Irelia
Platform

The platform

How to build it Describe a business in chat. Your agent is live in 30 minutes. How it works Your funnel with an agent inside it, from first message to CRM. How to sell it One workspace per client. Your brand, billing, and margin.

Connect & secure

Channels Reach leads on WhatsApp and Facebook. More coming. Integrations Native lead forms and a calendar with real availability. Connect anything via Zapier or Make. Security Built for you to put your name on, and your client's trust.
Irelia 101 See how the platform works, end to end.
Solutions

What the agent does

Book appointments It offers real slots in chat and writes them to your calendar. Qualify & route It answers every lead, scores intent, and routes the hot ones. Reactivate dormant leads It re-opens old conversations and brings quiet leads back. Reduce no-shows Reminders on the same channel keep appointments kept. Customer care 24/7 It answers common questions any hour, in any language. Nurture leads It follows up over time until a lead is ready to book.

By industry

Dental & medical clinics Salons & beauty Real estate & construction Finance & insurance Automotive Restaurants & food Hotels & hospitality
PricingCustomers
Resources

Tools

ROI calculator See how much you can earn reselling AI agents. Credit calculator Price usage and find your margin per client.

Learn & connect

Documentation Setup guides and references at docs.irelia.ai. Contact Talk to the team about partnering with Irelia.
40% Earn 40% for life Refer other marketers to Irelia and earn 40% of their plan, every month, for as long as they stay. Explore the referral program
EN English IT Italiano
Login Start free
Irelia
EN English IT Italiano

The platform

How to build it Describe a business in chat. Your agent is live in 30 minutes. How it works Your funnel with an agent inside it, from first message to CRM. How to sell it One workspace per client. Your brand, billing, and margin.

Connect & secure

Channels Reach leads on WhatsApp and Facebook. More coming. Integrations Native lead forms and a calendar with real availability. Connect anything via Zapier or Make. Security Built for you to put your name on, and your client's trust.

What the agent does

Book appointments It offers real slots in chat and writes them to your calendar. Qualify & route It answers every lead, scores intent, and routes the hot ones. Reactivate dormant leads It re-opens old conversations and brings quiet leads back. Reduce no-shows Reminders on the same channel keep appointments kept. Customer care 24/7 It answers common questions any hour, in any language. Nurture leads It follows up over time until a lead is ready to book.

By industry

Dental & medical clinicsSalons & beautyReal estate & constructionFinance & insuranceAutomotiveRestaurants & foodHotels & hospitality
Pricing
Customers

Tools

ROI calculator See how much you can earn reselling AI agents. Credit calculator Price usage and find your margin per client.

Learn & connect

Documentation Setup guides and references at docs.irelia.ai. Contact Talk to the team about partnering with Irelia.
40% Earn 40% for life Refer other marketers and earn 40% of their plan, every month.
Login Start free

Legal

Data Processing Agreement (DPA) Irelia ↔ Partner

Version 1.0 dated 16 September 2026

This data processing agreement (hereinafter the “DPA”) is entered into between Automation Genius By KDL, a sole proprietorship of Kristian Di Lillo, VAT no. IT02789630692, with registered office at Contrada Santa Maria Maggiore 4, 66011 Bucchianico (CH), Italy, certified email (PEC) nextwaveai@pec.it, owner of the Irelia trademark and commercial brand (hereinafter “Irelia”), and the Partner accepting the General Terms and Conditions for Partners (hereinafter the “Agreement”). Irelia and the Partner are jointly referred to as the “Parties”.

Art. 1 — Scope, relationship with the Agreement and definitions

1.1 Subject matter. The DPA governs, pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR), the processing of Workspace Data carried out by Irelia on behalf of the Partner in the performance of the Agreement.

1.2 Relationship with the Agreement. The DPA is an integral part of the Agreement and is accepted together with it (Agreement, Art. 1.16). In the event of conflict regarding the processing of personal data, the DPA prevails (Agreement, Art. 21.5). For every other aspect — liability, indemnity, term, termination, notices, governing law and jurisdiction — the Agreement applies.

1.3 Definitions. Capitalised terms have the meaning set out in Art. 1 of the Agreement. In addition:

(a) Workspace Data: the personal data processed in the Workspaces of the Account as a result of the use of the Platform and the data referred to in clause 3.5(f), described in Art. 3; (b) Workspace Controller: the Partner, for the Workspaces it uses for its own purposes; the Client, for the Workspaces configured for the Client; (c) Sub-processor List: the list of Sub-processors published by Irelia at https://irelia.ai/legal/subprocessors, in the version in force; (d) Breach: a personal data breach within the meaning of Art. 4(12) GDPR.

