chatleadr Docs

Data Processing Terms

Effective date: 1 September 2026

These Data Processing Terms form part of the Terms of Service and apply whenever we process personal information on a Customer's behalf. Section 21 of POPIA requires that this be in writing before processing starts, so these terms apply automatically to every account and do not need to be separately signed.

If a term is defined in the Terms of Service it carries the same meaning here. Where these terms conflict with the Terms of Service, these terms govern the subject matter they cover.

1. Definitions#

Customer Personal Data means personal information relating to a Visitor that we process on the Customer's behalf through the service, as described in Annex A.

Data Protection Law means POPIA, and GDPR to the extent it applies to the Customer's use of the service.

Operator and responsible party carry their POPIA meanings. Processor and controller carry their GDPR meanings. This document uses the POPIA terms; read them as the GDPR equivalents where GDPR applies.

Visitor, Agency and Client carry the meanings given in section 2 of the Privacy Policy.

2. Roles of the Parties#

For Customer Personal Data, the Customer is the responsible party and we are the operator. The Customer decides what its bot asks, what it records and why. We process it only to provide the service and only on the Customer's documented instructions, which consist of these terms, the Terms of Service, and the configuration the Customer sets in the Dashboard.

For account information we are the responsible party in our own right, not a joint one with the Customer. This covers the Customer's own contact details, billing records and usage counts, and it is governed by the Privacy Policy rather than by these terms.

We will tell the Customer if an instruction appears to us to breach Data Protection Law. We are not obliged to give legal advice and the Customer is not entitled to rely on our silence as approval.

3. Our Obligations#

We will:

  1. process Customer Personal Data only on the Customer's documented instructions, and for no purpose of our own;
  2. not sell Customer Personal Data, and not use it to train models. Conversation content is sent to our model provider to generate a reply, under terms instructing that provider not to train on it;
  3. not use one Customer's data to improve the service for another Customer;
  4. keep it confidential, and bind everyone with access to the same duty;
  5. maintain the security measures in clause 5;
  6. assist the Customer as set out in clause 7;
  7. delete or return it as set out in clause 9.

4. When a Customer Runs Bots for Its Own Clients#

This clause governs the arrangement an Agency operates under. It applies to any Customer who uses the service on behalf of another business, whether or not that Customer is on a plan named for it, and whether or not the bot carries our name.

The chain of responsibility. Where an Agency runs a bot for a Client, the Client is ordinarily the responsible party for the Visitor information that bot collects. The Agency is that Client's operator. We are the Agency's sub-operator, which under GDPR makes us a sub-processor appointed by a processor.

The Agency warrants that, for each Client whose bot it configures:

  1. it has the Client's authority to use the service for that Client's data;
  2. it has a written agreement with that Client which permits it to appoint us, and which imposes on the Agency obligations no less protective than these terms;
  3. the instructions it gives us are consistent with the instructions the Client has given it, and it will not instruct us to do anything the Client has not authorised;
  4. it has given the Client the information about us that the Client needs in order to meet its own notice obligations, including the sub-processor list.

We deal with the Agency, not the Client. The Agency is our sole point of contact and remains liable to us for its Clients' use of the service under the Terms of Service. We have no contract with the Client. If a Client contacts us directly with a request about their data, we will refer them to the Agency and tell the Agency we have done so.

A Client's data subject request reaches us through the Agency. The Agency is responsible for responding to its Clients within whatever time its own agreement with them requires, and clause 7 sets out what we will do to help.

White labelling changes what people see and nothing else. Where an Agency presents the service under its own name, whether to a Visitor on a website or to a Client signed in to the dashboard, the processing described in Annex A is unchanged, and so is everything in this document.

On termination, we act on the Agency's instruction, not the Client's, subject to clause 9. An Agency whose relationship with a Client ends should export or delete that Client's data before it closes the workspace.

We do not contract directly with a Client. A Client has no account with us and no agreement with us. Where a Client requires a direct agreement with the operator processing its data, the Agency should hold that data outside Chatleadr or the Client should become a Customer in its own right.

5. Security#

We will maintain appropriate technical and organisational measures, including:

  • encryption of traffic in transit;
  • encryption at rest of uploaded documents under a key held per workspace, so that one Customer's files cannot be decrypted with another Customer's key;
  • delegated authentication, so that we do not hold Customer passwords;
  • separation of each workspace's data at the query level;
  • retention windows enforced in software, as set out in section 6 of the Privacy Policy.

