Amio
Product
AI CHATBOT for E-COMMERCE
AI chatbot
Conversational AI platform
Conversational designer
Build fast with no-code
AI knowledge base
Feeds, scraping, pdf, etc.
Chatbot analytics
Insights for chatbot improvements
Helpdesk connectors
Zendesk
Gorgias
Freshdesk
Freshchat
All helpdesk connectors
e-commerce  platforms
Shopify
WordPress
WooCommerce
Magento
All ecommerce platforms
WHY CHOOSE AMIO AI CHATBOT?
60%+ cost savings
3x online conversions
5* customer service
4.9 software rating
Success stories Pricing
Resources
Resources
Blog
AI insights & trends
Documentation
Setup & support
Status
Real-time service updates
API reference
Integrate with ease
FEATURED POST
Live Chat Advantages: 12 Reasons It's More Than Just Support
Discover 12 live chat advantages beyond support — faster responses, higher conversions, lower costs, and better customer experience for e-commerce stores.
Start free Log in
Request a demo
Log in

Data Processing Agreement

Effective / Last updated: 6 October 2026

1. Parties, applicability and relationship to the Agreement

1.1 This Data Processing Agreement (DPA) forms part of the Agreement between Amio s.r.o., Bartoškova 1411/20, Nusle, 140 00 Praha 4, Czech Republic, Company ID 06177794, VAT ID CZ06177794 (Amio), and the customer identified in the applicable Order or other accepted commercial arrangement (Customer). It applies where Amio processes Customer Personal Data on behalf of Customer in connection with the Services.
1.2 This DPA becomes binding when the Agreement is validly accepted in accordance with the Terms of Service or when the parties otherwise validly agree to it. Customer’s express acceptance of the Terms of Service that incorporate this DPA, or its signature or electronic acceptance of an Order that incorporates those Terms or this DPA, also constitutes acceptance of this DPA, provided the incorporated documents are made available before acceptance. Mere use by an Authorized User does not create a separate DPA. A separate handwritten or electronic signature is not required unless the parties expressly agree otherwise or mandatory law requires it.
1.3 The Terms of Service, applicable Order and this DPA are read together. If there is a conflict, this DPA prevails only to the extent the conflict concerns processing of Customer Personal Data. For all other matters, including fees, service scope, disclaimers, indemnities and liability, the Agreement continues to apply. Mandatory international-transfer terms prevail only to the extent they require a different result.
1.4 Amio’s Privacy Policy describes processing for which Amio acts as an independent controller. It is a transparency notice and is not an additional acceptance mechanism for this DPA.

2. Definitions and roles

2.1 Capitalized terms not defined in this DPA have the meaning given in the Terms of Service. Applicable Data Protection Law means data-protection or privacy law that applies to the relevant processing under this DPA, including, where applicable, the EU GDPR, UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws.
2.2 Customer Personal Data means personal data contained in Customer Data that Amio processes on behalf of Customer as a processor or subprocessor. Personal Data, Controller, Processor, Data Subject, Processing, Personal Data Breach and Supervisory Authority have the meanings given by Applicable Data Protection Law.
2.3 Where Customer determines the purposes and means of processing, Customer is Controller and Amio is Processor. Where Customer processes personal data on behalf of another controller, Customer is Processor and Amio is Customer’s Subprocessor. References in this DPA to Customer instructions or obligations apply according to Customer’s actual role.
2.4 Amio may separately act as an independent controller for personal data for which Amio determines the purposes and essential means, such as business-contact, contracting, billing, tax, fraud-prevention, account-security, legal-compliance and corporate recordkeeping data. This DPA does not govern that independent-controller processing and does not recharacterize processing merely by label; the actual role is determined by the facts and Applicable Data Protection Law.
2.5 Subprocessor means a third party engaged by or on behalf of Amio to process Customer Personal Data in the performance of the Services, excluding a third-party service, channel, integration or system selected, directed or controlled by Customer where that third party acts independently of Amio.

3. Processing on documented instructions

3.1 Amio will process Customer Personal Data only on Customer’s documented instructions, including instructions concerning transfers to a third country or international organisation, unless Union or Member State law to which Amio is subject requires other processing. If such law requires processing outside Customer’s instructions, Amio will inform Customer of that legal requirement before the processing, unless the law prohibits such information on important grounds of public interest.
3.2 The Agreement, Customer’s configuration and use of the Services, Customer’s support requests, instructions submitted through available administrative functionality, and other written directions accepted by Amio constitute documented instructions. The initial instructions are to process Customer Personal Data as necessary to provide, secure, support and operate the Services in accordance with the Agreement.
3.3 If Amio considers a Customer instruction to infringe Applicable Data Protection Law, Amio will immediately inform Customer and may suspend the affected instruction until it is modified, withdrawn or otherwise lawfully resolved. This does not require Amio to provide legal advice to Customer.
3.4 If an instruction is lawful but materially outside the functionality, configuration, support or professional services included in the Agreement, Amio may require a separate written agreement, reasonable implementation period and additional fees where lawful. Nothing in this Section limits assistance that Amio must provide under mandatory law.

