LEGAL
Data Processing Agreement
The Article 28 agreement that applies when Respira processes personal data on your behalf. It is offered as a standing agreement, so you do not have to wait on a signature to have one in place.
1. Scope and how this becomes binding
This Data Processing Agreement (the "DPA") is entered into between Respira, operated by Mihai Dragomirescu, established in Brașov, Romania ("Respira", "Processor"), and the customer identified in the applicable subscription or order ("Customer", "Controller"). It forms part of, and is governed by, the Terms of Service (the "Agreement").
This DPA applies to the extent Respira processes personal data on the Customer's behalf in the course of providing Respira for WordPress, the Respira MCP server, the Respira dashboard, and related add-ons (together, the "Service"), and to the extent Regulation (EU) 2016/679 ("GDPR") or the UK GDPR applies to that processing.
The Customer accepts this DPA by written notice to word@respira.press identifying the account it applies to. No counter-signature is required for it to take effect, and a counter-signed copy is available on request at no charge. Where the Customer has its own DPA or an executed Article 28 agreement with Respira, that document prevails over this one to the extent of any conflict.
If a term here does not work for your organisation, say which one and why. A single operator can amend a contract faster than a company can, and most requests are reasonable.
2. Roles of the parties
The parties have distinct roles depending on the data in question, and it is worth being precise rather than blanket-labelling everything.
- Respira as processor. For personal data contained in or reachable through the Customer's connected WordPress sites, and for material the Customer submits through support, Respira acts as processor on the Customer's documented instructions.
- Respira as controller. For the Customer's own account data, being the data needed to create and administer the account, authenticate users, bill the subscription, secure the Service, and meet Respira's legal obligations, Respira acts as controller. That processing is described in the Privacy Policy rather than governed by this DPA.
- Customer as controller. The Customer determines the purposes and means of processing carried out through the Service, including which sites are connected, which agents are authorised, and what those agents are instructed to do.
Where the Customer is itself a processor acting for its own client, for example an agency operating a site on behalf of an end customer, Respira acts as sub-processor and this DPA applies as though references to the Controller were references to that client, with the Customer warranting it has the authority to enter into it.
3. Subject matter, duration, nature and purpose
Required by Article 28(3). The full description is in Annex I. In summary:
- Subject matter. Provision of the Service: connecting AI agents to the Customer's WordPress sites, and reading, creating and modifying content on those sites at the Customer's direction.
- Duration. The term of the Agreement, plus the retention periods in clause 12.
- Nature and purpose. Hosting, transmission, structured transformation, storage of operational metadata, diagnostics, and support.
- Where the Customer's site content lives. Content of a connected WordPress site is processed by the Respira plugin on the Customer's own server, and page snapshots taken before an edit are stored in the Customer's own WordPress database. That content is not routinely transmitted to or stored by Respira. It reaches Respira only where the Customer sends it in a support request, or where it appears incidentally in an error diagnostic.
4. Processing on documented instructions
Respira processes personal data only on the Customer's documented instructions, including for international transfers, unless required to do otherwise by Union or Member State law, in which case Respira will inform the Customer of that requirement before processing unless the law prohibits it on important grounds of public interest.
The Agreement, this DPA, the Customer's configuration of the Service, and the calls the Customer's authorised agents and users make through it together constitute the Customer's documented instructions.
For the avoidance of doubt, instructions issued by an AI agent that the Customer has connected and authorised are the Customer's instructions. The Customer is responsible for what it authorises an agent to do, for the scope it grants that agent, and for reviewing the result. Respira provides access profiles and per-tool permission controls, approval workflows, snapshots, and an audit log as the means to exercise that control, and recommends they be configured before granting write access to a site containing personal data.
Respira will inform the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law.
5. Confidentiality
Respira ensures that persons authorised to process personal data are bound by an appropriate duty of confidentiality, and limits access to those who need it to provide the Service, to support the Customer, or to meet a legal obligation.
Respira is operated by a single person. Access to production data is therefore held by that person and by the sub-processors listed in Annex III, and by no one else.
6. Security of processing
Respira implements appropriate technical and organisational measures under Article 32, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. The measures in force are listed in Annex II.
Respira may update those measures over time provided the update does not materially reduce the overall level of security. Annex II is maintained as the current statement of measures rather than a frozen snapshot.
