sumchatLegal

Sumchat Data Processing Addendum

Effective date: September 27, 2026 · Version 1.0

This Data Processing Addendum ("DPA") is part of the Terms of Service between Kaitlian LLC ("Sumchat") and Customer, and applies automatically to every workspace ; no signature required. It governs Sumchat's processing of Customer Personal Data: personal information contained in Customer Content, including personal information that Customer's published sites collect from their visitors and end users.

1. Roles and scope

1.1 For Customer Personal Data, Customer is the business/controller (or, where Customer acts for its own client, a processor acting on that client's behalf) and Sumchat is Customer's service provider/processor. Where U.S. state privacy laws with controller/processor terminology apply, those terms have the meanings given there; under the California Consumer Privacy Act as amended ("CCPA"), Sumchat is a "service provider."

1.2 This DPA does not apply to personal information Sumchat processes as a business in its own right; Customer's account, billing, and support records; which is described in the Privacy Policy.

1.3 The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects are described in Annex I.

2. Sumchat's processing commitments

Sumchat will:

3. Assistance

3.1 Rights requests. Customer can access content through the Services and request export, correction, or deletion through privacy@sumchat.ai. If a consumer request under applicable privacy law reaches Sumchat directly and identifies Customer's workspace or site, Sumchat will forward it to Customer without undue delay and will not respond substantively except to direct the requester to Customer. Sumchat will provide reasonable further assistance Customer needs to honor verified requests.

3.2 Assessments. Taking into account the nature of processing, Sumchat will provide reasonable assistance with data protection assessments and regulator consultations applicable law requires of Customer, with respect to processing performed by the Services.

4. Security incidents

Sumchat will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data, with the information reasonably available to Sumchat (nature of the incident, categories and approximate volumes affected, measures taken, and a contact), supplementing as investigation proceeds. Customer is responsible for its own legal notification obligations to individuals and regulators (for California residents, currently notification within 30 days of discovery); Sumchat will provide the cooperation Customer reasonably needs to meet them, including the 30-day and attorney-general timelines. Sumchat's notice is not an admission of fault.

5. Subprocessors

5.1 Authorization. Customer generally authorizes Sumchat to engage subprocessors to provide the Services. The current list; with each subprocessor's role; is published at /legal/subprocessors.

5.2 Notice and objection. Sumchat will update the list at least 14 days before a new subprocessor processes Customer Personal Data (the page states the mechanism for change notice). If Customer reasonably objects on data-protection grounds within that window, the parties will discuss in good faith; if Sumchat cannot reasonably accommodate the objection, Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unexpired period.

5.3 Flow-down. Sumchat imposes on each subprocessor, by written contract, data-protection obligations materially equivalent to this DPA's, and remains responsible to Customer for its subprocessors' performance.

6. Audits, deletion, and remedies

6.1 Audit. Sumchat will make available information reasonably necessary to demonstrate compliance with this DPA; documentation of the Annex II measures and, when Sumchat obtains third-party security audit reports or certifications, summaries of them; and will allow and cooperate with reasonable assessments by Customer or its designated assessor. The parties agree that Sumchat may first satisfy an assessment request with current documentation and reports; an on-site or interactive audit occurs at most once per 12 months, on 30 days' notice, at Customer's expense, under confidentiality, scoped to Customer Personal Data, and must not compromise other customers' data or Sumchat's security.

6.2 Deletion and return. Customer can export Customer Content at any time and for 30 days after termination (Terms § 13.4). On deletion of a workspace (or on Customer's written request), Sumchat deletes Customer Personal Data from live systems and lets backups age out on standard cycles, except where law requires retention.

6.3 Remediation. Upon notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data by Sumchat, and Sumchat will cooperate.

7. International provisions (conditional)

7.1 The parties do not intend the GDPR, UK GDPR, or Swiss FADP to apply to the Services, which are offered from the United States to U.S. customers. To the extent they nonetheless apply to Customer's processing (for example, because Customer's published site targets people in the EU):

7.2 In case of conflict between the SCCs and this DPA, the SCCs control where they apply.

8. General

This DPA is subject to the Terms' limitation of liability (which applies in aggregate across the Terms and this DPA), governing law, and dispute-resolution provisions. If a privacy law applicable to Customer requires additional processor terms, the parties will negotiate them in good faith; until then this DPA is construed to satisfy the strictest applicable requirement it can. Sumchat may update this DPA per the Terms' change process, provided updates do not degrade the protections here.


Annex I; Description of processing

Annex II; Technical and organizational measures

Annex III; Subprocessors

The current subprocessor list is maintained at /legal/subprocessors and is incorporated here.