3.5 AI, retrieval and service-quality processing

Customer instructs Amio to process Customer Personal Data for inference and generation, retrieval, search and indexing, classification, routing, automation, configured actions, troubleshooting, support, security, abuse prevention, service-quality evaluation, and customer-specific configuration, adaptation or fine-tuning, in each case solely to provide, secure, support and operate the Services for Customer.
By default, Amio will not use Customer Personal Data or Customer Confidential Information to train or fine-tune general-purpose or foundation AI models. Amio will not authorize an AI Subprocessor to do so. Such processing may occur only if Customer separately and expressly authorizes it through a written agreement or an administrative setting expressly designated for that purpose and recorded as Customer’s instruction, and only where otherwise permitted by Applicable Data Protection Law.
Service improvement language in the Agreement or Documentation does not override the restrictions in this Section with respect to Customer Personal Data.

3.6 Customer responsibilities and restricted data

Customer is responsible for the lawfulness, accuracy and quality of Customer Data; for providing required notices and obtaining required legal bases, rights and authorizations; for configuring the Services consistently with Customer’s intended use; and for not instructing Amio to process Customer Personal Data unlawfully.
Unless the parties expressly agree otherwise in writing, the Services are not intended for deliberate processing of special categories of personal data under GDPR Article 9, data relating to criminal convictions or offences under GDPR Article 10, payment-card authentication data, passwords or other end-user authentication secrets, or other categories that require materially different safeguards under Applicable Data Protection Law (Restricted Data). Customer must not intentionally submit Restricted Data to the Services. Incidental or unsolicited submission by an End User does not by itself expand the agreed processing scope.

4. Details of processing

The subject matter, duration, nature and purposes of processing, categories of Data Subjects and types of Customer Personal Data are described in Annex I. Customer may configure the Services in ways that affect those details. Customer is responsible for ensuring that its configuration remains within the Agreement and Applicable Data Protection Law.

5. Confidentiality and personnel

5.1 Amio will ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality.
5.2 Amio will limit personnel access to Customer Personal Data to persons who require access for the performance, security, support or lawful administration of the Services and will apply role-appropriate access controls.
5.3 Amio may use employees, contractors and professional advisers in operating the Services, provided their access is subject to appropriate confidentiality and security obligations. A person acting under Amio’s direct authority is not a Subprocessor merely because that person is a contractor.

6. Security

6.1 Taking into account the state of the art, costs of implementation, nature, scope, context and purposes of processing, and the risk to Data Subjects, Amio will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Personal Data.
6.2 The current categories of measures are described in Annex II. Amio may modify technical or organisational measures as the Services, technology and risks evolve, provided the changes maintain an appropriate level of security and do not materially reduce the overall protection of Customer Personal Data.
6.3 Customer acknowledges that no internet-based service can guarantee absolute security. Customer is responsible for securing its accounts, credentials, Authorized Users, integrations and endpoints; using available security controls appropriately; and promptly notifying Amio of suspected unauthorized access to Customer’s account or credentials.

7. Subprocessors

7.1 Customer grants Amio general written authorization to engage Subprocessors to process Customer Personal Data for the purposes of providing the Services.

7.2 Amio will maintain a current list of Subprocessors processing Customer Personal Data on Customer’s behalf, including relevant further Subprocessors in the processing chain. The list will identify their legal names, addresses and contact details, processing functions, and relevant processing and storage countries, including relevant remote-access locations and transfer mechanisms. Amio will proactively supply the current list, or a direct accessible link to a customer-only resource containing it, with the materials made available to Customer for acceptance of the Agreement and before the relevant processing begins. Amio will keep the list up to date and readily available to Customer while Customer Personal Data is processed. Customer’s access to the current list will not depend on submitting an information request. Customer may also request a copy at privacy@amio.io. Additions and replacements remain subject to the active advance written notice and objection process in Sections 7.3 to 7.6; updating the list alone does not replace that notice.

7.3 Before a new Subprocessor begins processing Customer Personal Data, or an existing Subprocessor is replaced, Amio will give affected Customers advance written notice. Where the Services allow Customer to configure one or more Subprocessor-notification email addresses, Amio will send the notice to those configured addresses. If no such address is configured, Amio will send the notice to the notice contact maintained for Customer under the Agreement. Customer is responsible for keeping those contact details current. The notice will identify the intended addition or replacement and will be sent as soon as reasonably practicable after the change is decided, and in any event at least 10 days before the change takes effect, unless a longer period is required by mandatory law.