7. Sub-processors
The Customer gives general written authorisation for Respira to engage sub-processors, subject to this clause.
- The sub-processors engaged as at the date of this DPA are listed in Annex III, and the same list with fuller detail per vendor is maintained publicly at the Trust Center.
- Respira imposes on each sub-processor data protection obligations no less protective than those in this DPA, by written contract, and remains fully liable to the Customer for the performance of that sub-processor's obligations.
- Respira will give the Customer at least 30 days' notice before adding or replacing a sub-processor. To receive that notice, email word@respira.press asking to be added to the sub-processor notification list.
- The Customer may object to a new sub-processor on reasonable data protection grounds within that 30 day period. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of any prepaid fees for the unused remainder of the term.
8. International transfers
Respira is established in Romania and the Service's primary data store is located in the European Union (Frankfurt). The default position is therefore that personal data stays in the EEA.
Where a sub-processor listed in Annex III processes personal data outside the EEA, that transfer is made under the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, incorporated by reference into the relevant sub-processor agreement, together with any supplementary measures identified as necessary by a transfer impact assessment. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum applies to those clauses.
The processing region of each sub-processor is stated in Annex III and on the Trust Center.
9. Assistance with data subject rights and Articles 32 to 36
Taking into account the nature of the processing, Respira assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise rights under Chapter III of the GDPR, being access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making.
Where a data subject contacts Respira directly regarding data processed on the Customer's behalf, Respira will not respond to the substance of the request. It will refer the data subject to the Customer and notify the Customer without undue delay.
Respira also assists the Customer in ensuring compliance with Articles 32 to 36, covering security of processing, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to Respira.
This assistance is provided at no additional charge, except where a request is manifestly unfounded, excessive, or repetitive, in which case Respira may charge a reasonable fee notified in advance.
10. Personal data breach
Respira notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf.
The notification describes the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Where the full picture is not available within 72 hours, Respira provides what is known and follows up in phases rather than delaying the first notification.
Notification is sent by email to the account contact and, where the breach is not confined to a single account, posted publicly on the Trust Center.
11. Audit and information
Respira makes available to the Customer the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.
In practice, and proportionate to a single-operator service, this means:
- The published Trust Center and Annex II of this DPA are the standing documentation of measures and sub-processors, and are kept current.
- Respira responds to a written security questionnaire or information request once per twelve month period at no charge, within 30 days.
- An on-site or remote inspection may be conducted on 30 days' written notice, no more than once per twelve month period unless a breach or a supervisory authority requires otherwise, during business hours, subject to confidentiality undertakings, and conducted so as not to disrupt the Service or compromise the confidentiality of other customers' data. The Customer bears its own costs and Respira's reasonable costs for inspections beyond the annual questionnaire.
Respira does not hold a SOC 2 or ISO 27001 certification and does not claim one. The documentation above is offered in place of an audit report, and this is stated plainly so that it is not discovered late in a procurement process.
12. Return and deletion
On termination or expiry of the Agreement, Respira deletes or returns all personal data processed on the Customer's behalf, at the Customer's choice, and deletes existing copies, unless Union or Member State law requires storage.
- Export. The Customer may request a machine-readable export of its account, sites, telemetry and billing history at any time during the term and for 30 days afterwards.
- Deletion. Absent an export request, active data is deleted within 30 days of termination, and residual copies in backups age out within a further 30 days under the backup rotation described in Annex II.
- Retained by law. Billing and transaction records are retained for the period required by Romanian and EU accounting and tax law. Those records are retained for that purpose alone.
- Content on the Customer's own site. Content and snapshots stored in the Customer's WordPress database are under the Customer's control and are not deleted by Respira. Deactivating the plugin leaves them in place.
13. General
- Order of precedence. In the event of conflict, this DPA prevails over the Agreement in respect of the processing of personal data.
- Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, to the extent permitted by applicable law. Nothing here limits any liability that cannot be limited by law, including a data subject's rights under Article 82.
- Changes. Respira may update this DPA where required by law, by a supervisory authority, or to reflect a change in the Service. Material changes are notified by email to accounts that have accepted it, at least 30 days before they take effect.
