This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies to any Customer who installs the DocuBot chat widget on their own website, allowing end visitors to interact with it. It describes how we process, on the Customer's behalf, the personal data of those visitors.
1. Roles: who is controller and who is processor
With respect to the personal data of the end visitors who use the widget on the Customer's site:
- The Customer is the data controller: they decide which documents are uploaded, what content is indexed, how the bot is configured, and what the resulting conversations are used for.
- DocuBot acts as the data processor: it processes that data solely to provide the Service contracted by the Customer, following their configuration.
With respect to the Customer's own account data (email, password, configuration), DocuBot is the data controller, as explained in the Privacy Policy.
2. Object and duration of processing
The object of the processing is to allow the widget to answer questions from the Customer's visitors using the Customer's uploaded documents, and to show the Customer the resulting history and analytics. The processing lasts for as long as the Customer keeps the collection active in their account.
3. Processing only under instructions
DocuBot processes visitor data solely in accordance with the Customer's documented instructions, expressed through the configuration available in the dashboard (documents uploaded, bot settings, allowed origins, usage limits). DocuBot does not use that data for any purpose of its own, such as training third-party models, advertising, or transferring it to another Customer.
If we consider that a Customer instruction infringes applicable data protection regulations, we will inform them before carrying it out.
4. Data processed and data subjects
Data subjects: visitors to the Customer's website who interact with the chat widget.
Categories of data:
- Content of the messages written by the visitor in the chat.
- Responses generated by the bot and the sources cited.
- Rating of the response (👍/👎), if the visitor uses it.
- Technical conversation session identifier.
- Any personal data the visitor voluntarily chooses to write in their message (for example, their name or email if they mention them while asking something).
DocuBot does not actively request identifying data from end visitors; such data only arises if the visitor voluntarily includes it in their message.
5. Subprocessors
The Customer authorizes DocuBot to use the following subprocessors to provide the Service:
| Subprocessor | Function | Processing location |
|---|---|---|
| OpenAI (or another compatible language model provider, configurable by DocuBot) | Generation of the chat response from the relevant content found in the Customer's documents | Outside Argentina (including the U.S.), under its own data protection commitments |
| Hosting and infrastructure provider | Hosting of the application and the database | Depending on the infrastructure provider contracted at any given time |
DocuBot will inform the Customer of any change to this list of subprocessors with reasonable advance notice, so the Customer can object for justified reasons related to data protection.
6. Security measures
DocuBot applies the technical and organizational measures described in the security section of the Privacy Policy (mandatory authentication, hashed passwords, secure session cookies, widget origin validation, upload size and count limits) to protect the data processed on the Customer's behalf.
7. Confidentiality
DocuBot personnel or collaborators with access to visitor data are subject to confidentiality obligations, and access is limited to what is necessary to operate and support the Service.
8. Assistance with data subject rights
If a visitor exercises before the Customer a right of access, rectification, erasure, or objection over data held by DocuBot, the Customer can resolve it directly from the dashboard (for example, reviewing or deleting conversations), or request our assistance by writing to hola@docubot.dev.
9. Incident notification
If we detect a security breach affecting personal data processed on the Customer's behalf, we will notify them without undue delay, with the information available about its nature, scope, and the measures taken or proposed, so the Customer can comply with their own notification obligations if applicable.
10. Return or deletion of data
Deleting a collection from the dashboard immediately and irreversibly erases all of its uploaded documents, indexed content, conversation history, and associated configuration from DocuBot's production systems, except for what must be retained in backups for a limited period as described in the Privacy Policy.
11. Audits
The Customer may reasonably request information about the security measures and subprocessors used, to verify compliance with this Agreement. Given the size of the Service, this is handled through written documentation rather than on-site audits, unless otherwise agreed between the parties.
12. Customer responsibilities
As the data controller, the Customer is responsible for:
- Having a legal basis (for example, their own privacy notice on their site) for their visitors to interact with the widget.
- Only uploading documents that they own or are authorized to use.
- Configuring the bot so that it does not prompt visitors to share unnecessary sensitive data.
- Handling requests from their own visitors in their capacity as controller toward them.
13. Term
This Agreement remains in effect while the Customer uses the Service and keeps the widget installed on their site, and terminates together with the Terms of Service.
14. Contact
Questions about this Data Processing Agreement: hola@docubot.dev.