7.4 Customer may object during that notice period only on reasonable and substantiated data-protection grounds relating to the intended Subprocessor. The objection must identify the specific concern and the Customer Personal Data or processing affected. General commercial preference, competitive concerns, or an objection unrelated to protection of Customer Personal Data does not constitute a valid objection under this Section.
7.5 Amio will consider a valid objection in good faith and may address it by providing relevant information, implementing a feasible mitigation, or avoiding the affected Subprocessor where commercially and technically reasonable. Amio is not required to build bespoke infrastructure, maintain a parallel service architecture or appoint an alternative provider solely for one Customer unless separately agreed.
7.6 If the parties cannot resolve a valid objection before the Subprocessor is required for the affected Service, either party may terminate the affected Service to the extent reasonably necessary to avoid the objected processing. Customer will not incur an early-termination charge solely for that termination and Amio will refund prepaid subscription fees allocable to the unused period of the terminated affected Service. Fees for Services already provided and usage already incurred remain payable.
7.7 Amio will enter into a written agreement with each Subprocessor that imposes the data-protection obligations required by Applicable Data Protection Law for the relevant processing, including obligations required by GDPR Article 28(4) where applicable. Amio remains responsible for performance of its processor obligations notwithstanding its use of Subprocessors, subject to the liability provisions of the Agreement and any mandatory transfer mechanism.

8. Assistance to Customer

8.1 Taking into account the nature of the processing and information available to Amio, Amio will provide assistance required by Applicable Data Protection Law in relation to Data Subject rights, security obligations, personal-data-breach notifications, data-protection impact assessments and prior consultation with Supervisory Authorities.
8.2 Customer will use available self-service functionality, standard exports, Documentation and compliance materials before requesting manual assistance where those means reasonably satisfy the request. Amio is not required to develop bespoke functionality merely because Customer receives a Data Subject request or conducts a DPIA.
8.3 If Amio receives a request directly from a Data Subject relating to Customer Personal Data, Amio will not respond on Customer’s behalf unless Customer instructs Amio to do so or Applicable Data Protection Law requires Amio to respond. Where reasonably practicable and legally permitted, Amio will refer the requester to Customer or inform Customer of the request.
8.4 Customer remains responsible for determining whether and how to respond to Data Subjects and Supervisory Authorities, for the content of its DPIAs and notices, and for meeting deadlines applicable to Customer.
8.5 Amio may charge reasonable fees for assistance that is materially beyond the ordinary functionality, documentation and support included in the Services, to the extent permitted by Applicable Data Protection Law. Fees will not be imposed in a manner that obstructs a mandatory right or an assistance obligation that must be provided without additional charge.

9. Personal Data Breaches

9.1 Amio will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. This obligation applies whether the breach occurs within Amio’s environment or at a Subprocessor.
9.2 Notification will include information then reasonably available to Amio that Customer may require to comply with Applicable Data Protection Law, such as the nature of the breach, relevant categories of data and Data Subjects where known, likely consequences where reasonably assessable, measures taken or proposed, and a contact point for follow-up. Amio may provide information in phases as the investigation develops and will provide material updates without undue delay.
9.3 Notification does not constitute an admission of fault or liability. Unsuccessful attempts, scans, blocked attacks, or other security events that do not result in a Personal Data Breach affecting Customer Personal Data do not trigger notice under this Section.
9.4 Amio will take reasonable steps within its control to contain, investigate and remediate a Personal Data Breach and will provide Customer with reasonable cooperation required by Applicable Data Protection Law.

10. Audits and compliance information

10.1 Amio will make available information reasonably necessary to demonstrate compliance with its obligations as Processor under Applicable Data Protection Law. Customer agrees that available compliance documentation, security descriptions, certifications, independent assessments and third-party reports may be used first where they reasonably address Customer’s verification need.
10.2 Where information supplied under Section 10.1 is insufficient and Applicable Data Protection Law entitles Customer to further verification, Amio will allow and contribute to reasonable audits or inspections relating to the processing of Customer Personal Data.
10.3 Under ordinary circumstances, Customer may request no more than one audit in any 12-month period and will give at least 30 days’ advance written notice. Those limits do not apply where a shorter or additional audit is required by a competent Supervisory Authority, mandatory law, or a material Personal Data Breach or substantiated compliance concern that reasonably requires urgent verification.
10.4 Audits must be proportionate in scope and duration, conducted during normal business hours where practicable, and organized to minimize disruption. Customer and its auditor must comply with reasonable security and confidentiality requirements. An external auditor must be appropriately qualified, independent, not a direct competitor of Amio, and bound by confidentiality obligations.
10.5 An audit may not require access to another customer’s data, information that would create an unreasonable security risk, source code, trade secrets unrelated to the audit objective, penetration testing of production systems without prior written agreement, or physical access to third-party data centres where Amio has no contractual right to grant such access. Equivalent independent evidence may be used where direct inspection is impracticable.
10.6 Customer will bear its own audit costs. To the extent lawful, Amio may charge reasonable fees for extraordinary assistance, repeated audits, bespoke evidence production or on-site support that is not required because of Amio’s material non-compliance. Amio will not charge in a way that obstructs a mandatory audit right.
10.7 Audit information and findings are Amio Confidential Information and may be used only for compliance, risk-management and regulatory purposes relating to the Agreement, except where disclosure is required by law.

