Legal
Data Processing Agreement
The Article 28 GDPR text that applies between you, the business using Grammateas, and us, who provide her. It forms an integral part of the Terms of Use.
Version 1.0 · 12 September 2026 · This English version is provided for convenience; in case of divergence the Greek text prevails.
Do you need a signed copy? Send your business details to i.kotrotsios@rm.gr and you will receive it signed as a PDF within two working days, at no charge. We are also happy to review your own DPA template.
1. The parties and their roles
Controller: the business or professional with an active Grammateas subscription ("the Customer"). They decide the purposes and means of the processing: which calls the assistant answers, what she says, whether she records, how long the data is kept.
Processor: Retail Management Solutions, VAT number 801291892, Grammou 73, Marousi 15124, Greece ("we"). We process data solely in order to provide the service.
2. Subject matter, duration, nature and purpose
- Subject matter: the provision of the "Grammateas" AI receptionist service.
- Duration: for as long as the subscription lasts, plus the period for returning or deleting the data.
- Nature and purpose: receiving and answering telephone calls, converting speech to text and text to speech, composing an answer with a language model, booking appointments, keeping messages, sending notifications, storing transcripts and (optionally) recordings, and service statistics.
Categories of data subjects
Customers, suppliers and any third party who calls or is called from the Customer's numbers; the Customer's employees.
Categories of data
Full name, telephone number, e-mail address and postal address where given, the content of the conversation (audio and transcript), appointments, messages, the history of the communication and the notes the assistant keeps.
Special categories of data (Article 9 GDPR). The service is not intended for the systematic processing of health data or other special categories. Where, by the nature of the Customer's activity (a medical practice, say), such data is mentioned on calls, the Customer must secure an appropriate legal basis, set the retention and the recording accordingly, and tell us so that we can agree additional measures.
3. Processing only on instructions
We process the data only on the Customer's documented instructions — the settings they make in the platform and this agreement constitute such instructions. If we are required by EU or Member State law to process otherwise, we inform them beforehand, unless that law itself forbids it. If we consider that an instruction infringes the GDPR, we tell them at once.
We do not use the Customer's data for our own purposes, nor for advertising, nor to train artificial-intelligence models — ours or anybody else's.
4. Confidentiality
Everyone on our team with access is bound in writing by a duty of confidentiality that survives the end of their engagement. Access is granted only to what is strictly necessary, and it is logged.
5. Security measures (Article 32)
- Encryption in transit (TLS) for every connection; encryption of stored secrets and credentials.
- Strict separation of data per customer: every record carries a customer identifier and every query is filtered by it.
- Access control based on roles and permissions, with every sensitive action written to an audit log.
- The language model executes no code, SQL or URLs; it acts only through explicitly allowed tools, with permission and approval checks.
- No personal details and no secrets in the logs.
- Backups with tested restores; separate test environments with no real data.
- Automatic deletion of recordings at the end of the retention period the Customer has set.
In detail: Security.
6. Sub-processors
The Customer gives general authorisation for the use of the sub-processors published on the Sub-processors page. Every addition or replacement is announced by e-mail at least 30 days in advance; the Customer may object on reasonable data protection grounds and, if no solution is found, terminate the agreement at no cost. We impose the same obligations on every sub-processor and remain fully liable to the Customer for their acts.
7. Transfers outside the EEA
The main storage is inside the EU. Where processing by an artificial-intelligence or e-mail provider takes place in a third country, the transfer rests on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, with a transfer impact assessment and additional technical measures.
8. Data subject rights
Taking into account the nature of the processing, we help the Customer respond to requests under Articles 15–22: the platform provides search, export and erasure of one person's data in a single action (the identifying details, the words of every conversation, the recordings and the notes are deleted, while the statistics remain anonymous). If a data subject request reaches us, we do not answer it ourselves: we pass it to the Customer without delay.
9. Personal data breaches
We inform the Customer without undue delay and in any event within 24 hours of becoming aware of a breach affecting their data, with everything we have: what happened, which data it concerns, what we have done and what we recommend. We assist them in notifying the authority and the data subjects.
10. Assistance to the Customer
We assist them, so far as is reasonable, with impact assessments (Article 35), with prior consultation of the authority (Article 36) and with documenting the security measures, providing the information we hold.
11. Return and deletion
At the end of the agreement, the Customer chooses return or deletion. The data remains available for export for 30 days and is then permanently deleted from the active systems; backups expire on their own cycle and are not restored. Excluded is whatever the law requires to be kept, which remains under restricted processing.
12. Audits
We make available to the Customer all information demonstrating compliance with Article 28 and allow audits, once a year or after a security incident, with 30 days' notice, during business hours and without interrupting the service or disclosing other customers' data. The audit may be carried out by an independent auditor bound by confidentiality.
13. General
In the event of a conflict, this agreement prevails over the Terms of Use on matters of personal data. Greek law and the GDPR apply. Any material amendment is announced 30 days in advance.
Contact on matters concerning this agreement: i.kotrotsios@rm.gr, tel. +30 210 3004011.