Effective [EFFECTIVE DATE]
Data Processing Agreement
1. Definitions
“Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach” have the meanings given in applicable data-protection law (including the GDPR where it applies). “Customer Personal Data” means personal data WebIntel processes on the Customer’s behalf under the Terms.
2. Roles & scope
The Customer is the Controller of Customer Personal Data (principally the messages and details of the Customer’s website visitors). WebIntel is the Processor and processes such data only to provide the service. Details of the processing are set out in Annex I.
3. Processing on documented instructions
WebIntel processes Customer Personal Data only on the Customer’s documented instructions (including as configured in the dashboard and as set out in the Terms), unless required by law, in which case WebIntel will inform the Customer unless legally prohibited. WebIntel does not sell Customer Personal Data and does not use it to train third-party foundation models.
4. Confidentiality
WebIntel ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it only on a need-to-know basis.
5. Security measures
WebIntel implements appropriate technical and organisational measures as described in Annex II, including encryption in transit, per-tenant data isolation enforced in the storage layer, redaction of detected personal data before storage, access controls, and rate limiting.
6. Sub-processors
The Customer authorises WebIntel to engage the sub-processors listed in the Privacy Policy to process Customer Personal Data. WebIntel imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance. WebIntel will give the Customer reasonable prior notice of any new sub-processor [via email / dashboard], and the Customer may object on reasonable data-protection grounds.
7. Assistance & data-subject requests
Taking into account the nature of the processing, WebIntel will assist the Customer, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Customer’s obligations to respond to Data Subject requests and to carry out data-protection impact assessments and prior consultations. If WebIntel receives a request directly from a Data Subject, it will refer them to the Customer.
8. Personal Data Breach notification
WebIntel will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its own notification obligations.
9. International transfers
Where WebIntel transfers Customer Personal Data across borders, it does so under an appropriate transfer mechanism (such as the EU Standard Contractual Clauses), which are incorporated by reference where applicable.
10. Return & deletion
On termination of the service, or on the Customer’s request, WebIntel will delete Customer Personal Data within a reasonable period, unless retention is required by law. Records carry an automatic expiry consistent with the retention configured for the Customer.
11. Audits
WebIntel will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality and security conditions and frequency limits.
12. Annexes
Annex I — Details of processing
| Subject matter | Provision of the WebIntel AI chat assistant to the Customer. |
|---|---|
| Duration | For the term of the Terms, plus the deletion period. |
| Nature & purpose | Storing website content; retrieving relevant passages; generating grounded answers; capturing leads the visitor volunteers; producing aggregate analytics. |
| Types of personal data | Visitor messages (with detected PII redacted before storage); volunteered contact details (name, email, phone) with consent; coarse/truncated IP, user-agent, origin, locale, timestamps. |
| Categories of data subjects | The Customer’s website visitors and end users. |
| Special categories | Not intended; the Customer must not configure the service to collect special-category data. |
Annex II — Technical & organisational measures
- TLS encryption for all traffic crossing the public internet.
- Per-tenant isolation enforced in the storage layer; every record scoped by tenant.
- Redaction of detected personal data before storage; message text never written to logs or traces.
- Cryptographically derived, origin-restricted widget keys; hashed account passwords.
- Prompt-injection / jailbreak detection, rate limiting, and abuse prevention.
- Access controls and confidentiality obligations for personnel.
- Automatic data expiry and deletion on request.
[Signatures / execution block, if you require a signed DPA. Many SaaS providers make this DPA self-executing by reference from the Terms.]