Data Processing Agreement
Our comprehensive DPA ensures GDPR compliance and protects your data processing activities with InsertChat.
7-day free trial · Cancel anytime · No commitment
Full data processing
agreement
Our complete DPA covering all data processing obligations and responsibilities.
Introduction
1. Definitions
2. Processing of Personal Data
2.1 Scope and Nature: Subject matter covers AI agent and customer support services provision. Duration is the agreement term plus legal obligation requirements. Nature includes collection, recording, storage, analysis, retrieval, and deletion.
2.2 Categories of Data Subjects: Customer's end users and website visitors, employees and representatives, customers and prospects.
2.3 Categories of Personal Data: Contact information (name, email, phone), communication data (chat messages, conversation history), technical data (IP address, browser info, device identifiers), usage data (interaction patterns, timestamps, session data).
3. Customer Obligations
4. InsertChat Obligations
5. Security Measures
5.1 Technical Measures: 256-bit AES encryption for data at rest, TLS 1.3 encryption for data in transit, multi-factor authentication for system access, regular security monitoring and intrusion detection, secure software development lifecycle.
5.2 Organizational Measures: Role-based access controls and least privilege principle, regular employee security training and background checks, incident response and business continuity procedures, regular security audits and penetration testing, enterprise security certification and compliance monitoring.
6. Sub-processors
6.1 Authorized Sub-processors: Hetzner (Cloud infrastructure and hosting), Cloudflare (Cloud infrastructure and hosting), Stripe (Payment processing), AWS (Email delivery).
6.2 Sub-processor Changes: InsertChat will provide 30 days' prior notice of any changes to sub-processors. Customer may object to new sub-processors within 30 days of notification.
7. International Data Transfers
8. Data Subject Rights
9. Data Breach Notification
10. Audits and Compliance
10.1 Regular Audits: InsertChat undergoes regular third-party security audits and maintains enterprise security certification. Audit reports are available to customers upon request under appropriate confidentiality agreements.
10.2 Customer Audits: Customer may conduct audits of InsertChat's processing activities upon reasonable notice and at Customer's expense, subject to confidentiality obligations and operational requirements.
11. Data Retention and Deletion
12. Liability and Indemnification
13. Term and Termination
How we protect
your data
We implement industry-leading security measures to ensure your data remains safe and private.