Legal

Data Processing Addendum

This addendum is part of the Integrava Terms of Service. It applies when Customer Success Point SRL processes personal data on your instructions as a processor.

Last updated: 24 September 2026

1. Parties and scope

This Data Processing Addendum ("DPA") is between you (the workspace customer, "you") and Customer Success Point SRL ("Integrava", "we"). It covers personal data in workspace content that you or your end users submit to the service, including support tickets, conversations, email, knowledge documents, embed and help-center messages, and integration content you sync.

It does not cover personal data for which we are the controller, such as your account registration, our own billing records, and security logs about use of the platform. That processing is described in the Privacy Policy.

2. Roles

You are the controller of workspace content. We are the processor. We process that data only to provide the Integrava service, as set out in the Terms of Service and in settings you enable (channels, AI provider, integrations, and support access).

You are responsible for having a lawful basis, for notices to your end users, and for the instructions you give us, including which model provider and integrations to use.

3. Details of processing

  • Subject matter — hosting and operating the support platform you configure
  • Duration — for the life of the workspace, plus the retention periods in the Privacy Policy after deletion or expiry
  • Nature and purpose — storage, retrieval, AI-assisted replies using your provider key, email and widget delivery, analytics, and the integrations you connect
  • Data — identifiers and message content your users and agents submit, plus credentials you store for connected systems (encrypted)
  • Data subjects — your end customers, your employees and contractors who use the workspace, and people mentioned in content you upload

4. Security

We maintain technical and organizational measures appropriate to the service: encryption of stored secrets, workspace isolation, role-based access, audit logging, and infrastructure controls on AWS in eu-north-1. No method of transmission or storage is completely secure.

Support staff can view a workspace only after an owner grants access, for 1, 3, 7, 14, or 30 days (7 days if you do not choose a duration). You can turn that access off at any time.

5. Subprocessors

You authorize the Integrava subprocessors listed in section 1 of the Subprocessors page (AWS, Amazon SES, and Stripe). We will update that page before we add or replace one of those providers. If you object to a new Integrava subprocessor on reasonable data-protection grounds, contact contact@integrava.ai and we will discuss stopping the affected processing or ending the subscription.

Model providers, Tavily, Cloudflare Turnstile, and product integrations are not appointed by us for every customer. They receive data only because you enable them and, for AI and Tavily, because you supply the API key. You must have your own terms with those providers.

6. International transfers

Workspace content we host stays in the European Economic Area (AWS eu-north-1, Stockholm) unless you instruct a transfer.

Where we are the exporter to an Integrava subprocessor outside the EEA, the transfer uses the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as the roles require, together with any required transfer assessment.

When you send prompts or integration data to a provider with your own credentials, you instruct that transfer. The transfer tool is your agreement with that provider, including its Standard Contractual Clauses or an equivalent safeguard. We do not claim a separate Integrava contract with your model vendor.

7. Data subject requests

We will assist you with access, deletion, restriction, and portability requests for workspace content, taking into account how the service works. You can delete many records in the product (tickets, knowledge, integrations, and team members). Account and workspace deletion timelines are in the Privacy Policy (14-day and 30-day grace periods).

If a person contacts us directly about data you control, we may refer them to you unless we are legally required to respond ourselves.

8. Deletion and return

During the subscription you can export and delete workspace content with the tools we provide. Integrava does not automatically export a workspace when you schedule deletion. When workspace deletion runs, we delete the workspace and cascaded tenant data. We retain the billing archive, the platform audit of the deletion, and anonymised demo-abuse signals, as described in the Privacy Policy. A legal hold blocks deletion until it is cleared. Backups follow the infrastructure backup schedule and age out on that schedule.

9. Incidents and audits

We will notify the workspace owner without undue delay after becoming aware of a personal-data breach that affects workspace content we process for you, with the information we reasonably have so you can meet your own notice duties.

On written request, and no more than once a year unless a breach or a regulator requires it, we will make available information reasonably needed to show this DPA is being followed. That may be a summary of controls rather than on-site access to multi-tenant systems.

10. Order of terms

If this DPA conflicts with the Terms on a point of data protection, this DPA controls. Otherwise the Terms apply, including liability limits, except where the law does not allow a processor to limit liability for its own data-protection duties.

Customer Success Point SRL — Romania, Bucharest, Drum Gura Putnei 133 Et. POD Ap. 19 Cod 032603. Unique registration code: 45173010. contact@integrava.ai