This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies to any Customer who installs the Sitebot chat widget on their own website, allowing end visitors to interact with it. It describes how we process, on the Customer's behalf, the personal data of those visitors.
1. Roles: who is controller and who is processor
With respect to the personal data of the end visitors who use the widget on the Customer's site:
- The Customer is the data controller: they decide which site is crawled, what content is indexed, how the bot is configured, and what the resulting conversations are used for.
- Sitebot acts as the data processor: it processes that data solely to provide the Service contracted by the Customer, following their configuration.
With respect to the Customer's own account data (email, password, configuration), Sitebot is the data controller, as explained in the Privacy Policy.
2. Object and duration of processing
The object of the processing is to allow the widget to answer questions from the Customer's site visitors using that site's content, and to show the Customer the resulting history and analytics. The processing lasts for as long as the Customer keeps the site active in their account.
3. Processing only under instructions
Sitebot processes visitor data solely in accordance with the Customer's documented instructions, expressed through the configuration available in the dashboard (site to crawl, bot settings, allowed origins, usage limits). Sitebot does not use that data for any purpose of its own, such as training third-party models, advertising, or transferring it to another Customer.
If we consider that a Customer instruction infringes applicable data protection regulations, we will inform them before carrying it out.
4. Data processed and data subjects
Data subjects: visitors to the Customer's website who interact with the chat widget.
Categories of data:
- Content of the messages written by the visitor in the chat.
- Responses generated by the bot and the sources cited.
- Rating of the response (👍/👎), if the visitor uses it.
- Technical conversation session identifier.
- Any personal data the visitor voluntarily chooses to write in their message (for example, their name or email if they mention them while asking something).
Sitebot does not actively request identifying data from end visitors; such data only arises if the visitor voluntarily includes it in their message.
5. Subprocessors
The Customer authorizes Sitebot to use the following subprocessors to provide the Service:
| Subprocessor | Function | Processing location |
|---|---|---|
| OpenAI (or another compatible language model provider, configurable by Sitebot) | Generation of the chat response from the relevant content found on the site | Outside Argentina (including the U.S.), under its own data protection commitments |
| Hosting and infrastructure provider | Hosting of the application and the database | Depending on the infrastructure provider contracted at any given time |
Sitebot will inform the Customer of any change to this list of subprocessors with reasonable advance notice, so the Customer can object for justified reasons related to data protection.
6. Security measures
Sitebot applies the technical and organizational measures described in the security section of the Privacy Policy (mandatory authentication, hashed passwords, secure session cookies, widget origin validation, protection against access to internal networks) to protect the data processed on the Customer's behalf.
7. Confidentiality
Sitebot personnel or collaborators with access to visitor data are subject to confidentiality obligations, and access is limited to what is necessary to operate and support the Service.
8. Assistance with data subject rights
If a visitor exercises before the Customer a right of access, rectification, erasure, or objection over data held by Sitebot, the Customer can resolve it directly from the dashboard (for example, reviewing or deleting conversations), or request our assistance by writing to hola@sitebot.dev.
9. Incident notification
If we detect a security breach affecting personal data processed on the Customer's behalf, we will notify them without undue delay, with the information available about its nature, scope, and the measures taken or proposed, so the Customer can comply with their own notification obligations if applicable.
10. Return or deletion of data
Deleting a site from the dashboard immediately and irreversibly erases all of its indexed content, conversation history, and associated configuration from Sitebot's production systems, except for what must be retained in backups for a limited period as described in the Privacy Policy.
11. Audits
The Customer may reasonably request information about the security measures and subprocessors used, to verify compliance with this Agreement. Given the size of the Service, this is handled through written documentation rather than on-site audits, unless otherwise agreed between the parties.
12. Customer responsibilities
As the data controller, the Customer is responsible for:
- Having a legal basis (for example, their own privacy notice on their site) for their visitors to interact with the widget.
- Only submitting for crawling sites that they own or are authorized to crawl.
- Configuring the bot so that it does not prompt visitors to share unnecessary sensitive data.
- Handling requests from their own visitors in their capacity as controller toward them.
13. Term
This Agreement remains in effect while the Customer uses the Service and keeps the widget installed on their site, and terminates together with the Terms of Service.
14. Contact
Questions about this Data Processing Agreement: hola@sitebot.dev.