Legal
Data Processing Agreement
Version 1.0, 8 October 2026
Available on request: email support@pivra.ai to sign. This is our standard DPA for Pivra for business. Send your company’s legal name, address and signatory, and we will send it back countersigned. If you need changes, tell us what and why.
1. Parties and roles
This Data Processing Agreement (“DPA”) is between the customer named in the signature block (“Customer”) and Bluebird Technologies Pty Ltd (ABN 57 628 676 764), trading as Pivra (“Pivra”). It forms part of the Terms of Service (the “Agreement”) for Pivra for business (the “Service”).
For personal data the Customer puts into the Service, or that the Customer’s website visitors and contacts give the Customer’s chatbot (“Customer Personal Data”), the Customer is the controller and Pivra is the processor. Pivra is a controller only for its own account, billing and website data, under its Privacy Policy.
“Data Protection Laws” means the laws that apply to the processing, which may include the Privacy Act 1988 (Cth), the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection. Terms such as controller, processor, personal data and personal data breach have the meanings given in the GDPR.
2. Processing on instructions
Pivra processes Customer Personal Data only to provide the Service and on the Customer’s documented instructions. The Agreement, this DPA and the Customer’s configuration of the Service are those instructions. Pivra will tell the Customer if it believes an instruction breaks Data Protection Laws, unless the law forbids it.
Pivra does not sell Customer Personal Data and does not use it to train AI models. The details of the processing are in Annex 1.
3. Customer responsibilities
The Customer is responsible for having a lawful basis for the processing, for giving its visitors and contacts the notices they need (for example in its own privacy policy and the chatbot’s welcome message), for not asking the chatbot to collect special category data it does not need, and for the accuracy of the knowledge it adds.
4. Confidentiality and security
Pivra ensures that people authorised to process Customer Personal Data are bound by confidentiality. Pivra keeps appropriate technical and organisational measures in place to protect it, as described in Annex 2 and on the security page, and may update them as long as the overall level of protection does not go down.
5. Sub-processors
The Customer gives general authorisation for Pivra to use the sub-processors listed in Annex 3. Pivra will list a new or replacement sub-processor on its security page at least 30 days before it starts processing Customer Personal Data. An emergency replacement needed for security or to keep the Service running may start sooner, and Pivra will list it promptly. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the Agreement and receive a refund of the unused part of the current prepaid billing period, which is its only remedy for the change.
Pivra uses each sub-processor under that provider’s own data processing terms, which require it to protect personal data, and remains responsible to the Customer for the sub-processors it chooses.
6. International transfers
Customer Personal Data is hosted in Australia and is processed in the United States by OpenAI to generate replies. Sub-processors may give their staff support access from other countries.
Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 (“SCCs”), Module Two (controller to processor), or Module Three (processor to processor) where the Customer is itself a processor, which are incorporated by reference. For the SCCs: clause 7 (docking) applies; clause 9(a) option 2 (general authorisation) applies with the notice period in section 5; the option in clause 11 does not apply; clauses 17 and 18 are governed by and subject to the courts of Ireland; Annexes I to III are Annexes 1 to 3 of this DPA.
For transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) applies, with Tables 1 to 3 completed from this DPA and either party able to end it as allowed in Table 4. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.
7. Requests from individuals
Taking into account the nature of the processing, Pivra will help the Customer respond to requests from individuals to exercise their rights. The Customer can view conversations and leads in the dashboard. When the Customer asks and supplies details that identify the person (such as their email address or phone number), Pivra will export or delete that person’s conversations and lead details within 30 days. If Pivra receives a request directly, it will pass it to the Customer and not answer it itself, unless the law requires otherwise.
8. Personal data breaches
Pivra will notify the Customer without undue delay, and in any case within 72 hours, after Pivra confirms a personal data breach affecting Customer Personal Data. The notice will describe, as far as Pivra then knows, what happened, the data and people likely affected, the likely consequences, and what Pivra is doing about it, and Pivra will add to it as it learns more. Notice is sent to the account owner’s email address. Notifying is not an admission of fault.
