Agent AI Chat
Terms of ServicePrivacy PolicyData Processing AddendumDocumentation

Data Processing Addendum

Last updated: 12 August 2026

Draft — pending legal review. This DPA has not yet been reviewed by a lawyer. If you need a signed DPA for your own compliance (e.g. GDPR Art. 28), contact us — this page is the interim reference version until a formal, counter-signable version is available.

1. Purpose and scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Zihad Hosan, operating as Agent AI Chat ("Processor", "we"), and the Customer ("Controller"). It applies to personal data of the Customer's website visitors ("End Visitors") that we process on the Customer's behalf when they interact with the Customer's embedded chat widget.

It does not cover the Customer's own account data (email, billing information), which we process as an independent controller under the Privacy Policy.

2. Roles

The Customer is the Controller of End Visitor personal data collected through their widget. Agent AI Chat is the Processor, acting only on the Controller's instructions as set out in this DPA and the Terms of Service.

3. Subject matter and nature of processing

  • Subject matter: hosting and operating the AI chat widget embedded on the Controller's website
  • Duration: for the term of the Terms of Service, plus the retention period in Section 8
  • Nature and purpose: receiving End Visitor chat messages, generating grounded AI responses using the Controller's configured content, and storing the resulting session/message records so the Controller can review conversations
  • Categories of data subjects: End Visitors who interact with the widget
  • Categories of personal data: chat message content and any personal data an End Visitor voluntarily includes in it (e.g. a name or email address they type in), plus technical metadata (session timestamps). We do not require or prompt for special-category data; Controllers must not configure the widget to solicit it.

4. Processor obligations

We agree to:

  • Process End Visitor personal data only on the Controller's documented instructions (as reflected in the Controller's own configuration of the widget and content)
  • Ensure that access to production data is restricted to what's necessary to operate the Service
  • Assist the Controller, to the extent reasonably possible, in responding to End Visitor rights requests (access, deletion, export) relating to their chat data
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting their End Visitors' data
  • Not sell End Visitor personal data or use it for purposes unrelated to operating the Service, and not knowingly use it to train third-party models

5. Sub-processors

The Controller authorizes the following sub-processors:

  • Neon (database hosting, AWS eu-west-2 / London) — stores chat session and message records
  • Vercel (application hosting) — runs the application that receives and serves chat requests
  • OpenRouter (LLM API provider) — receives chat message content and Controller-configured content to generate the AI response text

Lemon Squeezy is not listed here as it processes Customer billing data, not End Visitor chat data. We'll notify Customers of material changes to this sub-processor list via email or in-app notice, and Customers may object on reasonable data-protection grounds by contacting hello@zihadhosan.dev.

6. International transfers

End Visitor chat data is stored in the EU (AWS eu-west-2, London). Processing by OpenRouter and Vercel may involve transfer outside the EU/UK; where it does, we rely on those sub-processors' own transfer safeguards (e.g. Standard Contractual Clauses).

7. Security measures

  • Encryption in transit (HTTPS/TLS) for all application traffic
  • Password hashing for account credentials (not applicable to End Visitor chat data, which is unauthenticated)
  • Access to the production database restricted to the operator
  • Tenant isolation: each Customer's content and chat data is scoped to their own tenant record and not accessible to other Customers

8. Data retention and deletion

End Visitor chat sessions and messages are retained while the Controller's account is active. The Controller can delete individual chat sessions, their configured content, or their entire account; account deletion erases associated End Visitor chat data from production. We do not independently retain End Visitor chat data after the Controller deletes it or their account, except where required by law.

9. Audits

On reasonable written request, and no more than once per 12 months absent a specific incident, we will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA. As a small operation, formal third-party audit certifications (e.g. SOC 2) are not yet in place.

10. Liability

Liability under this DPA is subject to the limitation of liability in the Terms of Service.

11. Contact

Data protection queries: hello@zihadhosan.dev.