Data Processing Agreement (DPA)
Last modified: July 31, 2026
AI Data Processing Agreement: Short Answer
This DPA explains how Chat Data processes personal data for AI chat services, including customer account data, end-user chat data, chatbot conversations, subprocessors, the data retention matrix, security controls, Protected Health Information handling in HIPAA-configured workspaces, and GDPR/FADP obligations. It is intended for customers evaluating Chat Data as a processor for AI chatbot, live chat, and workflow automation deployments.
For AI and LLM workflows, customers should review which data is processed, which subprocessors may be involved, how data subjects are categorized, how retention works, and how Chat Data supports controller obligations under applicable data protection laws.
1. Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between ChatData LLC ("Processor"), a company specializing in AI-powered chat solutions, and the customer ("Controller") for the provision of services. This DPA sets out the terms and conditions for the processing of personal data by the Processor on behalf of the Controller in accordance with the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Purpose and Scope
ChatData provides an AI chat function that may be offered to its clients. This Agreement establishes the terms under which ChatData will process personal data on behalf of its clients in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).
3. Definitions
- "Data Protection Laws" means all applicable laws and regulations relating to the processing of personal data, including but not limited to the GDPR and FADP.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data.
- "AI Chat Function" means the artificial intelligence-powered chat solution provided by ChatData.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed.
- "Data Protection Impact Assessment (DPIA)" means an assessment of the impact of the envisaged processing operations on the protection of personal data.
4. Data Types and Categories
4.1 Categories of Data Subjects
ChatData processes personal data relating to the following categories of data subjects:
- Website Users - Visitors to chat-data.com website
- Registered Users - Chat Data account holders (Controllers)
- End Users - Individuals interacting with client chatbots (Data Subjects)
- Leads - Potential customers captured through chatbots or website forms
4.2 Types of Personal Data Processed
The following categories of personal data may be processed:
Contact Information
- Names
- Email addresses
- Phone numbers
Social Media and Platform Identifiers
- Facebook Page Scoped IDs (PSID)
- Instagram usernames
- General usernames
Technical Data
- IP addresses
- Unique identifiers (UUIDs)
- Device fingerprints
- Login timestamps and data
- Source platform information
Authentication Data
- Passwords (encrypted/hashed)
- OAuth tokens (Google authentication)
- Session data
Profile and Business Data
- Avatar images
- Referral codes and information
- Industry type and business information
- Use case descriptions
- Business pain points
Usage and Analytics Data
- Credits and usage tracking
- File storage usage statistics
- System analytics and metrics
Communication Data
- Chat messages and conversations
- Form submissions and responses
- Custom form data
Cookies and Tracking Data
- Session cookies
- Analytics cookies (website only)
- Preference cookies
Log Data
- Technical system logs
- Access logs
- Error logs
4.3 Processing Purposes
Personal data is processed for the following purposes:
- Service Provision - Delivering chat functionality, user management, and lead generation services
- Authentication and Security - Account security, access control, and fraud prevention
- Fraud Prevention and Abuse Detection - Preventing abuse of free plans and detecting fraudulent account creation using email addresses, browser fingerprints, and IP addresses
- Analytics and Optimization - Usage tracking, performance optimization, and service improvement
- Marketing and Attribution - Lead nurturing, customer attribution tracking, and business intelligence
- Legal Compliance - Meeting legal obligations and regulatory requirements
- Technical Operations - System maintenance, debugging, troubleshooting, and quality assurance
4.4 Data Retention Periods
ChatData retains data only as long as there is a business need for its use, or to meet regulatory or contractual requirements. Once data is no longer needed, it is securely disposed of or archived. Personal data is deleted or de-identified as soon as it no longer has a business use.
