Data Processing Agreement (DPA)

Last Updated: September 17, 2026

This Data Processing Agreement ("DPA") is entered into between Trebbble S.A., a company registered in Greece ("Abelo", "Processor", "we", "us") and the entity or individual agreeing to the Abelo Terms of Use ("Customer", "Controller", "you").


This DPA supplements and forms an integral part of the Abelo Terms of Use (the "Agreement") and governs the processing of Personal Data by Abelo on behalf of the Customer in connection with the Abelo Platform and Services.

1. Definitions


For the purposes of this DPA:


1.1. "Applicable Data Protection Law" means the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the Greek Data Protection Law (Law 4624/2019), the Greek Electronic Communications Privacy Law (Law 3471/2006), and any other national laws or regulations implementing or supplementing the GDPR as applicable to the processing.


1.2. "Customer Personal Data" means any Personal Data processed by Abelo on behalf of the Customer in the course of providing the Services under the Agreement.


1.3. "Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" shall have the meanings given to them in Article 4 of the GDPR.


1.4. "Subprocessor" means any third party engaged by Abelo to process Customer Personal Data in connection with the provision of the Services.


1.5. "Standard Contractual Clauses" or "SCCs" means the contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries.


2. Scope, Roles and Instructions


2.1 Roles of the Parties


The parties acknowledge and agree that with respect to Customer Personal Data processed under the Agreement:


  • the Customer acts as the Data Controller; and

  • Abelo acts as the Data Processor processing Customer Personal Data solely on the Customer's documented instructions.


2.2 Customer Responsibilities


The Customer represents, warrants, and undertakes that:


  • it has collected and processed Customer Personal Data in accordance with Applicable Data Protection Law;

  • it has established an appropriate legal basis under GDPR Article 6 (and, where applicable, Article 9) for the processing, including having obtained all necessary prior, explicit, and verifiable consents for direct promotional marketing;

  • it provides accurate privacy disclosures to its end-users and customers regarding third-party processing; and

  • its instructions to Abelo comply with Applicable Data Protection Law.


2.3 Documented Instructions


Abelo shall process Customer Personal Data only:


  • to provide, maintain, support, and secure the Platform and Services as set out in the Agreement;

  • in accordance with the documented instructions of the Customer, including configurations, campaign schedules, workflows, integrations, and other settings configured by the Customer in the Platform; and

  • as otherwise required by European Union or Member State law to which Abelo is subject. In such a case, Abelo shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.


If Abelo considers that a documented instruction from the Customer infringes Applicable Data Protection Law, Abelo shall immediately inform the Customer and may suspend performance of the affected instruction until the Customer confirms, modifies, or withdraws it. Abelo shall not be required to carry out an instruction that would cause Abelo to violate Applicable Data Protection Law.


The Agreement and this DPA, together with the Customer's configurations and instructions submitted through the Platform and any additional documented instructions agreed by the parties, constitute the Customer's documented instructions to Abelo.


3. Confidentiality and Personnel


3.1. Abelo shall ensure that persons authorized to process Customer Personal Data (including its employees, contractors, and agents) are bound by appropriate statutory or contractual confidentiality obligations.


3.2. Abelo shall take reasonable steps to ensure the reliability of any personnel who have access to Customer Personal Data, ensuring that access is strictly limited to those individuals who need to know the information to provide the Services.


4. Security of Processing


4.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Abelo shall implement appropriate Technical and Organizational Measures (TOMs) to ensure a level of security appropriate to the risk, pursuant to Article 32 of the GDPR.


4.2. The technical and organizational security measures implemented by Abelo are set out in Annex 2 of this DPA. Abelo may update or modify these measures from time to time, provided that such updates do not materially reduce the overall level of security of the Services.


5. Subprocessors


5.1 Authorization to Engage Subprocessors


The Customer grants Abelo general written authorization to engage Subprocessors to assist in delivering the Services. An authoritative list of current Subprocessors is maintained at:

https://abelo.ai/legal/subprocessors


5.2 Obligations on Subprocessors


Where Abelo engages a Subprocessor, Abelo shall:


  • enter into a written agreement with the Subprocessor imposing data protection obligations no less protective than those imposed on Abelo under this DPA; and

  • remain fully liable to the Customer for the performance of the Subprocessor’s obligations where the Subprocessor fails to fulfill its data protection obligations.


