Overview
This Data Processing Addendum ("DPA") applies when TellSpotAI processes personal information as a processor or service provider on behalf of a Customer under the TellSpotAI Terms of Service or another written agreement. This DPA is intended to support compliance with applicable data-protection laws, including, where applicable, Saudi Arabia's Personal Data Protection Law, the GDPR, UK GDPR, Swiss data-protection law, U.S. state privacy laws, and similar laws.
1. Definitions and Roles
Customer Personal Data means personal information processed by TellSpotAI on behalf of the Customer in connection with the service.
For Customer-uploaded Knowledge Base content, visitor conversations, Customer Contact Methods, Spot configuration, and related Customer Personal Data, the Customer generally acts as controller or business and TellSpotAI generally acts as processor or service provider.
For account registration, billing administration, platform security, fraud and abuse prevention, service analytics, internal account administration, support, legal compliance, Platform Analytics, and TellSpotAI's own business operations, TellSpotAI may act as an independent controller as described in the Privacy Policy.
2. Processing Details
Processing may include hosting, storing, transmitting, retrieving, indexing, classifying, generating, displaying, securing, supporting, aggregating, pseudonymizing, de-identifying, deleting, anonymizing, and otherwise processing Customer Personal Data as needed to provide TellSpotAI.
Customer Personal Data may include account data, Customer Content, Customer Contact Methods, Spot configuration, visitor messages, AI responses, limited samples or summaries, contact-request classifications, response outcomes, usage events, timestamps, language metadata, technical logs, and related analytics metadata.
Subject Matter
Provision of TellSpotAI services, including AI-powered Spots, public chat, QR-linked pages, Knowledge Base processing, contact-method display, support, security, analytics, and account operations.
Duration
For the term of the Customer's use of TellSpotAI and any additional period required or permitted for deletion processes, backups, security, legal compliance, audit, disputes, or legitimate operational needs.
Nature and Purpose
Hosting, storage, retrieval, classification, AI response generation, display, transmission, support, security monitoring, abuse prevention, Customer analytics, billing support where enabled, service improvement, and documented Customer instructions.
Categories of Data Subjects
Customer administrators and users, End Users, visitors, support contacts, billing contacts, reporters of abuse, and individuals whose information is included in Customer Content.
Categories of Personal Data
Account data, contact details, Customer Contact Methods, visitor messages, AI responses, technical logs, usage events, support communications, billing metadata where enabled, and Knowledge Base content that may contain personal information.
Sensitive Data
Not intended unless expressly authorized by written agreement, supported by a lawful basis, required notices or consents, and appropriate safeguards.
3. Processing Instructions
TellSpotAI will process Customer Personal Data to provide the service, follow documented Customer instructions, comply with the agreement, maintain security and service integrity, prevent fraud and abuse, provide support, comply with law, and perform other processing permitted under applicable data-protection law.
The Customer instructs TellSpotAI to use the infrastructure and independent providers reasonably selected by TellSpotAI to provide, secure, support, scale, and improve the service, subject to this DPA.
The Customer is responsible for ensuring that its instructions and use of the service are lawful.
4. Platform Analytics and Independent Controller Processing
Customer authorizes TellSpotAI to derive classifications, limited metadata, statistical measures, fingerprints, pseudonymized records, aggregated information, and de-identified information from service data to the extent reasonably necessary to operate, secure, measure, support, and improve the service.
Where TellSpotAI uses personal information for platform security, fraud and abuse prevention, billing administration, legal compliance, internal account and service-health administration, or Platform Analytics for its own lawful purposes, TellSpotAI acts as an independent controller and processes that information under the Privacy Policy and applicable law.
Cross-customer Platform Analytics must not disclose raw Customer Content, raw Knowledge Base content, identifiable visitor chat content, or Customer-specific confidential information to another Customer.
TellSpotAI may retain and use aggregated or de-identified information that does not reasonably identify an individual or Customer for lawful operational and business purposes. Pseudonymized information remains subject to applicable data-protection obligations.