Personal data is retained for the following periods at a summary level:
- Chat Messages and Conversations - Retained by the maximum retention period of the user's plan or shorter upon user's requirement
- Lead Data - Retained for the life of the associated chatbot, and deleted within 30 days of chatbot deletion, a deletion request, or contract termination
- User Account Data - Retained while account is active plus 30 days after deletion request
- Uploaded Files, Images, and Audio - Deleted within 30 days of a deletion request or contract termination; plan-specific limits may apply
- Log Data - Retained for 30 days only
- Backups - Encrypted backups are retained on a rolling 30-day cycle and expire on that schedule
- Payment and Billing Records - Retained as required by legal and tax requirements, minimum 7 years
- Security Incident Records - Retained for six (6) years from incident closure, in accordance with 45 CFR §164.530(j)
- Session Cookies - Deleted when session ends
- Analytics Cookies - Required for our service to operate correctly
Data Retention Matrix
The following matrix documents retention periods by system and data category.
| System or Application | Data Description | Retention Period |
|---|---|---|
| ChatData Platform (Oracle Cloud Infrastructure — Switzerland) | Customer conversation data, chat messages, and training content | 30 days after deletion request or contract termination; plan-specific limits may apply |
| ChatData Platform (Oracle Cloud Infrastructure — Switzerland) | User account data and profile information | 30 days after deletion request |
| ChatData Platform (Oracle Cloud Infrastructure — Switzerland) | Lead and contact records captured via chatbots and forms | Retained for the life of the associated chatbot; deleted within 30 days of chatbot deletion, deletion request, or contract termination |
| ChatData Platform (Oracle Cloud Infrastructure — Switzerland), HIPAA-configured workspaces | Automated PHI redaction of conversation and lead records | Identifiers redacted on the workspace-configured schedule; redaction is irreversible for redacted fields |
| Microsoft Azure Blob Storage (Switzerland) | Uploaded files, images, audio, customer content, and PHI | 30 days after deletion request or contract termination; plan-specific limits may apply |
| Oracle Cloud Infrastructure & Microsoft Azure (Switzerland) | System and application logs | 30 days |
| OCI & Microsoft Azure Backups (Switzerland) | Encrypted database, vector storage, and file backups | Rolling 30-day backup cycle; backup data expires and is overwritten on schedule |
| Third-Party LLM Providers (OpenAI EU endpoints, Anthropic, Google Gemini, Cohere) | API request/response data (per provider policies). BAAs are in place with OpenAI and Anthropic where required. Infrastructure BAAs are in place with Microsoft (Azure) and Oracle (OCI) covering storage and processing of ePHI. | Per third-party provider retention policies and BAA terms |
| Customer-elected third-party model providers (e.g. DeepSeek via OpenRouter) | Conversation content transmitted to optional models selected by the customer; may be used for provider model training | Per third-party provider retention policies; not governed by ChatData agreements |
| Microsoft Azure OpenAI Service (Sweden Central) | Fallback LLM API request/response data, used when a primary model provider is unavailable or returns errors | Not retained for model training; per Azure OpenAI service terms |
| Thesys | UI response generation data | Conversation context transmitted per request to generate UI components; not retained by ChatData. Vendor retention per their published policy. Not available in workspaces configured for HIPAA. |
| Composio | MCP integration data | Integration parameters and responses transmitted per request to execute customer-configured integrations; not retained by ChatData. Vendor retention per their published policy. Not available in workspaces configured for HIPAA. |
| Cloudflare (Global CDN & DNS) | DNS, CDN, caching, and rate limiting logs | 30 days |
| Stripe | Payment information, usage metering, and financial data | Per legal and tax requirements; minimum 7 years |
| SendGrid | Email delivery metadata and logs | Per SendGrid retention settings and legal requirements |
| PostHog (EU Cloud) | Frontend and backend session analysis and user behavior data | 1 year or per user deletion request |
| Google Analytics | Main website visitor behavior and traffic analysis (does not track client chatbot traffic) | 26 months (default setting) |
| Incident tracking system (ChatData) | Security incident records, investigations, risk assessments, and breach notification documentation | Six (6) years from incident closure, per 45 CFR §164.530(j) |
4.5 Deletion Timelines and Backups
Deletion requests are applied to production systems within thirty (30) days of the request or of contract termination, through a combination of automated and manual deletion processes. Encrypted backups are retained on a rolling 30-day cycle and expire on that schedule; deleted data is not restored from backup except as part of a full disaster-recovery event. Accordingly, deleted data is fully purged from all ChatData systems, including encrypted backups, within sixty (60) days of the deletion request.
Personal data is securely deleted following contract termination in accordance with company policy, contractual commitments, and all relevant laws and regulations. Personal data is also deleted in response to a verified request from a consumer or data subject, where ChatData does not have a legitimate business interest or other legal obligation to retain the data.