9. Impact assessments
Pivra will give the Customer reasonable information it needs to carry out a data protection impact assessment or consult a supervisory authority about the Service, where the Customer cannot get that information itself.
10. Deletion or return on termination
Before the Agreement ends, the Customer can export conversations from the dashboard on paid plans, or ask Pivra for an export of Customer Personal Data. Deletion is handled by Pivra’s team, on the Customer’s written request or at termination: within 60 days after the end of the Agreement, or of an earlier request, Pivra will delete Customer Personal Data from its live systems, unless the law requires it to keep some of it, in which case this DPA keeps applying to that data. Backups expire on the providers’ backup schedules and are not restored except for disaster recovery.
11. Audits
Once a year, on request, Pivra will answer a written security questionnaire to show compliance with this DPA. Pivra does not yet hold a SOC 2 report or ISO 27001 certificate. If the answers are not enough, or a supervisory authority requires it, any further audit is by agreement between the parties, carried out remotely where possible, at the Customer’s cost, under confidentiality, and without access to other customers’ data.
12. General
If this DPA conflicts with the Agreement, this DPA wins for the processing of Customer Personal Data; if it conflicts with the SCCs or UK Addendum, they win. Each party’s liability under this DPA is subject to the limits in the Agreement, unless Data Protection Laws or the SCCs do not allow that. Except where the SCCs or the UK Addendum say otherwise, this DPA is governed by the law that governs the Agreement (New South Wales, Australia); the SCCs are governed by Irish law, as set out in section 6. It lasts as long as Pivra processes Customer Personal Data.
Annex 1. Details of processing
- Subject matter and duration
- Providing Pivra for business under the Agreement, for its term and until deletion under section 10.
- Nature and purpose
- Hosting the Customer’s knowledge; generating chatbot replies; searching the knowledge; storing conversations, leads and handover requests; sending alerts and messages on the channels the Customer turns on; analytics for the Customer.
- Data subjects
- Visitors and contacts who use the Customer’s chatbot; the Customer’s staff who use the dashboard; people named in knowledge the Customer adds.
- Personal data
- Conversation content; contact details visitors choose to give (name, email, phone, address); booking and enquiry details; IP address, approximate location and browser details; staff names and email addresses.
- Special category data
- None intended. The Customer should not configure the chatbot to collect it.
- Frequency
- Continuous, while the chatbot is live.
- Controller contact
- The signatory named in the signature block.
- Processor contact
- Bluebird Technologies Pty Ltd, trading as Pivra: support@pivra.ai
- Competent supervisory authority
- As set out in clause 13 of the SCCs for the Customer’s establishment or representative.
Annex 2. Technical and organisational measures
- Hosting in Sydney, Australia (Fly.io, Supabase); HTTPS for all traffic.
- Encryption at rest by the database and storage provider; integration API keys, custom action headers and Messenger, Instagram and Slack tokens additionally encrypted with AES-256-GCM by the application; saved API keys and access tokens never returned to the browser.
- Uploaded files quarantined until a malware scan passes.
- Two-factor sign-in (TOTP) available to every account; team roles for dashboard access.
- Server-side checks that each request belongs to the workspace it asks about.
- AI requests sent to OpenAI with response storage turned off.
More detail, including what we have not done yet, is on the security page.
Annex 3. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Website, dashboard and chat widget delivery | Global edge network |
| Fly.io | Application, API and upload scanning | Australia (Sydney) |
| Supabase | Database, sign-in and file storage | Australia (Sydney) |
| OpenAI | Generating replies and embeddings | United States |
| Stripe | Payments (paid plans) | Global |
| Amazon SES | Email delivery and the email channel, where used | Sydney region, as configured |
| Twilio or Meta | SMS alerts and messaging channels, if turned on | Global |
Integration providers the Customer connects (such as a CRM or calendar) receive data on the Customer’s instruction and are not Pivra’s sub-processors.
Signature
Signed for the Customer and for Bluebird Technologies Pty Ltd by their authorised signatories, with name, title and date. The DPA takes effect on the later signature date.