Legal
Data processing agreement
1. Parties and roles
The customer who holds the Hazelchat account is the controller. Jan-Philipp Peters, sole trader, Germany (postal address on request at hello@hazelchat.co) (“Hazelchat”) is the processor. Account data of the customer itself (email address, credentials, workspace settings) is processed by Hazelchat as an independent controller and is covered by the privacy notice, not by this agreement.
2. Subject matter, duration, nature and purpose
Hazelchat operates a chat that the controller installs on its verified website. On the controller's behalf, Hazelchat stores visitor conversations and any enquiries, retrieves passages from the controller's approved content to answer questions, records the privacy notice version shown when an enquiry was made, notifies the controller that an enquiry has arrived, applies the retention period the controller configures, and provides export, search and deletion tools. Processing lasts as long as the account exists and ends with the deletion described in section 11.
3. Types of data and data subjects
- Data subjects: visitors of the controller's website who use the chat, and any persons mentioned in their messages.
- Data: questions and answers, including the source passages shown; enquiry name, email address and message; the permission wording and notice version displayed, with timestamp, conversation and publication reference; a short-lived conversation credential; hashed technical identifiers used to limit abuse; content-free usage events (chat opened, offered link followed, opener message shown or clicked) recorded by kind and conversation, without the page or any identifier.
- No special categories of data are intended. The controller must not configure the chat to solicit such data.
4. Instructions
Hazelchat processes visitor data only on the controller's documented instructions. The controller's configuration in the product — approved content, published versions, privacy details, retention periods, notification and capture settings, deletion and export actions — constitutes its instructions. Additional instructions must be given in text form to hello@hazelchat.co. Hazelchat will inform the controller without delay if, in its opinion, an instruction infringes data protection law, and may suspend that instruction until it is confirmed.
5. Confidentiality
Only persons bound to confidentiality and instructed in data protection have access to visitor data. Access is limited to what operating the service requires; Hazelchat does not read conversations or enquiries for its own purposes.
6. Security
Hazelchat implements the technical and organisational measures in Annex 2 and reviews them as the service develops. Measures may be replaced by others that provide at least the same level of protection.
7. Subprocessors
The controller gives general authorisation for the subprocessors in Annex 1. Hazelchat will notify the controller by email at least 30 days before adding or replacing a subprocessor. If the controller objects on reasonable data-protection grounds and no solution is found, the controller may close the account before the change takes effect. Hazelchat imposes data-protection obligations on each subprocessor by contract that are equivalent to those in this agreement and remains liable to the controller for its subprocessors' performance.
8. Assistance with data subject rights
The product lets the controller search saved enquiries and linked conversations by email address, export them, and delete individual records or the whole workspace. Hazelchat will forward without delay any visitor request that reaches it directly and will assist the controller with requests it cannot fulfil through the product, taking into account the nature of the processing. Hazelchat cannot identify anonymous conversations that have no associated enquiry.
9. Personal data breaches
Hazelchat notifies the controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting visitor data. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact for further information, as far as known at that time; further information follows as it becomes available. Hazelchat does not send notices to data subjects or authorities on the controller's behalf unless instructed.
10. Impact assessments and audits
Hazelchat assists the controller with data protection impact assessments and prior consultations insofar as they concern the processing under this agreement. Hazelchat provides the information needed to demonstrate compliance with Art. 28 GDPR, including this agreement, the privacy notice and Annexes 1 and 2. The controller may audit compliance with 30 days' notice, at most once a year unless a breach or a supervisory authority requires more, during business hours and without disrupting the service or exposing other customers' data. Reasonable costs of on-site audits are borne by the controller.
11. Deletion and return
Conversations and enquiries are deleted automatically after the retention period configured by the controller (default 90 days). The controller can delete individual records at any time and can export the workspace as JSON and CSV before closing the account. Closing the account deletes the workspace and cancels queued work immediately. Encrypted backups expire within 30 days; a separate deletion record ensures that deleted data is deleted again if an older backup is ever restored. Emails already delivered to the controller cannot be recalled. No visitor data is retained afterwards unless Union or member-state law requires it.
