Data Processing Agreement
This DPA governs how Widgenix processes personal data on behalf of business customers whose widget visitors are located in the EU, UK, Switzerland, India, or other jurisdictions with equivalent processor obligations.
How this DPA applies
This DPA is incorporated by reference into our Terms of Service and applies automatically whenever you use Widgenix to process personal data of your own website visitors or customers ("Data Subjects"), to the extent GDPR, the UK GDPR, India's DPDP Act, 2023, or a substantially similar law applies to that processing. You do not need to countersign anything for this DPA to take effect for standard plans.
Enterprise customers: if your procurement process requires a separately signed and negotiated DPA (e.g., with customer-specific audit clauses or liability terms), contact legal@widgenix.ai — we can provide an executable version for signature.
1. Definitions
Terms such as "personal data," "processing," "controller," "processor," and "data subject" have the meanings given in GDPR (Regulation (EU) 2016/679), and equivalent terms under India's DPDP Act, 2023 ("Data Fiduciary" and "Data Processor") are read as corresponding to "controller" and "processor" respectively for the purposes of this DPA.
2. Roles of the parties
As between Widgenix and the customer, the customer is the controller (or Data Fiduciary) of personal data collected through their embedded widgets, and Widgenix is the processor (or Data Processor), acting only on the customer's documented instructions as set out in the Widgenix dashboard configuration, the Terms of Service, and this DPA.
3. Details of processing
| Detail | Description |
|---|---|
| Subject matter | Provision of AI-powered chat and voice widgets, and the underlying dashboard |
| Duration | The term of the customer's subscription, plus any post-termination retention/export window |
| Nature & purpose | Automated processing of visitor messages, voice audio, and lead information to generate AI responses and enable business functions the customer configures |
| Categories of data subjects | Visitors to the customer's website; the customer's own admin users |
| Categories of personal data | Chat/voice content, session identifiers, optional name/email/phone submitted via lead forms, IP address (transient) |
| Special categories of data | Not intentionally processed. Customers must not configure widgets to solicit special-category data (health, biometric, etc.) without a separate written agreement |
4. Sub-processors
The customer authorizes Widgenix to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| OpenRouter | LLM inference for chat and RAG-based responses | United States |
| ElevenLabs | Text-to-speech voice synthesis for the voice widget | United States |
| Stripe | Payment processing and subscription billing | United States / Ireland (Stripe Payments Europe) |
| [Hosting provider, e.g. Vercel / AWS / Render] | Application hosting and infrastructure | [Region(s) — disclose if data residency matters to your customers] |
| [Database provider, e.g. Supabase / Neon / RDS] | Storage of chat logs, leads, and account data | [Region(s)] |
We will provide reasonable advance notice of any new sub-processor via email or an in-product notice, and customers may object on reasonable data-protection grounds within a reasonable period (e.g., 14–30 days — set the actual number once finalized with counsel).
5. Security measures
Widgenix implements appropriate technical and organizational measures, including encryption in transit and at rest, access controls limiting data access to authorized personnel, network security controls, and regular review of our infrastructure, appropriate to the risk presented by the processing described above.
6. Assistance with data subject rights
Where a data subject exercises a right (access, deletion, correction, portability) directly with Widgenix regarding data we process on the customer's behalf, we will promptly forward the request to the relevant customer and provide reasonable assistance to help them respond, using the tools and support available in the Widgenix dashboard where possible.
7. Personal data breach notification
If Widgenix becomes aware of a personal data breach affecting customer data, we will notify the affected customer without undue delay, and in any case within the timeframe required by applicable law (commonly within 72 hours of becoming aware, under GDPR), with information reasonably available to us about the nature and likely consequences of the breach and steps taken to address it.
8. Audit rights
Widgenix will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for audits, including inspections, conducted by the customer or an auditor mandated by the customer, subject to reasonable advance notice, confidentiality obligations, and no more than once per year absent a specific compliance concern.
9. International transfers
Where personal data is transferred outside the country or region in which it was originally collected, Widgenix relies on appropriate transfer mechanisms, such as the EU Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum, incorporated into this DPA by reference where applicable to a given customer's data flows.
10. Liability & term
Liability under this DPA is subject to the limitation of liability set out in our Terms of Service. This DPA remains in effect for as long as Widgenix processes personal data on the customer's behalf under the Terms of Service.
11. Contact us
For DPA-related questions, an executable signature copy, or to review our current sub-processor list: legal@widgenix.ai
