SweetRouterAPI

SweetRouter

Data Processing Addendum

Effective date: October 9, 2026Číst česky

This Data Processing Addendum ("DPA") forms part of the Agreement between OneClick AI Solutions s.r.o. ("SweetRouter", "we") and the Customer under our Terms of Service, and applies to personal data we process on the Customer's behalf. It is available in English and Czech; if the versions differ, the English version prevails.

1. Definitions

Terms defined in the Terms of Service have the same meaning here. "GDPR" means Regulation (EU) 2016/679. "Covered Data" means personal data contained in Customer Content that we process on the Customer's behalf to provide the Service. "Sub-processor" means a processor we engage to process Covered Data. "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Covered Data. "SCCs" means the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. The terms "controller", "processor", "data subject" and "processing" have the meanings given in the GDPR.

2. Roles of the parties

2.1 For Covered Data, the Customer is the controller (or a processor acting for its own customer) and we are the processor (or sub-processor).

2.2 For account, billing, support and API call data that we process for our own purposes, we act as an independent controller as described in our Privacy Policy. This DPA does not apply to that processing.

2.3 We do not use Covered Data for our own purposes, including to train AI models.

3. Instructions

3.1 We process Covered Data only on the Customer's documented instructions, which are the Agreement, this DPA and the Customer's use of the Service, unless EU or Member State law requires otherwise. In that case we will inform the Customer before processing unless the law prohibits it.

3.2 We will tell the Customer promptly if, in our opinion, an instruction infringes data protection law.

4. Customer obligations

4.1 The Customer is responsible for having a lawful basis for the processing of Covered Data, for giving data subjects the information required by law, for obtaining any consents required, and for ensuring its instructions comply with data protection law.

4.2 Customer Content may include special categories of personal data (for example, data concerning a person's sex life) where End Users share it in conversations. The Customer is responsible for ensuring that any such processing is lawful.

5. Confidentiality

5.1 We limit access to Covered Data to personnel who need it to provide the Service and ensure they are bound by confidentiality obligations.

6. Sub-processors

6.1 The Customer grants us general authorisation to engage the Sub-processors listed in Schedule 2 and any replacement or additional Sub-processor appointed under this section.

6.2 We impose data protection obligations on each Sub-processor that are no less protective than this DPA, and we remain responsible for their performance.

6.3 We will give at least 7 days' notice of any intended addition or replacement of a Sub-processor by updating this page and notifying the Customer by email or in the Console. The Customer may object on reasonable data protection grounds within those 7 days. If we cannot resolve the objection within 30 days, either party may terminate the affected part of the Service.

7. Assistance

7.1 We will promptly forward to the Customer any request from a data subject relating to Covered Data and will not respond to it ourselves except to say it has been forwarded. Taking into account the nature of the processing, we will provide reasonable assistance to the Customer in responding to such requests, carrying out data protection impact assessments and consulting supervisory authorities.

8. Security

8.1 We implement appropriate technical and organisational measures to protect Covered Data, taking into account the nature, scope, context and purposes of the processing and the risks to data subjects. The minimum measures are described in Schedule 3.

9. Security Incidents

9.1 We will notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a Security Incident affecting Covered Data. We will provide the information reasonably available to us to help the Customer meet its own notification obligations, and will take reasonable steps to contain and mitigate the incident.

9.2 Our notification of or response to a Security Incident is not an acknowledgement of fault or liability.

10. Audits and information

10.1 We will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including documentation of our security measures and our Sub-processors' certifications where available.

10.2 If that information is not sufficient, the Customer may carry out an audit, at its own cost, no more than once a year (unless required by a supervisory authority), on at least 30 days' written notice, during business hours, with a scope agreed in advance, and in a way that does not disrupt our operations or compromise the security or confidentiality of other customers' data. Audits may be carried out by an independent auditor bound by confidentiality who is not our competitor. Audit results are our confidential information.

