Juridique

Accord de traitement des données (DPA)

Ce document est en anglais, c'est cette version qui fait foi.

Effective 1 October 2026.

1. parties and scope

This agreement is between the customer who uses Spookat (“you”, the controller) and Jakub Merta, a sole trader registered in Poland (jednoosobowa działalność gospodarcza), NIP 5833455773, REGON 522668870 (“we”, the processor). It forms part of the terms of service and covers the personal data we process for you when your website visitors use the Spookat widget.

2. what we process

3. instructions

We process the data only on your documented instructions. Your instructions are these terms, your plan and the settings you choose in the snippet, the dashboard, the API or through your agent. If we think an instruction breaks data protection law, we’ll tell you. If the law makes us process data in some other way, we’ll tell you first unless the law forbids it.

4. confidentiality and security

Everyone who can access your data is bound to keep it confidential. We apply the technical and organisational measures in Annex 2 and keep them up to date.

5. subprocessors

You give us general authorisation to use the subprocessors in Annex 3. We’ll announce a new or replaced subprocessor on this page and by email at least 30 days before it starts. If you object on reasonable data protection grounds and we can’t work it out, you can end the affected subscription and we’ll refund any prepaid period you won’t use. We bind every subprocessor to data protection terms at least as strict as these, and we stay responsible for them.

Services you connect yourself, such as your Slack workspace, your Discord server, your webhook endpoints and your AI agent, are not our subprocessors. We send data there because you tell us to, and their terms apply.

6. helping you

We help you answer requests from data subjects. The dashboard, API and MCP let you delete any conversation, the dashboard exports everything we hold for a site (the API exports the conversations), and we’ll help with anything those tools don’t cover. We also help, as far as reasonable, with security, breach notifications, impact assessments and consultations with supervisory authorities.

7. breaches

If we become aware of a personal data breach affecting your data, we’ll tell you without undue delay, and aim to do so within 48 hours. We’ll tell you what happened, what data and people are affected, and what we’re doing about it, and keep you updated as we learn more.

8. transfers

We host your data in the EU. We only transfer it outside the EEA to subprocessors listed in Annex 3, based on an adequacy decision or the European Commission’s Standard Contractual Clauses.

9. deletion

Messages are deleted automatically when your plan’s history runs out: 3 days with no plan, 30 on broke af, 90 on cool guy, 365 on vc money. When you delete a site, its keys, members, invites, channel connections, webhooks, settings and activity log are removed at once, and its conversations, messages and visitors are wiped within minutes. Only the domain and its billing record (plan, Paddle ids, dates) are kept, to record that its trial was used and to match past invoices. Backups age out within 30 days. You can export everything before you delete it.

When a trial or a subscription ends without a new plan, the site has no plan. History older than 3 days is hidden from you for 30 days, so a plan picked in that time brings it back, and then deleted; backups age out within 30 days after that. The export has all of it until then. With no plan, chats and messages from visitors are kept and shown to you, but can’t be answered until you pick a plan.

10. audits

We’ll give you the information you need to show that we meet Art. 28 GDPR. If that’s not enough, you can audit us once a year, with 30 days’ notice, during business hours, at your own cost, and under confidentiality.

11. liability and order

Liability follows the terms of service. If this agreement and the terms disagree about personal data, this agreement wins.

annex 1: processing details

See section 2.

annex 2: security measures

annex 3: subprocessors

subprocessor what for where
OVH Sp. z o.o. hosting Warsaw, Poland, EU
Cloudflare, Inc. network proxy and CDN: every request to our hosts, the widget’s included, passes through it in transit United States, global network, Standard Contractual Clauses
Backblaze, Inc. database backups; provider-side encryption at rest required EU region
Postmark (ActiveCampaign, LLC) email: reply follow-ups to visitors who left an email, notices to your team United States, Standard Contractual Clauses
OpenRouter, Inc. intent tags (cool guy and up) and live translation (vc money), both coming soon, and only for sites that turn them on. OpenRouter passes the message text to the AI model provider it routes to, which processes it only to answer that request United States, Standard Contractual Clauses

Paddle.com Market Limited sells and bills Spookat subscriptions bought on spookat.com as merchant of record. Subscriptions bought through the Shopify App Store or the Wix App Market are billed by Shopify or Wix. Each of them processes your billing details, never your visitors’ chats, so none is a subprocessor under this agreement.