1.4 Excluded data. The following remain outside the DPA: (a) the data for which Irelia is the controller — data of the Partner, of the Users and of the parties submitting contact requests — processed in accordance with Irelia’s Privacy Notice (Agreement, Art. 16.2); (b) the data processed by Meta and by the other independent controllers referred to in Art. 9 for their own purposes.

Art. 2 — Roles of the Parties

2.1 Irelia as processor. Irelia processes Workspace Data as a processor (Art. 4(8) GDPR), exclusively on behalf of the Partner and, through the Partner, of the Workspace Controller, and in order to deliver the Platform. Irelia does not determine the purposes and means of the processing and does not process Workspace Data for its own purposes.

2.2 Role of the Partner. The Partner’s role depends on the use of each Workspace: (a) for the Workspaces it uses for its own purposes, the Partner is the controller and Irelia is its processor; (b) for the Workspaces configured for a Client, the Client is the controller, the Partner is a processor on behalf of the Client and Irelia is a sub-processor (Art. 28(2) and (4) GDPR). The role follows from the factual circumstances (Art. 4(7) GDPR), not from declarations: the Platform neither requires nor records any qualification. Irelia’s obligations under the DPA are identical in both cases.

2.3 Chain towards the Client. When the Partner acts as a processor of its Client, Irelia agrees to be engaged by the Partner as a sub-processor and to use, for that purpose, the Sub-processors. The Partner: (a) warrants that it has entered into with the Client an agreement under Art. 28(3) GDPR with safeguards no lower than those of the DPA (Agreement, Art. 9.3(h)), that it has obtained from the Client the authorisation to engage Irelia and the Sub-processors, and that it forwards to the Client the communications received from Irelia under the DPA that concern the Client; (b) fulfils towards the Client the obligations that Irelia fulfils towards the Partner. Irelia has no relationship with the Client under the DPA, without prejudice to the functionalities referred to in clause 5.3.

2.4 Single point of contact. Every instruction, request, authorisation and communication under the DPA takes place between Irelia and the Partner. The Partner is liable to Irelia for compliance with the DPA by its Clients and the Users, as if it were its own conduct (Agreement, Art. 5.3). Requests received by Irelia from a Client, an End User or a third party are handled in accordance with clause 5.4.

Art. 3 — Description of the processing

3.1 Subject matter and nature. The processing consists of the operations necessary to deliver the Platform: receiving and sending messages on the Channels; storing conversations and contacts; processing messages through the language models and the tools configured by the Workspace Controller, following pseudonymisation (Art. 14); indexing the content uploaded to the Workspace for the AI Agent’s replies; executing the actions configured by the Workspace Controller, including those on the services it connects with its own credentials; export and erasure; technical support upon the Partner’s request; retention and erasure in accordance with Art. 10.

3.2 Purposes. The processing is intended to enable the Workspace Controller to manage, through AI Agents, the conversations with its End Users for the purposes it determines in the configuration of the Workspace and states in its own privacy notice — by way of example, assistance, information, commercial qualification, bookings, collection of orders and requests. Irelia pursues no purposes of its own.

3.3 Duration. The processing lasts for the term of the Agreement and, for retention and erasure only, for the periods under Art. 10.

3.4 Data subjects. (a) End Users; (b) the other natural persons whose personal data are contained in the conversations — for example, a third party mentioned by the End User — in the content uploaded to the Workspace — for example, the Workspace Controller’s staff named in a document — or in the services connected by the Workspace Controller; (c) for the data referred to in clause 3.5(f), the Clients’ contact persons and contacts.

3.5 Categories of data. (a) Identifying and contact data of End Users: name, telephone number, profile identifiers on the Channels; (b) content of the conversations: End User messages, AI Agent replies, messages sent by Users or through templates, including text, attachments and information provided by the End User; (c) data collected or generated by the AI Agent in executing the configuration: preferences, requests, appointments, qualification outcome, notes; (d) data contained in the documents and content uploaded to the Workspace; (e) data of the services connected by the Workspace Controller with its own credentials — for example, events, attendees and availability of a calendar — to the extent necessary for the configured actions; (f) where the Partner uses the Platform’s billing tools (Agreement, Art. 8.4): personal, tax and contact details of the Clients and data on their subscriptions, which Irelia configures and updates on behalf of the Partner on the Partner’s account with the payment service provider; payment instrument data are collected and processed directly by such provider, which acts under its contract with the Partner and is not a Sub-processor of Irelia; (g) technical metadata: message identifiers, timestamps, delivery and operation outcomes.

