ChatSys Data Processing Agreement (DPA)

This DPA supplements the Terms of Service and applies where ChatSys processes personal data on your behalf under GDPR Article 28.

Last updated May 17, 2026

Key takeaways
  • You are the data controller; ChatSys is the data processor acting on your instructions.
  • Three subprocessors: Supabase, Stripe, and a third-party AI inference provider — all under Standard Contractual Clauses.
  • Each workspace is isolated with PostgreSQL row-level security and AES-256 encryption at rest.
  • A countersigned DPA is available to paid customers — email privacy@chatsys.ai.
  • 72-hour breach notification. Effective May 17, 2026 and reviewed June 2026.

Last updated: June 2026

A Data Processing Agreement (DPA) is a contract required under GDPR Article 28 whenever one company processes personal data on behalf of another. When you use ChatSys to run a chatbot, your visitors' personal data is processed on your behalf — so you are the controller and ChatSys is the processor. This DPA documents the roles, the subprocessors involved, the security measures we apply, and how we handle data-subject requests, breaches, and deletion.

What is a DPA and why do you need one?

Under GDPR Article 28, a controller may only use a processor that provides sufficient guarantees and is bound by a written contract — the DPA. If you handle the personal data of people in the EU or UK and use ChatSys to do it, you need a DPA in place. This page is that agreement; paid customers can also request a countersigned copy.

Who is the data controller and who is the processor?

For personal data your visitors submit through your agent, you are the data controller and ChatSys is the data processor. We process personal data only on your documented instructions — which, in practice, means operating the features you enable. The roles and responsibilities are governed by this DPA together with our Terms of Service.

What data does ChatSys process on your behalf?

  • ·Subject matter: providing the ChatSys service.
  • ·Duration: for as long as your account is active.
  • ·Data types: account info, scraped/uploaded content, conversation messages, usage metrics.
  • ·Data subjects: your team members and your site's visitors.

Which subprocessors does ChatSys use?

We use three subprocessors, each operating under Standard Contractual Clauses. We give 30 days' notice before adding a new subprocessor so you can object.

SubprocessorPurposeSafeguard
SupabaseHosting, database, storage & authenticationStandard Contractual Clauses
StripeSubscription billing & paymentsStandard Contractual Clauses
AI inference providerHosted model inference for chat responsesStandard Contractual Clauses

What security measures apply?

We apply technical and organizational measures including:

  • ·TLS 1.3 encryption for all data in transit.
  • ·AES-256 encryption for data at rest.
  • ·PostgreSQL row-level security isolating every workspace.
  • ·Least-privilege access controls for staff and systems.
  • ·GDPR-ready processes with a DPA available on request.
  • ·SOC 2 certification in progress.
  • ·72-hour breach notification to affected customers.
  • ·A 30-day deletion window on cancellation.

ChatSys never trains shared models on customer content. For more detail, see our Security overview.

How does ChatSys handle data-subject requests and breach notifications?

We assist you in responding to data-subject requests for access, rectification, erasure, portability, and objection. Because you control your workspace, you can fulfill most requests directly from the dashboard. If we become aware of a personal-data breach affecting your data, we will notify you within 72 hours so you can meet your own notification obligations.

What happens to your data when you cancel?

On termination we delete or return personal data within a 30-day window, subject to short backup-rotation cycles and legal retention. You can export your data during the active period and the deletion window before it is removed.

International data transfers & SCCs

Where personal data is transferred internationally, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) with each subprocessor, to ensure your data remains protected to GDPR standards.

How do I get a countersigned DPA?

A countersigned DPA is available to paid customers. Email privacy@chatsys.ai to request one. Larger teams can review procurement details on the Enterprise page, or create an account to get started. See also our Privacy Policy.

Frequently asked questions

Is ChatSys GDPR compliant and does it have a DPA?+
Yes. ChatSys is built to be GDPR-ready and offers a Data Processing Agreement (DPA) covering the GDPR Article 28 obligations of a processor. Paid customers can request a countersigned copy by emailing privacy@chatsys.ai.
What subprocessors does ChatSys use?+
Three: Supabase (hosting, database, storage, and authentication), Stripe (subscription billing), and a third-party AI inference provider (model inference). All operate under Standard Contractual Clauses, and ChatSys gives 30 days' notice before adding a new subprocessor.
Is ChatSys the controller or the processor for an AI chatbot?+
For personal data your visitors submit through your chatbot, you are the data controller and ChatSys is the data processor. ChatSys processes that personal data only on your documented instructions — in practice, operating the features you enable.
How are data-subject access requests handled?+
ChatSys assists you in responding to data-subject requests for access, rectification, erasure, portability, and objection. Because you control your workspace, you can fulfill most requests directly from the dashboard; for anything else, contact privacy@chatsys.ai.
What happens to my data when I cancel?+
On termination ChatSys deletes or returns personal data within a 30-day window, subject to short backup-rotation cycles and legal retention. You can export your data during the active period and the deletion window.