Legal
Data Processing Addendum
Last updated: 3 August 2026
This is our standard DPA. To execute it, email [email protected] and we will countersign. This page is provided for review and does not constitute legal advice.
1. Definitions
"Controller" means the customer: the organisation that holds the OpenAgent subscription and determines the purposes and means of processing. "Processor" means OpenAgent, operated by Kiebot from Bengaluru, India, which processes personal data on the Controller's behalf. "Applicable data protection law" means the EU General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act), in each case to the extent applicable to the processing. Terms such as "personal data", "data subject" and "processing" carry the meanings given in that law.
2. Subject matter and duration
This Addendum governs the Processor's processing of visitor chat data and related records on the Controller's behalf in the course of providing the OpenAgent service. It applies for the term of the Controller's subscription and until the deletion obligations in section 9 are discharged.
3. Nature and purpose of processing
The Processor processes personal data to deliver the service the Controller signed up for: running live chat between the Controller's website visitors and operators, generating AI responses via the LLM provider the Controller has configured, maintaining CRM records of contacts and conversations, and producing analytics over the Controller's own conversation data.
4. Data subjects and categories of data
Categories of data subjects: the Controller's website visitors, and the Controller's own operators (agents and admins with dashboard accounts).
Categories of personal data: name, email address, phone number where the Controller collects it, chat transcripts and file attachments, page-visit metadata (URLs visited during a chat session, timestamps, user-agent), and country derived from IP address.
5. Processor obligations
The Processor shall:
- process personal data only on the Controller's documented instructions, which include the subscription agreement, this Addendum and the configuration the Controller sets in the dashboard;
- ensure that persons authorised to process the data are bound by confidentiality obligations;
- maintain technical and organisational security measures, including encryption in transit (TLS) and at rest, tenant isolation so that each workspace's data is segregated, redaction of personally identifiable information from message content before it is sent to the LLM provider, and audit logging of administrative actions;
- assist the Controller, taking into account the nature of the processing, in meeting its own obligations under applicable data protection law.
6. Subprocessors
The Controller grants general authorisation for the following subprocessors, engaged as at the date above:
- Hosting infrastructure: a cloud VPS provider hosting the application, database and object storage.
- Cloudflare: CDN and TLS termination in front of the service.
- ZeptoMail (Zoho): transactional email (account notifications, alerts).
The LLM provider that generates AI responses (Google Gemini, OpenAI, Anthropic, OpenRouter, or a self-hosted model endpoint the Controller runs, such as Ollama) is engaged only when the Controller configures its own API key or endpoint. The Controller selects that provider and contracts with it directly; it acts on the Controller's instructions rather than as a subprocessor appointed by the Processor. The Processor never routes data to an LLM the Controller has not explicitly enabled.
The Processor will give the Controller at least 30 days' notice by email before adding or replacing a subprocessor, during which the Controller may object on reasonable data-protection grounds.
7. Data subject rights
The Processor assists the Controller in responding to data subject requests. Export and erasure of conversation and contact data are available in-product from the dashboard, so most access and deletion requests can be fulfilled by the Controller directly. For anything not covered in-product, the Processor will assist on request to [email protected] within 30 days.
8. Breach notification
The Processor will notify the Controller of a personal data breach affecting the Controller's data without undue delay, and in any case within 72 hours of becoming aware of it. The notification will describe the nature of the breach, the data and data subjects affected as far as known, and the measures taken or proposed.
9. Deletion or return on termination
On termination of the subscription, the Controller has 30 days to export its data from the dashboard. After that window the Processor permanently deletes the Controller's personal data, including from backups on their rolling 30-day cycle, except where retention is required by law.
10. Audits
The Processor makes available summary security reports (SOC-style descriptions of controls) sufficient to demonstrate compliance with this Addendum. Where those reports are not sufficient, the Controller may request an audit, including an on-site audit, by arrangement: reasonable notice, at most once per year absent a specific incident, and at the Controller's cost.
11. International transfers
Operational data is hosted in the region agreed at signup. Business-tier customers can opt for dedicated single-tenant infrastructure in a region of their choice. The Processor will not transfer personal data outside the agreed region except as needed to provide the service (for example, calls to the LLM provider the Controller has configured) or as required by law. See the Privacy Policy for current hosting details.