Data Processing Agreement

Data Processing Agreement

WeConnect.chat Poortland 66, 1046 BD Amsterdam, the Netherlands Chamber of Commerce (KvK): 70559201 Contact: privacy@weconnect.chat

Version 2.1 — effective 10 June 2026


1. Scope and incorporation

1.1 This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between WeConnect.chat (“WeConnect”, “we”, “us”) and the customer accepting those Terms (“Customer”, “you”). By accepting the Terms and Conditions you enter into this DPA. No separate signature is required.

1.2 If you require a signed counterpart — for example because your own customers, your regulator or your procurement process requires one — contact privacy@weconnect.chat and we will provide an executable version of this same document.

1.3 This DPA applies where and to the extent that we process personal data on your behalf in providing the Services. Where this DPA conflicts with the Terms and Conditions in respect of the processing of personal data, this DPA prevails.

1.4 Scope of the Services covered. This DPA covers the WeConnect.chat conversational platform: chat interfaces, knowledge bases, conversation management and the associated administration environment. Voice services are provided as a separate product, do not form part of these Services, and do not process data from the chat environment. If voice services are added to your deployment, this DPA and Annex 3 will be updated in advance in accordance with Clause 8.


2. Definitions

Terms defined in the General Data Protection Regulation (EU) 2016/679 (“GDPR”) — including personal data, processing, data subject, controller, processor, sub-processor and personal data breach — carry the meaning given to them in the GDPR.

Customer Data means all data that you or your end users enter into or have processed by the Services, including knowledge sources, conversation content, transcripts and derived representations such as vector embeddings.

Knowledge Base means the documents and question-answer pairs you supply that the Services use to ground their responses.

Sub-processor means a third party engaged by us to process Customer Data.


3. Roles of the parties

3.1 You act as controller in respect of Customer Data. We act as processor.

3.2 You are responsible for establishing a lawful basis for the processing, for informing data subjects, and for the lawfulness of the content you supply to the Services.

3.3 We act as controller in respect of your account and billing data, and in respect of our own website. That processing is described in our Privacy Policy and falls outside this DPA.


4. Subject matter, nature, purpose and duration

4.1 We process personal data solely to provide the Services to you.

4.2 The subject matter, nature and purpose of the processing, the categories of data subjects and the types of personal data are set out in Annex 1.

4.3 This DPA takes effect on your acceptance of the Terms and Conditions and remains in force for as long as we process personal data on your behalf. It terminates once processing has ended and Clause 13 has been performed.


5. Processing instructions

5.1 We process personal data only on your documented instructions. The Terms and Conditions, this DPA and your configuration of the Services together constitute those instructions.

5.2 We do not process personal data for our own purposes.

5.3 Where we are required by Union or Member State law to process personal data outside your instructions, we will inform you before processing, unless that law prohibits such notification on important grounds of public interest.

5.4 We will inform you without undue delay if, in our opinion, an instruction infringes the GDPR or other data protection law.


6. No use of Customer Data for model training

6.1 Customer Data is not used to train, fine-tune or otherwise improve any artificial intelligence model or large language model, whether developed by us or by a third party.

6.2 This prohibition applies equally to anonymised, pseudonymised and aggregated forms of Customer Data, unless you expressly agree otherwise in writing in advance.

6.3 The prohibition extends to prompts, inputs, uploads, conversation logs, transcripts and metadata.

6.4 We contract with our language model sub-processors on terms under which data submitted through their programming interfaces is not used to train or improve their models, and we keep those settings demonstrably active. We verify these settings in the provider account configuration, not only in the provider’s published policy, and we re-verify them at least annually and on any change of provider or plan.

6.5 How the Services work. The Knowledge Base is not used to adjust model weights. It is stored as a segregated knowledge source, converted into vector representations and retrieved per query to ground a response — a technique known as retrieval-augmented generation. Where our marketing materials refer to “training” a chatbot, this means configuring the Knowledge Base and expressly does not mean training a model within the meaning of this Clause.

6.6 We acknowledge that vector representations are derived from Customer Data and are not treated as anonymous. They are subject to all provisions of this DPA, including the retention periods and the deletion obligation in Clause 13.


7. Confidentiality

7.1 We ensure that persons authorised to process personal data are bound by confidentiality, whether contractually or by statutory obligation.

7.2 Access to personal data is limited to those personnel for whom access is necessary to provide the Services.


8. Sub-processors

8.1 You grant us general authorisation to engage sub-processors, on condition that we impose the obligations of this DPA on them in writing and remain fully liable to you for their performance.

8.2 The current list of sub-processors is set out in Annex 3 and is maintained at https://weconnect.chat/legal/subprocessors.

8.3 We will notify you at least 30 days before adding or replacing a sub-processor. You may object on reasonable, documented grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the Services without penalty and receive a pro rata refund of prepaid fees for the unused period.

