convchat

Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Appik Studio, Switzerland (“ConvChat”, the processor) and the customer (the controller) for the use of the ConvChat service. It applies automatically to every customer — no signature required — and implements Art. 28 GDPR and the Swiss nFADP. Customers who need a countersigned copy can request one at contact@appik-studio.com.

1. Scope & roles

This DPA applies to all personal data that ConvChat processes on behalf of the customer in the course of providing the service — chiefly the personal data of the customer’s website visitors (“end users”). For this data the customer is the controller and ConvChat is the processor. It does not apply to data for which ConvChat is itself the controller (customer account and billing data), which is covered by the Privacy Policy.

2. Subject matter, duration & purpose

Subject matter: operation of a live-chat widget, shared inbox, AI assistant and email continuation on the customer’s websites. Duration: the term of the customer’s subscription, plus the deletion period in section 11. Nature & purpose: storing, displaying, routing and answering customer-support conversations, including AI-generated answer suggestions from the customer’s FAQ content and continuation of conversations by email.

3. Data subjects & personal data

Categories of data subjects: visitors and end users of the customer’s websites; the customer’s own agents and staff.

Categories of personal data: identification data the end user provides (name, email address); conversation content (messages, attachments where supported); technical and usage context supplied by the host page (page URL, browser locale, custom visitor attributes set by the customer); and coarse IP-derived location (country and city only — the raw IP address is not stored). The service is not designed for special categories of data; the customer agrees not to direct such data into it.

4. Instructions

ConvChat processes end-user data only on the customer’s documented instructions, which consist of this DPA, the customer’s configuration of the service, and any further written instructions agreed between the parties. ConvChat will inform the customer if, in its view, an instruction infringes applicable data protection law.

5. Confidentiality

Persons authorised by ConvChat to process end-user data are bound by contractual confidentiality obligations and process the data only as needed to provide and support the service.

6. Security measures

ConvChat implements appropriate technical and organisational measures under Art. 32 GDPR, including encryption in transit (TLS), encryption at rest by its infrastructure providers, strict workspace-level isolation of customer data, least-privilege access for staff, and storage of only coarse location data instead of IP addresses. The current measures are described on the Security page, which is incorporated into this DPA by reference and may be updated, provided the level of protection is not reduced.

7. Subprocessors

The customer grants ConvChat a general authorisation to engage subprocessors. The current list, with purposes and locations, is published in the Privacy Policy. ConvChat will give the customer at least 30 days’ notice before adding or replacing a subprocessor; the customer may object on reasonable data protection grounds, in which case the parties will seek a solution and, failing one, the customer may terminate the affected service with a pro-rata refund. ConvChat imposes data protection obligations on each subprocessor equivalent to those in this DPA and remains liable for their performance.

8. International transfers

Some subprocessors process data outside Switzerland and the EU/EEA (see the subprocessor list). For such transfers, ConvChat relies on the EU Standard Contractual Clauses (Module 3, processor to processor, adapted for Swiss law as required by the FDPIC) and, where the recipient is certified, on the Swiss–U.S. Data Privacy Framework. Transfer documentation is available on request.

9. Assistance & breach notification

Taking into account the nature of the processing, ConvChat assists the customer with data subject requests (access, correction, deletion, portability) and, where needed, with data protection impact assessments and consultations with supervisory authorities. ConvChat notifies the customer without undue delay, and at the latest within 72 hours of becoming aware, of any personal data breach affecting end-user data, with the information the customer needs to meet its own notification duties.

10. Audits

ConvChat makes available the information reasonably necessary to demonstrate compliance with this DPA — primarily through its published security documentation and answers to written audit questionnaires, which is the proportionate route for a service of this size. Where an audit on site is legally required, the customer may conduct one (directly or through an independent auditor bound to confidentiality) at most once per year, during business hours, with at least 30 days’ notice, at its own cost and without access to other customers’ data.

11. Deletion & return of data

During the term, the customer can delete end-user data through the product. Upon termination of the subscription, ConvChat will, at the customer’s choice, return the end-user data in a common machine-readable format and/or delete it. Absent a request, all end-user data is deleted within 30 days of termination, except where law requires longer storage. Deletion extends to subprocessors.

12. Final provisions

In case of conflict between this DPA and the Terms of Service, this DPA prevails for data protection matters. Liability is governed by the Terms of Service to the extent permitted by data protection law. This DPA is governed by Swiss law; the place of jurisdiction is Lausanne, Switzerland.