Meistars AI

Data Processing Agreement

Version 2026-10-06 · The Latvian version is legally binding. The Russian and English versions are translations for convenience.

In short. You manage your customers’ data (names, contacts, addresses, offers, approvals, invoices) as the controller; we process it only on your behalf as the processor. We do not use it for our own purposes, we store it in the EU (Frankfurt), protect it, help you answer your customers’ requests and notify you of security incidents. This agreement is Annex 1 to the Terms of Service (Article 28 GDPR).

1. Parties and subject matter

The controller is the user who registered the Meistars AI account (a business or a person carrying out economic activity). The processor is Deniss Harlass, reg. No. fiziska persona, Rīga, Latvija. The agreement is concluded electronically by accepting the Terms of Service (Article 28(9) GDPR) and remains in force while the account exists and during the retention period in section 9.

The subject matter, duration, nature and purpose of the processing, the types of data and the categories of data subjects are described in Annex A.

2. Processing only on the controller’s instructions (Article 28(3)(a) GDPR)

3. Confidentiality (b)

Only persons who need access to provide the service, support, security or legal compliance and who have committed to confidentiality or are under a statutory obligation of confidentiality have access to the data. The processor does not look at the controller’s data without need; for support only at the controller’s request or with their knowledge.

4. Security (c, Article 32 GDPR)

The processor implements the technical and organisational measures described in Annex B and reviews them. Measures may change provided the level of protection is not reduced.

5. Sub-processors (d, Article 28(2) and (4) GDPR)

6. Transfers outside the EEA (Chapter V GDPR)

The database and the app’s server functions are located in the EU (Frankfurt). Some sub-processors are US companies or process data in the US (e.g. OpenAI). Transfers take place only on the basis of a European Commission adequacy decision (EU–US Data Privacy Framework, where the sub-processor is certified) or the European Commission’s standard contractual clauses (Decision (EU) 2021/914) with supplementary measures (encryption, data minimisation). Copies of the relevant documents are available on request.

7. Assistance with data subject rights (e)

8. Assistance with security, incidents and assessments (f)

9. End of processing: deletion or return (g)

10. Information and audits (h)

The processor makes available the information necessary to demonstrate compliance with this agreement and allows audits or inspections. The controller gives at least 30 days’ notice of an audit; audits take place no more than once in 12 months (except after a breach or at an authority’s request), during business hours, under confidentiality and at the controller’s cost. The processor may first provide written answers and sub-processors’ certificates or reports.

11. Controller’s obligations

The controller ensures that it has a legal basis for the processing and for the instructions given to the processor, informs data subjects (Articles 13–14 GDPR) and does not enter special categories of data or criminal records data unless necessary.

12. Liability and precedence

Section 13 of the Terms of Service applies to the parties’ liability, without limiting the rights of data subjects under Article 82 GDPR. On data protection matters this agreement prevails over the Terms of Service.

Annex A. Description of the processing

Subject matter and purposePreparing estimates and offers, sending them to the customer, receiving the customer’s decision and questions and keeping the evidence, preparing invoices and the accountant export, AI assistance (speech recognition, structuring descriptions, reading price lists), storage and backups, sending e-mail on the controller’s behalf (notifications to the controller, approval copy to the customer, invoice to the customer, monthly link to the accountant).
NatureCollection, recording, storage, structuring, consultation, transfer to sub-processors, disclosure to the customer through a link, erasure.
DurationWhile the account exists; invoice archive as in section 9.
Data subjectsThe controller’s customers (usually private homeowners; also company contact persons); persons who approve or reject an offer or ask a question; persons mentioned in notes or descriptions or visible in photos.
Types of dataName or company name; phone; e-mail; site address and legal address; company reg. and VAT number; job descriptions, voice transcripts, notes, photos; offer content and amounts; approval record (typed name, decision, comment, time, language, confirmation wording, pseudonymised IP derivative, browser identifier); questions and contact details; invoice data; e-mail log entries (type, status, keyed hash of the recipient address, time).
Special categoriesNot intended. The controller does not enter them (they may appear incidentally in photos or notes — the controller prevents this).

Annex B. Technical and organisational measures