Data Processing Agreement
This Data Processing Agreement ("DPA") is between you, the customer ("Controller"), and SummitBots ("SummitBots", "Processor"). It forms part of our Terms of Service and applies whenever we process personal data on your behalf that is subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or similar data protection law. It takes effect automatically when you use the service. If you need a countersigned copy, email support@summitbots.io.
If this DPA and the Terms conflict on data protection, this DPA wins. If this DPA and the Standard Contractual Clauses conflict, the Clauses win.
1. Roles and scope
For chat transcripts, leads, and documents that your widget collects or that you upload, you are the controller and we are your processor. We process that data only to provide the service, and only on your documented instructions. Those instructions are the Terms, this DPA, and how you configure and use the service. If we believe an instruction breaks data protection law, we will tell you.
Account data about you as our customer (your sign-in email and billing details, for example) is not covered here. We act as controller for that data, as described in our Privacy Policy.
2. Details of processing
- Subject matter and purpose: running an AI chat assistant on your website, generating replies, capturing leads, and delivering them to you by email, webhook, or SMS.
- Data subjects: visitors to your website who use the chat widget, and any individuals named in documents you upload.
- Categories of personal data: chat message content, the page path where a chat started, a random session identifier, and contact details visitors choose to submit (typically name, email, and phone number). It also includes any personal data contained in documents you upload.
- Special categories: none intended. Do not configure the service to collect health, biometric, or other special-category data. Visitors may still type anything into a chat, and we process what they send.
- Frequency and duration: continuous, for as long as you use the service, subject to the retention periods in section 8.
3. Confidentiality
Everyone we authorize to process your personal data is bound by confidentiality. Access to production data is limited to what is needed to run and support the service.
4. Security
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS) for all traffic, and encryption at rest by our database provider
- Tenant isolation: every read and write is scoped to your widget key and checked on each request
- Admin passwords stored as scrypt hashes, and session tokens stored only as SHA-256 hashes
- httpOnly, same-site session cookies with a 7-day expiry, and individual session revocation
- Rate limiting on public endpoints, and an audit log of administrative actions
- Automatic deletion of chat transcripts after 90 days
- Chat content is not used to train AI models
5. Subprocessors
You authorize us to use the subprocessors below. Each is bound by written data protection terms that give at least the protection this DPA requires, and we remain responsible for their performance.
- Anthropic, PBC (United States): generates assistant replies from conversation content
- Vercel Inc. (United States): application hosting and server logs
- Neon, Inc. (United States): database storing conversations, leads, and documents
- Resend (United States): delivers lead notification emails
- Twilio Inc. (United States): SMS lead alerts, only on plans and accounts where SMS is enabled
- Voyage AI (United States): turns uploaded documents and visitor questions into search embeddings
We will give you at least 30 days' notice before adding or replacing a subprocessor, by updating this page and emailing your account address. If you object on reasonable data protection grounds, tell us within that period. If we cannot resolve it, you may terminate the affected service and receive a pro-rata refund of any prepaid fees.
6. International transfers
We and our subprocessors process data in the United States. For transfers out of the EEA, the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference. You are the data exporter and we are the data importer. The optional docking clause (Clause 7) applies. Under Clause 9, the general written authorization in section 5 applies. Clause 11's optional redress language does not apply. Clauses 17 and 18 select the law and courts of Ireland. Annex I is section 2 of this DPA, and Annex II is section 4.
For transfers from the UK, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies. For transfers from Switzerland, the Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection.
7. Helping you meet your obligations
- Data subject requests. You can export a conversation or your leads as CSV, and permanently delete a conversation together with any lead captured in it, from your portal. If a visitor contacts us directly, we will forward the request to you and will not act on it without your instruction, unless the law requires us to.
- Breaches. We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data. We will include what we know at that point and send updates as we learn more.
- Impact assessments. We will give you reasonable information you need for a data protection impact assessment or prior consultation with a supervisory authority.
8. Deletion and return
- Chat transcripts are deleted automatically 90 days after a conversation starts.
- Leads are kept until you delete the conversation they came from or close your account.
- When your account is closed, its conversations, messages, leads, documents, and SMS records are deleted immediately. Residual copies in our database provider's point-in-time recovery history expire within that provider's recovery window, currently 6 hours. Export anything you need before closing.
9. Audits
On request, we will provide the information reasonably needed to show compliance with this DPA, including written answers to a reasonable security questionnaire once a year. You agree that these answers, together with this DPA, satisfy your audit rights under this DPA and the Standard Contractual Clauses. This does not limit an audit that a supervisory authority carries out itself.
10. Liability and term
Each party's liability under this DPA is subject to the limits in the Terms, except where the Standard Contractual Clauses or applicable law do not allow it. This DPA lasts as long as we process personal data for you.
Contact
Questions about this DPA, or a request for a countersigned copy: support@summitbots.io.