OyeChats
FeaturesSolutionsIntegrationsPricingDocsBlogContact us

Data Processing Addendum

The OyeChats Data Processing Addendum governing how we process personal data on behalf of our customers.

Last updated · v1.0

Introduction and Applicability

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between OyeChats, a brand of Digibranders Pvt Ltd, India ("OyeChats," "we," "us"), and the customer that has entered into the Agreement ("Customer," "you"). It applies whenever OyeChats processes Personal Data on your behalf in the course of providing the Services.

This DPA is designed to satisfy the requirements that apply to a data processor under the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") and, where your processing is subject to it, the EU General Data Protection Regulation 2016/679 and the UK GDPR (together, "GDPR").

Roles of the Parties

For Personal Data processed under this DPA, you are the Controller (Data Fiduciary under the DPDP Act) and OyeChats is your Processor (Data Processor). You determine the purposes and means of the processing.

Separately, OyeChats acts as an independent Controller for the account data of its own customers (such as your login credentials, billing records, and support correspondence). That processing is described in our Privacy Policy and is not governed by this DPA.

Scope and Purpose of Processing

OyeChats processes Personal Data for the following purposes and no others:

  • Operating the chat widget and generating AI responses to Visitor messages.
  • Storing chat transcripts, lead capture submissions, and Visitor metadata.
  • Routing conversations to your operators for live chat and delivering the notifications you configure.
  • Producing analytics and lead qualification scores.
  • Securing, supporting, and troubleshooting the Services.

Security Measures

OyeChats implements and maintains appropriate technical and organizational measures designed to protect Personal Data, including:

  • Encryption of Personal Data in transit using TLS.
  • Encryption at rest for primary databases and object storage.
  • Logical tenant isolation.
  • Role-based access controls and least-privilege access to production systems.
  • Audit logging of administrative and operator actions.
  • A documented incident response process.

Sub-processors

You provide a general authorization for OyeChats to engage Sub-processors to deliver the Services. The Sub-processors we currently engage are:

  • DigitalOcean: Application server and managed database hosting. (India / United States)
  • Cloudflare (R2): Object storage and CDN delivery of the embeddable widget. (Global edge network)
  • OpenAI: Large language model inference and embedding generation. (United States)
  • Google (Gemini API): Large language model inference and embedding generation. (United States)
  • Brevo: Transactional email delivery. (European Union)
  • Razorpay: Payment processing. (India)
  • Sentry: Application error monitoring. (United States)
  • Langfuse: LLM observability. (European Union)

We will give you at least 30 days' advance notice before adding or replacing a Sub-processor that processes Personal Data.

Personal Data Breach Notification

OyeChats will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf.

We will reasonably cooperate with your own notification obligations to supervisory authorities and to affected Data Subjects.

Data Retention and Deletion

During the term of the Agreement, Personal Data is retained according to the retention settings available in the dashboard and the schedule described in the Privacy Policy.

On termination or expiry of the Agreement, you may export Customer Data for up to 30 days. After that export window, OyeChats will delete or irreversibly anonymize all Personal Data processed on your behalf within 30 days.

International Data Transfers

Where Personal Data subject to the GDPR is transferred to a country without an adequacy decision, OyeChats relies on appropriate safeguards, typically the European Commission's Standard Contractual Clauses.

Audit Rights

OyeChats will make available to you the information reasonably necessary to demonstrate compliance with this DPA. In the first instance, we satisfy audit requests through written responses to security and privacy questionnaires and copies of relevant policy documentation.

Contact

Questions about this DPA can be sent to support@oyechats.com.