Data Processing Agreement
Version 2026-10-06 · The Latvian version is legally binding. The Russian and English versions are translations for convenience.
1. Parties and subject matter
The controller is the user who registered the Meistars AI account (a business or a person carrying out economic activity). The processor is Deniss Harlass, reg. No. fiziska persona, Rīga, Latvija. The agreement is concluded electronically by accepting the Terms of Service (Article 28(9) GDPR) and remains in force while the account exists and during the retention period in section 9.
The subject matter, duration, nature and purpose of the processing, the types of data and the categories of data subjects are described in Annex A.
2. Processing only on the controller’s instructions (Article 28(3)(a) GDPR)
- The processor processes personal data only on documented instructions from the controller. The instructions are: the Terms of Service, this agreement and the controller’s actions in the app (e.g. entering a customer, sending an offer, issuing an invoice, deleting, exporting).
- The controller instructs the processor to transfer data to the sub-processors in section 5, including outside the EEA, in accordance with section 6.
- If EU or Latvian law requires processing without an instruction, the processor informs the controller before processing unless the law prohibits this.
- If the processor considers that an instruction infringes the GDPR or other data protection law, it informs the controller immediately.
- The processor does not use the controller’s customer data for its own purposes, does not profile it, does not send advertising to the controller’s customers and does not use it to train AI models.
3. Confidentiality (b)
Only persons who need access to provide the service, support, security or legal compliance and who have committed to confidentiality or are under a statutory obligation of confidentiality have access to the data. The processor does not look at the controller’s data without need; for support only at the controller’s request or with their knowledge.
4. Security (c, Article 32 GDPR)
The processor implements the technical and organisational measures described in Annex B and reviews them. Measures may change provided the level of protection is not reduced.
5. Sub-processors (d, Article 28(2) and (4) GDPR)
- The controller gives general authorisation to engage sub-processors. The current list: Sub-processors.
- The processor gives at least 14 days’ notice of an intended addition or replacement of a sub-processor in the app or by e-mail and updates the list page. The controller may object on reasonable grounds. If no solution is found, the controller may end the agreement by deleting the account before the change takes effect. In urgent security cases the notice may be shorter.
- The processor concludes a written contract with each sub-processor imposing substantially the same data protection obligations and remains fully liable to the controller for the sub-processors’ performance.
6. Transfers outside the EEA (Chapter V GDPR)
The database and the app’s server functions are located in the EU (Frankfurt). Some sub-processors are US companies or process data in the US (e.g. OpenAI). Transfers take place only on the basis of a European Commission adequacy decision (EU–US Data Privacy Framework, where the sub-processor is certified) or the European Commission’s standard contractual clauses (Decision (EU) 2021/914) with supplementary measures (encryption, data minimisation). Copies of the relevant documents are available on request.
7. Assistance with data subject rights (e)
- In the app the controller can correct and delete customers and drafts and download all data (JSON).
- Customer approval records and jobs with customer decisions cannot be deleted in the app (they are evidence). If the controller decides they must be deleted (e.g. after a justified erasure request), the processor deletes them on the controller’s written instruction within 10 working days.
- If a data subject (e.g. your customer) contacts the processor, the processor does not answer on the merits but forwards the request to the controller within 5 working days and tells the data subject that the request has been passed to the controller.
8. Assistance with security, incidents and assessments (f)
- The processor notifies the controller of a personal data breach affecting the controller’s data without undue delay — the target is within 48 hours of becoming aware of it — at the account e-mail, with the information listed in Article 33(3) GDPR as far as available, and supplements it later.
- Notifying the Data State Inspectorate (within 72 hours) and data subjects is the controller’s duty; the processor helps with information.
- On request the processor provides information the controller needs for a data protection impact assessment or prior consultation (Articles 35–36 GDPR).
9. End of processing: deletion or return (g)
- Before deleting the account the controller can download the data (Settings → Download my data; Invoices → For accountant).
- When the account is deleted, all of the controller’s data is deleted from the live database immediately. It remains in the encrypted nightly backups until they are deleted automatically (30 days) and is not restored except for disaster recovery.
