OyeChats
FeaturesSolutionsIntegrationsPricingDocsBlogContact us

Data Processing Addendum

The OyeChats Data Processing Addendum governing how we process personal data on behalf of our customers.

Last updated · v1.0

Introduction and Applicability

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Digibranders Private Limited, trading as OyeChats ("OyeChats," "we," "us"), and the customer that has entered into the Agreement ("Customer," "you"). It applies whenever OyeChats processes Personal Data on your behalf in the course of providing the Services.

This DPA is designed to satisfy the requirements that apply to a data processor under the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") and, where your processing is subject to it, the EU General Data Protection Regulation 2016/679 and the UK GDPR (together, "GDPR").

Where this DPA conflicts with the rest of the Agreement, this DPA prevails in respect of the processing of Personal Data. This DPA takes effect when you accept the Agreement and continues for as long as OyeChats processes Personal Data on your behalf.

Roles of the Parties

For Personal Data processed under this DPA, you are the Controller (Data Fiduciary under the DPDP Act) and OyeChats is your Processor (Data Processor). You determine the purposes and means of the processing.

You are responsible for the lawfulness of the instructions you give us, for giving Data Subjects the notice their law requires, and for obtaining any consent required before the widget collects their data. This matters particularly under the DPDP Act, which does not provide a legitimate-interest basis to fall back on.

Separately, OyeChats acts as an independent Controller for the account data of its own customers (such as your login credentials, billing records, and support correspondence). That processing is described in our Privacy Policy and is not governed by this DPA.

Scope and Purpose of Processing

OyeChats processes Personal Data for the following purposes and no others:

  • Operating the chat widget and generating AI responses to Visitor messages.
  • Storing chat transcripts, lead capture submissions, and Visitor metadata.
  • Deriving geography and network signals from a Visitor's IP address, and verifying the deliverability of email addresses submitted through lead-capture forms.
  • Routing conversations to your operators for live chat and delivering the notifications you configure.
  • Producing analytics and lead qualification scores.
  • Securing, supporting, and troubleshooting the Services.

The categories of Data Subjects, categories of Personal Data, and duration of processing are set out in Annex I below.

Processing on Documented Instructions

OyeChats processes Personal Data only on your documented instructions. The Agreement, this DPA, the configuration choices you make in the dashboard, and your use of the Services are your instructions to us.

If we consider an instruction to infringe applicable data protection law, we will inform you without undue delay, and may suspend performance of that instruction until it is confirmed or withdrawn.

If applicable law requires us to process Personal Data other than on your instructions, we will inform you of that requirement before processing, unless the law prohibits us from doing so. We will not disclose Personal Data to a public authority except where legally compelled, and where permitted we will notify you and disclose only the minimum required.

Confidentiality of Personnel

OyeChats ensures that every person authorized to process Personal Data under this DPA is bound by a written obligation of confidentiality that survives the end of their engagement, has been informed of the confidential nature of the data, and receives access only on a least-privilege basis for as long as they need it.

Security Measures

OyeChats implements and maintains appropriate technical and organizational measures designed to protect Personal Data. They are set out in Annex II below.

We may update those measures over time, provided we do not materially reduce the level of protection they provide.

Sub-processors

You provide a general authorization for OyeChats to engage Sub-processors to deliver the Services. Each Sub-processor is engaged under a written contract imposing data protection obligations at least as protective as those in this DPA, and OyeChats remains responsible to you for its Sub-processors' performance.

The Sub-processors we currently engage are:

  • DigitalOcean: Application server and managed database hosting. (India)
  • Cloudflare: Object storage for uploaded knowledge base files, and CDN delivery of the embeddable widget. (Global edge network)
  • Vercel: Hosting for the marketing site and the customer dashboard front-end. (United States)
  • OpenAI: Large language model inference. (United States)
  • Google: Large language model inference (fallback) and all text embedding generation. (United States)
  • Spider.cloud: Web crawling and content extraction for knowledge base ingestion. (United States)
  • Jina AI: Web content extraction for knowledge base ingestion. (Germany / European Union)
  • ipapi.is: IP geolocation and network intelligence lookups. (European Union)
  • Reoon: Email address deliverability verification. (Singapore)
  • Brevo: Transactional email delivery. (European Union)
  • Expo: Mobile push notification delivery to operators. (United States)
  • Razorpay: Payment processing. (India)
  • Sentry: Application error monitoring. (United States)
  • Langfuse: LLM observability. (European Union)

We will give you at least 30 days' advance notice before adding or replacing a Sub-processor that processes Personal Data. If you have a reasonable data protection objection to a new Sub-processor, tell us within that notice period and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected Services without penalty and receive a pro-rata refund of pre-paid fees for the unused remainder of the Subscription Term.

Data Subject Requests

The Services give you the ability to access, correct, export, and delete Personal Data about your Visitors, so that you can respond to a Data Subject request yourself.

Where a request cannot be fulfilled through the Services, OyeChats will provide reasonable assistance, at your cost where the assistance is substantial, to help you respond within your statutory deadline.

If a Data Subject contacts OyeChats directly about Personal Data we process on your behalf, we will not respond to the substance of the request. We will refer them to you and inform you promptly.

Assistance with Your Compliance Obligations

Taking into account the nature of the processing and the information available to us, OyeChats will provide reasonable assistance with:

  • Your obligation to keep processing secure.
  • Your obligations to notify Personal Data Breaches to supervisory authorities and to Data Subjects.
  • Your data protection impact assessments, and any prior consultation with a supervisory authority arising from one.

Personal Data Breach Notification

OyeChats will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf.

