Sumchat Data Processing Addendum
Effective date: September 27, 2026 · Version 1.0
This Data Processing Addendum ("DPA") is part of the Terms of Service between Kaitlian LLC ("Sumchat") and Customer, and applies automatically to every workspace ; no signature required. It governs Sumchat's processing of Customer Personal Data: personal information contained in Customer Content, including personal information that Customer's published sites collect from their visitors and end users.
1. Roles and scope
1.1 For Customer Personal Data, Customer is the business/controller (or, where Customer acts for its own client, a processor acting on that client's behalf) and Sumchat is Customer's service provider/processor. Where U.S. state privacy laws with controller/processor terminology apply, those terms have the meanings given there; under the California Consumer Privacy Act as amended ("CCPA"), Sumchat is a "service provider."
1.2 This DPA does not apply to personal information Sumchat processes as a business in its own right; Customer's account, billing, and support records; which is described in the Privacy Policy.
1.3 The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects are described in Annex I.
2. Sumchat's processing commitments
Sumchat will:
- (a) Process only on instructions. Process Customer Personal Data only on Customer's documented instructions; these Terms, the DPA, Customer's and its members' use and configuration of the Services, and Agent direction and approvals given in the workspace; and for no other purpose, unless required by law (in which case Sumchat will inform Customer unless legally prohibited).
- (b) Never sell or share. Not sell Customer Personal Data, not share it for cross-context behavioral advertising, and not retain, use, or disclose it for any purpose, including any commercial purpose; other than providing the Services under the Terms, or as the CCPA expressly permits (for example, security, debugging, and legal compliance).
- (c) No use outside the relationship. Not retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties, and not combine it with personal information received from other sources, except as permitted by CCPA regulations to perform a business purpose.
- (d) No training. Not use Customer Personal Data to train or improve machine-learning models, and contractually prohibit its AI subprocessors from doing so.
- (e) Confidentiality. Ensure persons it authorizes to process Customer Personal Data are bound by confidentiality obligations.
- (f) Security. Implement and maintain the technical and organizational measures in Annex II.
- (g) Compliance and notice. Comply with obligations applicable to service providers/processors under applicable privacy laws and provide the level of privacy protection those laws require; notify Customer promptly if it determines it can no longer meet its obligations under applicable privacy law or this DPA, in which case Customer may take the steps in Section 6.3.
- (h) Certification. Sumchat certifies that it understands and will comply with the restrictions in this Section 2.
3. Assistance
3.1 Rights requests. Customer can access content through the Services and request export, correction, or deletion through privacy@sumchat.ai. If a consumer request under applicable privacy law reaches Sumchat directly and identifies Customer's workspace or site, Sumchat will forward it to Customer without undue delay and will not respond substantively except to direct the requester to Customer. Sumchat will provide reasonable further assistance Customer needs to honor verified requests.
3.2 Assessments. Taking into account the nature of processing, Sumchat will provide reasonable assistance with data protection assessments and regulator consultations applicable law requires of Customer, with respect to processing performed by the Services.
4. Security incidents
Sumchat will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data, with the information reasonably available to Sumchat (nature of the incident, categories and approximate volumes affected, measures taken, and a contact), supplementing as investigation proceeds. Customer is responsible for its own legal notification obligations to individuals and regulators (for California residents, currently notification within 30 days of discovery); Sumchat will provide the cooperation Customer reasonably needs to meet them, including the 30-day and attorney-general timelines. Sumchat's notice is not an admission of fault.
5. Subprocessors
5.1 Authorization. Customer generally authorizes Sumchat to engage subprocessors to provide the Services. The current list; with each subprocessor's role; is published at /legal/subprocessors.
5.2 Notice and objection. Sumchat will update the list at least 14 days before a new subprocessor processes Customer Personal Data (the page states the mechanism for change notice). If Customer reasonably objects on data-protection grounds within that window, the parties will discuss in good faith; if Sumchat cannot reasonably accommodate the objection, Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unexpired period.
5.3 Flow-down. Sumchat imposes on each subprocessor, by written contract, data-protection obligations materially equivalent to this DPA's, and remains responsible to Customer for its subprocessors' performance.
6. Audits, deletion, and remedies
6.1 Audit. Sumchat will make available information reasonably necessary to demonstrate compliance with this DPA; documentation of the Annex II measures and, when Sumchat obtains third-party security audit reports or certifications, summaries of them; and will allow and cooperate with reasonable assessments by Customer or its designated assessor. The parties agree that Sumchat may first satisfy an assessment request with current documentation and reports; an on-site or interactive audit occurs at most once per 12 months, on 30 days' notice, at Customer's expense, under confidentiality, scoped to Customer Personal Data, and must not compromise other customers' data or Sumchat's security.
