Serlion

Data Processing Agreement

Art. 28 GDPR · Version 1.1 · Updated 28 September 2026

The terms on which Serlion processes personal data belonging to visitors to your website. This is a contract between you as controller and us as processor, and it forms part of the Terms of Service.
Contents (15)
01

Parties and status

Controller
You, the Serlion customer, identified by the account you subscribed with.
Processor
Farooq Quraishi, trading as Serlion (Einzelunternehmen)
Processor address
c/o Impressumservice Dein-Impressum Stettiner Str. 41 35410 Hungen Germany
Processor contact
[email protected]

You determine the purposes and means of processing the personal data of your website's visitors. We process it only for you. Where this agreement and the Terms of Service disagree about the processing of that data, this agreement wins.

02

Subject matter and duration

Subject matter
The subject matter is the processing needed to deliver the Serlion chat assistant and, where you use it, Lanus, as described in the Terms of Service.
Duration
This agreement starts when you create an account and runs for as long as we process personal data on your behalf. Its obligations continue after your subscription ends until the data is deleted or returned under section 11.
03

Nature, purpose and data

Detail
Nature of processingCollection, storage, transmission to AI providers and to the chat channels and alert destinations you connect, retrieval, analysis and erasure, by automated means.
PurposeAnswering questions from your website visitors and from people who write to you on a chat channel you connect, passing conversations to your team, capturing leads you have asked to capture, alerting your team where you have asked us to, and producing the analytics in your dashboard.
Categories of data subjectVisitors to your website who interact with the widget; people who write to you on a chat channel you connect (Telegram, WhatsApp, LINE, Discord or email); and any person mentioned in a conversation.
Types of personal dataMessage content; any contact details a visitor chooses to type, such as an email address or phone number; the display name and identifiers a connected channel passes along with each message, such as a username, a WhatsApp phone number or the sender’s email address; files a visitor attaches; IP address, browser and device information; timestamps; a derived sentiment signal.
Special categoriesNot requested, not required, and not knowingly collected. A visitor may nonetheless type anything into a free-text box, so you should configure the assistant accordingly.
04

Processing on instructions

We process personal data only on your documented instructions, including as to transfers, unless required otherwise by EU or Member State law. Where such a legal requirement applies we will inform you before processing, unless the law forbids that notice.

Your documented instructions are, taken together:

  • this agreement and the Terms of Service;
  • the settings you choose in your dashboard, including the assistant’s configuration, the knowledge base you upload, your retention plan, your AI provider on Bring Your Own Key plans, and any chat channel, team alert, webhook or Cal.com integration you enable;
  • any further written instruction you send to [email protected].
Default step
One processing step happens by default rather than by a setting you choose, so it is recorded here as part of the service: ten minutes after a conversation goes quiet, its transcript is copied to Lanus, which runs on our infrastructure under the same controller and the same retention windows. You may ask us to exclude your account at any time by writing to [email protected], and we will do so.
Unlawful instructions
We will tell you if, in our opinion, an instruction infringes the GDPR or other data protection law.
Never
We do not use your visitors' personal data for our own purposes, do not sell it, and do not use it to train AI models.
05

Confidentiality

Serlion is operated by a sole proprietor, and access to production systems holding customer data is limited to that one person, who is bound to confidentiality. If anyone else is ever given access, they will be placed under a written confidentiality undertaking before access is granted, and Annex A will be updated to say so.

06

Security measures

We implement appropriate technical and organisational measures under Art. 32 GDPR, taking account of the state of the art, implementation cost, and the nature, scope, context and purposes of processing. The measures in force are set out in Annex A.

We may change individual measures as technology moves, provided the level of protection is not reduced. Material changes are announced the same way as changes to the subprocessor list.

07

Subprocessors

You give general written authorisation under Art. 28(2) GDPR for the subprocessors listed in Annex B.

  • We will give you at least 30 days’ notice by email before adding or replacing a subprocessor.
  • You may object on reasonable data protection grounds within those 30 days by writing to [email protected].
  • If we cannot offer a reasonable alternative, you may terminate the affected part of the service without penalty, with a pro rata refund of any fees paid for the unused remainder of the period.
  • Each subprocessor is bound by data protection obligations no less protective than those in this agreement, and we remain fully liable to you for its performance.
08

Assistance to you

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in meeting your own obligations.