The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Where we cannot provide all of that at once, we will provide it in phases without further undue delay.

We will reasonably cooperate with your own notification obligations to supervisory authorities, to the Data Protection Board of India, and to affected Data Subjects. Our notification is not an admission of fault or liability.

Data Retention and Deletion

During the term of the Agreement, Personal Data is retained according to the retention settings available in the dashboard and the schedule described in the Privacy Policy. Note that your plan tier governs how far back conversation history remains accessible to you; it is not an automatic deletion schedule.

On termination or expiry of the Agreement, you may request an export of Personal Data within 30 days. After that window, OyeChats will delete or irreversibly anonymize all Personal Data processed on your behalf within a further 30 days, except where retention is required by applicable law, in which case we will retain only what the law requires and continue to protect it under this DPA.

You may request deletion of Personal Data at any point during the term by writing to support@oyechats.com. Deletion is currently carried out by our team on request rather than through a self-service control in the dashboard, and is completed within 30 days.

International Data Transfers

Where Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA by reference and apply to that transfer, with Module Two (controller to processor) applying between you and OyeChats and Module Three (processor to processor) applying where you are yourself a processor.

For the purposes of the Clauses: the data exporter is you, the data importer is OyeChats, Clause 7 (docking) applies, Clause 9 option 2 (general written authorization for Sub-processors) applies with the 30-day notice period set out above, Clause 11 does not include the optional independent dispute resolution body, Clause 17 selects the law of Ireland, and Clause 18(b) selects the courts of Ireland. Annex I and Annex II of the Clauses are populated by Annex I and Annex II of this DPA, and the Sub-processor list above serves as Annex III.

Where Personal Data is subject to the UK GDPR, the UK International Data Transfer Addendum to the Clauses applies, with the information in Part 1 taken from this DPA and Annexes and neither party permitted to end the Addendum under Section 19.

Where Personal Data is subject to the Swiss FADP, the Clauses apply with references to the GDPR read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner as the competent authority.

Audit Rights

OyeChats will make available to you the information reasonably necessary to demonstrate compliance with this DPA. In the first instance, we satisfy audit requests through written responses to security and privacy questionnaires and copies of relevant policy documentation.

Where that is not sufficient to demonstrate compliance, and where you are required to conduct an audit or inspection by applicable data protection law or by your supervisory authority, OyeChats will allow for and contribute to an audit of the processing, conducted by you or by an independent auditor you appoint who is not our competitor. Such an audit is subject to at least 30 days' written notice, reasonable confidentiality undertakings, scoping that avoids disruption to the Services or access to other customers' data, and no more than once in any 12-month period unless a Personal Data Breach or a regulator's direction requires otherwise. You bear the cost of the audit and of our reasonable assistance.

Liability

Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Where the Standard Contractual Clauses apply, nothing in this section limits any liability the Clauses impose towards a Data Subject.

Annex I: Details of Processing

Subject matter and nature of the processing: provision of an AI chat and live-chat service embedded on the Customer's websites, including storage, retrieval, AI inference, enrichment, analytics, notification, and support.

Duration: for the term of the Agreement, plus the post-termination export and deletion windows described above.

Categories of Data Subjects:

  • Visitors to websites where the Customer has deployed the widget.
  • The Customer's Authorized Users and operators.

Categories of Personal Data:

  • Identifiers and contact details submitted by a Visitor: name, email address, phone number, company.
  • Conversation content: messages exchanged with a Bot or an operator, timestamps, and ratings.
  • Technical and network data: IP address, browser and device type, derived city, region and country, derived network and organization signals, page URL, referrer, and campaign parameters.
  • Email verification results for addresses submitted through lead-capture forms.
  • Derived qualification signals and conversation summaries generated from the above.
  • Operator account data: name, email, role, activity logs, and push notification tokens.

Sensitive Personal Data: the Services are not designed for, and the Customer must not configure a Bot to solicit, special categories of data under Article 9 GDPR, government identifiers, or payment card details. Any such data a Visitor volunteers unprompted in free text is processed as ordinary conversation content, and the Customer remains responsible for it.

Frequency of transfer: continuous, on an ongoing basis for the duration of the Agreement.

Annex II: Technical and Organizational Measures

Encryption. TLS 1.3 for all API, widget, and dashboard traffic. Encryption at rest for primary databases and object storage. Encrypted database backups, rotated on a 30-day cycle.

Access control. Role-based access control on the platform and on production systems, least-privilege provisioning, multi-factor authentication for production access, and separate credentials for each persona (customer, operator, widget, administrator).

Tenant isolation. Every query is scoped to the owning account, and each Bot's knowledge base and conversations are logically isolated from every other tenant's.

Data minimization at boundaries. Visitor IP addresses are stripped from every API response, dashboard view, CSV export, and third-party observability trace, at a single enforced point in the code.

Logging and monitoring. Audit logging of administrative and operator actions, immutable transition logs for live-chat handovers, application error monitoring, and health monitoring of the platform.

Environment separation. Production and non-production workloads run in separate environments with separate credentials and separate observability projects.

Resilience. Automated encrypted backups, rate limiting, and graceful degradation when a plan limit or an upstream provider limit is reached.

Incident response. A documented incident response process, with the breach notification commitments set out above.

Personnel. Confidentiality obligations for all personnel with access to Personal Data, and least-privilege access granted for the duration of need.

Sub-processor governance. Written data protection terms with every Sub-processor, and the notice and objection process set out above.

Contact

Questions about this DPA can be sent to support@oyechats.com, or to our Grievance Officer and Data Protection Contact, Siddique Ahmed, at Digibranders Private Limited, Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India.