11. Return and deletion

11.1 On termination or expiry of the processing Services, and subject to the switching, transition and retrieval rights in the Terms of Service and applicable mandatory law, Customer may instruct Amio to return or delete Customer Personal Data. Return may be provided through Amio’s then-available standard export functionality and supported formats.
11.2 If Customer does not give a different lawful instruction by the end of the applicable retrieval or switching period, Customer instructs Amio to delete Customer Personal Data in accordance with Amio’s standard deletion process, except to the extent Applicable Data Protection Law requires return instead. Active/production Customer Personal Data will be deleted within 30 days after the applicable deletion instruction or, if Customer gives no different instruction, within 30 days after the end of the applicable retrieval or switching period.
11.3 After returning Customer Personal Data, Amio will delete remaining active/production processor copies within 30 days, subject to Customer’s applicable switching, transition and retrieval rights. Where return occurs before those periods expire, copies required to fulfil those rights may be retained until the relevant period ends and will then be deleted within 30 days, unless Customer lawfully instructs earlier deletion or continued processing, or Union or Member State law requires storage. This Section does not extend any earlier mandatory deletion deadline or the outer deadline for full erasure under the Terms. Data retained because of a legal requirement will remain protected and will be processed only as required by that law.
11.4 After Customer Personal Data is deleted from active systems, residual copies may remain solely in backups until automatically deleted or overwritten through the ordinary AWS backup lifecycle. All such backup copies are subject to a maximum age of 30 days from creation; accordingly, residual Customer Personal Data in backups will persist for no more than 30 days after deletion from active systems. During that period, backup data remains access-restricted, is not restored for ordinary use, and, if restored for disaster recovery or legal compliance, is again subject to this DPA and the applicable deletion instruction.
11.5 Amio’s independent-controller records, such as billing, tax, corporate, security and legal-claim records, are not Customer Personal Data merely because they relate to Customer and are retained under Amio’s controller obligations and Privacy Policy.
11.6 Amio will provide a standard confirmation of deletion where required by Applicable Data Protection Law or applicable transfer terms. Where a legally required certification or equivalent confirmation is required, Amio will provide it to the extent required. Bespoke forensic deletion evidence, restoration of expired backups or custom migration services are not included unless legally required or separately agreed.

12. International transfers

12.1 Amio is established in the Czech Republic. Processing of Customer Personal Data by Amio in the EEA does not by itself require the EU Standard Contractual Clauses for international transfers merely because the Customer is located elsewhere or because the Agreement refers to the SCCs.
12.2 Where Amio makes a restricted onward transfer of Customer Personal Data to a Subprocessor or other recipient outside the EEA, UK or Switzerland, as applicable, Amio will use a lawful transfer mechanism required for that transfer. Depending on the circumstances, this may include an applicable adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, Swiss-recognized safeguards, or another mechanism permitted by Applicable Data Protection Law.
12.3 For an EEA restricted transfer from Amio as Processor to a Subprocessor, Amio will ordinarily use Module Three (Processor to Processor) of the European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914, unless another valid mechanism applies. Those SCCs are entered into between Amio and the relevant recipient; Customer’s acceptance of this DPA does not purport to execute a contract between Customer and an unnamed third-party recipient.
12.4 Amio may rely on an adequacy arrangement, including the EU–US Data Privacy Framework, only where the relevant recipient, data and processing are within the scope of that arrangement. Where SCCs or another Article 46 safeguard is required, Amio will complete the applicable annexes, assess the transfer as required, and implement supplementary measures where necessary.
12.5 Where Amio transfers Customer Personal Data from the EEA back to or at the direction of a Customer outside the EEA and that transfer is a restricted transfer for which the EU SCCs are an appropriate mechanism, the parties will be treated according to their actual roles. Module Four applies where Amio acts as Processor exporter and Customer acts as Controller importer; Module Three may apply where both parties act as processors in the relevant transfer chain. Annex III applies only to such a transfer between Customer and Amio where required.
12.6 For restricted transfers governed by UK data-protection law, Amio will use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU SCCs, or another lawful safeguard as appropriate to the actual transfer. Mandatory terms of the selected UK mechanism govern to the extent they conflict with this DPA.
12.7 For restricted transfers governed by Swiss data-protection law, the applicable safeguard will be interpreted and adapted only to the extent required by Swiss law and official Swiss guidance. Where the same transfer is also subject to the GDPR, the EU requirements continue to apply in parallel.
12.8 On reasonable request, Amio will provide Customer information reasonably necessary to understand the transfer mechanism used for Customer Personal Data, subject to confidentiality, security and third-party restrictions.