Access, backups and logging. Access to production systems is limited to named administrators, of whom there is currently one. The database is backed up and a backup is overwritten within 35 days. Actions that change or remove data in a workspace are written to that workspace's activity log, which the Customer can read, and which records identifiers rather than the content of what was changed.

This clause states the measures in place today rather than a target. We will update it when the measures change, and a change that reduces them is a change to these terms under clause 19 of the Terms of Service.

6. Sub-Processors#

The Customer authorises us to appoint the sub-processors listed on the sub-processors page, and any replacement or addition notified under this clause.

We remain liable to the Customer for the acts and omissions of our sub-processors as if they were our own.

We will impose on each sub-processor data protection obligations no less protective than these terms.

We will give 30 days' notice before a new sub-processor begins processing Customer Personal Data, by updating the sub-processors page and emailing every Customer who has asked to be told. The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may terminate the affected part of the service and we will refund any amount paid for a period after termination.

An Agency's Clients are not sub-processors of ours, and an integration a Customer switches on is not one either. Clause 4 and the sub-processor page explain both.

7. Assistance#

Data subject requests. Where a Visitor exercises a right against the Customer, we will provide the Customer with the means to find, export and delete that Visitor's information through the Dashboard. Where the Dashboard cannot do it, we will assist on request, taking into account the nature of the processing.

Breach notification. We will notify the Customer without undue delay after becoming aware of a security compromise affecting Customer Personal Data, and provide the information the Customer reasonably needs to meet its own notification obligations under section 22 of POPIA or Article 33 of GDPR. Notifying the Customer is not an admission of fault.

Assessments. We will provide the Customer with the information it reasonably requires to carry out a data protection impact assessment.

8. Cross-Border Transfers#

Customer Personal Data is processed outside South Africa, and outside the European Economic Area, by the sub-processors identified on the sub-processors page.

Each recipient is bound by terms giving Customer Personal Data protection substantially similar to POPIA, including a restriction on passing it on again, which is the basis relied on under section 72(1)(a) of POPIA. Where the recipient sits outside the European Economic Area, those terms incorporate the European Commission's Standard Contractual Clauses, which is the basis relied on under Article 46 of GDPR.

We will not appoint a sub-processor that will not agree to those terms. Section 9 of the Privacy Policy states the same position.

9. Return and Deletion#

The Customer can perform every deletion in this clause itself, from the Dashboard. Section 7 of the Privacy Policy sets out exactly what each one removes, what it redacts and what it keeps.

On the Customer's written request at any time, we will delete Customer Personal Data within 30 days.

On termination, where the Customer does not ask, we will delete it within 90 days of the account closing. Backups follow their own cycle and are overwritten within 35 days.

Export first. The service exports leads as CSV and conversations through the Dashboard. We do not undertake to return Customer Personal Data in any other format, and after deletion there is nothing left to return: deleting a workspace destroys the key its uploaded files are encrypted under, which makes any remaining copy of one permanently unreadable.

Three things survive a deletion, and Data Protection Law permits each. Suppression records, because deleting the record of an opt-out would cause the contact it exists to prevent. Billing and usage totals, which are financial records carrying no contact details. Conversation transcripts belonging to an erased contact are redacted rather than deleted, leaving the number of turns and their timing, so that an invoice already issued still reconciles.

Where the law requires us to retain anything else, we will isolate it and stop processing it for any other purpose.

10. Audit#

We will make available the information reasonably necessary to demonstrate compliance with these terms.

Where a Customer requires an audit beyond that, it may be carried out once in any twelve month period, on reasonable notice, at the Customer's cost, subject to confidentiality, and limited to information relating to that Customer.

Details of the Processing (Annex A)#

Subject matter: provision of the Chatleadr conversational chatbot service.

Duration: for as long as the account is open, plus the retention and deletion periods in clause 9.

Nature and purpose: hosting and displaying a chatbot, generating replies to Visitor messages, running the workflows a Customer has configured, capturing leads, storing uploaded files, and reporting on all of it.

Categories of data subject: Visitors who interact with a Customer's bot, and where an Agency is involved, Visitors to that Agency's Clients.

Categories of personal data: as set out in section 4 of the Privacy Policy. In summary: conversation content, name, email address, telephone number, any other field a Customer's form collects, channel account identity on WhatsApp and Instagram, uploaded files, and traffic source.

Special categories: none are required by the service, and clause 9 of the Terms of Service prohibits configuring a form to collect health information. A Customer may nonetheless receive special category information incidentally, for example a file upload that receives a curriculum vitae or an identity document. A Customer who does so is responsible for the additional conditions POPIA and GDPR impose on that information, and should note that uploaded documents carry the shortest retention window we operate.