3.6 Special categories. The purpose of the Platform does not involve the processing of data referred to in Arts. 9 and 10 GDPR. The Workspace Controller may configure the AI Agent to collect them only under the conditions of the AUP (Agreement, Art. 11.9); data of such categories provided spontaneously by the End User are retained as part of the conversation. Irelia processes them with the same measures as the other Workspace Data, without dedicated processing; the lawfulness of the processing and any additional safeguards are the responsibility of the Workspace Controller.

Art. 4 — Partner’s instructions

4.1 Documented instructions. The DPA, the Agreement and the configuration of the Workspace performed by the Workspace Controller through the Platform — AI Agents, tools, Channels, permissions, uploaded content — constitute the Partner’s documented instructions within the meaning of Art. 28(3)(a) GDPR, including when the configuration is performed by the Client, through the Partner (clause 2.4). Irelia processes Workspace Data only on the basis of such instructions, unless an obligation under Union or Italian law requires it to process differently; in that case it informs the Partner before processing, unless the law prohibits this.

4.2 Further instructions. The Partner may request from Irelia processing that cannot be performed through the Platform’s functionalities — for example, the erasure of data according to its own criteria or the exclusion of certain tools — only in writing. Irelia performs it if compatible with the Platform and with the Sub-processors, and may make it subject to a fee if it involves activities not included in the Plan. If Irelia considers that an instruction infringes the GDPR or other data protection legislation, it informs the Partner and may suspend its performance until clarification (Art. 28(3), last sentence).

4.3 Platform restrictions. The Config-gate, the AUP, the available Channels, the tools that can be enabled, the permissions and the other structural restrictions of the Platform reflect the intended purpose of the Platform and its design in compliance with the applicable rules (Recital 78 GDPR). They do not constitute a determination by Irelia of the purposes or means of the processing, nor instructions of the Partner: within such restrictions the Workspace Controller freely decides what to process, for which purposes and with which tools. The requirements of the AUP are not instructions within the meaning of Art. 28(3)(a) (Agreement, Art. 3.7).

Art. 5 — Irelia’s obligations and data subject rights

5.1 Confidentiality. Irelia allows the processing of Workspace Data only by authorised persons, bound by confidentiality obligations and instructed on data protection; it limits access to what is necessary for delivery, maintenance and support activities, in accordance with the measures under Art. 14.

5.2 Assistance with data subject rights. Irelia assists the Partner in responding to requests for the exercise of data subject rights (Arts. 15-22 GDPR) relating to Workspace Data: it provides the data or performs the requested operation within twenty calendar days of the Partner’s written request, within the limits of the Platform’s functionalities and of the data present in its own systems. For data that may still be present at the Sub-processors during their transient retention periods, Irelia forwards the request and communicates the outcome, without the preceding time limit applying. Requests that the Partner can carry out independently through the Platform do not require Irelia’s intervention.

5.3 Rights-exercise functionalities. Irelia makes available in the Platform to the Partner and, for the Workspaces configured for a Client, to the Client: export of Workspace Data; erasure of individual contacts or conversations, or of all Workspace Data, without erasing the AI Agents’ configuration; rectification of contact data editable in the Platform; cancellation of the service on the Workspace; viewing of the contractual documents. Such functionalities are tools by which Irelia facilitates the exercise of data subject rights (Art. 12(2) GDPR) and do not constitute a determination of the purposes or means of the processing (Art. 4(7)); the Workspace Controller decides whether and how to use them. They are a structural condition of the Platform: they cannot be disabled, reduced or hidden through permissions or other configurations; export and erasure remain accessible after termination pursuant to clause 10.4. The scope of the export is defined in clause 14.3.

5.4 Requests addressed to Irelia. If Irelia receives a request relating to Workspace Data from a data subject, a Client or a third party, it acknowledges receipt to the sender and refers it to the Partner within five working days, stating that Irelia acts as a processor and that the request is forwarded to the Partner, without replying on the merits. Requests from authorities and Irelia’s legal obligations remain unaffected.

5.5 End User requests in conversations. Requests for the exercise of rights that the End User addresses to the AI Agent are handled by the Workspace Controller. Irelia makes available in the Platform tools that enable the AI Agent to recognise three requests made by the End User in the conversation and to execute them on the Workspace data relating to that End User: (a) access, by providing the End User with their own data; (b) erasure, subject to the End User’s confirmation; (c) objection to promotional communications (Art. 21(2) GDPR), by marking the contact as not contactable for communications initiated by the Workspace (Agreement, Arts. 11.8 and 11.11). Such tools are enabled by default and the Workspace Controller may disable them. For the requests that the tools do not execute — in particular rectification and restriction — and where the tools are disabled, the Partner ensures that the AI Agents’ configuration includes instructions to recognise the requests and route them to the Workspace Controller, using the templates made available by Irelia; it passes this obligation on to its Clients. Irelia provides adequate tools and documentation and does not guarantee the Workspace Controller’s configuration choices.