4.6 Legal Holds
Under certain circumstances, ChatData may become subject to legal proceedings requiring retention of data associated with legal holds, lawsuits, or other matters as stipulated by legal counsel. Such records are exempt from the retention periods specified above and are retained in accordance with the requirements identified by legal counsel. All such holds and special retention requirements are subject to annual review.
5. Processing of Personal Data
5.1 Processing Scope and Legal Basis
ChatData processes data solely for the purpose of enabling and improving its AI chat function for clients and their end users. The legal basis for processing includes:
- Processing necessary for the performance of a contract
- Processing based on legitimate interests
- Processing based on explicit consent where required
- Processing necessary for compliance with legal obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure that persons authorized to process Personal Data have committed themselves to confidentiality
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
- Assist the Controller in responding to requests from data subjects
- Assist the Controller in ensuring compliance with security obligations, data breach notifications, and data protection impact assessments
- Delete or return all Personal Data after the end of services
- Make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28
5.2 Data Storage and Processing Locations
ChatData maintains the following data storage and processing infrastructure:
- All conversation data and training data are stored in Switzerland, which has been recognized by the European Commission as providing an adequate level of data protection
- Primary server infrastructure is provided by Oracle Cloud Infrastructure
- Blob storage is provided by Azure Cloud Service, hosted in Switzerland
- Infrastructure Business Associate Agreements (BAAs) are in place with Microsoft (Azure) and Oracle (OCI) covering the storage and processing of ePHI
- ChatData operates remotely and does not operate physical servers or on-premises storage; all customer data is stored in cloud infrastructure (Oracle Cloud Infrastructure and Microsoft Azure)
- Training data is stored in our own vector database storage on Oracle Cloud Infrastructure servers
- We do not use any third-party vendors for storing training data
- Training data will not be shared with any vendors
- All log data (including technical logs, access logs, and system logs) are stored on Switzerland servers. While log data is not transferred to the United States, authorized ChatData personnel may remotely access this data from the United States for operational purposes including debugging, troubleshooting, and system maintenance
Any transfer of personal data outside the European Economic Area (EEA) is conducted in compliance with GDPR Chapter V requirements, including:
- Use of Standard Contractual Clauses (SCCs) where applicable
- Ensuring adequate safeguards for data transfers
- Maintaining records of data transfer mechanisms
5.3 Data Access and Usage
ChatData may access the data only for:
- Debugging purposes
- Troubleshooting
- Service analysis and improvement
- Quality assurance
5.4 Data Sharing Restrictions
ChatData shall not:
- Resell any client data
- Share client data with third parties
- Disclose client data without prior written consent
- Use client data for purposes other than those specified in this agreement
5.5 PII Anonymization Controls
ChatData provides configurable anonymization that allows the Controller to automatically mask personally identifiable information (PII) before it is transmitted to third-party LLM providers and/or before conversation content is stored within Chat Data systems.
- Controllers can enable anonymization per workspace and select the PII categories (for example: email, phone, credit card, banking, government ID, IP address, and medical identifiers) that should be protected.
- When enabled for LLM processing, sensitive values are replaced with consistent placeholders (such as EMAIL_1 or PHONE_1) prior to any outbound request to language model providers, ensuring that providers never receive the original values.
- When enabled for data retention, the same placeholders are stored in Chat Data conversation history, analytics, and exports so that transcripts remain useful without exposing raw PII.
- Controllers can disable anonymization at any time, and the feature operates without altering existing automations or workflows beyond the substitution of placeholders.
5.6 Data Classification
ChatData classifies data and information systems according to legal requirements, sensitivity, and business criticality so that information receives the appropriate level of protection. Information systems and applications are classified according to the highest classification of data they store or process.
- Confidential - Highly sensitive data requiring the highest levels of protection, with access restricted to specific employees or departments. This includes Customer Data, personally identifiable information (PII), Protected Health Information (PHI/ePHI), authentication credentials, secrets and private keys, and incident and risk assessment reports.
- Restricted - ChatData proprietary information requiring thorough protection, with access restricted to employees with a need-to-know based on business requirements. This is the default classification for all company information unless stated otherwise.
