Data Processing Agreement
Last updated: 2026-07-06
This DPA documents how Astroworld processes personal data on behalf of business customers. The business is the data controller and Astroworld is the data processor. Download a copy for your records.
Sign in to one-click accept this DPA for your company.
DATA PROCESSING AGREEMENT (DPA)
Astroworld Chat
Last updated: 2026-07-06
This Data Processing Agreement ("DPA") forms part of the agreement between the
business customer ("Customer", the data controller) and Astroworld ("Processor",
the data processor) for the use of Astroworld Chat.
1. ROLES
The Customer is the data controller for personal data processed through
Astroworld Chat (including data of the Customer's own website visitors). Astroworld
acts solely as data processor and processes personal data only on the Customer's
documented instructions.
2. SUBJECT MATTER AND DURATION
The Processor provides an AI chat widget and dashboard. Processing lasts for the
duration of the subscription and until data is deleted under section 8.
3. NATURE AND PURPOSE OF PROCESSING
Hosting, storing, and processing chatbot configuration, knowledge base content,
and visitor conversations in order to answer visitor questions on the Customer's
behalf. Where the Customer enables the relevant features, processing also includes:
(a) remembering returning visitors (storing details a visitor states about
themselves, such as their name, interests and preferences, so they need not
repeat them); (b) deriving conversational insights for the Customer's team
(an automated read of tone, mood, sentiment, urgency, buying stage, satisfaction,
stated concern/goal/budget and language); (c) lead scoring and visitor analytics
(an automated score and behavioural signals such as pages viewed, device, browser
and approximate location); and (d) proactive triggers, showing an automated
prompt based on visitor behaviour (such as time on page, scrolling, the page or
country, or returning visits) and recording whether a visitor engaged with it, so
the Customer can measure each prompt's performance; and (e) commerce assistance -
where the Customer connects their store, helping visitors check stock and build a
checkout link or place an order, and recording those actions together with the
order/cart value (not card data) so the Customer can see the sales their chatbot
generated in their reports; (f) appointment booking, reminders, waitlist, rebooking and intake, where the
Customer enables booking, storing the visitor's name, email, chosen time and any
additional booking-form details the Customer asks for (such as a phone number) to
schedule an appointment and, if reminders are enabled, sending a reminder email
before it with a self-service reschedule/cancel link, and, where the Customer runs a
waitlist, recording the visitor's name, email and desired day so that, when an earlier
appointment frees up, the visitor can be emailed a time-limited link to claim it, and
, where the Customer enables rebooking, emailing a past customer, once a set period
after their appointment has elapsed, a link to book their next visit (skipped if they
have already booked again), and, where the Customer enables pre-appointment intake -
collecting the answers the visitor gives to the questions the Customer has configured;
and (g) review invitations -
where the Customer enables it, inviting the visitor to leave a review at the
Customer's own review link after the visitor gives a positive rating. These features are configurable
and can be turned off, and any retention window is set by the Customer. Where the Customer is on the per-seat, per-resolution
plan, processing also includes metering usage for billing: counting the number of AI
resolutions handled for the Customer's account and the model tier used for each
(Standard, Smart or Premium), together with the number of active team seats, so the
Customer can be billed for seats and for resolutions above the included monthly allowance.
