Data Processing Addendum
Last updated: 26 June 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Dwosix SH.P.K. (“Dwosix”, “Processor”) and the business customer (“Customer”, “Controller”). It governs the processing of personal data that we carry out on the Customer’s behalf when providing Barosa FrontDesk AI, and reflects the requirements of Article 28 GDPR, the Swiss FADP, and the data-protection law of the Republic of Kosovo. Where this DPA conflicts with the Terms on data protection, this DPA prevails.
1. Roles and scope
The Customer is the controller and Dwosix is the processor with respect to End-User personal data processed through the Platform. Each party will comply with its obligations under applicable data-protection law. This DPA applies for as long as we process such data.
2. Details of processing
- Subject matter: provision of the AI receptionist and lead-management Service.
- Duration: the term of the subscription plus any retention period.
- Nature and purpose: hosting, storing, transmitting, and AI-processing of conversations and leads to deliver the Service.
- Categories of data: End-User contact details (name, phone, email), message content, requested services, and conversation metadata.
- Data subjects: the Customer’s End Users and prospects.
3. Processing on instructions
We process personal data only on the documented instructions of the Customer, including as set out in the Terms and this DPA, unless required by law (in which case we will inform the Customer unless legally prohibited). The Customer’s configuration and use of the Service constitute its instructions.
4. Confidentiality
We ensure that personnel authorised to process personal data are bound by confidentiality obligations and access data only as needed to provide the Service.
5. Security measures
We implement appropriate technical and organisational measures including encryption of secrets (such as Provider Keys) and data in transit, role-based access control, tenant isolation, rate limiting, input validation, audit logging, and regular review. The Customer is responsible for the security of its own credentials and devices.
6. Sub-processors
The Customer authorises Dwosix to engage sub-processors to provide the Service, including AI providers (e.g. OpenAI, Anthropic), cloud hosting, email delivery, and payment processing. We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will provide a current list on request and give reasonable notice of changes so the Customer may object on reasonable data-protection grounds.
7. International transfers
Where personal data is transferred outside Kosovo, the EEA, or Switzerland, we use an approved transfer mechanism such as the Standard Contractual Clauses or an adequacy decision.
8. Assistance to the Controller
Taking into account the nature of the processing, we will provide reasonable assistance to the Customer to: respond to data-subject requests (access, rectification, erasure, portability, objection); meet security, breach-notification, and data-protection-impact-assessment obligations; and consult with supervisory authorities where required.
9. Personal-data breach
We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s data, and provide information reasonably available to help the Customer meet its notification obligations.
10. Return and deletion
On termination, and at the Customer’s choice, we will delete or return the Customer’s personal data and delete existing copies within a reasonable period, unless retention is required by law. The Customer may export data before termination where technically feasible.
11. Audits
We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits, and in a manner that does not compromise other customers’ security.
12. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
13. Contact
Data-protection contact: privacy@barosa.ch, Dwosix SH.P.K., Rruga Xhevat Ajvazi 15, Gjilan, Republic of Kosovo.