Legal
Data Processing Agreement
This DPA governs how CertifChat processes personal data on your behalf when you use the Service. It forms part of our Terms of Service.
Last updated: July 24, 2026
1. Scope and roles
This Data Processing Agreement ("DPA") applies where CertifChat processes personal data on your behalf in providing the Service, and it supplements our Terms of Service. For that data, you are the controller (or a processor acting for your own customer) and CertifChat is the processor. For data where CertifChat decides the purpose, such as your account and billing information, we act as controller under our Privacy Policy, and this DPA does not apply. Where the context requires, terms such as controller, processor, personal data, processing, and data subject have the meaning given in the GDPR and comparable data protection laws.
2. Your instructions
We process personal data only to provide and support the Service and only on your documented instructions, which include this DPA, the Terms, your configuration of the Service, and any later written instructions you give. We will tell you if, in our opinion, an instruction breaches applicable data protection law, unless we are legally prohibited from doing so. If a law requires us to process data beyond your instructions, we will inform you first where that is permitted.
3. Confidentiality
We ensure that the people authorized to process your personal data are bound by confidentiality obligations and are given access only to the extent needed to do their work.
4. Security
We implement appropriate technical and organizational measures to protect personal data, described in Annex II below. We regularly review these measures and may update them, provided the level of protection is not reduced.
5. Sub-processors
You give general authorization for us to engage the sub-processors listed in Annex III to help provide the Service. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. If we add or replace a sub-processor, we will update Annex III and, where you have asked to be notified, give you reasonable prior notice so you can object on reasonable data protection grounds. If we cannot resolve a reasonable objection, you may stop using the affected part of the Service and, if needed, terminate as your only remedy.
6. Data subject requests
Taking into account the nature of the processing, we will assist you with appropriate measures, so far as possible, to respond to requests from data subjects exercising their rights. If we receive such a request directly about data we process for you, we will, unless legally required to act, direct the person to you.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and we will provide the information you reasonably need to meet your own notification duties, along with the steps we are taking to address the breach.
8. Assistance
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you meet your obligations for security, breach notification, data protection impact assessments, and prior consultation with authorities.
9. Deletion and return
On termination of the Service, and on your request, we will delete or return the personal data we process for you and delete existing copies, unless the law requires us to keep it. Absent your instruction, we will delete the data within a reasonable period after termination as described in our Privacy Policy.
10. Audits
We will make available the information reasonably necessary to demonstrate our compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. To respect the confidentiality and security of our systems and other customers, audits take place on reasonable prior notice, no more than once a year unless a supervisory authority or a breach requires otherwise, and may be satisfied through our existing documentation and reports.
11. International transfers
Some sub-processors are located outside your country, including in the United States. Where personal data protected by European Economic Area or United Kingdom law is transferred to a country without an adequacy decision, the transfer is made under appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and completed with the details in the Annexes.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms. If there is a conflict between this DPA and the Terms on the subject of data protection, this DPA controls. This DPA remains in effect for as long as we process personal data for you.
Annex I: Description of processing
Parties. The data exporter is you, the customer using the Service. The data importer is CertifChat.
Subject matter and duration. Processing of personal data as needed to provide the Service for the term of your subscription and any wind-down period.
Nature and purpose. Hosting, storing, indexing, and retrieving the content you connect; generating AI answers with citations; operating the embeddable chat widget; and providing analytics and support related to the Service.
Categories of data subjects. Your end users who interact with your chatbot, and any individuals referenced in the sources and content you connect.
Types of personal data. Conversation messages and content; a visitor identifier and IP address; ratings and feedback; contact details an end user chooses to submit; and any personal data contained in the sources you connect. You should not connect special category data unless you have implemented the additional protections the law requires.
Annex II: Technical and organizational measures
- encryption of personal data in transit;
- passwords stored only as salted hashes, and secrets held outside the codebase;
- tenant isolation and access controls so each account's data is scoped to that account, with origin checks on the widget;
- rate limiting and abuse protections, and validation of outbound fetches to prevent access to internal systems;
- least-privilege access for our personnel and use of vetted providers for infrastructure;
- logging and monitoring to detect and investigate security events; and
- regular review of these measures, with updates that maintain or improve the level of protection.
Annex III: Sub-processors
- OpenAI: large language model and embedding processing for answers and search.
- Supabase: database, authentication, and file storage.
- Paddle: Merchant of Record for payment and subscription processing.
- Resend: transactional email delivery.
- Hostinger: hosting for the API and content crawler, including caching and queueing.
- Google Analytics: aggregate website analytics.
These sub-processors operate in the United States and the European Union. The specific region where data is processed depends on each provider's configuration, and transfers are covered by the safeguards in section 11.
Contact
To ask about this DPA, request a signed copy, or raise a data protection matter, email hello@certifchat.com or use our contact page.