8.4 To receive sub-processor notifications, send a request to privacy@weconnect.chat. Notifications are sent by email to the address you designate.


9. Security

9.1 We implement appropriate technical and organisational measures within the meaning of Article 32 GDPR. These are set out in Annex 2.

9.2 We will maintain at least an equivalent level of security for the duration of this DPA.


10. International transfers

10.1 Customer Data at rest in the platform — including knowledge bases, vector representations, conversation records and backups — is stored within the European Economic Area.

10.2 Certain sub-processors are established outside the EEA and process Customer Data there in the course of delivering specific functions, in particular the generation of responses by language models. Such processing is transient: the data is processed to produce a response and is not retained by us outside the EEA. Providers may retain data briefly for abuse monitoring under their own terms, as recorded in Annex 3.

10.3 Where personal data is transferred outside the EEA, the transfer takes place on the basis of the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by additional technical and organisational measures where required. Where a recipient is also certified under the EU-US Data Privacy Framework, that certification applies in addition to and not instead of the Standard Contractual Clauses.

10.4 Annex 3 states, for each sub-processor, the processing location and the transfer mechanism relied upon.

10.5 A transfer impact assessment is available on request at privacy@weconnect.chat.


11. Data subject rights

11.1 Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests under Chapter III GDPR. The Services provide functionality to search, export and delete conversation records and knowledge base content.

11.2 If we receive a request directly from a data subject, we will not act on it independently. We will forward it to you within five working days and inform the data subject that you are the controller.


12. Personal data breaches

12.1 We will notify you without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting Customer Data.

12.2 The notification will describe, so far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and the contact point for further information. Where the full picture is not available within 48 hours, we will provide the information we hold and supplement it as the investigation progresses.

12.3 We will not notify a supervisory authority or data subjects on your behalf unless legally required to do so.

12.4 Breach notifications are sent by email to the contact address in your account, and simultaneously to any additional address you designate for this purpose. Our contact point is privacy@weconnect.chat, monitored on working days between 09:00 and 17:30 CET. Notifications received outside those hours are actioned on the next working day; the 48-hour period in Clause 12.1 runs continuously and is not suspended outside working hours.


13. Assistance, audits, return and deletion

13.1 Assistance. We provide you with reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, by supplying information about the operation of the Services, the data flows involved and the measures in Annex 2.

13.2 Audits. We make available the information necessary to demonstrate compliance with Article 28 GDPR, in the first instance by way of a completed supplier questionnaire and the documentation referred to in this DPA. Where that information is demonstrably insufficient, you may commission an audit by an independent expert bound by confidentiality, at most once per year, on at least 30 days’ written notice, during business hours, and in a manner that does not disrupt our operations or compromise the confidentiality of other customers’ data. Audit costs are borne by you unless the audit reveals a material failure on our part, in which case we bear the reasonable costs and remedy the failure without delay.

13.3 Return and deletion. On termination we delete all Customer Data within 30 days, or return it in a commonly used machine-readable format if you request this within that period. Deletion expressly includes vector representations, transcripts, log files and backups. Backups are overwritten within the ordinary backup cycle, which does not exceed 35 days from termination. We confirm deletion in writing on request.

13.4 We retain data beyond these periods only where required by Union or Member State law, and only for as long as that obligation lasts. Where we do so, the data remains subject to the confidentiality and security obligations of this DPA and is not processed for any other purpose.


14. Liability

14.1 Liability under this DPA is governed by the limitation of liability set out in the Terms and Conditions.

14.2 Article 82 GDPR continues to apply in full as between the parties and data subjects.


15. General

15.1 We may amend this DPA where required by changes in law, regulation or supervisory guidance, or where we change sub-processors in accordance with Clause 8. We will publish material changes at least 30 days in advance and notify customers by email.

15.2 This DPA is governed by Dutch law. Disputes are submitted to the competent court in Amsterdam.



Annex 1 — Description of the processing

Subject matter: provision of a conversational chat service based on a Knowledge Base supplied by the Customer.

Nature of the processing: collection, recording, organisation, structuring, storage, retrieval, use, transmission, restriction and erasure.

Purpose: answering end user questions, grounding responses in the Customer’s knowledge sources, and routing conversations to the Customer’s personnel where configured.

Duration: for the term of the Terms and Conditions, plus the deletion period in Clause 13.3.

Categories of data subjects

  • End users interacting with the chat service
  • The Customer’s personnel using the administration environment
  • Any individuals referred to in content the Customer places in the Knowledge Base

Types of personal data

  • Conversation content, including anything an end user voluntarily enters
  • Transcripts of conversations
  • Contact details, where provided by the end user
  • Technical data: IP address, browser and device type, timestamps, session identifiers
  • Administrator account data: name, email address, role, authentication data
  • Personal data contained in the Knowledge Base, where present

Special categories of personal data: not intended. The Customer instructs end users not to enter special categories of personal data and configures the Services accordingly. We do not knowingly process them and do not solicit them.