- Governing law. This DPA is governed by the laws of Romania, and the courts of Brașov, Romania have exclusive jurisdiction, without prejudice to any mandatory jurisdiction under applicable data protection law.
- Contact. word@respira.press for anything in this document, including acceptance, the sub-processor notification list, a security questionnaire, or a counter-signed copy.
Annex I · Description of processing
Categories of data subjects.
- The Customer's personnel and authorised users of the Service.
- Individuals whose personal data appears in the content of a connected WordPress site, to the extent that content is transmitted to Respira in a support request or an error diagnostic. Depending on the site, this may include the Customer's own registered users, commenters, customers, or newsletter subscribers.
Categories of personal data.
- Identification and contact data: name, email address.
- Account and authentication data: user identifier, authentication tokens, API keys, plan and subscription state.
- Connection metadata: site URL, WordPress and plugin versions, active page builder, server capability information.
- Usage and audit data: tool calls made, timestamps, outcome and error state, and entries in the audit log recording which agent performed which action.
- Diagnostic data: stack traces, request paths and status codes, with PII scrubbing applied by default.
- Billing data: billing name, address, and payment method tokens, held by the payment processor.
- Support content: whatever the Customer chooses to include in a support request.
Special categories of data.
The Service is not designed for, and the Customer should not deliberately route, special category data under Article 9 or criminal conviction data under Article 10. Where such data exists in the content of a connected site, it is processed on the Customer's own server as described in clause 3, and the Customer remains responsible for the lawfulness of that processing.
Frequency. Continuous for the duration of the Agreement.
Duration. The term of the Agreement plus the retention periods in clause 12.
Annex II · Technical and organisational measures
The measures in force under Article 32, and the current state of each.
- Encryption. TLS 1.3 in transit. AES-256 at rest on the primary data store.
- Data residency. Primary database, authentication and file storage in the European Union (Frankfurt, eu-central-1).
- Access control. Authorisation enforced at the database layer through Postgres Row-Level Security, with reads scoped to the authenticated user unless an explicit administrative gate applies. Authentication by magic link or OAuth.
- Agent scoping. Access profiles and per-tool permission switches, enforced server-side at the same chokepoint for both the REST layer and the abilities handler, so a client cannot bypass them by ignoring the advertised tool list.
- Change integrity. Page snapshots taken before builder writes, approval workflows for live edits, and write receipts reporting whether stored data actually changed.
- Audit logging. Actions recorded in an append-only audit log, each row sealed with an HMAC chained from the previous row so that editing or deleting a row is detectable at that row. Chain verification is available on demand.
- Secret management. Secrets held in environment configuration, never shipped in client bundles, rotated quarterly.
- Backups and recovery. Daily point-in-time recovery with 30 day retention on the primary database.
- Monitoring. Error and reliability events collected in the EU region with PII scrubbing enabled by default. Uptime monitoring on public endpoints.
- Data minimisation. Recorded per sub-processor in Annex III and published per vendor on the Trust Center, stating the smallest set of personal data each one receives.
- Pseudonymisation. Analytics identifiers are the account's opaque user identifier rather than direct identifiers where the vendor supports it. Session replays mask input fields.
Annex III · Authorised sub-processors
Current as of August 5, 2026. This annex is generated from the same source as the Trust Center table and the processor list in the Privacy Policy, so the three cannot disagree.
- Supabase · Auth, primary Postgres, file storage, edge functions.
- Vercel · Hosting, edge network, serverless function execution.
- Google Analytics 4 · Aggregate page-view + event analytics.
- PostHog · Product analytics inside the dashboard.
- Customer.io · In-app messaging and journeys.
- Chatwoot · Live chat support widget.
- Resend · Transactional and broadcast email delivery.
- Polar · Payment + subscription billing.
- Anthropic · Marketing copy generation, plus AI-assisted engineering and support.
- Google (Gemini API) · Image generation for social and marketing visuals.
- OpenAI · Fallback image generation for social and marketing visuals.
- Sentry · Error tracing and reliability monitoring.
- Frankfurter (ECB) · USD → EUR FX rate for the Earn page.
Retired. The following receive no new personal data. They are listed because records they still hold remain within the scope of an access or erasure request.
- LemonSqueezy · Retired. Legacy payment and subscription billing.