Skip to content

Data Processing Agreement

Last updated: 5 October 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Frontbits LLC, a limited liability company registered in Sharjah Media City (Shams) Free Zone, Sharjah, United Arab Emirates ("Processor", "we"), and the business using Chatloom ("Customer", "you"). It applies whenever we process personal data on your behalf ("Customer Personal Data"). If this DPA and the Terms conflict about personal data, this DPA wins.

1. Roles

You are the controller of Customer Personal Data, and we are your processor. Where you act as a processor for someone else, we are your sub-processor.

2. Details of the processing

  • Subject matter and purpose: providing the Service: chatbots on your website, your inbox, alerts, reports and connected apps.
  • Duration: while you use the Service, plus the deletion periods in section 9.
  • Nature: storing, organising, retrieving, analysing (for example, labelling chats by topic) and sending data to subprocessors to provide the Service, including generating AI replies.
  • Data subjects: your website visitors and customers, and your team members.
  • Categories of data: chat messages; contact details visitors give (name, email, phone); messages for your team; call bookings; ratings; technical context (page, referrer, device, browser, time zone, language); order details from your connected store; details of signed-in customers your website shares.
  • Special categories: none intended. You agree not to use the Service to collect special categories of data (such as health data).

3. Our obligations

We will:

  1. process Customer Personal Data only on your documented instructions (these Terms, this DPA and your settings in the Service), unless the law requires otherwise, in which case we'll tell you first unless the law forbids it;
  2. make sure everyone authorised to process it is bound by confidentiality;
  3. keep the security measures in Annex 1 in place, and only change them in ways that don't reduce overall security;
  4. help you respond to requests from individuals exercising their rights. The Service includes tools to find, export and delete a visitor's data, and we'll assist further if you ask;
  5. help you with data protection impact assessments and consultations with authorities where they concern the Service;
  6. not sell Customer Personal Data, not use it for advertising, and not use it to train AI models.

4. Subprocessors

You authorise the subprocessors in Annex 2. We'll tell you at least 30 days before adding or replacing one, by email or in the dashboard. If you object on reasonable data protection grounds, we'll discuss it in good faith; if we can't resolve it, you may end the affected part of the Service without penalty. We impose data protection terms on each subprocessor that protect your data at least as well as this DPA, and we remain responsible for them.

5. Personal data breaches

If we become aware of a breach affecting Customer Personal Data, we'll tell you without undue delay, and in any case within 72 hours, with what we know about its nature, the data and people affected, likely consequences and the measures taken. We'll update you as we learn more and help you meet your own notification duties. Our incident response process is described on our Security page.

6. International transfers

We may transfer Customer Personal Data to the countries where we and our subprocessors operate (see Annex 2). Where the law requires safeguards for a transfer, the European Commission's Standard Contractual Clauses (Module 2 controller to processor, or Module 3 processor to processor), with the UK Addendum where relevant, are incorporated into this DPA by reference, with the details in this DPA filling in their annexes.

7. Your obligations

You are responsible for having a lawful basis to collect and use the data, for telling your website visitors how their data is used (the Service provides a privacy notice for the chat and suggested wording for your privacy policy), and for the instructions you give us being lawful.

8. Audits

We'll make available the information reasonably needed to show we comply with this DPA, including answering security questionnaires. If that isn't enough, you may audit our compliance once a year, at your cost, with at least 30 days' notice, through an independent auditor bound by confidentiality, in a way that doesn't disrupt the Service or other customers' data.

9. Deletion and return

You can export your data and delete chats, visitors' data, chatbots and workspaces in the Service at any time. When you delete your workspace or account, we delete Customer Personal Data within 30 days, and it disappears from backups as they expire (within four weeks after that), unless the law requires us to keep it.

10. Liability and term

Each party's liability under this DPA is subject to the limits in the Terms, except where the law doesn't allow it. This DPA lasts as long as we process Customer Personal Data for you.

Annex 1: Security measures

  • Encryption in transit: all traffic to Chatloom uses HTTPS (TLS). Calls to our subprocessors use HTTPS, and the app reaches its database over our hosting provider's encrypted private network.
  • Encryption at rest: the database and backups are stored on our hosting provider's encrypted storage. Credentials for connected services (such as Shopify and Slack) are additionally encrypted by the application with AES-256-GCM.
  • Access control: each business's data is kept in its own workspace, reachable only by its team members, with roles (owner, admin, member). Only owners and admins can connect other apps or use the privacy tools. Access to production systems is limited to authorised Frontbits staff using accounts protected by strong passwords and two-factor authentication.
  • Passwords: account passwords are hashed with bcrypt and never stored in plain text. Sign-in attempts are rate limited.
  • Logging: changes to chatbots and teams are recorded in the Activity log, and every view or export of customers' personal data is recorded in an access log kept for one year, which workspace owners and admins can read.
  • Backups: automated nightly backups, kept for up to four weeks, plus a backup before every database change.
  • Separation of environments: development and testing use separate systems with test data only.
  • Data minimisation and retention: we only request the data each feature needs (for example, Shopify access is read-only and limited to orders). Chats are deleted automatically after the period each business chooses, and Shopify order details after 90 days.
  • Abuse protection: public endpoints are rate limited, and order lookups require both the order number and the email the order was placed with.

Annex 2: Subprocessors

ServiceWhat it does for ChatloomLocationWhen it's used
Railway CorporationHosting, database and backupsUnited StatesAlways
Anthropic, PBCAI model that writes chat replies, summaries and labelsUnited StatesAlways
Resend, Inc.Sending Chatloom's emails (password reset, invites, alerts, weekly reports)United StatesAlways
Stripe, Inc.Payments and billing for paid plansUnited StatesPaid plans
Slack Technologies, LLCAlerts posted to the business's Slack channelUnited StatesOnly if the business connects Slack
Shopify Inc.Looking up a customer's order in the chatCanada / United StatesOnly if the business connects Shopify
Cal.com, Inc. / Calendly LLCBooking calls from the chatUnited StatesOnly if the business adds booking links
Browser push services (Apple, Google, Mozilla)Delivering notifications to team members' devicesUnited StatesOnly for people who turn on notifications

Contact

Data protection questions: [email protected]. Frontbits LLC, Sharjah Media City (Shams) Free Zone, Sharjah, United Arab Emirates.