6.2 Deletion and return. Customer can export Customer Content at any time and for 30 days after termination (Terms § 13.4). On deletion of a workspace (or on Customer's written request), Sumchat deletes Customer Personal Data from live systems and lets backups age out on standard cycles, except where law requires retention.
6.3 Remediation. Upon notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data by Sumchat, and Sumchat will cooperate.
7. International provisions (conditional)
7.1 The parties do not intend the GDPR, UK GDPR, or Swiss FADP to apply to the Services, which are offered from the United States to U.S. customers. To the extent they nonetheless apply to Customer's processing (for example, because Customer's published site targets people in the EU):
- this DPA constitutes the processor terms Article 28 GDPR requires, with Sumchat as processor and Customer as controller;
- the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (or Module Three where Customer is a processor), are incorporated by reference for transfers from the EEA, completed as follows: Clause 7 (docking) included; Clause 9 option 2 (general authorization, 14 days); Clause 11 optional language excluded; Clause 17 option 1 with Irish law; Clause 18 Irish courts; Annexes I–III of the SCCs are completed by Annexes I–III of this DPA; and for the UK, the ICO's International Data Transfer Addendum (with the tables completed by the same Annexes) and for Switzerland the recognized Swiss adaptations apply;
- Sumchat will notify Customer if it receives a legally binding request from a public authority for Customer Personal Data unless prohibited, and will challenge overbroad requests where reasonably possible.
7.2 In case of conflict between the SCCs and this DPA, the SCCs control where they apply.
8. General
This DPA is subject to the Terms' limitation of liability (which applies in aggregate across the Terms and this DPA), governing law, and dispute-resolution provisions. If a privacy law applicable to Customer requires additional processor terms, the parties will negotiate them in good faith; until then this DPA is construed to satisfy the strictest applicable requirement it can. Sumchat may update this DPA per the Terms' change process, provided updates do not degrade the protections here.
Annex I; Description of processing
- Subject matter and duration: provision of the Sumchat Services to Customer's workspace, for the service term plus the export and deletion windows in Terms § 13.4.
- Nature and purpose: hosting, storage, computation, AI-assisted generation and editing at Customer's direction, communications transmission (messaging/voice/social) at Customer's direction, publishing and serving Customer's sites, and support; as described in the Terms.
- Categories of data subjects: Customer's members and personnel; Customer's clients and business contacts; correspondents of Customer's Agents; callers to Customer's voice line; visitors, account holders, and form submitters on Customer's published sites.
- Categories of personal data: identifiers and contact details; workspace content and communications (including messages, attachments and call transcripts); site end-user account data (email addresses, session records) and content those users submit (forms, orders, posts); usage and device metadata connected to the foregoing. Special categories are not sought by the Services; whether they appear in Customer Content is under Customer's control and subject to AUP § 6.
- Sensitive data restrictions: per AUP § 6 (no biometric identifiers, health records, or SSNs through published sites without prior written approval).
- Frequency: continuous, as directed by Customer's use.
Annex II; Technical and organizational measures
- Authorization and isolation. Authenticated identity determines access to personal and workspace records. Workspace roles and brand assignments constrain operations on shared storage; private files and personal Google connections require their owner's authority.
- Encryption. TLS protects data in transit; hosting providers supply encryption at rest for databases and object storage.
- Credential custody. Google tokens remain in a dedicated server-side credential service. Agent tools receive operation results, not the underlying tokens. Application secrets are server-side and are excluded from logs and application source.
- Access control. Web access uses verified phone identity and revocable browser sessions. Sensitive operator endpoints require separate authorization. Publishing and purchasing follow the Services' authenticated approval flows.
- Application isolation. Hosted customer applications run in sandboxed workers. The platform establishes the authorized principal and application scope before serving protected resources.
- Availability and recovery. Managed database and object storage, retained file and production versions, and provider recovery facilities support operational recovery. Customer Content remains subject to the export and deletion commitments in the Terms.
- Monitoring and response. Operational logs and recovery checks support incident detection; security and abuse contacts accept reports. Section 4 governs incident notices.
- Data minimization. No advertising trackers on platform surfaces. Content is sent to service providers as needed for requested work, under the no-training commitments in this DPA. Access, correction, export and deletion requests are available through the Privacy Policy contact.
- Personnel. Access to production systems is limited to authorized personnel bound by confidentiality, on a need-to-access basis.
Annex III; Subprocessors
The current subprocessor list is maintained at /legal/subprocessors and is incorporated here.