Last updated: · Version: dpa-2026-09-25
This Data Processing Agreement ("DPA") is part of the Terms of Service between the Customer (controller) and Mielikkix AS, org. no. {{VERIFY: org. number}} (processor). It meets the requirements of GDPR article 28 and applies whenever we process personal data on the Customer's behalf.
1. Subject matter and duration
We process personal data to provide the Mielikkix chat widget, AI agents and dashboard to the Customer. The DPA lasts as long as we process personal data for the Customer.
2. Nature and purpose
Storing, retrieving, analysing (including with AI language models), transmitting and deleting data, only to answer the Customer's end users, capture leads, book appointments, handle calls and reviews, and show results in the Customer's dashboard.
3. Data subjects and categories of data
- Data subjects: the Customer's website visitors, callers, customers and reviewers, and the Customer's staff.
- Data: chat messages and AI replies; names, email addresses, phone numbers and messages from lead and booking forms; appointment times; caller phone numbers and call audio (transcribed in real time, not stored); public reviews and replies; technical data such as session IDs.
- Special categories (GDPR art. 9) are not meant to be processed. The Customer must not configure the service to collect them without our written agreement.
4. Our obligations as processor
- We process personal data only on the Customer's documented instructions (these terms, the Customer's settings and written requests), unless the law requires otherwise. If an instruction seems to break data protection law, we will tell the Customer.
- Everyone with access to the data is bound by confidentiality.
- We apply the security measures described on our Security page (GDPR art. 32).
- We help the Customer respond to data subject requests (access, erasure, etc.), for example by exporting or deleting a given visitor's conversations.
- We help the Customer with security, breach notification, impact assessments and prior consultations (art. 32–36), within reason.
- We notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information the Customer needs to meet its own reporting duties.
- We make available the information needed to show compliance with this DPA and allow audits, on reasonable notice and at the Customer's cost.
5. Subprocessors
The Customer gives general authorisation for the subprocessors listed on our Subprocessors page. We will notify the Customer at least {{VERIFY: 30}} days before adding or replacing a subprocessor, and the Customer may object on reasonable grounds. If we can't resolve the objection, the Customer may terminate the affected service. We impose the same data protection obligations on every subprocessor and remain responsible for them.
6. International transfers
Where a subprocessor is outside the EEA, transfers rely on an adequacy decision (such as the EU-US Data Privacy Framework) or the EU Standard Contractual Clauses {{VERIFY: mechanism per vendor}}.
7. Deletion and return
When the Customer deletes its account, we permanently delete the Customer's personal data 30 days later (a grace period in which the Customer can cancel), unless the law requires us to keep it. Before deleting, the Customer can download a copy in a machine-readable format from the dashboard.
8. Contact
Questions about this DPA or requests under it: post@mielikkix.no.