- Public - Documents intended for public consumption, such as product descriptions, release notes, and external-facing policies.
Confidential data is subject to additional handling requirements, including that it shall not be used or stored in non-production systems or environments, that confidential systems shall not allow unauthenticated or anonymous access, and that transfers to people or entities outside the company shall only be made under a legal contract or arrangement with the explicit written permission of management or the data owner.
5.7 Protected Health Information and HIPAA-Configured Workspaces
Protected Health Information (PHI/ePHI) is processed only in workspaces configured for HIPAA, under an executed Business Associate Agreement (BAA), and in accordance with the retention and redaction controls documented in the Data Retention Matrix in Section 4.4.
- PHI/ePHI may only be transmitted through channels covered by an appropriate Business Associate Agreement. Non-BAA-capable third-party channels are blocked on HIPAA-configured workspaces.
- Optional third-party models and vendors that are not covered by a ChatData agreement are never enabled by default and are not available in workspaces configured for HIPAA.
- In HIPAA-configured workspaces, ChatData applies automated redaction of PHI identifiers in conversation and lead records on the workspace-configured schedule. Redaction is irreversible for redacted fields.
- Security incident records, investigations, risk assessments, and breach notification documentation are retained for six (6) years from incident closure, in accordance with 45 CFR §164.530(j).
6. Sub-processors and Service Providers
ChatData engages the following Sub-processors and Service Providers:
6.1 Language Model Providers
- OpenAI - Provides LLM API
- We maintain a Business Associate Agreement (BAA) with OpenAI
- OpenAI API requests are routed through the EU endpoint (https://eu.api.openai.com) across the platform for GDPR compliance
- OpenAI does not retain or use data for model training purposes
- Anthropic - Provides LLM API
- We maintain a Business Associate Agreement (BAA) with Anthropic
- Anthropic does not retain or use data for model training purposes
- Google Gemini - Provides LLM API
- Natively restricts the use of API calls for model training
- Data is not used for training purposes
- Cohere - Provides reranking LLM API service
- We have enabled the option to prevent data usage for training purposes
- Data is not used for model training
- DeepSeek - Accessed through OpenRouter, as a customer-elected optional model
- We do not have a direct contract with DeepSeek
- Data processed through DeepSeek models may be used for training purposes
- Users should be aware that their data might be used for training if they use DeepSeek models
- Customer-elected optional models are never enabled by default. Where a Controller explicitly selects such a model, the Controller acts as the data owner authorizing that transfer
- These models are not available in workspaces configured for HIPAA, and are excluded from ChatData's vendor data-handling and disposal commitments
6.2 Infrastructure Providers
- Oracle Cloud Infrastructure
- Provides server hosting
- Provides database storage
- Hosts our vector database for training data
- Azure Cloud Service
- Provides file storage
- Provides backup LLM API services
- Azure LLM models are used as a fallback when a selected model is unavailable or when a model provider request returns errors; we route to the closest available Azure model in those cases
- Azure LLM backup models are hosted in the Sweden Central region
- Cloudflare
- Provides DNS hosting
- Provides CDN service
- Provides caching
- Provides rate limiting
6.3 Analytics Providers
- PostHog (EU Cloud)
- Provides frontend and backend session analysis and user behavior data
- Data is retained for 1 year, or deleted earlier upon a user deletion request
- Google Analytics
- Essential service for chat-data.com website analytics and functionality
- Processes only website visitor data from chat-data.com domain
- Does not process or access client chatbot data
- Not involved in client data processing activities
- Cannot be disabled as it is required for website operations and user experience optimization
6.4 Integration and UI Service Providers
- Thesys
- Provides UI-based response generation for enhanced chat interactions
- Processes conversation context to generate dynamic user interface components
- Data is processed only for the purpose of generating UI responses
- Conversation context is transmitted per request and is not retained by ChatData
- Not available in workspaces configured for HIPAA
- Composio
- Provides built-in MCP (Model Context Protocol) apps integration
- Enables chatbots to connect with external tools and services
- Data is processed only for the purpose of executing requested integrations
- Integration parameters and responses are transmitted per request and are not retained by ChatData
- Not available in workspaces configured for HIPAA
6.5 Payment and Communication Providers
- Stripe
- Processes payment information, usage metering, and financial data
- Retained per legal and tax requirements, minimum 7 years
- SendGrid
- Provides transactional email delivery
- Processes email delivery metadata and logs, retained per SendGrid retention settings and legal requirements
6.6 Customer-Operated Backends and Integrations
Where a Controller connects a customer-operated backend or integration, conversation content is transmitted to infrastructure that the Controller controls. This is permitted in workspaces configured for HIPAA; the Controller retains responsibility for the HIPAA compliance of that infrastructure, including any Business Associate Agreement required for it.