5.3 Notification of Subprocessor Changes

Abelo shall notify the Customer of any intended appointment of a new Subprocessor or replacement of an existing Subprocessor (for example, via notification in the Platform or email) at least fourteen (14) calendar days before the new Subprocessor starts processing Customer Personal Data.


5.4 Right to Object

The Customer may object in writing to the appointment of a new Subprocessor on reasonable grounds relating to the protection of Customer Personal Data within fourteen (14) calendar days of receiving notice. If the Customer objects on such grounds, the parties shall discuss the objection in good faith. If Abelo cannot reasonably accommodate the objection without altering the Services, the Customer may terminate the affected Services without penalty by providing written notice to Abelo before the new Subprocessor commences processing.


6. International Data Transfers


6.1. Abelo processes and stores Customer Personal Data primarily within the European Economic Area ("EEA").


6.2. Where Abelo transfers Customer Personal Data to a recipient in a country outside the EEA that does not benefit from an adequacy decision by the European Commission pursuant to Article 45 of the GDPR, Abelo shall ensure that the transfer is subject to an appropriate transfer mechanism under Chapter V of the GDPR.


Such mechanisms may include:


  • the EU-U.S. Data Privacy Framework, where the recipient entity in the United States is validly certified and the transfer falls within the scope of that certification;

  • the European Commission Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914, using the module applicable to the relationship between the relevant data exporter and data importer; or

  • another legally recognized transfer mechanism under Chapter V of the GDPR.


6.3. Transfers to Subprocessors


Where Abelo engages a Subprocessor located outside the EEA in a country that does not benefit from an applicable adequacy decision, Abelo shall put in place an appropriate transfer mechanism before the Subprocessor begins processing Customer Personal Data.


Where Abelo relies on the Standard Contractual Clauses for such a transfer, Abelo shall enter into the applicable SCC module with the relevant Subprocessor and complete the information required by those clauses, including the identification of the parties, description of the transfer, categories of Personal Data and Data Subjects, competent supervisory authority, applicable Technical and Organizational Measures, and relevant Subprocessor information.


Where required by Applicable Data Protection Law, Abelo shall also carry out any transfer assessment reasonably necessary to determine whether supplementary contractual, technical, or organizational measures are required.


Abelo shall make reasonable information regarding the applicable international transfer mechanism available to the Customer upon request, subject to confidentiality obligations and appropriate redaction of commercially sensitive or security-related information.


7. Assistance to the Controller


7.1 Data Subject Requests


Taking into account the nature of the processing, Abelo shall assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer's obligation to respond to requests for exercising the Data Subject's rights laid down in Chapter III of the GDPR (including access, rectification, erasure, and restriction).


If Abelo receives a request directly from a Data Subject concerning Customer Personal Data, Abelo shall promptly advise the Data Subject to submit their request directly to the Customer and notify the Customer where practicable.


7.2 Security, Breach Notification, and DPIAs


Taking into account the nature of processing and the information available to Abelo, Abelo shall assist the Customer in ensuring compliance with:


  • the security obligations under Article 32 GDPR;

  • the notification of Personal Data Breaches to supervisory authorities and Data Subjects under Articles 33 and 34 GDPR; and

  • conducting Data Protection Impact Assessments (DPIAs) and prior consultations with competent supervisory authorities under Articles 35 and 36 GDPR where required.


7.3 Personal Data Breach Notification


In the event of a confirmed Personal Data Breach affecting Customer Personal Data, Abelo shall notify the Customer without undue delay and, where feasible, within forty-eight (48) hours of becoming aware of the breach. Such notification shall describe:


  • the nature of the breach;

  • the categories and approximate number of Data Subjects and records concerned;

  • the likely consequences of the breach; and

  • the remedial measures taken or proposed to be taken by Abelo.