4. CATEGORIES OF DATA SUBJECTS AND DATA
Data subjects: the Customer's staff (account users) and the Customer's website
visitors. Personal data: account name and email; the content of visitor
conversations (which may contain personal data the visitor chooses to type) -
and, where the Customer enables live typing preview, what a visitor is typing
may be shown to the Customer's agents in real time, shortly before it is sent;
and, where the Customer enables them, a remembered visitor profile (e.g. name,
stated interests and preferences), automated conversational insights (tone, mood,
sentiment, intent/buying stage and similar), and a lead score with visitor
analytics (pages viewed, device/browser, approximate location, session activity);
and, where the Customer enables proactive triggers, a record of which automated
prompts a visitor was shown and whether they engaged; and, where the Customer
connects a store, a record of commerce actions (stock checks, checkout links and
orders) and their order/cart value for the Customer's sales reporting, not card
details, which are handled by the store or payment provider; and, where the
Customer enables booking, the visitor's name, email, chosen appointment time and
any additional fields the Customer's booking form collects (for example a phone number)
(used to schedule the appointment and, if enabled, to email a reminder with a
reschedule/cancel link), and, where the Customer runs a waitlist, the visitor's
name, email and desired day (used to email a claim link when a matching appointment
opens up), and, where the Customer enables rebooking, a record of when a rebooking
invite was emailed to a past customer so it is sent only once, and, where the Customer
enables pre-appointment intake, the visitor's answers to the questions the Customer has
configured; and, where the Customer
configures a lead or quote-request
form, the fields they define, which may include contact details and free-text such
as the service requested, project scope or postcode. Where the Customer is on the
per-seat, per-resolution plan, the Processor also records usage and billing metrics: per-tier
counts of AI resolutions handled for the account, the model tier used, and the number of active
team seats. These are aggregate counts used to calculate the invoice and are not used to profile
individual visitors.
The Processor does not itself request special-category data (e.g. ID numbers, payment
details, health data). Where the Customer configures their own questions (intake, lead
or quote forms), the Customer decides what is asked and is responsible for not
soliciting special-category data without a lawful basis. Visitors are asked not to
share sensitive data and can erase what is remembered at any time.
5. PROCESSOR OBLIGATIONS
The Processor will: (a) process personal data only on documented instructions;
(b) ensure persons authorised to process data are bound by confidentiality;
(c) implement appropriate technical and organisational security measures;
(d) assist the Customer with data subject requests and security obligations;
(e) make available information needed to demonstrate compliance.
6. SUB-PROCESSORS
The Customer authorises the Processor to engage the sub-processors listed in the
Privacy Policy. The current list is:
- Anthropic (United States): AI model that generates chatbot answers
- Hetzner Online GmbH (Germany (EU)): Primary application and database hosting
- Strato AG (Germany (EU)): Secondary hosting and backups
- Stripe (United States / EU): Subscription billing and payment processing
- Resend (United States / EU): Transactional email delivery
- Google Ireland Ltd. (Google Analytics) (Ireland (EU) / United States (EU-US Data Privacy Framework)): Website analytics via Google Consent Mode: full analytics (with cookies) only with your consent; without consent, only anonymous, cookieless, aggregated measurement signals (no personal data stored)
- Trustpilot (Denmark (EU)): Review-collection widget shown in the account dashboard (receives page-load connection data such as IP and browser; sets no cookie on our own site)
The Processor will inform the Customer of intended changes and give the Customer
the opportunity to object.
7. SECURITY MEASURES
All data is hosted in the European Union (Germany). Traffic is encrypted in
transit with TLS (HTTPS). Access to production systems is restricted and
key-based. Payment card data is handled entirely by Stripe; Astroworld never
stores card numbers.
8. DELETION AND RETURN
On request, or on account deletion, the Processor deletes all personal data
associated with the Customer's account. The Customer can export their data at
any time from the dashboard. Conversation data is retained for the configured
retention period and then deleted.
9. DATA SUBJECT REQUESTS
The Processor will, taking into account the nature of processing, assist the
Customer in responding to requests to exercise data subject rights (access,
rectification, erasure, portability, restriction, objection).
10. PERSONAL DATA BREACH
The Processor will notify the Customer without undue delay after becoming aware
of a personal data breach affecting the Customer's data.
11. INTERNATIONAL TRANSFERS
Primary hosting is in the EU. Where a sub-processor processes data outside the
EU, appropriate safeguards (such as Standard Contractual Clauses) apply.
12. AUDIT
The Processor will make available information reasonably necessary to
demonstrate compliance with this DPA.
13. GOVERNING LAW
This DPA is governed by the laws applicable to the main service agreement and
the GDPR.
To countersign this DPA, contact [email protected].