5.6 Assistance to the controller. Irelia assists the Partner, and through the Partner the Client, in fulfilling the obligations under Arts. 32-36 GDPR — security, Breaches, data protection impact assessment, prior consultation — by making available the information at its disposal on the Platform and on the Sub-processors (Art. 14, Sub-processor List and documentation published by Irelia). Further activities, specific to the Partner or to a Client, may be subject to a fee.

5.7 Information and audits. Irelia makes available to the Partner the information necessary to demonstrate compliance with Art. 28 GDPR: the DPA, Art. 14, the Sub-processor List and the security documentation it makes available on request, including under a confidentiality undertaking. Where such documentation is not sufficient, the Partner, or an independent third party appointed by it and bound by confidentiality, may carry out an audit with thirty days’ written notice, no more than once per calendar year, remotely and during business hours, with agreed scope and duration, without access to the data of other Partners or to the Sub-processors’ systems, at the Partner’s expense. The frequency limit does not apply to audits requested by a supervisory authority or following a Breach. Irelia informs the Partner if it considers that an audit request exceeds what is necessary under Art. 28(3)(h).

Art. 6 — Personal data breaches

6.1 Notification. Irelia notifies the Partner of any Breach of Workspace Data without undue delay and in any event within twenty-four hours of becoming aware of it (Art. 33(2) GDPR). The notification contains, to the extent available: the nature of the Breach, the categories and approximate number of data subjects and data concerned, the likely consequences, the measures taken or proposed and the point of contact; information not available is provided in subsequent phases, without delay.

6.2 Levels. Irelia classifies security events on three levels and communicates them to the Partner as follows: (a) confirmed Breach — confirmed access, disclosure, alteration or loss of Workspace Data: notification under clause 6.1; (b) incident with unconfirmed potential risk to Workspace Data — suspected access, exploited vulnerability, incident at a Sub-processor with possible impact: communication within forty-eight hours with the assessment in progress, followed by the notification under clause 6.1 if the Breach is confirmed; (c) incident with no exposure of Workspace Data: informational communication, where useful to the Partner.

6.3 Roles. The assessment of the risk to data subjects, the notification to the supervisory authority (Art. 33) and the communication to data subjects (Art. 34) are the responsibility of the controller: the Partner for its own Workspaces, the Client — through the Partner — for those configured for a Client. Irelia does not notify the authority or the data subjects on behalf of the controller, save upon its written request or by legal obligation, and does not communicate the Breach to Clients or third parties without agreement with the Partner, without prejudice to the communications due under the terms binding Irelia towards the Channel providers, of which it informs the Partner. Irelia cooperates with the Partner by providing the information and assistance reasonably necessary and documents the Breach, its circumstances and the measures taken.

6.4 Containment and communications. Irelia adopts without delay containment and recovery measures in accordance with its incident management procedures, including the revocation of compromised credentials and the suspension of the affected components, even where this involves a service interruption (Agreement, Art. 19.1(e)). Communications under this Article are made to the contact details referred to in the Agreement, Art. 21.3, and to the Account email address; the notification does not constitute an admission of liability.

Art. 7 — Sub-processors

7.1 General authorisation. The Partner gives general authorisation (Art. 28(2) GDPR) for the engagement of the Sub-processors indicated in the section of the Sub-processor List dedicated to Workspace data, in the version in force on the date of acceptance. The List indicates for each Sub-processor the entity, the service, the data processed, the country of processing and the transfer mechanism.

7.2 Sub-processors’ obligations. Irelia imposes on each Sub-processor, by contract, data protection obligations equivalent to those of the DPA, including sufficient guarantees regarding technical and organisational measures (Art. 28(4) GDPR); the Sub-processors’ contractual documents are referenced in the List. If a Sub-processor fails to fulfil its data protection obligations, the Partner addresses Irelia, which is liable as if the non-performance were its own (Art. 28(4), last sentence), within the limits of clause 13.1; Irelia then seeks recourse against the Sub-processor.