- Exception — invoices. The controller must keep source documents for at least 5 years (Article 28(5) of the Latvian Accounting Act). The controller therefore instructs the processor: when the account is deleted, keep the data of issued invoices and credit notes (invoice details, buyer details, lines, amounts) and the controller’s identification data (name, reg. No., VAT No., users’ e-mails) in a closed archive that is not accessible in the app, until the end of the 5th calendar year after the year of issue, and then delete them. The archive is used only to provide the documents to the controller or to an authority with a lawful right to request them. The controller may ask in writing for earlier deletion, confirming that they keep the documents themselves.
10. Information and audits (h)
The processor makes available the information necessary to demonstrate compliance with this agreement and allows audits or inspections. The controller gives at least 30 days’ notice of an audit; audits take place no more than once in 12 months (except after a breach or at an authority’s request), during business hours, under confidentiality and at the controller’s cost. The processor may first provide written answers and sub-processors’ certificates or reports.
11. Controller’s obligations
The controller ensures that it has a legal basis for the processing and for the instructions given to the processor, informs data subjects (Articles 13–14 GDPR) and does not enter special categories of data or criminal records data unless necessary.
12. Liability and precedence
Section 13 of the Terms of Service applies to the parties’ liability, without limiting the rights of data subjects under Article 82 GDPR. On data protection matters this agreement prevails over the Terms of Service.
Annex A. Description of the processing
| Subject matter and purpose | Preparing estimates and offers, sending them to the customer, receiving the customer’s decision and questions and keeping the evidence, preparing invoices and the accountant export, AI assistance (speech recognition, structuring descriptions, reading price lists), storage and backups, sending e-mail on the controller’s behalf (notifications to the controller, approval copy to the customer, invoice to the customer, monthly link to the accountant). |
|---|---|
| Nature | Collection, recording, storage, structuring, consultation, transfer to sub-processors, disclosure to the customer through a link, erasure. |
| Duration | While the account exists; invoice archive as in section 9. |
| Data subjects | The controller’s customers (usually private homeowners; also company contact persons); persons who approve or reject an offer or ask a question; persons mentioned in notes or descriptions or visible in photos. |
| Types of data | Name or company name; phone; e-mail; site address and legal address; company reg. and VAT number; job descriptions, voice transcripts, notes, photos; offer content and amounts; approval record (typed name, decision, comment, time, language, confirmation wording, pseudonymised IP derivative, browser identifier); questions and contact details; invoice data; e-mail log entries (type, status, keyed hash of the recipient address, time). |
| Special categories | Not intended. The controller does not enter them (they may appear incidentally in photos or notes — the controller prevents this). |
Annex B. Technical and organisational measures
- Database and server functions in the EU (Frankfurt); encrypted connections (HTTPS/TLS, HSTS); encryption at rest provided by the database provider.
- Tenant separation in the database (Row Level Security on every table); the app connects with a restricted role that cannot bypass it; composite foreign keys prevent linking another tenant’s records.
- Passwords are stored only as scrypt hashes; session tokens only as SHA-256 hashes; cookie httpOnly, SameSite=Lax, Secure.
- Customer links are 256-bit HMAC tokens (only a hash is stored), they expire and are revoked when an offer is pulled back for editing.
- Approval records are append-only (database triggers); approved offers and issued invoices cannot be changed.
- IP addresses are not stored in clear: in approvals as a keyed hash; in the rate limiter as a keyed hash deleted after a short time.
- Rate limiting (login, sign-up, public actions, AI); Content Security Policy, anti-framing, file type checks by content.
- Voice recordings and imported price-list files are not stored. For estimates only the job description and the price-list names and units are sent to OpenAI — no customer contact details and no prices.
- Access to production systems only for the service operator, with strong passwords and two-factor authentication on provider accounts; the admin view shows aggregate statistics only.
- A nightly database copy (pg_dump) made by a read-only role; restoring the copy is tested automatically; the copy is encrypted with AES-256 (gpg) and kept for 30 days as a GitHub Actions artifact; the decryption key is kept outside GitHub.
- E-mail: password-reset and e-mail-verification tokens are single-use and stored only as SHA-256; the e-mail log holds no subject or content and the recipient only as a keyed hash, and is deleted after 90 days; no tracking pixels or link tracking.
- Known limitations (being addressed): no two-factor authentication for user accounts; e-mail verification is not mandatory.