13. U.S. state privacy laws

13.1 This Section applies only to Customer Personal Data subject to a U.S. state privacy law that imposes processor, service-provider or contractor requirements on Amio in the relevant circumstances.

13.2 California

To the extent the California Consumer Privacy Act, as amended, and its implementing regulations apply and Customer is a Business disclosing Personal Information to Amio as a Service Provider or Contractor, Customer discloses the Personal Information to Amio only for the specific business purposes of hosting and storing Customer Data; transmitting communications; operating Customer-configured chat, email, AI-agent, automation and integration functionality; retrieving and generating Customer-directed responses and outputs; providing support and troubleshooting; maintaining service security and integrity; preventing fraud and abuse; and evaluating service quality solely to provide, maintain and improve the Services for Customer within the direct business relationship.
Amio will not sell or share that Personal Information; will not retain, use or disclose it outside the specified business purposes or as otherwise permitted by the CCPA; will not retain, use or disclose it outside the direct business relationship except as permitted by the CCPA; and will not combine it with Personal Information received from or on behalf of another person, or collected from Amio’s own interactions with a consumer, except as permitted by the CCPA.
Amio will provide the same level of privacy protection required of a Business by the CCPA for the covered Personal Information, will notify Customer if Amio determines that it can no longer meet its applicable obligations, and grants Customer the right to take reasonable and appropriate steps to help ensure use is consistent with Customer’s obligations and to stop and remediate unauthorized use. Verification may be satisfied through the process in Section 10 unless Applicable Data Protection Law requires otherwise. Where Amio acts as a Contractor, Amio certifies that it understands the applicable restrictions stated in this Section and will comply with them.
Amio will require applicable subcontractors handling covered Personal Information to be bound by contract terms required by the CCPA for the relevant role and processing.

13.3 Other U.S. states

Where another applicable U.S. state privacy law requires processor terms, Amio will process Customer Personal Data on Customer’s instructions for the purposes specified in the Agreement; maintain confidentiality and reasonable security; assist with applicable consumer requests and required assessments to the extent mandated and proportionate; impose required obligations on subprocessors; and provide required compliance information, in each case subject to the limits permitted by that law and the audit process in Section 10.
Nothing in this DPA guarantees that Amio will qualify for a particular statutory role regardless of the facts. The parties’ status is determined by Applicable Data Protection Law and the actual processing.

14. Liability

14.1 Subject to Section 14.2 and mandatory law, all exclusions, limitations and caps on liability in the Agreement apply to claims arising out of or relating to this DPA as part of the Agreement. No separate or higher liability cap applies solely because a claim concerns privacy, confidentiality or data protection unless an Order expressly states otherwise.
14.2 Nothing in this DPA limits or alters liability where mandatory law or an applicable incorporated international-transfer mechanism prohibits that limitation or establishes a different liability regime. Any such exception applies only to the claims and obligations for which the mandatory rule or transfer mechanism requires it and does not create a general uncapped category for all privacy claims.

15. Term, amendments and notices

15.1 This DPA remains in force for as long as Amio processes Customer Personal Data on behalf of Customer under the Agreement.
15.2 Amio may make administrative, clerical or other non-material changes to this DPA, and changes that increase data-protection safeguards, by directly notifying Customer, provided those changes do not materially reduce Amio’s obligations or Customer’s rights under Applicable Data Protection Law. Changes required by applicable law, regulation or a binding authority may take effect to the extent and at the time required after direct notice to Customer where notice is legally permitted. Any other material change to the processing obligations governed by Article 28 GDPR will take effect only upon Customer’s express agreement, including through a signed or electronically accepted Order, amendment, renewal or other affirmative acceptance that identifies or incorporates the updated DPA. Subprocessor additions and replacements remain governed by Section 7, and mandatory transfer terms may be changed only as permitted by those terms and Applicable Data Protection Law.
15.3 A website publication alone does not replace active advance Subprocessor notice required by Section 7. Customer is responsible for keeping its notice contact information current.
15.4 Formal notices under this DPA may be sent using the notice mechanism in the Agreement. Privacy questions may be sent to privacy@amio.io and legal notices to Amio may be sent to the notice address specified in the Terms of Service.

16. Governing law and precedence

16.1 Except where Applicable Data Protection Law or a mandatory transfer mechanism requires otherwise, this DPA is governed by the law and jurisdiction specified in the Agreement.
16.2 The order of precedence in the Terms of Service applies. For matters concerning processing of Customer Personal Data, this DPA prevails over inconsistent general terms. An applicable Order or separately signed data-protection addendum may expressly vary this DPA if it identifies the intended variation and is valid under Applicable Data Protection Law.

Annex I — Description of Processing

A. Subject matter

Provision of the Services described in the Agreement, including AI customer-agent, chat, email, automation, integration, knowledge, retrieval, product-recommendation and related functionality configured by Customer.

