WebIntel AI

Effective [EFFECTIVE DATE]

Data Processing Agreement

1. Definitions

“Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach” have the meanings given in applicable data-protection law (including the GDPR where it applies). “Customer Personal Data” means personal data WebIntel processes on the Customer’s behalf under the Terms.

2. Roles & scope

The Customer is the Controller of Customer Personal Data (principally the messages and details of the Customer’s website visitors). WebIntel is the Processor and processes such data only to provide the service. Details of the processing are set out in Annex I.

3. Processing on documented instructions

WebIntel processes Customer Personal Data only on the Customer’s documented instructions (including as configured in the dashboard and as set out in the Terms), unless required by law, in which case WebIntel will inform the Customer unless legally prohibited. WebIntel does not sell Customer Personal Data and does not use it to train third-party foundation models.

4. Confidentiality

WebIntel ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it only on a need-to-know basis.

5. Security measures

WebIntel implements appropriate technical and organisational measures as described in Annex II, including encryption in transit, per-tenant data isolation enforced in the storage layer, redaction of detected personal data before storage, access controls, and rate limiting.

6. Sub-processors

The Customer authorises WebIntel to engage the sub-processors listed in the Privacy Policy to process Customer Personal Data. WebIntel imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance. WebIntel will give the Customer reasonable prior notice of any new sub-processor [via email / dashboard], and the Customer may object on reasonable data-protection grounds.

7. Assistance & data-subject requests

Taking into account the nature of the processing, WebIntel will assist the Customer, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Customer’s obligations to respond to Data Subject requests and to carry out data-protection impact assessments and prior consultations. If WebIntel receives a request directly from a Data Subject, it will refer them to the Customer.

8. Personal Data Breach notification

WebIntel will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its own notification obligations.

9. International transfers

Where WebIntel transfers Customer Personal Data across borders, it does so under an appropriate transfer mechanism (such as the EU Standard Contractual Clauses), which are incorporated by reference where applicable.

10. Return & deletion

On termination of the service, or on the Customer’s request, WebIntel will delete Customer Personal Data within a reasonable period, unless retention is required by law. Records carry an automatic expiry consistent with the retention configured for the Customer.

11. Audits

WebIntel will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality and security conditions and frequency limits.

12. Annexes

Annex I — Details of processing

Subject matterProvision of the WebIntel AI chat assistant to the Customer.
DurationFor the term of the Terms, plus the deletion period.
Nature & purposeStoring website content; retrieving relevant passages; generating grounded answers; capturing leads the visitor volunteers; producing aggregate analytics.
Types of personal dataVisitor messages (with detected PII redacted before storage); volunteered contact details (name, email, phone) with consent; coarse/truncated IP, user-agent, origin, locale, timestamps.
Categories of data subjectsThe Customer’s website visitors and end users.
Special categoriesNot intended; the Customer must not configure the service to collect special-category data.

Annex II — Technical & organisational measures

[Signatures / execution block, if you require a signed DPA. Many SaaS providers make this DPA self-executing by reference from the Terms.]