12. International transfers
Visitor data is stored in the European Union. Two subprocessors are located outside the EEA: Backblaze, Inc. receives only encrypted backup archives that it cannot decrypt, and OpenRouter, Inc. receives question text and retrieved passages only if the controller enables AI evidence selection, on routes without data retention. The safeguards are named in Annex 1. Enabling the AI feature in Settings is the controller's instruction to use that transfer.
13. Final provisions
In the event of a conflict, this agreement takes precedence over the terms of service for the processing of visitor data. Liability follows the terms of service. Governing law and jurisdiction follow section 12 of the terms of service. Amendments require text form; Hazelchat may update Annex 2 as security measures improve.
Annex 1 — Subprocessors
| Subprocessor and location | Purpose and visitor data received | Transfer safeguard |
|---|---|---|
| netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany | Server hosting. All stored visitor data. | Not required (EU) |
| Backblaze, Inc., 201 Baldwin Avenue, San Mateo, CA 94401, USA. Data stored in an EU data center (EU Central region, Amsterdam, Netherlands). | Encrypted backup storage. Encrypted archives only; the key is held by Hazelchat. | Standard contractual clauses in Backblaze's data processing addendum; archives are encrypted before upload with a key Backblaze does not hold. |
| OpenRouter, Inc., 169 Madison Avenue, New York, NY 10016, USA, and the model provider selected by the controller from the list offered in the product — currently models from OpenAI, DeepSeek, Mistral, Google, MiniMax, Alibaba, Moonshot AI, Z.ai, xAI and Anthropic, each reached through an OpenRouter route without data retention; for open-weight models that route is operated by a hosting provider on OpenRouter's platform. | AI evidence selection, only when the controller enables it. Question text and up to eight retrieved passages; no contact details or identifiers. | Standard contractual clauses approved by the European Commission (Art. 46 GDPR) in OpenRouter's data processing agreement. |
Brevo (Sendinblue SAS, France) sends the controller's enquiry notifications; these contain no visitor data. Better Stack monitors public availability and receives no visitor data. Both are therefore not subprocessors of visitor data and are listed in the privacy notice for transparency.
Annex 2 — Technical and organisational measures
- Access control: key-based administrative access to the server only; application services run as unprivileged system users with restricted filesystems; the web interface reaches the application only through a reverse proxy over HTTPS.
- Tenant isolation: every request resolves the authenticated account's own workspace server-side; public chat credentials are bound to a verified origin, expire after 24 hours and cannot administer, export or delete anything.
- Website verification: the chat only starts hosted conversations from exact origins whose ownership was proven by DNS record or verification file and is rechecked every seven days.
- Transport and storage: TLS for all public connections; credentials stored as salted scrypt hashes; session and link tokens stored only as hashes.
- Document handling: uploaded files are parsed in memory in an isolated environment with no network, a separate user, a read-only root and hard memory, CPU and process limits; originals are never stored or backed up.
- Abuse limits: persistent rate limits and daily budgets per workspace and globally; hashed technical identifiers only.
- Logging: operational logs contain request identifiers, route names, status codes and durations, never message content, addresses or tokens; retained 30 days.
- Availability and recovery: daily encrypted backups to EU storage with a 30-day ceiling; weekly automated restore checks; monthly full recovery rehearsal; content-free monitoring with alerting.
- Deletion: automatic retention enforcement; immediate deletion on request or account closure; an independent deletion record replayed before any restored data is accessible.
- Notification hygiene: enquiry notifications go only to the verified account owner and contain no visitor content; open and click tracking are disabled.
- Organisation: single-operator service: only the provider has access to production systems, over key-based SSH from a managed device, with no shared accounts; credentials are kept in a password manager and provider accounts use two-factor authentication where offered; personal data is accessed only to provide the service or on a documented customer request; there are no employees, and any contractor works only under written confidentiality and data-processing terms; incident-response and recovery runbooks are documented, and restoration is rehearsed weekly and the full application recovery monthly.