B. Duration

For the term of the Agreement and any post-termination period during which Amio lawfully retains processor copies solely to provide retrieval, switching or return, to carry out the applicable deletion instruction, or because Applicable Data Protection Law requires continued processor storage or processing. Processor copies are not retained merely for Amio’s own dispute-resolution purposes. Any records that Amio lawfully retains as an independent controller for security, legal claims, billing, tax or corporate purposes are governed by Section 11.5 rather than this Annex. Backup copies may remain only as described in Section 11.4.

C. Nature and purposes

Collection or receipt; recording; hosting; storage; organization; structuring; indexing; retrieval; consultation; classification; analysis; inference and generation; transmission; integration; configured automation and actions; support; troubleshooting; security and abuse prevention; service-quality evaluation; customer-specific configuration or adaptation; restriction; return; and deletion. These operations are performed for the purposes described in Section 3 and the Agreement.

D. Categories of Data Subjects

Customer’s End Users, website visitors, customers and prospective customers who interact with Customer through the Services; Customer personnel and Authorized Users to the extent Amio processes their personal data on Customer’s behalf rather than as an independent controller; and other individuals whose personal data Customer or an End User includes in Customer Data.

E. Categories of Customer Personal Data

Conversation, chat and email content; attachments and media; names, email addresses, telephone numbers, account, customer, order, ticket, reservation or similar identifiers; social or messaging identifiers; Customer-supplied attributes; transaction, delivery, product and support context linked to an individual; knowledge-source content and files that contain personal data; integration payloads; IP addresses, timestamps, channel identifiers and other technical metadata processed on Customer’s behalf; and other personal data Customer submits or causes the Services to process within the agreed scope.
Restricted Data described in Section 3.6 is not intended to be processed unless the parties expressly agree otherwise in writing.

F. Frequency

Continuous, periodic or on-demand, depending on Customer’s configuration and use of the Services.

G. Customer rights and obligations

Customer retains the rights and obligations of Controller or Processor applicable to its role under Applicable Data Protection Law. Customer may issue documented instructions within the scope of the Agreement and may exercise the rights expressly provided in this DPA and mandatory law.

Annex II — Technical and Organisational Measures

Amio maintains measures designed to provide a level of security appropriate to the risk. The measures below describe controls implemented in connection with the Services and may evolve in accordance with Section 6.2.

1. Encryption and transmission security

Customer Personal Data is protected in transit using TLS 1.2 or later for supported interfaces. Production databases storing Customer Personal Data use encryption at rest. Credentials used to access systems processing Customer Personal Data are subject to access restrictions.

2. Identity and access management

Access to production systems and Customer Personal Data is restricted according to role and legitimate need. Privileged access is limited to authorized personnel and requires authenticated access. Supported APIs require authenticated access, and API credentials can be revoked or rotated when necessary.

3. Tenant and environment separation

Customer Data is logically separated by tenant through application authorization and data-access controls designed to prevent one Customer from accessing another Customer’s data. Production environments are separated from development and testing environments.

4. Secure operations and change management

Material changes to production services are subject to Amio’s software-development and operational change process before deployment. Production deployment and configuration access is restricted to authorized personnel. Security risks identified through operation of the Services are addressed according to their assessed risk.

5. Availability, backup and recovery

Amio uses backup, redundancy and recovery measures appropriate to the Services and the risk of loss. Backup copies are access-restricted and are automatically deleted or overwritten through configured AWS lifecycle controls. All backup copies containing Customer Personal Data are subject to a maximum age of 30 days from creation. Where a retained backup is available, Amio can use it to support restoration following material operational failure. These measures do not create a separate customer-facing recovery-time or uptime guarantee unless an Order or SLA expressly states one.

6. Incident response

Amio maintains a process for identifying, escalating, containing, investigating and remediating security incidents, including assessment of whether an event constitutes a Personal Data Breach and notification under Section 9.

7. Personnel and confidentiality

Personnel with access to Customer Personal Data are subject to confidentiality obligations. Access is removed or adjusted when responsibilities change or access is no longer required.

8. Vendor and Subprocessor management

Amio evaluates relevant data-protection and security considerations when engaging Subprocessors and enters into required contractual data-protection terms.

Annex III — Restricted transfers between Customer and Amio

This Annex applies only where a transfer directly between Customer and Amio is a restricted transfer for which the mechanism below is legally required. It does not apply to ordinary processing by Amio in the EEA and does not replace the transfer contracts Amio enters into directly with non-EEA Subprocessors.

