Chatifier.AI

Chatifier Data Processing Addendum

Last updated: 30 July 2026. This Data Processing Addendum ("DPA") forms part of the Chatifier Terms of Service and applies to every customer whose assistant processes personal data of website visitors.

Parties: g-square.ai LTD (United Kingdom), operating Chatifier (chatifier.ai) ("Processor"), and the customer ("Controller").

  1. Subject matter & duration. Processing of website-visitor personal data — chat messages, voice audio during active sessions, submitted contact details, and technical data — to operate the Controller's AI assistant, for the duration of the Controller's subscription.
  2. Nature & purpose. Hosting; retrieval over Controller-provided content; AI answer generation via the subprocessors listed on the Subprocessors page; lead capture; conversation storage and summaries; usage metering and billing.
  3. Controller instructions. Chatifier processes visitor data only to provide the service as configured by the Controller in the dashboard; that configuration constitutes the Controller's documented instructions. Chatifier will inform the Controller if, in its opinion, an instruction infringes applicable data protection law.
  4. Confidentiality. Persons authorised to process the data are bound by confidentiality obligations.
  5. Security. Measures include: encryption in transit (TLS) and encryption of conversation and document content at rest; tenant-scoped data access enforced server-side; access restricted to the operator; layered rate limiting and abuse controls; nightly encrypted backups with 30-day automatic expiry.
  6. Subprocessors. The Controller grants general authorisation for the subprocessors listed on the Subprocessors page. Chatifier will update that page at least 30 days before adding a subprocessor that processes visitor personal data; the Controller may object on reasonable data protection grounds and terminate the affected service if the objection cannot be resolved.
  7. Data subject rights. Chatifier assists the Controller in fulfilling access, correction, deletion, and export requests via the dashboard tools or, where those do not suffice, on request at support@chatifier.ai.
  8. Breach notification. Chatifier will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting visitor data, with the information reasonably required for the Controller's own notification obligations.
  9. Deletion and return. The Controller can export conversations and documents from the dashboard at any time. On termination, visitor data is deleted in accordance with the Data Retention Schedule.
  10. International transfers. Transfers to US-based AI subprocessors are covered by the EU-U.S. Data Privacy Framework certification of the relevant provider or by Standard Contractual Clauses, as listed on the Subprocessors page.
  11. Audit. Chatifier will make available information reasonably necessary to demonstrate compliance with this DPA. Audits are limited to once per 12 months, at the Controller's cost, on 30 days' written notice, and must not disturb other customers' data or service.
  12. Controller obligations. The Controller must not configure the assistant to request payment-card data, government identifiers, health information, or other special-category data, and remains responsible for providing its own visitors with privacy information covering the assistant.