Data Processing Addendum
Effective date: October 4, 2026
This Data Processing Addendum ("DPA") applies automatically when you use TalkingDot to process personal data about your website visitors, leads or users. You do not need to sign anything. If you need a countersigned copy, email privacy@talkingdot.com.
Parties and scope
This DPA forms part of the Terms of Service between TalkingDot ("Processor", "we") and the customer that holds a TalkingDot account or workspace ("Controller", "you"). It applies to personal data that we process on your behalf when providing the service ("Customer Personal Data"). Words such as "controller", "processor", "personal data", "processing" and "personal data breach" have the meanings given in the EU General Data Protection Regulation (GDPR) and, where relevant, the UK GDPR (together, "Data Protection Laws").
If you act as a processor for another controller, we act as your sub-processor, and you are responsible for passing on the relevant instructions and information.
Roles of the parties
You are the controller of Customer Personal Data: you decide whether to install the messenger, what data to collect and how long to keep it. We are your processor. For data about your own account and teammates, we act as a controller, as described in our Privacy Policy.
Details of the processing
| Subject matter | Providing the TalkingDot live chat service under the Terms. |
|---|---|
| Duration | For as long as you use the service, plus the deletion periods described in this DPA. |
| Nature and purpose | Hosting, storing, transmitting, displaying and organising data so you can chat with your visitors, manage contacts, run chatbots and automation, publish a help center, send notifications and produce reports. |
| Data subjects | Visitors to your websites and hosted chat pages; leads and prospects; your users and customers; anyone else who contacts you through the service. |
| Personal data | Contact details provided (name, email address, phone number, company); visitor identifiers; custom attributes and events you send; messages, attachments, ratings and form answers; pages viewed, referrer and visit counts; browser, operating system, device type, language and time zone; approximate location (country, region, city); IP address (full, truncated or not stored, as you choose); notes and tags added by your teammates. |
| Special categories | None intended. Do not use the service to collect special categories of data unless you have a lawful basis and appropriate safeguards. |
| Frequency | Continuous, while the service is in use. |
Your obligations
- Have a lawful basis for the processing and give your visitors the information the law requires, including a privacy notice that mentions live chat.
- Make sure your instructions comply with Data Protection Laws.
- Configure the service to suit your needs, including IP storage, conversation retention, the domain allow-list and identity verification.
- Keep your account credentials and API keys secure and control who has access to your workspaces.
Our obligations
Instructions
We process Customer Personal Data only on your documented instructions, which are the Terms, this DPA, your settings and your use of the service, unless the law requires otherwise. In that case we will tell you before processing, unless the law prohibits it. We will tell you if we believe an instruction infringes Data Protection Laws.
Confidentiality
Everyone we authorise to process Customer Personal Data is bound by confidentiality and accesses it only as needed to provide, support or secure the service.
Security
We maintain appropriate technical and organisational measures to protect Customer Personal Data, including password hashing, optional two-factor authentication, role-based access, CSRF protection, a strict Content-Security-Policy, rate limiting, signed webhooks, signed links for attachments and an audit log of administrative actions. Our current measures are described on our Security page. We may update them, provided the overall level of protection is not reduced.
Subprocessors
You give us general authorisation to use subprocessors. Our current subprocessors are listed on our subprocessors page. Before a new subprocessor starts processing Customer Personal Data, we will update that page and its effective date. You may object on reasonable data-protection grounds within 30 days by emailing privacy@talkingdot.com. If we cannot resolve your objection, you may stop using the service and have your workspaces deleted. We impose data-protection obligations on each subprocessor that are no less protective than this DPA, and we remain responsible for their performance.
Data subject requests
The service gives you tools to answer requests from data subjects: you can export a contact's data, erase a contact together with their conversations, delete conversations and set closed conversations to be deleted automatically. If we receive a request directly, we will pass it to you without undue delay and will not respond ourselves, except to direct the person to you, unless you ask us to. Where you cannot fulfil a request with these tools, we will give reasonable assistance.
Assistance
Taking into account the nature of the processing and the information available to us, we will give reasonable help with your security obligations, data protection impact assessments and prior consultations with supervisory authorities.
Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As far as we know them, our notice will describe the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures taken or proposed. We will send it to the email addresses of the affected workspace owners and keep you updated as more information becomes available.
Deletion and return
You can export Customer Personal Data at any time while you use the service. When a workspace is deleted, or your account is closed, we delete the related Customer Personal Data from our live systems. Copies in backups are removed as those backups are overwritten, unless the law requires us to keep the data.
Audits and information
We will make available the information reasonably necessary to demonstrate compliance with this DPA, such as this DPA, our Security page and written answers to reasonable security questionnaires. If that is not enough, or if a supervisory authority requires it, you may audit our compliance once a year, with at least 30 days' notice, during business hours, at your own cost and under appropriate confidentiality terms. An audit must not give access to other customers' data.
International transfers
We and our subprocessors may process Customer Personal Data outside the country where it was collected. Where Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 (module two, or module three where you are a processor), together with the UK International Data Transfer Addendum where relevant, are incorporated into this DPA by reference, unless another lawful transfer mechanism applies.
Liability and order of precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws do not allow this. If this DPA conflicts with the Terms, this DPA prevails for matters relating to personal data. If the Standard Contractual Clauses apply and conflict with this DPA, the Clauses prevail.
How to accept this DPA
This DPA takes effect when you start using the service to process Customer Personal Data and stays in force for as long as we process it. To receive a copy countersigned by TalkingDot, email privacy@talkingdot.com with your organisation's legal name and address and the email address of your account.