The Processor may engage Sub-processors to process Personal Data, provided that:
- The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors
- The Controller shall have the right to object to such changes
- The Processor shall impose the same data protection obligations on Sub-processors
7. Security Measures
7.1 Technical and Organizational Measures
The Processor implements the following technical and organizational measures:
- Encryption of personal data at rest and in transit over public networks, in accordance with our internal Cryptography Policy
- Encryption of all backups
- Ability to ensure ongoing confidentiality, integrity, and availability
- Regular testing and evaluation of security measures
- Access control and authentication procedures, with access to confidential data restricted to specific employees, roles, or departments and documented approval required for non-preapproved roles
- Incident detection and response procedures
- Regular security assessments and both internal and external audits
- Employee confidentiality agreements
- Secure data transmission protocols
- Full-disk encryption on company-issued laptops used to access company or customer data, with screens configured to lock after five (5) minutes of non-use
- A prohibition on storing confidential data on personal phones or devices, or on removable media including USB drives, CDs, or DVDs
7.2 Data and Device Disposal
Data classified as restricted or confidential is securely deleted when no longer needed. ChatData assesses the data and disposal practices of third-party vendors, and only engages vendors that meet ChatData requirements for secure data disposal for the storage and processing of restricted or confidential data.
- Hard drives and mobile devices used to store restricted or confidential information are securely wiped using industry-standard secure erasure methods prior to disposal, or physically destroyed
- For devices that cannot be securely wiped due to damage, physical destruction or certified e-waste services with certificates of data destruction are used. Certificates of destruction are retained for at least one year
- Confidential and restricted hardcopy materials are shredded or otherwise disposed of using a secure method
8. Data Subject Rights
The Processor shall assist the Controller in fulfilling data subject requests by:
- Implementing appropriate technical and organizational measures
- Providing necessary information and assistance
- Facilitating the exercise of data subject rights, including:
- Right to access personal data
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Responding to data subject requests within the timeframes specified by applicable data protection laws
- Maintaining records of data subject requests and responses
9. Data Protection Impact Assessment
The Processor shall:
- Assist the Controller in conducting Data Protection Impact Assessments (DPIAs) where required
- Provide necessary information about processing operations
- Implement measures to address identified risks
- Maintain records of processing activities
- Assist the Controller in consultations with supervisory authorities where required
10. Data Breach Notification
The Processor shall:
- Notify the Controller without undue delay after becoming aware of a personal data breach
- Provide necessary information to assist the Controller in meeting its breach notification obligations
- Document all personal data breaches, including the facts, effects, and remedial actions taken
11. Audit Rights
The Controller may:
- Conduct audits or inspections of the Processor's facilities
- Request information necessary to demonstrate compliance
- Require the Processor to contribute to audits
The Processor measures and verifies compliance with its internal data management policies through various methods, including business tool reports and both internal and external audits. Current certifications, security posture, and compliance documentation are available in our Trust Center.
12. Liability
The Processor shall be liable for any damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to lawful instructions of the Controller.
13. Term and Termination
This DPA shall remain in effect as long as the Processor processes Personal Data on behalf of the Controller. Upon termination, the Processor shall securely delete or return all processed data as instructed by the Controller. Deletion is applied to production systems within thirty (30) days of contract termination, and data is fully purged from all systems, including encrypted backups, within sixty (60) days, as described in Section 4.5.
14. Governing Law
This Agreement shall be governed by and construed in accordance with the laws of the United States, without regard to its conflict of law principles.
15. Contact Information
For any questions regarding this DPA, data subject requests, or to exercise your rights under GDPR, please contact us at [email protected].
Our Data Protection Officer can be contacted at [email protected].