A. EU Standard Contractual Clauses

Where the European Commission Standard Contractual Clauses in the Annex to Implementing Decision (EU) 2021/914 (Approved EU SCCs) are required for a restricted transfer directly from Amio to Customer, the parties incorporate the full unmodified text of the Approved EU SCCs into this DPA by reference as if set out here in full, subject only to the selections and completions expressly permitted by the Approved EU SCCs. Each party’s signature of an Order or other written agreement, or electronic acceptance of the Agreement or this DPA where legally valid, constitutes that party’s agreement and signature to the applicable Approved EU SCCs and their completed annex information. Module Four applies where Amio is the Processor data exporter and Customer is the Controller data importer. Module Three applies where Amio is a Processor data exporter and Customer is a Processor data importer. Clause 7 (docking) is included and the optional independent-complaints provision in Clause 11(a) is not included. For Module Three, Clause 9(a) Option 2 (general written authorisation) applies only where Customer, as data importer, has the required general written authorisation from its controller. Customer must give its controller the prior notice required by that controller arrangement; if that arrangement specifies no period, the period is 10 days. Customer is responsible for its own Clause 9 compliance and subprocessor arrangements as importer; Section 7 of this DPA governs Amio’s Subprocessors and does not substitute for Customer’s obligations under Clause 9. For Clause 17, Czech law applies where permitted by the selected Module and circumstances. For Clause 18, the courts of the Czech Republic are selected where permitted.
For Approved EU SCC Annex I.A, the data exporter is Amio s.r.o., Bartoškova 1411/20, Nusle, 140 00 Praha 4, Czech Republic, Company ID 06177794, privacy contact privacy@amio.io, acting as Processor exporter. The data importer is Customer under the legal name, address and notice contact identified in the Agreement, Order or Customer account records, acting as Controller importer for Module Four or Processor importer for Module Three. The parties’ activities relevant to the transfer are the provision and use of the Services. The effective date for the SCCs is the date on which the applicable Agreement or Order becomes binding. For Annex I.B, the categories of data subjects and personal data are those in Annex I to this DPA that are included in the relevant transfer; transfers may be continuous, periodic or on-demand and may occur through Customer-directed access, retrieval, export, API or integration use of the Services. Customer, as importer, will retain and process imported data only as permitted by its applicable controller obligations, upstream instructions and law. For Annex I.C under Module Three, the competent EU supervisory authority is the Office for Personal Data Protection of the Czech Republic (Úřad pro ochranu osobních údajů) because Amio is established in the Czech Republic, unless Clause 13 requires a different authority for the particular transfer. Where Module Three applies, for Approved EU SCC Annex II, Customer must provide the technical and organisational measures it implements as data importer before Amio relies on the SCCs for the restricted transfer; such measures may be supplied in an Order, security schedule, questionnaire or other written record and are incorporated into this Annex. Annex II to this DPA describes Amio’s processor-side controls and does not substitute for the importer measures required from Customer under Module Three. Module Four does not require completion of SCC Annex II or a separate Customer security questionnaire merely for that purpose; the applicable security obligations under Module Four remain in force. If importer-specific information required by the Approved EU SCCs is missing, Amio may suspend the affected restricted transfer until Customer provides it. Under Module Three with Clause 9(a) Option 2, SCC Annex III is not used as a substitute for Customer’s own subprocessor obligations.

B. UK restricted transfers between Customer and Amio

Where the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (UK Addendum) is required for a restricted transfer directly from Amio to Customer, the parties incorporate the mandatory clauses of the UK Addendum and agree to be bound by them through the same signature or legally valid electronic acceptance described above. Table 1: the parties and key contacts are Amio as Exporter and Customer as Importer using the details in Section A above. Table 2: the Approved EU SCCs, Module and selections are those specified in Section A above. Table 3: the Appendix Information is the party, transfer and authority information specified or incorporated under Section A above, together with Customer importer security measures only where required for the selected Module or by mandatory UK transfer terms. Table 4: Exporter is selected as the party that may end the UK Addendum in accordance with the approved Addendum’s change mechanism. The mandatory UK governing-law, jurisdiction and interpretation provisions prevail where required.

C. Swiss restricted transfers between Customer and Amio

Where the Swiss Federal Act on Data Protection (FADP) requires the Approved EU SCCs to be adapted for a restricted transfer directly from Amio to Customer, the Approved EU SCCs incorporated in Section A apply with the following Swiss adaptations to the extent required: references to the GDPR are read as references to the FADP for processing governed by the FADP; the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority for FADP-governed processing, alongside the competent EU authority where the GDPR also applies; references to a Member State in Clause 18(c) do not exclude a data subject in Switzerland from bringing proceedings at their habitual residence in Switzerland; and for a transfer governed exclusively by the FADP, Swiss law governs Clause 17. Parallel GDPR obligations and the EU selections in Section A continue to apply to processing within the GDPR’s scope.

D. Priority

The applicable SCCs, UK Addendum or other mandatory transfer mechanism prevail over this DPA only to the extent necessary to resolve a conflict for the transfer they govern. The Agreement’s liability regime continues to apply to the maximum extent permitted by the applicable transfer mechanism and mandatory law.

