Draft, effective [EFFECTIVE DATE].

1. parties and scope

This agreement is between the customer who uses Spookat (“you”, the controller) and [COMPANY NAME], a sole trader registered in Poland, NIP [NIP], [ADDRESS] (“we”, the processor). It forms part of the terms of service and covers the personal data we process for you when your website visitors use the Spookat widget.

2. what we process

3. instructions

We process the data only on your documented instructions. Your instructions are these terms, your plan and the settings you choose in the snippet, the dashboard, the API or through your agent. If we think an instruction breaks data protection law, we’ll tell you. If the law makes us process data in some other way, we’ll tell you first unless the law forbids it.

4. confidentiality and security

Everyone who can access your data is bound to keep it confidential. We apply the technical and organisational measures in Annex 2 and keep them up to date.

5. subprocessors

You give us general authorisation to use the subprocessors in Annex 3. We’ll announce a new or replaced subprocessor on this page and by email at least 30 days before it starts. If you object on reasonable data protection grounds and we can’t work it out, you can end the affected subscription and we’ll refund any prepaid period you won’t use. We bind every subprocessor to data protection terms at least as strict as these, and we stay responsible for them.

Services you connect yourself, such as your Slack workspace, your Discord server, your webhook endpoints and your AI agent, are not our subprocessors. We send data there because you tell us to, and their terms apply.

6. helping you

We help you answer requests from data subjects. The dashboard, API and MCP let you delete any conversation and export everything we hold for a site, and we’ll help with anything those tools don’t cover. We also help, as far as reasonable, with security, breach notifications, impact assessments and consultations with supervisory authorities.

7. breaches

If we become aware of a personal data breach affecting your data, we’ll tell you without undue delay, and aim to do so within 48 hours. We’ll tell you what happened, what data and people are affected, and what we’re doing about it, and keep you updated as we learn more.

8. transfers

We host your data in the EU. We only transfer it outside the EEA to subprocessors listed in Annex 3, based on an adequacy decision or the European Commission’s Standard Contractual Clauses.

9. deletion

Messages are deleted automatically when your plan’s history runs out: 30 days on broke af, 90 on cool guy, 365 on vc money. When a subscription ends, we delete the site’s data within 30 days, and backups age out within 30 days after that. You can export everything before then.

10. audits

We’ll give you the information you need to show that we meet Art. 28 GDPR. If that’s not enough, you can audit us once a year, with 30 days’ notice, during business hours, at your own cost, and under confidentiality.

11. liability and order

Liability follows the terms of service. If this agreement and the terms disagree about personal data, this agreement wins.

annex 1: processing details

See section 2.

annex 2: security measures

annex 3: subprocessors

subprocessor what for where
[VPS PROVIDER] hosting [REGION], EU
Cloudflare, Inc. network proxy and CDN: every request to our hosts, the widget’s included, passes through it in transit United States, global network, Standard Contractual Clauses
Backblaze, Inc. encrypted backups EU region
Postmark (ActiveCampaign, LLC) email: reply follow-ups to visitors who left an email, notices to your team United States, Standard Contractual Clauses
OpenRouter, Inc. intent tags, only if you turn them on (cool guy and up) United States, Standard Contractual Clauses

Paddle.com Market Limited sells and bills Spookat subscriptions as merchant of record. It processes your billing details, never your visitors’ chats, so it is not a subprocessor under this agreement.