Skip to content

Legal

Data Processing Agreement

Last updated

This agreement sets out how ZebChat processes personal data on your behalf when you use ZebChat on your websites. It applies automatically to every customer.

1. Scope and roles

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Tech Avenue Labs (“ZebChat”, “Processor”) and the customer (“Customer”, “Controller”). It applies when ZebChat processes personal data on the Customer’s behalf in providing the Service, in particular personal data of the Customer’s website visitors and of the Customer’s team members.

Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the EU General Data Protection Regulation (“GDPR”) and, where applicable, the UK GDPR.

2. Processing on instructions

ZebChat processes Customer personal data only on the Customer’s documented instructions: these Terms, this DPA, and the Customer’s configuration and use of the Service (for example which widget features, retention period, integrations and AI provider it enables). ZebChat will tell the Customer if it believes an instruction breaks data protection law.

3. Details of the processing

ItemDescription
Subject matterProviding the ZebChat live chat, visitor tracking, AI assistant and related services
DurationFor the term of the Customer’s subscription and until deletion as described below
Nature and purposeHosting, storing, transmitting and displaying chat conversations and visitor activity; routing chats; sending notifications; generating reports; sending data to integrations and AI providers the Customer enables
Data subjectsVisitors to the Customer’s websites; the Customer’s team members; people whose data appears in the Customer’s knowledge base
Types of personal dataVisitor key, IP address, user agent, approximate location, pages viewed, referrer and campaign data, custom events and tags; names, email addresses, phone numbers and customer ids provided; message content and files; ratings; team members’ names, emails and activity
Special categoriesNot intended. The Customer should not use the Service to collect special categories of data unless it has a lawful basis and appropriate safeguards

4. Confidentiality

ZebChat ensures that people authorized to process Customer personal data are bound by confidentiality. Staff access to customer accounts is limited to what is needed for support and operations, requires re-authentication for sensitive actions, is time-limited and is recorded in audit logs, including the Customer’s own audit log.

5. Security measures

ZebChat implements appropriate technical and organizational measures, including:

  • tenant isolation enforced by PostgreSQL row-level security for every customer table;
  • passwords hashed with Argon2id; tokens and API keys stored as SHA-256 hashes; provider secrets and AI keys encrypted with AES-256-GCM;
  • short-lived access tokens, rotating refresh tokens and immediate session revocation;
  • role-based access control and an append-only audit log;
  • private file storage with short-lived signed links and file-type allow-lists;
  • encryption in transit (HTTPS/TLS) for the dashboard, apps, widget and APIs;
  • SSRF protection for webhooks, AI actions and knowledge-base crawling;
  • rate limiting, optional bot protection and monitoring of errors and performance;
  • regular backups with tested restores;
  • automated tests of the tenant boundary on every change.

More detail is on our Security page. ZebChat may update these measures as long as the overall level of protection does not decrease.

6. Subprocessors

The Customer gives ZebChat general authorization to engage the subprocessors listed on the Subprocessors page. ZebChat imposes data protection obligations on each subprocessor that are no less protective than this DPA and remains responsible for their performance.

ZebChat will announce new subprocessors on that page and, for customers who ask to be notified, by email, at least 30 days before they start processing Customer personal data. The Customer may object on reasonable data protection grounds; if we cannot resolve the objection, the Customer may terminate the affected service.

AI providers (such as Anthropic, OpenAI and Voyage AI) and endpoints that the Customer connects with its own keys or URLs are chosen by the Customer and act under the Customer’s own agreements with them. They are not ZebChat subprocessors.

7. International transfers

Where Customer personal data is transferred outside the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties rely on the European Commission’s Standard Contractual Clauses (and the UK addendum where relevant), which are incorporated into this DPA by reference.

8. Data subject requests and assistance

The Service lets the Customer export and erase a visitor’s data and set retention periods. Where the Customer cannot answer a data subject request with these tools, ZebChat will provide reasonable help. ZebChat will also provide reasonable information to help the Customer with data protection impact assessments and consultations with authorities.

9. Personal data breaches

ZebChat will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, with the information the Customer reasonably needs to meet its own obligations, and will take reasonable steps to contain and remedy it.

10. Return and deletion

During the subscription the Customer controls retention through the Service’s settings. When the Customer’s organization is deleted, ZebChat deletes Customer personal data and files, except where the law requires it to keep them; backups are overwritten on their normal schedule.

11. Audits

On request, ZebChat will make available the information reasonably necessary to demonstrate compliance with this DPA. Where that is not sufficient, the Customer may carry out an audit with reasonable notice, at its own cost, no more than once a year, under confidentiality and without access to other customers’ data.

12. General

If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data. Liability under this DPA is subject to the limits in the Terms, unless the law provides otherwise. Enterprise customers can request a countersigned copy at [email protected].

Contact

ZebChat is operated by Tech Avenue Labs, Hyderabad, India. See the contact page for email addresses.