Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between [Company legal name] ("Processor") and the Customer ("Controller"). It applies when we process personal data of the Customer’s end users on the Customer’s behalf. It is accepted together with the Terms; a countersigned copy is available on request.
1.Scope and instructions
We process end users’ personal data — chat messages, contact details they share, approximate location — only to provide the Service and only on the Customer’s documented instructions, which are the Terms, this DPA and the Customer’s settings in the dashboard. We will tell the Customer if we believe an instruction breaks the law.
2.Service provider terms
For the purposes of the CCPA and similar US state laws we are a service provider. We will not sell or share the personal data, retain, use or disclose it outside the direct business relationship with the Customer, or combine it with data from other sources except as the law allows service providers to do.
3.Confidentiality and security
Everyone authorized to process the data is bound by confidentiality. We maintain appropriate technical and organizational measures, including encryption in transit, access limited to our servers, encrypted storage of bot tokens, and access to leads only for verified Customers.
4.Subprocessors
The Customer authorizes the subprocessors listed on our Subprocessors page. We impose data protection obligations on them no less protective than this DPA and remain responsible for them. We give at least 14 days’ notice of changes; the Customer may object on reasonable grounds and, if we cannot resolve the objection, terminate the affected service with a pro-rated refund.
5.Assistance
We help the Customer respond to end users’ requests to access, correct or delete their data, and with security and data protection assessments, taking into account the nature of the processing.
6.Personal data breaches
We notify the Customer without undue delay, and in any case within 72 hours after becoming aware of a breach affecting its data, with the information we have, and update it as we learn more.
7.Deletion and return
On the Customer’s request we export or delete its conversations and leads within 30 days. Within 90 days after the end of the service we delete remaining Customer personal data, unless the law requires us to keep it.
8.Audits
On reasonable written request, no more than once a year, we provide information needed to demonstrate compliance with this DPA, including answers to security questionnaires.
9.International transfers
Data is processed in the United States and, for Telegram delivery, where the Customer has connected a bot. Where the law requires a transfer mechanism, the Standard Contractual Clauses (Module 2, controller to processor) are incorporated by reference.
10.Precedence
If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.