- You are the data controller; ChatSys is the data processor acting on your instructions.
- Three subprocessors: Supabase, Stripe, and a third-party AI inference provider — all under Standard Contractual Clauses.
- Each workspace is isolated with PostgreSQL row-level security and AES-256 encryption at rest.
- A countersigned DPA is available to paid customers — email privacy@chatsys.ai.
- 72-hour breach notification. Effective May 17, 2026 and reviewed June 2026.
Last updated: June 2026
A Data Processing Agreement (DPA) is a contract required under GDPR Article 28 whenever one company processes personal data on behalf of another. When you use ChatSys to run a chatbot, your visitors' personal data is processed on your behalf — so you are the controller and ChatSys is the processor. This DPA documents the roles, the subprocessors involved, the security measures we apply, and how we handle data-subject requests, breaches, and deletion.
What is a DPA and why do you need one?
Under GDPR Article 28, a controller may only use a processor that provides sufficient guarantees and is bound by a written contract — the DPA. If you handle the personal data of people in the EU or UK and use ChatSys to do it, you need a DPA in place. This page is that agreement; paid customers can also request a countersigned copy.
Who is the data controller and who is the processor?
For personal data your visitors submit through your agent, you are the data controller and ChatSys is the data processor. We process personal data only on your documented instructions — which, in practice, means operating the features you enable. The roles and responsibilities are governed by this DPA together with our Terms of Service.
What data does ChatSys process on your behalf?
- ·Subject matter: providing the ChatSys service.
- ·Duration: for as long as your account is active.
- ·Data types: account info, scraped/uploaded content, conversation messages, usage metrics.
- ·Data subjects: your team members and your site's visitors.
Which subprocessors does ChatSys use?
We use three subprocessors, each operating under Standard Contractual Clauses. We give 30 days' notice before adding a new subprocessor so you can object.
| Subprocessor | Purpose | Safeguard |
|---|---|---|
| Supabase | Hosting, database, storage & authentication | Standard Contractual Clauses |
| Stripe | Subscription billing & payments | Standard Contractual Clauses |
| AI inference provider | Hosted model inference for chat responses | Standard Contractual Clauses |
What security measures apply?
We apply technical and organizational measures including:
- ·TLS 1.3 encryption for all data in transit.
- ·AES-256 encryption for data at rest.
- ·PostgreSQL row-level security isolating every workspace.
- ·Least-privilege access controls for staff and systems.
- ·GDPR-ready processes with a DPA available on request.
- ·SOC 2 certification in progress.
- ·72-hour breach notification to affected customers.
- ·A 30-day deletion window on cancellation.
ChatSys never trains shared models on customer content. For more detail, see our Security overview.
How does ChatSys handle data-subject requests and breach notifications?
We assist you in responding to data-subject requests for access, rectification, erasure, portability, and objection. Because you control your workspace, you can fulfill most requests directly from the dashboard. If we become aware of a personal-data breach affecting your data, we will notify you within 72 hours so you can meet your own notification obligations.
What happens to your data when you cancel?
On termination we delete or return personal data within a 30-day window, subject to short backup-rotation cycles and legal retention. You can export your data during the active period and the deletion window before it is removed.
International data transfers & SCCs
Where personal data is transferred internationally, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) with each subprocessor, to ensure your data remains protected to GDPR standards.
How do I get a countersigned DPA?
A countersigned DPA is available to paid customers. Email privacy@chatsys.ai to request one. Larger teams can review procurement details on the Enterprise page, or create an account to get started. See also our Privacy Policy.