Data Processing Agreement
Last updated: August 2, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Customer" or "Controller") and Oracle Studios ("SetterFlow," "we," or the "Processor") and governs the processing of personal data carried out by SetterFlow on the Customer's behalf under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), in particular Article 28.
1. Roles of the Parties
For personal data of the Customer's end users and leads processed through the Service, the Customer acts as the Controller and SetterFlow acts as the Processor. SetterFlow processes such personal data only on documented instructions from the Customer, including as set out in the Terms of Service and this DPA.
2. Subject Matter, Nature & Purpose
SetterFlow processes personal data to provide the AI setter and chatbot platform: receiving and responding to messages through connected channels (such as Facebook Messenger and Instagram Direct Messages), qualifying and booking leads, generating AI responses, and producing analytics and lead records for the Customer. Processing continues for the duration of the Customer's use of the Service.
3. Categories of Data & Data Subjects
- Data subjects: the Customer's prospects, leads, and end users who message the Customer's connected accounts.
- Categories of data: name and profile identifier, email address (where available), gender, locale and timezone (where available), message content, conversation metadata, and booking details.
The Customer must not use the Service to process special categories of personal data (Article 9 GDPR) unless expressly agreed in writing.
4. Processor Obligations
- Process personal data only on the Controller's documented instructions, including regarding international transfers, unless required by law.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures under Article 32 GDPR.
- Assist the Controller, taking into account the nature of processing, in responding to data subject requests.
- Assist the Controller with its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments).
- Make available information necessary to demonstrate compliance and allow for audits as set out below.
5. Sub-processors
The Customer provides general authorisation for SetterFlow to engage sub-processors to deliver the Service. SetterFlow imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable for their performance. Current sub-processors include, among others:
- AI providers: OpenAI, Anthropic, Google — to generate responses
- Meta Platforms: Facebook / Instagram messaging delivery
- Hosting & infrastructure providers: to host and secure the Service
We will inform the Customer of intended changes to sub-processors and give the Customer the opportunity to object.
6. Security Measures
SetterFlow maintains appropriate technical and organisational measures including encryption of data in transit and at rest, application-level encryption of stored third-party access tokens and credentials, access controls, and regular security review, as further described in our Privacy Policy.
7. Personal Data Breaches
SetterFlow will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will provide reasonable information to help the Customer meet its own notification obligations under Articles 33 and 34 GDPR.
8. International Transfers
Where personal data is transferred outside the European Economic Area, SetterFlow ensures an appropriate transfer mechanism is in place, such as the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision, together with any required supplementary measures.
9. Data Subject Rights & Assistance
Taking into account the nature of the processing, SetterFlow assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, and objection).
10. Return & Deletion of Data
Upon termination of the Service, and at the Customer's choice, SetterFlow will delete or return the personal data and delete existing copies, unless retention is required by law. See our Data Deletion instructions for timelines.
11. Audits
SetterFlow makes available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and confidentiality.
12. Contact
To request a countersigned copy of this DPA or for any data protection queries, contact us at:
Email: info@oraclestudios.io
Company: Oracle Studios, Andrea Ioannou 14A, 8047 Paphos, Cyprus