7.3 Changes. Irelia notifies the Partner of the addition or replacement of a Sub-processor by updating the List and sending a notice to the Account email address at least sixty days before the new Sub-processor processes Workspace Data. Within such period the Partner may object in writing, on well-founded data protection grounds; the Parties discuss in good faith and Irelia may propose a solution. If the objection is not resolved, the Partner may withdraw from the Agreement with effect from the effective date of the change, as provided for in the Agreement, Art. 20.2, with a refund of the price of unconsumed Credits and of the portion of the Plan Fee relating to the period not enjoyed, pursuant to the Agreement, Art. 7.6(d). In the absence of an objection within the period, the Sub-processor is deemed authorised.

7.4 Urgent replacements. If the replacement of a Sub-processor is necessary for security reasons, due to the Sub-processor ceasing operations or failing to perform, or due to a measure by an authority, Irelia may proceed with reduced notice, informing the Partner without delay; the right of objection under clause 7.3 remains unaffected.

7.5 Parties that are not Sub-processors. The following are not Sub-processors of Irelia and are not subject to this Article: (a) Meta and the other independent controllers referred to in Art. 9; (b) the third-party services that the Workspace Controller connects to the Platform with its own credentials — for example, a calendar — which Irelia accesses on its instruction: the relationship with the provider of such services is that of the Workspace Controller; (c) the payment service provider of the Partner’s account (clause 3.5(f)).

Art. 8 — Transfers outside the EU

8.1 Location. Workspace Data are processed in the European Union, in the countries indicated in the Sub-processor List for each Sub-processor, including the United States, and, where the Partner is established outside the Union, in the country of its registered office (clause 8.6). Irelia does not transfer Workspace Data to third countries beyond what is indicated in the List and in clause 8.6.

8.2 Mechanism. Transfers to third countries not covered by an adequacy decision are carried out on the basis of the standard contractual clauses adopted by the European Commission (Decision (EU) 2021/914) incorporated in the contracts between Irelia and the Sub-processors (Art. 46(2)(c) GDPR). Where the Sub-processor is certified under an adequacy decision — including the EU-US Data Privacy Framework — the List indicates this as an additional safeguard; its possible invalidation does not affect the standard contractual clauses mechanism.

8.3 Supplementary measures. In addition to the standard contractual clauses, Irelia applies: (a) pseudonymisation before sending to the language model providers: the End User’s identifying data known to the Platform — contact name, telephone number, email address — are replaced with placeholders in Irelia’s systems before the transfer and reconstituted only in Irelia’s systems after the model’s reply; the model providers do not receive the actual values. The free-text content of messages is transmitted as written by the End User; (b) encryption of data in transit and at rest; (c) the contractual exclusion of the use of Workspace Data for model training (Art. 11); (d) for the Sub-processors operating in Union regions, indicated in the List, no transfer. The measures are described in Art. 14.

8.4 Assessment. Irelia documents the assessment of transfers to third countries (transfer impact assessment) for the Sub-processors concerned, updates it at each change to the List and makes it available to the Partner pursuant to clause 5.7.

8.5 Requests from third-country authorities. If it receives from an authority of a third country a request for access to Workspace Data, Irelia informs the Partner where the law allows, verifies its legitimacy and challenges it where there are reasonable grounds, limiting disclosure to the minimum necessary.

8.6 Partner established outside the Union. If the Partner’s registered office recorded in the Account is outside the European Union and the European Economic Area, the Partner’s access to Workspace Data through the Platform constitutes a transfer to a third country, which is based: (a) if the country of the registered office is covered by an adequacy decision of the European Commission — including the United Kingdom and Switzerland — on such decision (Art. 45 GDPR), without further formalities; (b) otherwise, on the standard contractual clauses of Decision (EU) 2021/914, which the Parties enter into before the activation of the Plan in the module corresponding to the Partner’s role on the Workspace — Module Four (processor → controller) for the Workspaces the Partner uses for its own purposes, Module Three (processor → processor) for those configured for a Client — and for which the DPA provides the description of the processing (Art. 3) and the security measures (Art. 14). The processing carried out by Irelia and the Sub-processors remains located as per clause 8.1.

Art. 9 — Distribution platforms and independent controllers

9.1 Meta. WhatsApp, Instagram and Facebook Messenger are provided by Meta Platforms Ireland Limited and by the companies of its group (“Meta”). Meta processes the data passing through its Channels — account identifiers, telephone numbers, message content and metadata — as an independent controller, for its own purposes and in accordance with its own terms and privacy notices. Meta is not a Sub-processor of Irelia and does not act on the instructions of Irelia or of the Partner.

