Data Processing Agreement
Last updated: August 27, 20261. Subject of the Agreement
1.1. This document (hereinafter referred to as the "Agreement" or "DPA") defines the procedure for processing personal data of the User's Clients (hereinafter referred to as "Client Personal Data") within the use of the LALAPAM platform (hereinafter referred to as the "Platform").
1.2. The User (hereinafter referred to as the "Controller") instructs LALAPAM (hereinafter referred to as the "Processor") to process the personal data of their Clients in accordance with the terms of this Agreement.
1.3. Personal data processing is carried out exclusively within the functionality of the Platform and for the purposes defined by the Controller. The Controller's enabling of specific Platform features (AI Features, Direct Channels, payment acceptance, etc.) constitutes the Controller's documented instruction for the corresponding processing.
1.4. The legal basis for processing is Article 6, Part 3 of Federal Law No. 152-FZ dated July 27, 2006 "On Personal Data" (hereinafter referred to as FZ-152).
1.5. This Agreement does not apply to the processing of data of the Client's unified account on the Platform (registration, authorization, consent log, security), with respect to which LALAPAM acts as an independent data controller in accordance with the Privacy Policy.
2. Definitions
- Controller (User) — an individual or legal entity (individual entrepreneur, self-employed person) using the LALAPAM Platform to serve their Clients and determining the purposes and means of processing their personal data.
- Processor (LALAPAM) — Individual Entrepreneur Denis N. Filipkin, providing the LALAPAM SaaS platform and processing Client personal data on behalf of the Controller.
- Client — an individual who books services, purchases goods, or makes reservations through the User's Platform.
- Client Personal Data — any information relating to a Client, provided by them during booking, purchase, or other interaction with the Platform.
- AI Features — Platform functionality that uses large language models of third-party providers, including the AI agent for automated communication with Clients.
- Direct Channels — functionality for sending and receiving messages through the Controller's own accounts in third-party messengers, connected by the Controller to the Platform.
3. Categories of Client Data
3.1. Under this Agreement, the Processor processes the following categories of Client personal data:
- First name, last name
- Phone number, email address
- Telegram ID, MAX ID, identifiers in other messengers connected to the Platform
- Order data (service names, dates, amounts)
- Booking form data (custom fields configured by the User)
- Content of the Client's correspondence in the Platform's communication channels, including dialogs with the Controller's AI agent
- Brief information about the Client's preferences and service history (AI agent memory), the Controller's notes about the Client
- Photos and files attached to orders
- Interaction history with the Platform
3.2. The Controller undertakes not to enter special categories of personal data (health information, religious beliefs, etc.) or biometric data into free-form fields, notes, and AI agent instructions. Information of such a nature communicated by the Client at their own initiative in correspondence is processed exclusively as the content of the respective communication.
4. Processor Obligations (LALAPAM)
4.1. The Processor undertakes to:
- Process Client data exclusively according to the Controller's documented instructions (including the Platform feature settings made by the Controller) and for the purposes defined by this Agreement.
- Ensure the confidentiality of processed personal data.
- Implement technical and organizational measures to protect personal data, including:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of sensitive data at rest (including credentials of connected messenger accounts)
- Role-based access control and isolation of organizations' data
- Logging of data operations
- Regular data backups
- Notify the Controller of any security incident within 72 hours of discovery.
- Assist the Controller in fulfilling data subject rights requests (access, rectification, erasure).
- Delete or return all Client personal data upon the Controller's request or upon termination of the agreement.
- Provide the Controller with information necessary to demonstrate compliance with the obligations under this Agreement.
- Not engage sub-processors without prior notification to the Controller and keep the list of sub-processors (Section 6) up to date.
5. Controller Obligations (User)
5.1. The Controller undertakes to:
- Obtain lawful consent from Clients for the processing of their personal data before using the Platform, and — for messages of an advertising nature — the recipient's prior consent in accordance with applicable advertising and communications legislation.
- Ensure a legal basis exists for the collection and processing of Client data in accordance with applicable legislation, including (when the corresponding features are used) grounds for transferring data to AI model providers and messenger operators, including cross-border transfer (Section 7).
- Define the purposes and scope of Client data processing.
- Fulfill the obligations of a personal data controller provided by FZ-152 with respect to their Clients' data (including, where required, notifying the authorized body about processing and about cross-border transfer of personal data).
- Notify the Processor of any restrictions on data processing.
- Promptly inform the Processor of any data subject requests received (requests for deletion, access, rectification, etc.).
- Respect Clients' opt-outs from receiving messages (including those recorded automatically via stop words) and not resume sending without new consent.
- Bear full responsibility for the lawfulness of Client data collection and for the content of messages sent to Clients.
- Publish their own privacy policy for their Clients.
6. Sub-processors
6.1. The Processor engages the following sub-processors to perform specific Platform functions:
| Sub-processor | Purpose | Jurisdiction |
|---|---|---|
| Resend | Email notification delivery | USA |
| Telegram Bot API | Telegram notifications | UAE |
| MAX (VK) | Notifications and messages in MAX, including delivery through accounts connected by the Controller (Direct Channels) | Russia |
| Operators of other connectable messengers (as Direct Channels become available: Telegram, WhatsApp, etc.) | Message delivery through accounts connected by the Controller | According to the messenger operator |
| Messenger integration infrastructure providers (when Direct Channels are used; the current list is available upon request) | Technical support for sending and receiving messages | Russia (unless otherwise indicated when the feature is connected) |
| OpenAI | AI Features (processing of queries and correspondence) | USA |
| DeepSeek | AI Features (processing of queries and correspondence) | China (PRC) |
| Providers of Russian AI models (including GigaChat, Sberbank PJSC — as they become available) | AI Features (processing of queries and correspondence) | Russia |
| FNS (My Tax) | Fiscal receipt generation | Russia |
| Web Push | Browser push notifications | Depends on provider |
6.2. The Controller will be notified of any changes to the list of sub-processors at least 30 days prior to the changes taking effect (by publishing an updated version of this Agreement and/or by notification through the Platform's communication channels).
