Data Processing Addendum
Effective 17 September 2026
In short
When your website runs AI Chat for Website, information about your visitors passes through our systems. This addendum is the contract for that: you are the controller, we are the processor, and we act only on your instructions.
It lists what we process, how it is protected, which sub-processors we use and where, how we help you with your visitors' requests, and what happens to the data when you leave.
This summary is here to help you read the document. The numbered sections below are the document.
1. What this is
This Data Processing Addendum ("DPA") forms part of the Terms of Service or, where one is signed, another written agreement for the Service (either, the "Agreement") between Devsmooth Ltd. ("Devsmooth") and the Customer. It applies whenever Customer Data includes personal data whose controller is the Customer ("Customer Personal Data"). If this DPA conflicts with the Agreement on the handling of personal data, this DPA prevails. Accepting the Terms accepts this DPA; no signature is needed.
2. Roles
The Customer is the controller of Customer Personal Data (or, where the Customer is an agency running the Service for its own client's website, a processor acting on that client's behalf), and Devsmooth is the Customer's processor. Under United States state privacy laws, Devsmooth is the Customer's "service provider": it does not sell or share Customer Personal Data, and does not retain, use or disclose it for any purpose other than providing the Service. Each party complies with the data protection laws that apply to it, including PIPEDA, British Columbia's PIPA and, where applicable, the EU and UK GDPR. Devsmooth is the controller, not a processor, of the account information of the Customer's own portal users, as the Privacy Policy describes. The details of the processing are in Annex 1.
3. Instructions
Devsmooth processes Customer Personal Data only on the Customer's documented instructions, which are: the Agreement, this DPA, and the Customer's use of the Service's controls (installing the widget, switching visit recording on or off, listing addresses to ignore, placing blocks, inviting team members, deleting a website, and so on). Devsmooth will inform the Customer if it considers an instruction unlawful, unless the law forbids telling.
One behaviour is not the Customer's to change: when a visitor's browser sends the Global Privacy Control signal, the Service records no visit for that visitor, whatever the Customer's setting.
4. Confidentiality and personnel
Access to Customer Personal Data is limited to people who need it to operate, secure and support the Service, and everyone with access is bound by confidentiality obligations.
5. Security
Devsmooth implements and maintains the technical and organisational measures in Annex 2, and may improve them over time, but not in a way that lowers the overall protection.
6. Sub-processors
The Customer gives general authorisation for the sub-processors in Annex 3. Devsmooth will publish changes to the list on this page at least 30 days before a new sub-processor processes Customer Personal Data, and will tell the account's owners by email or in the portal. If the Customer reasonably objects on data protection grounds and no accommodation can be found, the Customer may terminate the affected services and receive a refund of any fees prepaid for the period after termination. Devsmooth remains responsible for its sub-processors' performance and binds each of them to data protection obligations that offer at least the protection of this DPA, through their data processing terms.
7. Assistance with data subject requests
The Customer can see its visitors' conversations, visits, leads and people in the portal, and can find a visitor there by the email address or phone number they gave. The portal does not yet offer deletion of a single conversation, lead or person, or an export. Until it does, Devsmooth will carry out an access, correction, deletion or export request for the Customer, on the written request of an owner of the account, without charge and within 10 business days. Taking into account the nature of the processing, Devsmooth will also assist the Customer with objections and restrictions, with security and breach obligations, and with data protection impact assessments, as far as the information is available to Devsmooth.
A visitor who has given no contact details is known to the Service only by a random identifier held in their own browser; neither party can normally tie such records to a named person, and nothing in this DPA requires either party to collect more information in order to do so. If a data subject contacts Devsmooth directly about a Customer's website, Devsmooth will refer them to the Customer and tell the Customer, and will not answer the request itself unless the Customer asks it to.
8. Personal data breach
Devsmooth will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, by email to the account's owners, with the information the Customer needs for its own notification duties: what happened, what data and approximately how many data subjects are affected, what is being done, and a contact point. Where not everything is known at once, Devsmooth will provide it in phases. Devsmooth will not characterise the incident on the Customer's behalf.
9. Deletion and return
During the term, the Service deletes conversations 12 months after their last message and visits 6 months after their last activity, automatically. The Customer can delete a website from its account, which deletes that website's visits, conversations, leads, people, blocks and crawled text, and can ask Devsmooth for other deletions under section 7. After the Agreement ends, Devsmooth will on request provide an export of Customer Data for 30 days, then delete it from live systems. Devsmooth takes a copy of the database before each software update and keeps it on the production server. Such copies are not restored except to recover the Service, and are deleted within 35 days. Records Devsmooth must keep by law are retained only for that purpose and duration.
10. Audits
Devsmooth will make available the information reasonably necessary to demonstrate compliance with this DPA, starting with written answers and documentation. Devsmooth holds no third-party security certification or audit report at present and does not claim one. Where a law or authority requires more, the Customer (or an independent auditor that is not a competitor) may audit, at its own cost, at most once a year, on 30 days' notice, during business hours, without disrupting the Service, and under confidentiality.