9.2 Relationship with Meta. The relationship concerning the Meta Assets is between Meta and their owner (Agreement, Art. 10). Irelia accesses the Channels through the application it has registered with Meta, with the permissions delegated by the owner of the Meta Assets, and through the messaging service provider (Business Solution Provider) indicated in the List, which is a Sub-processor of Irelia. Under the terms binding it towards Meta, Irelia processes the data received through the Meta Channels exclusively on behalf of the Partner and, through the Partner, of the Workspace Controller, does not sell them and does not combine them across Workspaces; Meta may verify Irelia’s compliance with such terms. The Partner acknowledges this and complies with it to the extent of its responsibility (Agreement, Art. 11.8).

9.3 Notice to End Users. The Partner ensures that the Workspace Controllers’ privacy notices to End Users indicate Meta as an independent controller for the Channels it provides, with a reference to Meta’s privacy notices, using the text made available by Irelia or an equivalent (Agreement, Art. 9.3(i)). The text made available by Irelia is an example: the Workspace Controller adapts it to its own processing and remains solely responsible for its own privacy notice, with Irelia bearing no liability for its content.

9.4 Other independent controllers. The same qualification applies to any other Channel providers indicated in the List and, to the extent of their respective responsibility, to the parties referred to in clause 7.5.

Art. 10 — Retention and erasure

10.1 Retention periods. Irelia retains Workspace Data for the following periods, after which it erases them through automated procedures, including derived copies at the Sub-processors within the periods applicable to them. The Workspace Controller may erase them earlier at any time pursuant to clause 10.3.

DataStandard periodIf the service on the Workspace has ended (cancellation)If the Workspace is deleted by the Partner
Contacts and conversations with End Users, including messages, attachments and data collected by the AI Agent24 months from the last interaction with the contact (message or change to the contact); for contacts with no interactions, from their creationSame period: 24 months from the last interactionImmediate erasure
Content uploaded to the Workspace and related indexesNo expiry while the service is active; removable by the Workspace Controller at any time24 months from cancellationImmediate erasure
Technical infrastructure logsUp to 12 months from recording; beyond that, only if necessary for an ongoing incident, dispute or audit, until its closureSame period: 12 months from recordingSame period: 12 months from recording
Clients’ data on the Partner’s payment account (clause 3.5(f))Not part of the Workspace: they remain on the Partner’s account with the payment service provider, in accordance with the contract between the Partner and such provider; Irelia does not retain a copy beyond the delivery of the billing tools——

10.2 Retention instruction. By accepting the DPA, the Partner — as controller for its own Workspaces and, for those configured for a Client, as processor under the agreement with the Client (Agreement, Art. 9.3(h)) — instructs Irelia to retain Workspace Data until the periods under clause 10.1, including for data received through the Meta Channels and including after the cancellation of the service on a Workspace, a request to migrate the Meta Assets or the termination of the Agreement, save for early erasure pursuant to clauses 10.3 and 10.4. The Partner reproduces this instruction in the agreement with the Client.

10.3 Early erasure. The Workspace Controller may at any time, through the functionalities under clause 5.3, erase individual contacts or conversations or all Workspace Data, without erasing the AI Agents’ configuration, which remains; Irelia performs the erasure without undue delay, in its own systems and, for derived copies, at the Sub-processors within the periods applicable to them. Erasure requested in the exercise of a data subject’s right (Art. 17 GDPR) is performed in the same manner, subject to the exceptions under Art. 17(3). The cancellation of the service on a Workspace does not erase the data, which follow the periods under clause 10.1 and remain exportable and erasable pursuant to clause 5.3. The deletion of a Workspace, reserved to the Partner, erases without delay all Workspace Data and its configuration in the manner set out in this clause; the Partner is liable for this towards the Client.

10.4 Termination of the Agreement. Upon termination of the Agreement, for any reason, Irelia ceases all new processing of Workspace Data; the data are retained and erased in accordance with clause 10.1, without further periods, and fully erased no later than 24 months after termination. The Partner and the Clients retain, for such period, access solely to the export and erasure functionalities under clause 5.3 (Agreement, Art. 20.3(d)). Upon the Partner’s written request, Irelia erases early all Workspace Data of the Account and confirms execution; the choice between return and erasure (Art. 28(3)(g)) is exercised by the Workspace Controller through export and erasure via the same functionalities.

10.5 Exceptions and backups. Irelia may retain beyond the periods data whose retention is required by Union or Italian law, or necessary for an ongoing incident, dispute or request from an authority, limited to the purpose and duration necessary, informing the Partner where permitted. Backups are overwritten according to the ordinary cycles of Irelia’s and the Sub-processors’ systems, are not used for further processing and are restored only for service recovery; erased data that may be restored from them are erased again.

