Data Processing Terms
Effective: 7 September 2026 · Version 2026-09-07
These Data Processing Terms form part of the Terms of Service when a customer business uses Chap AI to process personal data. The customer is the data controller and Chap AI is the data processor, except where either party independently determines a different purpose or means of processing.
1. Processing details
The subject matter is delivery of the Chap AI customer-support service for the term of the customer’s account and any limited period needed for secure deletion, backups, disputes, or legal duties. Processing may include collecting, storing, organizing, retrieving, analyzing, generating AI-assisted output from, transmitting, and deleting account, contact, message, attachment, channel, and usage data. Data subjects may include the customer’s staff, prospects, customers, and other people who communicate with the customer.
2. Documented instructions
We process customer personal data only on documented instructions expressed through these terms, the customer’s configuration and use of the service, and written support requests, unless law requires otherwise. We will notify the customer if we believe an instruction infringes applicable data-protection law.
3. Confidentiality and security
People authorized to process customer personal data are bound by confidentiality duties. We maintain proportionate technical and organizational safeguards, including access controls, encrypted network transport, restricted production access, logging, and backups. Customers remain responsible for permissions, connected-channel settings, lawful collection, and secure user credentials.
4. Service providers
The customer gives general authorization for subprocessors needed to provide hosting, database, vector search, realtime delivery, email, authentication, analytics, AI, payments, and enabled messaging channels. Current categories and named providers are described in the Privacy Policy. We remain responsible for imposing appropriate data-protection obligations on subprocessors and will publish material provider changes. A customer with a reasonable data-protection objection may contact us before the change takes effect.
5. International transfers
Where processing crosses borders, we use a transfer mechanism permitted by applicable law and require relevant providers to protect the data. Customers authorize transfers needed for providers and channels they select, subject to those safeguards.
6. Assistance and incidents
Taking account of the service and information available to us, we will reasonably assist with data-subject requests, impact assessments, regulator consultations, and compliance enquiries. We will notify the affected customer without undue delay after confirming a personal-data breach involving customer data and provide available information needed for the customer’s legal duties.
7. Return, deletion, and audits
During an active account, the customer may retrieve data through available service features. On termination or a verified written request, we will delete or return customer personal data where reasonably possible, except data that law requires us to keep and copies awaiting expiry in protected backups. We will provide information reasonably necessary to demonstrate compliance and cooperate with a proportionate audit, subject to confidentiality, security, and cost arrangements.
8. Contact
Send data-processing requests through the contact form or email [email protected]. Include the workspace name and enough detail for us to verify authority.