11. Deletion and return

11.1 We do not store the text of chat messages or replies. Generated image and video files are deleted after 24 hours. Call details are deleted after 30 days.

11.2 On termination of the Agreement we will delete any remaining Covered Data within 30 days, unless EU or Member State law requires us to keep it. Because Covered Data is not stored long-term, return is not available beyond the download options in the Service.

12. International transfers

12.1 We may transfer Covered Data to Sub-processors outside the European Economic Area only where the destination is covered by an adequacy decision of the European Commission or where appropriate safeguards are in place, such as the SCCs (Module 3, processor to processor) entered into with the relevant Sub-processor.

12.2 Where the Customer is located in a country without an adequacy decision and we transfer Covered Data to it, the SCCs (Module 4, processor to controller) apply between us and the Customer and are incorporated into this DPA by reference. Clause 7 (docking clause) and the option in Clause 11(a) do not apply. Under Clauses 17 and 18 the SCCs are governed by Czech law and disputes are resolved by the courts of the Czech Republic. Annex I is completed with the information in Schedule 1, and Annex II with Schedule 3.

12.3 For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner applies to the SCCs. For transfers subject to the Swiss Federal Act on Data Protection, the SCCs apply with the necessary adaptations, with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.

13. Term, liability and precedence

13.1 This DPA applies for as long as we process Covered Data. Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where data protection law does not allow such limitation.

13.2 If this DPA conflicts with the Terms of Service in relation to the processing of Covered Data, this DPA prevails. This DPA is governed by the law of the Czech Republic.

Schedule 1: Details of processing

  • Subject matter and duration: providing the Service for the term of the Agreement.
  • Nature and purpose: receiving Customer Content through the API, passing it to AI models to generate Output, returning Output to the Customer, and storing generated files for 24 hours.
  • Categories of data subjects: the Customer's End Users and any other individuals whose data the Customer includes in Customer Content.
  • Categories of personal data: any personal data the Customer or its End Users include in Customer Content, such as names, messages and images, and an optional End User identifier.
  • Special categories: may include data concerning sex life or sexual orientation if End Users share it in conversations.
  • Frequency: continuous, for each API request.
  • Retention: message text is not stored; generated files are kept for 24 hours; call details for 30 days.
  • Processor contact: OneClick AI Solutions s.r.o., sweetsrouter@gmail.com.
  • Customer contact: the main administrator of the Customer's Account.

Schedule 2: Sub-processors

  • Supabase, Inc.: Database, authentication and file storage (EU (Frankfurt, Germany)).
  • Vercel Inc.: Website and API hosting (EU (Frankfurt, Germany); company based in the USA).
  • Upstash, Inc.: Rate limiting (API key identifiers and request counters) (EU region; company based in the USA).
  • Third-party AI model inference provider: Generating chat replies from the messages you send (Singapore).
  • Verda (DataCrunch Oy): Image and video generation (EU (Finland)).
  • Google Ireland Limited (Gmail): Email correspondence with customers (EU; data may also be processed in the USA).

Schedule 3: Technical and organisational measures

  • Encryption: TLS 1.2 or higher for all data in transit; encryption at rest provided by our database and storage providers.
  • Access control: personal accounts for all staff, least-privilege access to production systems, two-factor authentication on administrative accounts, prompt removal of access when no longer needed.
  • Credentials: API keys are stored only as one-way hashes; secrets are kept in environment variables and never in source code or client-side code.
  • Data minimisation: message text is not stored; call details are limited to what billing and security need and are deleted after 30 days.
  • Availability: managed database backups and hosting across redundant infrastructure.
  • Monitoring: logging of errors and security-relevant events at our hosting providers; rate limiting and abuse prevention on the API.
  • Vendor management: Sub-processors are selected for their security practices and bound by written data protection terms.
  • Incident response: a documented process for investigating, containing and reporting Security Incidents.
  • Personnel: confidentiality obligations for everyone with access to Covered Data.