Children’s data: where the Customer deploys the Services in a context involving minors, the Customer remains responsible for the lawful basis, for age-appropriate information, and for any required data protection impact assessment. We assist under Clause 13.1.

Retention periods

Category Retention
Conversation records and transcripts 12 months from the end of the conversation, unless the Customer configures a shorter period
Vector representations of the Knowledge Base for as long as the corresponding Knowledge Base is active; deleted within 30 days of removal
Technical log files 90 days
Administrator account data term of the agreement plus 90 days
Backups 35 days on a rolling basis
Billing records seven years, as required by Dutch tax law (processed by us as controller)

Customers on plans that include retention controls may configure shorter periods. Where a shorter period is configured, that period prevails over the table above.



Annex 2 — Technical and organisational measures

Access control

  • Role-based access control within the application, with permissions scoped to the customer environment
  • Multi-factor authentication required for administrative and production access
  • Production access restricted to named individuals on a least-privilege basis, granted only where necessary to operate or support the Services
  • Access rights reviewed quarterly and revoked promptly on role change or departure
  • Credentials and API keys held in a managed secrets store, never in source code

Encryption

  • In transit: TLS 1.2 or higher for all connections, with HTTP Strict Transport Security enforced
  • At rest: AES-256 encryption applied by our infrastructure providers to databases, object storage and backups
  • Backups encrypted at rest and in transit

Segregation

  • Each customer environment is logically segregated. Knowledge bases belonging to different customers, and to different brands within a single customer account, are stored under separate identifiers and every query is scoped to the requesting environment. Content cannot be retrieved across environments.
  • No shared model is trained on any customer’s data, so content cannot migrate between environments through a model.

Hosting and infrastructure

  • Application hosting, database and object storage within EEA regions; see Annex 3
  • Infrastructure providers maintain ISO 27001 and SOC 2 certified data centres with physical access control
  • Infrastructure managed as code, with changes applied through version-controlled deployments

Backup and continuity

  • Automated daily backups with 35-day rolling retention
  • Backups stored in an EEA region
  • Restore procedure tested at least annually

Logging and monitoring

  • Application and access logging retained for 90 days
  • Automated alerting on error rates, availability and anomalous authentication activity
  • Documented incident response procedure with a named responsible person

Organisational

  • Written confidentiality undertakings for all personnel and contractors with access to personal data
  • Documented personal data breach procedure aligned with Clause 12, tested against a written scenario at least annually
  • Password and device policy requiring full-disk encryption, automatic screen lock and managed password storage
  • Segregated development, test and production environments; production data is never used in development or test environments
  • Software dependencies monitored for known vulnerabilities, with security patches applied promptly
  • Sub-processor security posture reviewed before engagement and on material change

Pseudonymisation and minimisation

  • The Services collect only the data required to deliver a conversation
  • Customers are able to configure retention periods and to delete individual conversation records


Annex 3 — Sub-processors

Voice services are provided as a separate product and are out of scope for these Services. Their sub-processors are not listed here.

Sub-processor Role Personal data processed Established Processing location Transfer mechanism
Supabase Inc. Database, authentication and object storage All Customer Data, account data United States EU (Frankfurt) Standard Contractual Clauses
Vercel Inc. Application hosting and delivery Conversation content in transit, technical logs United States EU (Frankfurt) for compute; global edge network for static delivery Standard Contractual Clauses
Amazon Web Services, Inc. Underlying infrastructure and storage All Customer Data United States EU (Frankfurt) Standard Contractual Clauses; EU customers contract with AWS Europe SARL, Luxembourg
Railway Corp. Background job processing and supporting services Conversation content during processing United States EU (Amsterdam) Standard Contractual Clauses
OpenAI, L.P. Response generation Prompts and conversation content United States United States Standard Contractual Clauses
Anthropic PBC Response generation Prompts and conversation content United States United States Standard Contractual Clauses
Firecrawl (Sideguide Technologies, Inc.) Crawling customer-nominated websites to populate knowledge bases Content of crawled pages, where it contains personal data United States United States Standard Contractual Clauses

Model training. None of the above providers uses Customer Data to train or improve models. For the language model providers, this is the contractual default under their commercial terms and is additionally verified in our account configuration.

Provider-side retention. Language model providers may retain prompts and responses for a limited period for abuse and safety monitoring under their own terms — typically up to 30 days — after which the data is deleted. This retention is outside our control but within the scope of the Standard Contractual Clauses referenced above.

Last updated: 10 June 2026