Art. 11 — Excluded uses and limits of use

11.1 No training. Irelia does not use Workspace Data, or the conversations with End Users, to train, retrain or improve artificial intelligence models, whether its own or those of third parties, and obtains from the model-provider Sub-processors the contractual undertaking not to do so (Agreement, Art. 17.2).

11.2 No own purposes. Irelia does not use Workspace Data for its own purposes, does not disclose them to third parties other than the Sub-processors and does not combine them across Workspaces or with data from other sources. Irelia may produce, from the Platform’s operational data, aggregated and anonymous statistics — not attributable to a Workspace, a Controller or a data subject — for the management and improvement of the service; such statistics are not personal data (Recital 26 GDPR).

11.3 Support. Irelia’s staff access Workspace Data only upon request of the Partner, or of the Client through the Partner, for support activities, or when necessary for maintenance, security or the management of an incident; in such cases Irelia remains a processor and operates within the limits of Art. 14.

11.4 Limits of use by the Controller. The limits on the use of the Platform by the Workspace Controller — including those relating to special categories of data, the profiling of End Users and promotional communications — are set out in the AUP (Agreement, Art. 11), which the Partner passes on to its Clients. They delimit the acceptable use of the Platform and do not constitute instructions within the meaning of Art. 28(3)(a) (clause 4.3).

Art. 12 — Data protection officer, records and contacts

12.1 Data protection officer. Irelia has not designated a data protection officer: its core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data (Art. 37(1)(b) and (c) GDPR); Workspace Data are processed on behalf of the Controllers, each for its own perimeter. Irelia reviews this assessment as the scale and nature of the processing change and notifies the Partner of any designation.

12.2 Records. Irelia maintains the record of categories of processing activities carried out on behalf of the Controllers (Art. 30(2) GDPR) and makes it available to the supervisory authority on request.

12.3 Contacts. For every communication under the DPA — data subject requests, Breaches, audits, objections to Sub-processors — the Partner writes to info@irelia.ai; Irelia writes to the Account email address and, for acts with contractual effect, to the contact details referred to in the Agreement, Art. 21.3. The Partner indicates in the Account its data protection contact person or its data protection officer, where designated, and keeps it up to date.

Art. 13 — Liability, term, amendment and final clauses

13.1 Liability between the Parties. Irelia’s liability towards the Partner for non-performance of the DPA, including liability for the Sub-processors (clause 7.2), is governed by the Agreement, Art. 14, including the cap and the exclusions provided for therein; the Partner’s indemnity for breaches attributable to its own or its Clients’ configuration, use or processing choices is governed by the Agreement, Art. 15. The liability of each Party towards data subjects under Art. 82 GDPR remains unaffected. Between the Parties, the Party that has compensated a data subject is entitled to claim back from the other the part corresponding to its share of responsibility for the damage (Art. 82(5) GDPR); the Partner’s claim against Irelia falls within Irelia’s liability governed by the Agreement, Art. 14, to the extent the law allows it to be regulated between the Parties; Irelia’s claim against the Partner is absorbed by the indemnity under the Agreement, Art. 15.

13.2 Term. The DPA has the same term as the Agreement and remains effective, after its termination, for the time necessary for the retention and erasure of Workspace Data under Art. 10 and for the obligations that by their nature survive.

13.3 Amendment. Irelia may amend the DPA to adapt it to the law, to measures or guidelines of the authorities, to the evolution of the Platform, of the security measures or of the Sub-processors, without reducing the overall level of protection of Workspace Data. The amendment is notified to the Account email address, with publication of the new version at the DPA address, at least sixty days before it takes effect; amendments required by law, by an authority, by the Channel providers’ terms or by urgent security needs may take effect immediately (Agreement, Art. 18.4). A Partner that does not intend to accept the amendment may withdraw from the Agreement before the effective date pursuant to the Agreement, Art. 20.2, or, for amendments with immediate effect, within thirty days of the notification; withdrawal takes effect at the end of the current period and use of the Platform until such date does not constitute acceptance. In the absence of withdrawal, the amendment is deemed accepted on the effective date. Changes to the Sub-processor List follow Art. 7.

13.4 Versions. The DPA is published with a version number and date; the recording of the version accepted by the Partner and the accessibility of previous versions are governed by the Agreement, Art. 21.6.