You need toWhat we do
Answer a data subject request (Art. 15–22)Your dashboard lets you search, export and delete an individual conversation directly, which answers most requests without involving us. Where it does not, we help within the time you need to meet your one-month deadline.
Demonstrate security (Art. 32)Annex A, plus the evidence described in section 09.
Report a breach (Art. 33–34)The notification described in section 10.
Run a DPIA or prior consultation (Art. 35–36)The information about our processing that you reasonably need and that is available to us.

If a data subject contacts us directly about data we hold for you, we will not respond to the substance. We will forward the request to you without undue delay and tell the person that you are the controller.

09

Evidence and audits

Your right
We make available the information necessary to demonstrate compliance with Art. 28 and allow for audits, including inspections, conducted by you or an auditor you mandate.
Evidence first
In practice, and as Art. 28(3)(h) permits, this is satisfied in the first instance by written evidence: this agreement, Annex A, our subprocessor list, and written answers to a security questionnaire.
Audits beyond that
  • are limited to once per calendar year unless a breach or a supervisory authority requires otherwise;
  • must be requested at least 30 days in advance;
  • must not unreasonably disrupt operations;
  • are subject to confidentiality.
Costs
We may charge reasonable costs for an on-site audit.
10

Personal data breaches

Deadline
We notify you without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting data processed for you.
What it contains
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
In phases
Where full information is not available at once we provide it in phases without further undue delay.
Your reporting
Reporting the breach to your supervisory authority under Art. 33, and to data subjects under Art. 34, is yours to do as controller.
11

Return and deletion

Automatic
Conversation data is deleted automatically by a scheduled sweep after 90 days on Starter, Pro and Custom, 365 days on Scale and 15 days on Free, without you needing to ask.
On termination
On termination you may export your data from the dashboard. At your choice we delete or return all personal data processed for you within 30 days of the end of the service, and delete existing copies, unless EU or Member State law requires storage.
Backups
Backups are overwritten on their normal rotation cycle.
12

International transfers

At rest
Personal data is stored at rest in Germany.
Transfers
Transfers occur when a request is sent to a subprocessor outside the EU, listed in Annex B, and rest on EU Standard Contractual Clauses under Art. 46(2)(c) GDPR or on the EU–US Data Privacy Framework where the subprocessor is certified.
Services you connect
Chat channels, team alert destinations and other services you connect with your own account (the last group in Annex B) receive data on your instruction, under your own agreement with that provider. Putting a valid transfer mechanism in place for them is your responsibility as controller, as for your choice of AI provider below.
Bring Your Own Key
Selecting your AI provider is your instruction under section 04. If you select a provider in a country without an adequacy decision, currently DeepSeek (China), the transfer takes place on your instruction and putting a valid Art. 46 mechanism in place for it is your responsibility as controller. We will tell you which provider your account is routed to whenever you ask.
13

Acceptance and changes

Concluded
This agreement is concluded when you accept the Terms of Service and requires no separate signature.
Signed copy
If your organisation needs a signed counterpart for its own records, write to [email protected] and we will provide one.
Changes
Changes are notified by email at least 30 days in advance. Changes required by a change in law or by a supervisory authority may take effect sooner where necessary.
14

Annex A — Security measures

Technical and organisational measures under Art. 32 GDPR, current as of 28 September 2026.

AreaMeasure
Encryption in transitAll traffic, including the widget, the dashboard and every call to an AI provider, is carried over TLS.
Encryption at restProvider API keys on BYOK plans are encrypted with AES-256-GCM before storage and decrypted only in memory at the moment of use.
AuthenticationPasswords are hashed with bcrypt and are not recoverable, only checkable. Google Sign-In is available as an alternative. One-time sign-in codes and password-reset tokens are stored as SHA-256 hashes, with a short expiry and an attempt limit.
Access controlProduction access is limited to the sole proprietor and is authenticated. Customer data is partitioned by business identifier, and every query is scoped to it.
Input hardeningRequests to customer-supplied URLs, such as webhooks and knowledge-base sources, are filtered to block server-side request forgery against internal network addresses.
AvailabilityManaged AI requests fail over automatically across a pool of providers, so one provider outage does not take the assistant down.
Storage limitationConversation data is deleted by an automated sweep after 90 days on Starter, Pro and Custom, 365 days on Scale and 15 days on Free. Retention is enforced in code, not by policy alone.
DeletabilityCustomers can delete an individual conversation from the dashboard, taking effect immediately rather than at the next sweep.
Hosting securityInfrastructure is hosted in ISO 27001 certified data centres in Germany operated by Hetzner Online GmbH.
15

Annex B — Subprocessors

Authorised under section 07. This list is the same one published in the Privacy Policy and is kept current.

