Data Processing Agreement

Last updated: 2026-01-01

This Data Processing Agreement (DPA) is part of our Terms of Service. It explains how Chattering.ai handles personal data on your behalf when you use our product.

In short: your customers' data is yours. We process it only to run the service you signed up for, and we follow the rules laid out below to keep it safe.

1. Key Terms

A few terms come up often in this agreement. Here is what they mean in plain language:

  • Personal Data — any information that can identify a person, like a name, email address, or IP address
  • Processing — anything done with personal data: storing it, reading it, sending it, or deleting it
  • Controller — that's you, the Chattering customer. You decide what personal data to collect and why
  • Processor — that's us, Chattering.ai. We handle personal data only according to your instructions
  • Data Subject — the person whose data it is, typically your end customer or website visitor
  • Supervisory Authority — the government body that enforces data protection laws in a given country (for example, the ICO in the UK or the CNIL in France)

These terms carry the same meaning as they do under the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. What We Process and Why

We only process personal data based on your instructions. In practice, that means we store and use the data your customers share through the Chattering widget, inbox, and help center — things like names, email addresses, and conversation content — so the product works as you expect.

We won't use that data for our own purposes, and we won't move it to another country without telling you first and making sure the right safeguards are in place.

3. How We Keep Data Safe

We protect personal data with a set of security measures that match the sensitivity of the information:

  • All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access to production systems is restricted and logged
  • We run regular security reviews and fix issues promptly

You can read more about our security practices on our Security page.

4. Sub-processors

Sometimes we use other companies to help run parts of the service — for example, a hosting provider or a payment processor. These are called sub-processors.

We won't bring on a new sub-processor without telling you first. If we plan to add or replace one, we'll let you know in advance so you can raise any concerns.

5. Your Customers' Rights

People whose data we process on your behalf have rights under data protection laws. They can ask to see their data, correct it, or have it deleted. When someone makes a request like this, we'll help you respond to it. In most cases that means giving you the tools to export or delete the data yourself, or doing it on your behalf if you ask.

6. What Happens if There's a Breach

If we discover that personal data has been exposed or accessed without permission, we'll tell you as quickly as possible — certainly within 72 hours, as the GDPR requires. We'll give you enough detail to understand what happened, who might be affected, and what we're doing about it, so you can meet your own reporting obligations.

7. When the Agreement Ends

If you stop using Chattering, you choose what happens to the personal data we hold for you. We can either return it to you (as an export) or delete it. Once deleted, we remove all copies from our systems unless the law requires us to keep them for a specific period.

Contact

If you have questions about this DPA or need a signed copy for your records, email us at support@chattering.ai.

Legal entity details are available on request via support@chattering.ai.