DATA PROCESSING AGREEMENT (DPA) Astroworld Chat Last updated: 2026-07-06 This Data Processing Agreement ("DPA") forms part of the agreement between the business customer ("Customer", the data controller) and Astroworld ("Processor", the data processor) for the use of Astroworld Chat. 1. ROLES The Customer is the data controller for personal data processed through Astroworld Chat (including data of the Customer's own website visitors). Astroworld acts solely as data processor and processes personal data only on the Customer's documented instructions. 2. SUBJECT MATTER AND DURATION The Processor provides an AI chat widget and dashboard. Processing lasts for the duration of the subscription and until data is deleted under section 8. 3. NATURE AND PURPOSE OF PROCESSING Hosting, storing, and processing chatbot configuration, knowledge base content, and visitor conversations in order to answer visitor questions on the Customer's behalf. Where the Customer enables the relevant features, processing also includes: (a) remembering returning visitors (storing details a visitor states about themselves, such as their name, interests and preferences, so they need not repeat them); (b) deriving conversational insights for the Customer's team (an automated read of tone, mood, sentiment, urgency, buying stage, satisfaction, stated concern/goal/budget and language); (c) lead scoring and visitor analytics (an automated score and behavioural signals such as pages viewed, device, browser and approximate location); and (d) proactive triggers, showing an automated prompt based on visitor behaviour (such as time on page, scrolling, the page or country, or returning visits) and recording whether a visitor engaged with it, so the Customer can measure each prompt's performance; and (e) commerce assistance - where the Customer connects their store, helping visitors check stock and build a checkout link or place an order, and recording those actions together with the order/cart value (not card data) so the Customer can see the sales their chatbot generated in their reports; (f) appointment booking, reminders, waitlist, rebooking and intake, where the Customer enables booking, storing the visitor's name, email, chosen time and any additional booking-form details the Customer asks for (such as a phone number) to schedule an appointment and, if reminders are enabled, sending a reminder email before it with a self-service reschedule/cancel link, and, where the Customer runs a waitlist, recording the visitor's name, email and desired day so that, when an earlier appointment frees up, the visitor can be emailed a time-limited link to claim it, and , where the Customer enables rebooking, emailing a past customer, once a set period after their appointment has elapsed, a link to book their next visit (skipped if they have already booked again), and, where the Customer enables pre-appointment intake - collecting the answers the visitor gives to the questions the Customer has configured; and (g) review invitations - where the Customer enables it, inviting the visitor to leave a review at the Customer's own review link after the visitor gives a positive rating. These features are configurable and can be turned off, and any retention window is set by the Customer. Where the Customer is on the per-seat, per-resolution plan, processing also includes metering usage for billing: counting the number of AI resolutions handled for the Customer's account and the model tier used for each (Standard, Smart or Premium), together with the number of active team seats, so the Customer can be billed for seats and for resolutions above the included monthly allowance. 4. CATEGORIES OF DATA SUBJECTS AND DATA Data subjects: the Customer's staff (account users) and the Customer's website visitors. Personal data: account name and email; the content of visitor conversations (which may contain personal data the visitor chooses to type) - and, where the Customer enables live typing preview, what a visitor is typing may be shown to the Customer's agents in real time, shortly before it is sent; and, where the Customer enables them, a remembered visitor profile (e.g. name, stated interests and preferences), automated conversational insights (tone, mood, sentiment, intent/buying stage and similar), and a lead score with visitor analytics (pages viewed, device/browser, approximate location, session activity); and, where the Customer enables proactive triggers, a record of which automated prompts a visitor was shown and whether they engaged; and, where the Customer connects a store, a record of commerce actions (stock checks, checkout links and orders) and their order/cart value for the Customer's sales reporting, not card details, which are handled by the store or payment provider; and, where the Customer enables booking, the visitor's name, email, chosen appointment time and any additional fields the Customer's booking form collects (for example a phone number) (used to schedule the appointment and, if enabled, to email a reminder with a reschedule/cancel link), and, where the Customer runs a waitlist, the visitor's name, email and desired day (used to email a claim link when a matching appointment opens up), and, where the Customer enables rebooking, a record of when a rebooking invite was emailed to a past customer so it is sent only once, and, where the Customer enables pre-appointment intake, the visitor's answers to the questions the Customer has configured; and, where the Customer configures a lead or quote-request form, the fields they define, which may include contact details and free-text such as the service requested, project scope or postcode. Where the Customer is on the per-seat, per-resolution plan, the Processor also records usage and billing metrics: per-tier counts of AI resolutions handled for the account, the model tier used, and the number of active team seats. These are aggregate counts used to calculate the invoice and are not used to profile individual visitors. The Processor does not itself request special-category data (e.g. ID numbers, payment details, health data). Where the Customer configures their own questions (intake, lead or quote forms), the Customer decides what is asked and is responsible for not soliciting special-category data without a lawful basis. Visitors are asked not to share sensitive data and can erase what is remembered at any time. 5. PROCESSOR OBLIGATIONS The Processor will: (a) process personal data only on documented instructions; (b) ensure persons authorised to process data are bound by confidentiality; (c) implement appropriate technical and organisational security measures; (d) assist the Customer with data subject requests and security obligations; (e) make available information needed to demonstrate compliance. 6. SUB-PROCESSORS The Customer authorises the Processor to engage the sub-processors listed in the Privacy Policy. The current list is: - Anthropic (United States): AI model that generates chatbot answers - Hetzner Online GmbH (Germany (EU)): Primary application and database hosting - Strato AG (Germany (EU)): Secondary hosting and backups - Stripe (United States / EU): Subscription billing and payment processing - Resend (United States / EU): Transactional email delivery - Google Ireland Ltd. (Google Analytics) (Ireland (EU) / United States (EU-US Data Privacy Framework)): Website analytics via Google Consent Mode: full analytics (with cookies) only with your consent; without consent, only anonymous, cookieless, aggregated measurement signals (no personal data stored) - Trustpilot (Denmark (EU)): Review-collection widget shown in the account dashboard (receives page-load connection data such as IP and browser; sets no cookie on our own site) The Processor will inform the Customer of intended changes and give the Customer the opportunity to object. 7. SECURITY MEASURES All data is hosted in the European Union (Germany). Traffic is encrypted in transit with TLS (HTTPS). Access to production systems is restricted and key-based. Payment card data is handled entirely by Stripe; Astroworld never stores card numbers. 8. DELETION AND RETURN On request, or on account deletion, the Processor deletes all personal data associated with the Customer's account. The Customer can export their data at any time from the dashboard. Conversation data is retained for the configured retention period and then deleted. 9. DATA SUBJECT REQUESTS The Processor will, taking into account the nature of processing, assist the Customer in responding to requests to exercise data subject rights (access, rectification, erasure, portability, restriction, objection). 10. PERSONAL DATA BREACH The Processor will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data. 11. INTERNATIONAL TRANSFERS Primary hosting is in the EU. Where a sub-processor processes data outside the EU, appropriate safeguards (such as Standard Contractual Clauses) apply. 12. AUDIT The Processor will make available information reasonably necessary to demonstrate compliance with this DPA. 13. GOVERNING LAW This DPA is governed by the laws applicable to the main service agreement and the GDPR. To countersign this DPA, contact privacy@astroworldmc.com.