§1Parties and scope
This agreement is between the customer using Chatvoxo (the controller) and FORCESCRIPTS LTD (the processor), and forms part of the Terms of use. It takes effect when the customer starts using the service and lasts until the account is closed and the data is deleted.
It is made under Article 28 of UK GDPR and, for data of people in the EEA, Article 28 of the EU GDPR.
§2Details of the processing
Subject and purpose: running the chat window on the customer’s website, delivering chats to the customer’s team, generating AI replies when the customer chooses, sending notification emails to visitors and the team, and storing chats.
Duration: while the customer’s account is open, and for the retention period the customer chooses.
Types of data: messages, files sent, the name, email, phone and other form fields the customer defines that a visitor fills in, and chat ratings and comments; for visitors who start a chat, IP address, country, browser, system and device details, screen size, language and time zone, referring address and campaign tags, landing page, pages viewed while the chat is open, number of visits, and whether they are still on the site.
Data subjects: visitors to the customer’s website and agents in the customer’s team.
Processing of special category data is not intended; the customer agrees not to ask for it in the chat window.
§3Our obligations
We process the data only on the customer’s documented instructions. Those instructions are the Terms of use, this agreement, and the settings the customer makes in the dashboard. If we believe an instruction breaks data protection law, we tell the customer straight away.
Our staff and contractors with access to the data are bound by confidentiality and only access what their work needs.
We take technical and organisational measures under Article 32 of the GDPR: HTTPS encryption in transit, encryption of messages, files and visitor details in the database, one-way hashing of passwords, role-based access and security logging.
We help the customer answer visitors’ requests to exercise their rights, such as access and erasure. Requests that reach us directly are passed to the customer without delay.
We give the customer reasonable help with its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation).
When we become aware of a personal data breach, we notify the customer without undue delay and within 48 hours at most, with the details known at that time.
When the account is closed we delete the customer’s data within 30 days; before closing, the customer can ask for a copy. Data the law requires us to keep is excepted.
We give the customer the information needed to show we comply with this agreement, and allow an audit by the customer or an independent auditor once a year on reasonable notice.
§4Sub-processors
The customer gives general written authorisation for us to use the sub-processors below. We have a written contract with each one that gives the same level of protection as this agreement, and we remain responsible to the customer for their processing.
OpenAI, L.L.C. (United States): generating AI replies with Chatvoxo AI. Only when the customer uses Chatvoxo AI.
Resend, Inc. (United States): sending chat notification emails.
Cloudflare, Inc. (United States; storage in the European Union): storing chat files, encrypted on our side.
Our hosting and infrastructure provider (Turkey): servers and database.
We announce any new or replacement sub-processor on this page and by email at least 14 days in advance. The customer may object on reasonable grounds within that period; if we cannot agree, the customer may close the account and any unused balance is refunded.
If the customer connects its own API key on the Pro plan, the customer chooses that provider and has its own contract with it. That provider is not our sub-processor.
§5International transfers
Data is stored on servers in Turkey and some sub-processors are in the United States. We transfer data outside the UK or the EEA only with a valid transfer mechanism: an adequacy decision, or the EU Standard Contractual Clauses (Modules 2 and 3) together with the UK International Data Transfer Addendum. Where needed, these clauses are incorporated into this agreement by reference.
§6The customer’s obligations
The customer gives its visitors a privacy notice, has a valid legal basis for the processing, tells visitors that chat data may be sent to AI, and makes sure the instructions it gives us comply with the law. Choosing the retention period in the site settings is the customer’s decision.
§7Contact
Correspondence about this agreement: [email protected].
Write to [email protected].