materially affecting the Service, you may terminate your subscription and receive a pro-rata refund of any prepaid fees.

8. Term and termination

This DPA remains in force for the duration of your subscription to the Service. On termination of your subscription for any reason, Semplo will, at your choice and within 30 days of your written request, either delete or return all Personal Data processed under this DPA, and certify such deletion or return in writing. We may retain Personal Data where required to do so by applicable law, in which case we will notify you of the legal requirement.

9. Governing law

This DPA is governed by the laws of the Netherlands. Any disputes shall be subject to the jurisdiction of the courts of Amsterdam, the Netherlands.

10. Contact and requests

To submit data subject access requests, report a security incident, request a data export, or for any other DPA-related matter:

CompanySemplo B.V.
KVK42118388
AddressClaude Debussylaan 82, 1082 MD Amsterdam, Netherlands