Draft, effective [EFFECTIVE DATE].
1. parties and scope
This agreement is between the customer who uses Spookat (“you”, the controller) and [COMPANY NAME], a sole trader registered in Poland, NIP [NIP], [ADDRESS] (“we”, the processor). It forms part of the terms of service and covers the personal data we process for you when your website visitors use the Spookat widget.
2. what we process
- Subject matter and purpose: running the Spookat widget, inbox, API, webhooks and MCP for you: storing chat messages and delivering them between your visitors and your team.
- Duration: for as long as your subscription runs, plus the deletion periods in section 9.
- Data subjects: visitors who use the chat on your sites; your team members who reply; your own logged-in users, if you pass their ids to the widget.
- Categories of data: message content; a name or email address if the visitor types one; the site, page, browser and country at the moment a message is sent; timestamps; which teammate replied; the user id your app passes us. We derive country from the IP address and never store the IP address.
- Special categories: none intended. Don’t ask visitors for them in the chat.
3. instructions
We process the data only on your documented instructions. Your instructions are these terms, your plan and the settings you choose in the snippet, the dashboard, the API or through your agent. If we think an instruction breaks data protection law, we’ll tell you. If the law makes us process data in some other way, we’ll tell you first unless the law forbids it.
4. confidentiality and security
Everyone who can access your data is bound to keep it confidential. We apply the technical and organisational measures in Annex 2 and keep them up to date.
5. subprocessors
You give us general authorisation to use the subprocessors in Annex 3. We’ll announce a new or replaced subprocessor on this page and by email at least 30 days before it starts. If you object on reasonable data protection grounds and we can’t work it out, you can end the affected subscription and we’ll refund any prepaid period you won’t use. We bind every subprocessor to data protection terms at least as strict as these, and we stay responsible for them.
Services you connect yourself, such as your Slack workspace, your Discord server, your webhook endpoints and your AI agent, are not our subprocessors. We send data there because you tell us to, and their terms apply.
6. helping you
We help you answer requests from data subjects. The dashboard, API and MCP let you delete any conversation and export everything we hold for a site, and we’ll help with anything those tools don’t cover. We also help, as far as reasonable, with security, breach notifications, impact assessments and consultations with supervisory authorities.
7. breaches
If we become aware of a personal data breach affecting your data, we’ll tell you without undue delay, and aim to do so within 48 hours. We’ll tell you what happened, what data and people are affected, and what we’re doing about it, and keep you updated as we learn more.
8. transfers
We host your data in the EU. We only transfer it outside the EEA to subprocessors listed in Annex 3, based on an adequacy decision or the European Commission’s Standard Contractual Clauses.
9. deletion
Messages are deleted automatically when your plan’s history runs out: 30 days on broke af, 90 on cool guy, 365 on vc money. When a subscription ends, we delete the site’s data within 30 days, and backups age out within 30 days after that. You can export everything before then.
10. audits
We’ll give you the information you need to show that we meet Art. 28 GDPR. If that’s not enough, you can audit us once a year, with 30 days’ notice, during business hours, at your own cost, and under confidentiality.
11. liability and order
Liability follows the terms of service. If this agreement and the terms disagree about personal data, this agreement wins.
annex 1: processing details
See section 2.
annex 2: security measures
- TLS for all traffic to and from Spookat.
- Backups encrypted before they leave the server, kept in the EU.
- IP addresses used only in memory for delivery and rate limiting; never written to a database, log or error report.
- No cookies from the widget, and nothing loaded from our API before a visitor clicks.
- Automatic deletion when a plan’s history runs out; full wipe on cancellation.
- Production access limited to the operator, with two-factor authentication.
- Agent keys limited to replying and flagging; they can’t delete, export or touch billing.
- Webhooks signed with HMAC-SHA256 and a timestamp.
- Rate limits and spam protection on the public widget.
- Logs and error reports carry no message content and no IP addresses.
- Software kept up to date.
annex 3: subprocessors
| subprocessor | what for | where |
|---|---|---|
| [VPS PROVIDER] | hosting | [REGION], EU |
| Cloudflare, Inc. | network proxy and CDN: every request to our hosts, the widget’s included, passes through it in transit | United States, global network, Standard Contractual Clauses |
| Backblaze, Inc. | encrypted backups | EU region |
| Postmark (ActiveCampaign, LLC) | email: reply follow-ups to visitors who left an email, notices to your team | United States, Standard Contractual Clauses |
| OpenRouter, Inc. | intent tags, only if you turn them on (cool guy and up) | United States, Standard Contractual Clauses |
Paddle.com Market Limited sells and bills Spookat subscriptions as merchant of record. It processes your billing details, never your visitors’ chats, so it is not a subprocessor under this agreement.