6.3. The Controller has the right to object to the engagement of a new sub-processor within the specified notification period; if no agreement is reached, the Controller may stop using the corresponding feature or terminate the agreement.
6.4. Certain services are connected by the Controller independently on the basis of the Controller's own agreements with such services (for example, the YooKassa payment service for accepting Client payments, or the Controller's own messenger accounts). With respect to such services, the Processor transfers data on the Controller's instruction, and the terms of data processing by the service are determined by the Controller's agreement with the respective service; such services are not sub-processors of the Processor.
7. Cross-border Data Transfer
7.1. Client personal data may be transferred to jurisdictions listed in the sub-processors table (Section 6) to perform the corresponding Platform functions.
7.2. By enabling AI Features and/or Direct Channels, the Controller gives the Processor a documented instruction to transfer Client data to the corresponding sub-processors, including cross-border transfer (USA — OpenAI, PRC — DeepSeek, UAE — Telegram, other jurisdictions — according to Section 6).
7.3. The Controller, as the operator of their Clients' personal data, independently ensures compliance with the requirements of Article 12 of FZ-152 with respect to the instructed cross-border transfer (including, where required, notifying the authorized body and having legal grounds for transfer to countries that do not provide adequate protection of data subjects' rights). The Processor provides the Controller with information about recipients' jurisdictions (Section 6) and, upon request, other information necessary to fulfill these requirements.
7.4. Safeguards for cross-border transfers include: data encryption, data minimization, and contractual obligations of sub-processors to protect personal data.
8. Specifics of Processing for Certain Features
8.1. AI Features (AI agent). When the Controller enables the AI agent:
- the content of the Client's dialog and the necessary context (information about services, appointments, and the Client's preferences) are transferred to the AI model provider to generate a response;
- the Platform may generate and store brief information about the Client's preferences and service history (AI agent memory) within the Controller's organization; the Controller may review, correct, and delete such information using Platform tools;
- the Processor maintains a technical log of AI agent interactions (the request to the model, the context of the interaction, tool calls and their results, the model's response) to ensure the feature's operability, investigate incidents, and improve model quality; information from the log is used to further train the models; phone numbers and email addresses are removed before use;
- the Controller manages the AI agent (enabling/disabling, instructions, connected tools) and must monitor the material results of its operation;
- responses are generated automatically; no decisions producing legal consequences for the Client are made based solely on automated processing (appointments are created and modified based on the Client's will and/or under the Controller's control).
8.2. Direct Channels. When the Controller connects their own messenger accounts:
- to deliver a message, the Client's phone number and/or messenger identifier are transferred to the operator of the respective messenger;
- the credentials (session data) of the connected account are stored by the Processor in encrypted form and are used exclusively for sending and receiving messages on the Controller's instruction;
- the Processor applies automatic processing of recipient opt-outs (stop words): the Client's opt-out is recorded, and further sending of messages to them through the respective channel is stopped;
- the Processor may apply sending quotas and limits to reduce the risk of account blocking and to prevent bulk messaging without recipient consent;
- the Controller is responsible for the lawfulness of messaging, the existence of recipient consents, and the content of messages.
9. Data Subject Rights
9.1. Upon receiving a request from a Client (for access, rectification, or erasure of personal data), the Processor shall:
- Notify the Controller of the received request within 48 hours.
- Assist the Controller in fulfilling the data subject's request.
- Complete the deletion of personal data within 30 days after receiving confirmation from the Controller.
10. Security Incidents
10.1. The Processor shall notify the Controller of any security incident affecting Client personal data within 72 hours of discovery.
10.2. The incident notification shall contain: a description of the incident, the categories and approximate volume of affected data, measures taken to remediate the incident, and recommendations for minimizing consequences.
10.3. The Processor shall take all reasonable measures to minimize the consequences of a security incident.
11. Term and Termination
11.1. This Agreement remains in effect for the entire duration of the Terms of Service between the Controller and the Processor.
11.2. Upon termination of the Terms of Service, the Processor shall delete all Client personal data within 30 days.
11.3. Upon the Controller's request, the Processor shall provide a return of data in a machine-readable format prior to deletion.
12. Liability
12.1. Each party shall be liable for any breach of its obligations under this Agreement in accordance with the applicable legislation of the Russian Federation.
12.2. The Processor shall not be liable for: the unlawful collection of personal data by the Controller; data processing that falls outside the scope of the Controller's documented instructions; the content of messages and mailings sent by the Controller or in accordance with the Controller's settings (including automatic rules, scenarios, and the AI agent); the Controller's failure to comply with organizational protection measures and unlawful actions of the Controller's employees and representatives; the consequences of restriction or blocking of the Controller's accounts by third-party services and messengers.
12.3. The Processor's liability is limited in accordance with the Terms of Service.
13. Governing Law
13.1. This Agreement is governed by the legislation of the Russian Federation.
13.2. Federal Law No. 152-FZ dated July 27, 2006 "On Personal Data" applies to the processing of personal data.
13.3. Disputes arising from this Agreement shall be resolved in the manner prescribed by the Terms of Service.
14. Contact Information
14.1. Processor:
- Name: Individual Entrepreneur Denis N. Filipkin
- TIN: 731201040405
- Address: 6 Kirova St., apt. 225, Ulyanovsk, 432048, Russian Federation
- Email: support@lalapam.ru