8. Deletion or Return of Customer Personal Data


8.1. Upon termination or expiration of the Agreement, Abelo shall, at the choice of the Customer, delete or return all Customer Personal Data to the Customer, unless Union or Greek law requires continued retention of the Personal Data.


8.2. Notwithstanding Section 8.1, the Customer acknowledges that Abelo may retain:


  • minimal suppression lists (such as cryptographic hashes of phone numbers or opt-out flags) strictly necessary to honor recipient unsubscribe requests and prevent unlawful future re-messaging under GDPR Article 17(3)(b) and Article 21; and

  • commercial transaction, billing, and tax records required to comply with statutory accounting and tax obligations under Greek legislation.


9. Audits and Demonstration of Compliance


9.1. Abelo shall make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer.


9.2. Any audit shall be conducted:

  • upon reasonable advance written notice of at least thirty (30) days;

  • during normal business hours without disrupting Abelo's operations;

  • subject to reasonable confidentiality and security procedures; and

  • no more than once per twelve (12) month period, unless mandated by a competent supervisory authority or following a confirmed Personal Data Breach.


10. Governing Law and Jurisdiction


This DPA shall be governed by and construed in accordance with the laws of Greece. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the competent courts of Athens, Greece.


Annex 1: Details of Processing


1. Subject Matter of Processing

Provision of the Abelo multi-channel messaging platform, customer profile management, audience segmentation, marketing automation, e-commerce store synchronization, and delivery analytics.


2. Duration of Processing

For the duration of the Agreement between the Customer and Abelo, plus any statutory retention or post-termination deletion window.


3. Nature and Purpose of Processing

Ingesting, storing, synchronizing, segmenting, and transmitting messages (Viber, SMS, WhatsApp) to recipients on behalf of the Customer; verifying recipient phone numbers and authenticating requests via OTP; capturing link engagement metrics; and synchronizing e-commerce order and customer profile data.


4. Categories of Data Subjects

  • End-customers, subscribers, users, and recipients of the Customer.

  • Website visitors interacting with the Customer's online storefronts and embedded widgets.


5. Types of Personal Data

  • Identifiers: Name, telephone number (E.164 format), email address, customer account ID.

  • E-Commerce Records: Order history, purchase amounts, products viewed/purchased, cart abandonment events.

  • Messaging Records: Dispatch timestamps, message content, delivery status reports (DLRs).

  • Engagement & Telemetry: Click timestamps, URL redirect metadata, approximate geographic location, device category, browser type.

  • Consent & Preferences: Channel-specific opt-in status, timestamps, consent method, and unsubscribe flags.


Annex 2: Technical and Organizational Measures (TOMs)


Abelo maintains technical and organizational measures designed to ensure a level of security appropriate to the risk:


  1. Logical Separation & Multi-Tenant Isolation: All database storage (Google Cloud Datastore / NDB), analytics pipelines (BigQuery), task queues, and webhook processing enforce strict logical isolation scoped by organization_key. Queries and operations are structurally prohibited from accessing or modifying data belonging to other tenants.

  2. Encryption in Transit and at Rest:

    • All external communications with the Platform, APIs, and widgets are encrypted in transit using industry-standard TLS (TLS 1.2 and TLS 1.3).

    • All persistent databases, disks, and cloud storage buckets are encrypted at rest using AES-256 encryption.

  3. Cryptographic Suppression Protection: When contacts request erasure or unsubscribe from marketing channels, direct personal identifiers are removed while a secure one-way cryptographic hash of the phone number is preserved in suppression mechanisms to permanently prevent accidental re-import or re-enrollment.

  4. Access Control & Least Privilege: Access to production infrastructure is restricted to authorized personnel based on least-privilege principles, enforced via multi-factor authentication (MFA) and role-based access controls (RBAC).

  5. Real-Time Dispatch Safeguards: The Platform verifies current channel opt-in status in Datastore immediately prior to message dispatch, ensuring that recent opt-outs or revocations are respected before messages reach carrier gateways.

  6. Resilience & Backups: Automated daily backups and multi-zone redundancy across Google Cloud Platform infrastructure in the European Union (europe-west1).