11. International transfers
Customer Personal Data is processed in the locations listed in Annex 3: at present the United States and Canada. Canada benefits from a European Commission adequacy decision for organisations subject to PIPEDA. For Customer Personal Data subject to the EU or UK GDPR that is transferred to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (module 2, controller to processor; module 3 where the Customer is itself a processor), and the UK Addendum for UK data, with the annexes of this DPA supplying the required information, Devsmooth as data importer and the Customer as data exporter.
12. Liability and law
Liability under this DPA is subject to the limitations in the Agreement. This DPA is governed by the same law and jurisdiction as the Agreement, except where the Standard Contractual Clauses require otherwise.
Annex 1: details of processing
| Item | Description |
|---|---|
| Subject matter and nature | Hosting and operating a website chat: serving the widget, recording visits where the Customer has that switched on, generating AI answers from the Customer's public website, relaying conversations to the Customer's team, capturing contact details as leads and emailing them to the Customer, and keeping the records of the above. |
| Duration | The term of the Agreement, plus the export and deletion windows in section 9. |
| Purpose | Providing the Service to the Customer; no other purpose. In particular, not advertising and not the training of AI models. |
| Data subjects | Visitors to the Customer's websites; people who chat there; people whose contact details are given in a chat. |
| Categories of personal data: visits (only with visit recording on) | IP address and the country derived from it; user agent, device type, browser and operating system; language, time zone and screen size; addresses and titles of pages viewed (without query strings) and the times; referrer (without query string); UTM campaign tags; visit start, last activity and visible time; a hashed random browser identifier. |
| Categories of personal data: conversations | The visitor's messages; the assistant's answers, their sources and any withheld answer; the team's replies; helpful or not helpful marks; the page the chat started on; country; the hashed browser identifier; questions the assistant could not answer. |
| Categories of personal data: leads and people | Name, email address and phone number as given by the visitor; a note; status; first and last seen times. |
| Categories of personal data: abuse controls | Blocked IP addresses and blocked browser identifiers (hashed), with their expiry; the addresses the Customer asked to ignore. |
| Special categories | None intended. The Service is not designed for them, and the Customer agrees not to direct them to it. A visitor may type anything into a chat; the Customer should say in its notice that the chat is not the place for sensitive information. |
| Frequency of transfer | Continuous, while the widget is installed. |
Annex 2: technical and organisational measures
- TLS encryption for all traffic to the Service: the portal, the widget's interface and the live conversation streams. The connection between the application server and the AI model is HTTPS inside an encrypted private tunnel.
- The AI model and the embedding model run on hardware owned and operated by Devsmooth. No conversation content is sent to a third-party AI provider.
- Tenant isolation: every portal query is scoped to the signed-in user's account, and another account's identifiers answer "not found". Role-based access within an account (owner and agent).
- The widget's interface uses no cookies and no ambient credentials, accepts requests only from the origins of the website it was set up for, and gives a visitor access only to the conversations started with their own identifier.
- Passwords stored as salted argon2id hashes; session tokens, invitation tokens, emailed codes and visitor identifiers stored only as hashes; session cookies are HttpOnly, Secure and SameSite; a custom-header check protects the portal against cross-site request forgery.
- Data minimisation by design: page and referrer addresses stored without query strings; visitor IP addresses shown to the Customer only in a single visit's detail; a chat-only mode that records nothing until a chat starts; Global Privacy Control honoured; automatic deletion of conversations (12 months) and visits (6 months); the text of sent email erased after 30 days.
- Guards on the assistant: it has no tool that reads data, its prompt holds only the Customer's public website content and notes, a topic gate and an output check run on each turn, and rate limits apply per address and per visitor.
- The crawler reads public pages only, obeys
robots.txt, identifies itself, and refuses private, loopback, link-local and cloud metadata addresses. - Outbound email is sent through Devsmooth's own mail server over an encrypted, authenticated connection, and is DKIM-signed.
- Production access restricted to named administrators over key-based SSH. The database is not reachable from the internet.
Annex 3: sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| OVH US LLC (OVHcloud) | The virtual server that runs the application and its database: all Customer Personal Data | United States |
| Oracle Corporation (Oracle Cloud Infrastructure) | The virtual server that runs Devsmooth's own mail system. It relays the email the Service sends: lead and missed-chat notifications to the Customer (which contain the visitor's contact details and the conversation), and codes, invitations and notices to portal users | United Kingdom (London) |
The AI model runs on hardware owned and operated by Devsmooth itself, in Canada. That is Devsmooth's own processing, not a sub-processor.
Cloudflare, Inc. hosts the DNS records of our domain, as DNS only. Requests to the Service do not pass through Cloudflare, and it receives no Customer Personal Data.
There is no payment processor: paid plans are paid by invoice and the Service collects no card details. One will be added to this list, with the notice period in section 6, before self-serve card billing starts.