Legal

Data Processing Addendum

This addendum applies when ChatDek processes personal data on your behalf, mainly the chats, contact details and bookings of visitors to your websites. It forms part of our Terms of Service.

Last updated: 5 October 2026

The short version

  • You (the customer) control your visitors' data; Advergenix processes it only on your instructions to run ChatDek.
  • We keep it confidential, secure it, and only use the sub-processors listed below.
  • We help you answer visitors' data requests and tell you without undue delay about any breach.
  • When you close your account, we delete visitor data within 90 days.

This summary is for convenience only. The full text below is what applies.

1. Parties and scope

This Data Processing Addendum ("DPA") is between you, the ChatDek customer ("Customer", the controller), and Advergenix, which operates ChatDek ("Processor"). It applies to personal data that Advergenix processes on the Customer's behalf when providing ChatDek ("Customer Personal Data"). It is part of the Terms of Service; if they conflict on data protection, this DPA prevails.

This DPA is designed to meet the processor requirements of the EU and UK General Data Protection Regulation and similar laws. Where those laws do not apply to the Customer, Advergenix will still apply the protections in this DPA.

2. Details of the processing

  • Subject matter and purpose: providing ChatDek, an AI chat widget that answers website visitors, captures leads and form answers, books appointments, enables human handoff and shows this information to the Customer.
  • Duration: for as long as the Customer uses ChatDek, plus the deletion period in section 10.
  • Data subjects: visitors to the Customer's websites who use the widget, and people whose details the Customer adds (for example manual bookings).
  • Types of personal data: chat messages and replies, names, email addresses, phone numbers, form answers, appointment details, ratings, page URLs, language, IP address, browser and device information and time stamps, and any other information visitors choose to share.
  • Special categories: not intended. The Customer must not configure ChatDek to collect special-category data (such as health data) unless it has a lawful basis and has assessed the risks.
  • Processing operations: collection, storage, retrieval, sending to the AI provider to generate replies, display in the portal, notification, export and deletion.

3. Customer instructions

Advergenix processes Customer Personal Data only on the Customer's documented instructions. The Terms of Service, this DPA and the Customer's settings and actions in the portal are the Customer's complete instructions. Advergenix will tell the Customer if it believes an instruction breaks data protection law, unless the law prevents it from doing so. The Customer is responsible for having a lawful basis for the processing and for giving visitors the required privacy information.

4. Confidentiality

Advergenix ensures that anyone it authorises to process Customer Personal Data is bound by confidentiality and only has access where needed to provide, secure or support ChatDek.

5. Security measures

Advergenix maintains appropriate technical and organisational measures, including:

  • encryption in transit (HTTPS/TLS) for the website, portal, widget and APIs;
  • encrypted off-site backups, and encrypted storage of secrets such as API keys and email server passwords;
  • hashed passwords and mandatory two-factor authentication for Advergenix staff with administrative access;
  • separation of data by customer account and website, and per-website access permissions for team members;
  • applications running with restricted operating-system permissions, rate limiting and abuse protection;
  • logging of administrative actions and regular review of access.

6. Sub-processors

The Customer gives general authorisation for Advergenix to use sub-processors. The current sub-processors are listed below. Advergenix imposes data protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance.

Current sub-processors
Sub-processorPurposeLocation
OpenAI, L.L.C.Generating AI repliesUnited States
Hostinger International Ltd.Server hosting, databases and file storageUnited Kingdom
Backblaze, Inc.Encrypted backup storageUnited States / European Union
Email delivery provider (or your own SMTP server, if you connect one)Sending booking and notification emailsVaries
Browser push services (Google, Mozilla, Apple)Delivering push notifications your team switches onVaries

Advergenix will update this list at least 14 days before adding or replacing a sub-processor. If the Customer has a reasonable data-protection objection, it may tell us within that period; if we cannot address the objection, the Customer may cancel and receive a pro-rated refund for the unused part of its current period.

7. International transfers

Customer Personal Data is hosted in the United Kingdom and may be processed by sub-processors in other countries, including the United States. Where required, transfers are protected by an adequacy decision or by the standard contractual clauses (or UK equivalent) adopted with the relevant sub-processor.

8. Helping the Customer

  • Data subject requests: the portal lets the Customer view, export and delete visitor data. If Advergenix receives a request directly from a visitor, it will pass it to the Customer and not respond itself unless instructed.
  • Advergenix will provide reasonable help with data protection impact assessments and consultations with authorities relating to ChatDek.
  • Advergenix will promptly tell the Customer about legally binding requests from authorities for Customer Personal Data, unless the law prohibits it, and will challenge requests it considers unlawful.

9. Personal data breaches

Advergenix will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include what is known about the nature of the breach, the likely consequences and the measures taken or proposed, and Advergenix will provide updates as more is learned.

10. Deletion and return

The Customer can export its data from the portal at any time. When the Customer's account is closed, Advergenix deletes Customer Personal Data within 90 days, except where the law requires it to be kept. Encrypted backups are overwritten on a rolling basis and are not restored except for disaster recovery.

11. Audits

Advergenix will make available information reasonably needed to demonstrate compliance with this DPA, such as answers to security questionnaires. Where the law requires an audit, it may be carried out once a year on reasonable notice, during business hours, by the Customer or an independent auditor bound by confidentiality, at the Customer's cost.

12. Liability and contact

Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the law does not allow them. Questions about this DPA, or requests for a signed copy, can be sent to info@chatdek.com.