Data Processing Agreement
This Data Processing Agreement (DPA) applies where Chatdrill processes personal data on behalf of a customer. It forms part of the Terms of Service. A signed counterpart is available on request for customers who need one on file.
1. Scope and roles
This DPA is between the customer ('Controller') and ChatDrill Pte. Ltd. ('Processor'). It applies to the processing of personal data contained in customer data, and takes effect when the customer accepts the Terms of Service or signs an order form.
- The Controller determines the purposes and means of processing and is responsible for the lawfulness of the data it puts into Chatdrill, including any notice and consent required from its end users.
- The Processor processes personal data only on the Controller's documented instructions, which include the Terms of Service, this DPA and the Controller's use of the product's configuration options.
- Where the Processor determines the purposes and means itself — for example for account administration, billing and platform security — it acts as an independent controller under its Privacy Policy.
- The Processor will tell the Controller if, in its opinion, an instruction infringes applicable data protection law.
2. Details of the processing (Annex I)
Subject matter and duration
Provision of the Chatdrill customer conversation platform for the duration of the subscription, plus the deletion period described in section 11.
Nature and purpose
- Receiving, storing, routing and displaying conversations across the website widget, messaging channels and email.
- Generating AI answers and suggested replies from Controller-supplied content.
- Executing automation rules, assignment and escalation configured by the Controller.
- Recording visitor activity and producing analytics for the Controller.
- Backup, restoration, security monitoring and technical support.
Types of personal data
- Identifiers — name, email address, phone number, social or messaging handle, customer or order reference.
- Conversation content — messages, attachments, internal notes and any personal data the end user chooses to include.
- Technical data — IP address, approximate location, device, browser, referrer and pages viewed.
- Account user data — names, work emails and roles of the Controller's agents.
- Any other personal data the Controller elects to send through the API, an integration or a custom field.
Categories of data subjects
- The Controller's customers, prospects and website visitors.
- The Controller's employees and contractors who use the platform as agents or administrators.
Special category data is not requested and the platform is not designed to process it. The Controller should not configure fields that collect it, and should discourage end users from sending it.
3. Confidentiality of personnel
The Processor ensures that everyone authorised to process personal data is bound by a duty of confidentiality that survives the end of their engagement, receives security and privacy training appropriate to their role, and is granted access strictly on a need-to-know basis.
4. Security measures (Annex II)
The Processor implements appropriate technical and organisational measures, including:
- Encryption of personal data in transit using TLS 1.2 or higher, and encryption at rest for databases, object storage and backups.
- Role-based access control within the product, and least-privilege, individually attributed access to production systems for staff.
- Multi-factor authentication on administrative and infrastructure accounts.
- Network isolation, managed firewalls and hardened, patched infrastructure with a major cloud provider operating certified data centres.
- Separation of production, staging and development environments; production personal data is not used for testing.
- Automated, encrypted backups with periodic restore testing.
- Logging and monitoring of security-relevant events, with alerting on anomalous access.
- Code review, dependency vulnerability scanning and a documented change-management process before release.
- A documented incident response process, including internal escalation and customer notification.
- Vendor review before a new sub-processor is engaged.
The measures may be updated to keep pace with technology, provided the overall level of protection is not reduced. The current position, including controls that are on the roadmap rather than in place today, is published on the Security page.
5. Sub-processing
The Controller gives general authorisation for the Processor to engage sub-processors for hosting, AI model inference, email delivery, payments, analytics, error monitoring and support tooling.
- The Processor maintains a current list of sub-processors, available on request and notified to customers under an active DPA.
- The Processor gives at least 30 days' notice before a new sub-processor starts processing personal data.
- The Controller may object on reasonable data protection grounds within that period. The parties will work in good faith to find a solution; if none is available, the Controller may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
- Each sub-processor is bound by written terms offering protection equivalent to this DPA, and the Processor remains fully liable for its sub-processors' performance.
6. International transfers
Where processing involves a transfer of personal data outside the EEA, the United Kingdom or Switzerland to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Module Two: controller to processor), incorporated by reference, with the UK International Data Transfer Addendum where the UK GDPR applies.
- Annex I of the Clauses is completed by section 2 of this DPA; Annex II by section 4; Annex III by the sub-processor list.
- The supervisory authority is the competent authority of the Controller's establishment.
- The Processor supports the Controller's transfer impact assessments by providing the information reasonably needed to complete them.
7. Assistance with data subject requests
The product gives the Controller the ability to search, export, correct and delete personal data directly, which is normally sufficient to answer a data subject request without our involvement.
Where a data subject contacts the Processor directly, the Processor will not respond substantively but will refer them to the Controller and inform the Controller without undue delay. On request, and taking into account the nature of the processing, the Processor provides reasonable assistance with requests, data protection impact assessments and prior consultations with supervisory authorities.
8. Personal data breach
The Processor notifies the Controller without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting the Controller's data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information.
The Processor will not delay notification in order to complete its investigation, and will provide updates as facts are established. The Processor does not notify supervisory authorities or data subjects on the Controller's behalf unless the Controller instructs it to.
9. Audits and information
- The Processor makes available the information reasonably necessary to demonstrate compliance with this DPA, including a security overview and completed questionnaire responses.
- Where independent audit reports or certifications exist, they will be provided to satisfy an audit request in the first instance.
- Where they are not sufficient, the Controller may carry out an audit no more than once per year, on 30 days' written notice, during business hours, subject to confidentiality, at the Controller's cost and without unreasonable disruption. A supervisory authority may audit at any time as the law requires.
10. Return and deletion
The Controller can export its data at any time during the subscription. On termination, and at the Controller's choice, the Processor returns or deletes the personal data it processes on the Controller's behalf.
- Export remains available for 30 days after termination on request.
- Production data is deleted within 90 days of termination unless a longer period is required by law.
- Encrypted backups are overwritten on their normal cycle; data remaining in backup stays protected by this DPA until it is destroyed.
11. Liability, precedence and contact
Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where applicable law does not permit that limitation. If there is a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service on data protection matters.
Requests for a signed copy of this DPA, the current sub-processor list, or a completed security questionnaire are handled by our privacy team at the address given at the end of this page. ChatDrill Pte. Ltd. is incorporated in Singapore.
Last updated 12 August 2026. Questions about this document: privacy@chatdrill.com.
The other documents
Privacy Policy
This Privacy Policy explains how ChatDrill collects, uses, stores, shares and protects personal data when you use our website, the ChatDrill application and the related Services.
Read itTerms of Service
These terms govern your use of Chatdrill. They set out what we owe you, what you owe us, and what happens if either side wants to stop. Please read them before creating an account.
Read itCookie Policy
This policy explains which cookies and similar technologies Chatdrill uses on chatdrill.com and inside the application, what each category is for, and how to control them.
Read itNeed a signed Data Processing Agreement, our sub-processor list, or a completed security questionnaire? Ask us — or read the Security page first.