13.5 Final clauses. The DPA prevails over the Agreement as regards the processing of personal data (Agreement, Art. 21.5). For governing law, jurisdiction, notices, partial invalidity, tolerance and prevalence of the Italian text, the Agreement, Art. 21 applies. The standard contractual clauses incorporated in the contracts with the Sub-processors prevail, in the relationships they govern, to the extent strictly necessary for their effectiveness.

Art. 14 — Security measures and scope of the export

14.1 Technical and organisational measures. Taking into account the state of the art, the costs, the nature, scope, context and purposes of the processing, as well as the risks to data subjects (Art. 32 GDPR), Irelia applies the following measures, which it documents in its internal security policies:

(a) Encryption. Data in transit encrypted with TLS 1.2 or higher on all flows, including those to the Sub-processors; earlier protocols excluded. Data at rest encrypted with AES-256 or equivalent on storage systems, with keys managed by the infrastructure providers. (b) Pseudonymisation. Replacement with placeholders of the End User’s identifying data before sending to the language model providers, with reconstitution only in Irelia’s systems (clause 8.3(a)). Pseudonymised display of End Users’ identifying data in the Platform for Users without the relevant permission (Agreement, Art. 5.3). (c) Access control. Access to systems according to the principle of least privilege; multi-factor authentication mandatory for every access by Irelia’s staff to production systems and to the Sub-processors’ services; individual credentials, never shared; administrative access to the infrastructure reserved to the owner of the sole proprietorship; logical segregation of data by Account and by Workspace applied at application level, with periodic verification; User permissions defined by the Partner and the Client (Agreement, Art. 5.3); revocation of access for departing staff within 24 hours with rotation of the keys and technical secrets to which they had access. (d) Device security. Staff devices with full-disk encryption, security updates, anti-malware protection and automatic lock; no local storage of Workspace Data. (e) Development and operations. Separate development and production environments; code review before release; source code in a private repository with version control; keys and secrets excluded from the repository. (f) Logging and monitoring. Technical infrastructure logs with automatic alerts on errors; time-limited retention of system logs (Art. 10) and their preservation in the event of an incident. (g) Continuity and recovery. Automatic backups of storage systems at the respective providers; redundancy of language model providers with automatic routing; documented continuity and recovery procedures for the unavailability of each critical provider, with defined recovery objectives. (h) Incident management. Incident response plan with classification by severity, roles, containment, recovery, post-incident review and notification under Art. 6; plan tested at least annually. (i) Suppliers. Security assessment of the Sub-processors on the basis of certifications (ISO 27001, SOC 2 or equivalent) and of their contractual undertakings; annual review. (j) Organisation. Security policy approved by the owner of the sole proprietorship, reviewed at least annually and after every significant incident; confidentiality obligations and instructions to staff upon joining; risk register with six-monthly review.

14.2 Evolution. Irelia may update the measures in line with the state of the art and the risks, without reducing the overall level of protection; the updated version is made available pursuant to clause 5.7. The measures applied by the Sub-processors are described in the respective documents referenced in the List.

14.3 Scope of the export. The export referred to in clause 5.3 returns, in a structured, commonly used and machine-readable format, the Workspace Data retained in Irelia’s systems: contacts, conversations with related attachments and data collected by the AI Agent, uploaded content. It does not include: the indexes derived from the uploaded content (embeddings), which can be rebuilt from the content itself; the technical logs; the AI Agents’ configurations, which do not contain personal data of data subjects; the transient copies at the Sub-processors, to which clause 5.2 applies. The Workspace Controller also uses the export to respond to access and portability requests (Arts. 15 and 20 GDPR).

Irelia

AI sales agents you build, brand, and resell.

Irelia · Italy

  • How to build it
  • How it works
  • How to sell it
  • Channels
  • Integrations
  • Pricing

  • Book appointments
  • Qualify & route
  • Reactivate dormant leads
  • Reduce no-shows
  • Customer care 24/7
  • Nurture leads

  • Dental & medical clinics
  • Salons & beauty
  • Real estate & construction
  • Finance & insurance
  • Automotive
  • Restaurants & food
  • Hotels & hospitality

  • ROI calculator
  • Credit calculator
  • Referral program
  • Documentation

  • Manifesto
  • Customers
  • Security
  • Contact

© 2026 Irelia. All rights reserved.

Privacy Terms Cookie policy DPA Sub-processors
GDPR compliant You control the data. EU AI Act ready Checked before going live.

Start free

Create your account

Free for 45 days. Cancel anytime.

Already have an account? Log in

One last step

Read and sign

Read the agreement to the end, then approve the two statements below.

Scroll to the end to continue

The agreement couldn't load. Open the Terms and the DPA in a new tab, then reload.

Scroll to the end to continue