Amio
Phone
E-Mail
LinkedIn
Product
Pricing ROI Calculator Chatbot platform No-code builder AI knowledge base Analytics
Platforms
Shopify Wordpress WooCommerce Magento
Helpdesks
Zendesk Gorgias Freshdesk Freshchat Front
Comparison
Manychat Chatbase Tidio Botsonic Liveperson
Company
Contact Documentation Blog
Legal
Terms of Service Privacy Policy DPA Data Portability EU AI Act Transparency Cookies Status
© 2026 Amio
Amio

🍪 This Website Runs on Cookies! 🍪

We sprinkle cookies 🍬 all over this site to:

  • Personalize content and ads 🎨📢
  • Add some extra flavor with social media features 📱🤳
  • And analyze traffic like a cookie detective 🕵️‍♂️🚦

We also share your cookie crumbs 🍪 with our social media, advertising, and analytics partners. They might mix it with other crumbs you've shared or ones they've found while you were browsing. It's all part of the cookie magic! ✨

Necessary

Statistics

Marketing

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

__cf_bm [x2]

This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.

Maximum Storage Duration
1 day
Type
HTTP Cookie
__cflb

Registers which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.

Maximum Storage Duration
1 day
Type
HTTP Cookie
_cfuvid

This cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators.

Maximum Storage Duration
Session
Type
HTTP Cookie
amio_cookie_consent

Stores the user's cookie consent state for the current domain

Maximum Storage Duration
1 year
Type
HTTP Cookie
dmn_chk_#

Used to maintain the overall functionality of the website: Assigns the user to a server and detects potential errors on specific servers, allowing the website to reassign the users to another server.

Maximum Storage Duration
Session
Type
HTTP Cookie
io

Preserves user session state across page requests.

Maximum Storage Duration
Session
Type
HTTP Cookie

Learn more about this provider

test_cookie

Used to check if the user's browser supports cookies.

Maximum Storage Duration
1 day
Type
HTTP Cookie

Learn more about this provider

X-CSRF-TOKEN

Ensures visitor browsing-security by preventing cross-site request forgery. This cookie is essential for the security of the website and visitor.

Maximum Storage Duration
Session
Type
HTTP Cookie
6435520220509aa06a812f9a#pages

Stores cached animation data in IndexedDB so Rive-powered UI elements load correctly across page visits.

Maximum Storage Duration
Persistent
Type
IndexedDB
amio_chat_session

Preserves chat widget session state so conversations continue across page navigation.

Maximum Storage Duration
Persistent
Type
HTML Local Storage

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

ph_#_posthog [x2]

Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator.

Maximum Storage Duration
1 year
Type
HTTP Cookie
ph_#_primary_window_exists

Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator.

Maximum Storage Duration
Session
Type
HTML Local Storage
ph_#_window_id

Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator.

Maximum Storage Duration
Session
Type
HTML Local Storage
amio_first_touch_path

Stores the first page path visited on the website for attribution.

Maximum Storage Duration
1 year
Type
HTTP Cookie
amio_first_touch_type

Stores whether the first visit was from blog or non-blog content.

Maximum Storage Duration
1 year
Type
HTTP Cookie
amio_first_touch_url

Stores the full URL of the first page visited on the website.

Maximum Storage Duration
1 year
Type
HTTP Cookie

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

Learn more about this provider

_ga

Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.

Maximum Storage Duration
2 years
Type
HTTP Cookie
_ga_#

Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.

Maximum Storage Duration
2 years
Type
HTTP Cookie
_gcl_au

Used by Google AdSense for experimenting with advertisement efficiency across websites using their services.

Maximum Storage Duration
3 months
Type
HTTP Cookie
_gcl_ls

Tracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.

Maximum Storage Duration
Persistent
Type
HTML Local Storage
pagead/1p-user-list/#

Tracks if the user has shown interest in specific products or events across multiple websites and detects how the user navigates between sites. This is used for measurement of advertisement efforts and facilitates payment of referral-fees between websites.

Maximum Storage Duration
Session
Type
Pixel Tracker

Learn more about this provider

giphyPingbackId

Used to track the use of embedded GIF content.

Maximum Storage Duration
Session
Type
HTML Local Storage

Learn more about this provider

_leadgenie_session

Maintains session state for Apollo lead-generation tracking and form interactions.

Maximum Storage Duration
Session
Type
HTTP Cookie

Learn more about this provider

663488ac4c0766030082b2b3_canTrack

Stores whether Apollo tracking is permitted for the current visitor based on consent settings.

Maximum Storage Duration
Persistent
Type
HTML Local Storage
663488ac4c0766030082b2b3_eventQueue

Queues visitor interaction events for Apollo analytics before they are sent to the provider.

Maximum Storage Duration
Persistent
Type
HTML Local Storage
apolloAnonId

Assigns an anonymous identifier to track visitor interactions across sessions for lead-generation analytics.

Maximum Storage Duration
Persistent
Type
HTML Local Storage

Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can change or withdraw your consent at any time from the cookie settings on our website.

Your consent applies to the following domains: amio.io

Learn more in our Privacy Policy and Cookies Policy.