5. Customer Responsibilities
- Provide required privacy notices and obtain required consents or legal bases.
- Ensure Customer Content and Customer Contact Methods are lawful, accurate, authorized, and appropriate.
- Avoid submitting unnecessary personal information or sensitive personal information.
- Respond to End User and data-subject requests where the Customer acts as controller.
- Configure account access, roles, retention settings, and Spot settings appropriately.
- Use TellSpotAI only for permitted purposes and not for prohibited, regulated, or high-risk uses unless covered by written terms.
6. Confidentiality and Personnel
TellSpotAI will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access controls.
7. Security Measures
TellSpotAI will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, misuse, alteration, disclosure, and destruction. Measures may include encryption in transit, access controls, role-based permissions, authentication safeguards, audit logs, security monitoring, rate limiting, abuse prevention, backup controls, secure secret management, provider review, and vulnerability management.
8. Independent Providers and Subprocessors
The Customer authorizes TellSpotAI to engage independent providers and subprocessors to provide, secure, support, monitor, scale, and improve the service.
TellSpotAI will require providers that process Customer Personal Data on its behalf to process that data only for assigned services and under appropriate contractual, confidentiality, security, and data-protection obligations.
Provider categories are described on the Subprocessors page. TellSpotAI may add, replace, or remove providers as reasonably necessary. Where applicable law or a separate written agreement requires notice of a material change, TellSpotAI will provide notice through a reasonable method.
9. International Transfers
The Customer authorizes TellSpotAI and its independent providers to process Customer Personal Data in countries where they operate, subject to applicable law.
TellSpotAI will limit international transfers to data reasonably necessary for the applicable processing purpose and, where required, use appropriate safeguards, which may include data processing agreements, contractual protections, standard contractual clauses, transfer assessments, adequacy mechanisms, certifications, or other lawful transfer methods.
10. Data Subject Requests
If TellSpotAI receives a request from an individual relating to Customer Personal Data for which the Customer is controller, TellSpotAI may direct the individual to the Customer or respond according to the Customer's lawful instructions, unless legally required to act otherwise.
TellSpotAI will provide reasonable assistance required by applicable law and the agreement, taking into account the nature of processing and information available to TellSpotAI.
11. Personal Data Breach
TellSpotAI will notify the Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data, as required by applicable law. The notice may include available information regarding the nature of the incident, affected data, likely consequences, and measures taken or proposed.
12. Deletion and Return
Upon account deletion, termination, or valid written request, TellSpotAI will delete, anonymize, return, or restrict Customer Personal Data in accordance with the Terms, Privacy Policy, Customer settings, backup cycles, legal requirements, security needs, audit requirements, dispute resolution, and legitimate operational needs.
Information may remain in backups for a limited period and will not be restored except for disaster recovery, legal, security, or service-integrity purposes.
Limited raw analytical signals are generally retained for up to ninety days, and Customer-facing aggregated daily analytics may generally be retained for up to thirteen months, unless longer retention is reasonably necessary or permitted.
TellSpotAI may retain aggregated or de-identified information that no longer reasonably identifies an individual or Customer. Pseudonymized account-level or Spot-level analytical records remain subject to applicable deletion and restriction controls.
13. Audits and Compliance Information
TellSpotAI will make available reasonable information necessary to demonstrate compliance with this DPA, subject to confidentiality, security, privilege, provider obligations, and operational limitations.
Any audit must be lawful, reasonable, narrowly scoped, non-disruptive, avoid access to other customers' data, and be subject to prior written coordination. The parties may agree to rely on certifications, independent reports, questionnaires, or other proportionate evidence before an onsite audit.
14. Liability and Order of Precedence
The liability provisions in the Terms of Service or another written agreement apply to this DPA. If there is a conflict between this DPA and the Terms regarding processing of Customer Personal Data, this DPA controls for that processing matter.
15. Contact
- Privacy and data-processing requests: [email protected]
- General and legal contact: [email protected]
- Billing-related data questions: [email protected]