Infrastructure

Your account data and conversation history are stored in Germany.

SubprocessorPurposeLocationTransfer basis
Hetzner Online GmbHApplication servers and the PostgreSQL database holding accounts, settings and conversation history.Germany (EU)None required
Cloudflare, Inc.Hosting and delivery of the serlion.com website, and storage for files visitors attach to a conversation.EU edge network; company based in the USAStandard Contractual Clauses

Running the business

SubprocessorPurposeLocationTransfer basis
Paddle.com Market LtdMerchant of Record. Takes payment, issues your invoice and handles sales tax. Paddle, not Serlion, is the seller of record.United KingdomUK adequacy decision
Resend, Inc.Sends transactional email: sign-in codes, password resets, account notices, and notification emails to you and your team. If you set up the email inbox, it also receives the emails forwarded to your Serlion address and sends your replies.USAStandard Contractual Clauses
Google Ireland LimitedGoogle Sign-In, only if you choose to sign in that way.Ireland (EU), with onward transfer to the USAEU–US Data Privacy Framework

AI providers on Managed plans

On Bring Your Own Key plans none of these apply. Your requests go to the provider you pick, using your key.

SubprocessorPurposeLocationTransfer basis
Groq, Inc.Generates assistant replies. First provider tried.USAStandard Contractual Clauses
OpenAI, L.L.C.Generates assistant replies, and converts your knowledge-base content into the embeddings used to search it.USAStandard Contractual Clauses
Google LLCGenerates assistant replies using Gemini, and powers Lanus.USAEU–US Data Privacy Framework
Together AIBackup provider. Used only if all three above fail on a request.USAStandard Contractual Clauses
Fireworks AIBackup provider. Used only if all three above fail on a request.USAStandard Contractual Clauses
Anthropic PBCBackup provider. Used only if all three above fail on a request.USAStandard Contractual Clauses
OpenRouter, Inc.Backup provider. Used only if all three above fail on a request.USAStandard Contractual Clauses

Only if you switch them on

You connect each of these with your own account, under your own terms with that provider, and Serlion passes data to and from it only because you switched it on. Once data arrives there, you are the controller for it.

SubprocessorPurposeLocationTransfer basis
Telegram Messenger Inc.Carries messages between your customers and your chatbot or team, if you connect your own Telegram bot. Also delivers Telegram alerts to team members who connect their own Telegram through Serlion’s alerts bot; those alerts say what happened and link to your dashboard, and contain no visitor names, contact details or messages.Company based outside the EEA; data of users who signed up in the EEA or UK is stored in the NetherlandsYour own Telegram bot; each team member’s own Telegram account
Meta Platforms Ireland Limited (WhatsApp)Carries messages between your customers and your chatbot or team, if you connect your own WhatsApp Business number.Ireland (EU), with onward transfer to the USAYour own WhatsApp Business account
LY Corporation (LINE)Carries messages between your customers and your chatbot or team, if you connect your own LINE Official Account.JapanYour own LINE Official Account
Discord Inc.Carries direct messages between people in your Discord server and your chatbot or team, if you connect your own Discord bot. Also posts team alerts to Discord channels you choose.USAYour own Discord bot and webhooks
Slack TechnologiesPosts team alerts (a visitor’s name, contact details, message excerpt and a link to the conversation) to Slack channels you choose.USAYour own Slack workspace
Microsoft (Teams)Posts the same team alerts to Microsoft Teams channels you choose, through a Workflows webhook you create.Depends on your Microsoft 365 accountYour own Microsoft 365 account
Google (Google Chat)Posts the same team alerts to Google Chat spaces you choose.Depends on your Google Workspace accountYour own Google Workspace account
Cal.com, Inc.Meeting booking, only if you connect it.USAYour own Cal.com account
Your own webhook endpointReceives contact details a visitor types into a conversation, only if you configure a URL. You choose the destination and become the controller for whatever happens there.Wherever you host itDetermined by you

Objections to any subprocessor go to [email protected], under the procedure in section 07.

  • AES-256 Encrypted
  • TLS 1.3 in Transit
  • GDPR-Compliant (EU-Based)
  • 15-365 Day Retention, Disclosed
Serlion

Product

Demos

Support

Legal

© 2026 Serlion. All rights reserved.

Made in Germany