hazelchatLog in

Legal

Data processing agreement

Version of 14 September 2026. This agreement under Art. 28 GDPR forms part of the terms of service. It governs the personal data of your website visitors that Hazelchat processes on your behalf.

1. Parties and roles

The customer who holds the Hazelchat account is the controller. Jan-Philipp Peters, sole trader, Germany (postal address on request at hello@hazelchat.co) (“Hazelchat”) is the processor. Account data of the customer itself (email address, credentials, workspace settings) is processed by Hazelchat as an independent controller and is covered by the privacy notice, not by this agreement.

2. Subject matter, duration, nature and purpose

Hazelchat operates a chat that the controller installs on its verified website. On the controller's behalf, Hazelchat stores visitor conversations and any enquiries, retrieves passages from the controller's approved content to answer questions, records the privacy notice version shown when an enquiry was made, notifies the controller that an enquiry has arrived, applies the retention period the controller configures, and provides export, search and deletion tools. Processing lasts as long as the account exists and ends with the deletion described in section 11.

3. Types of data and data subjects

4. Instructions

Hazelchat processes visitor data only on the controller's documented instructions. The controller's configuration in the product — approved content, published versions, privacy details, retention periods, notification and capture settings, deletion and export actions — constitutes its instructions. Additional instructions must be given in text form to hello@hazelchat.co. Hazelchat will inform the controller without delay if, in its opinion, an instruction infringes data protection law, and may suspend that instruction until it is confirmed.

5. Confidentiality

Only persons bound to confidentiality and instructed in data protection have access to visitor data. Access is limited to what operating the service requires; Hazelchat does not read conversations or enquiries for its own purposes.

6. Security

Hazelchat implements the technical and organisational measures in Annex 2 and reviews them as the service develops. Measures may be replaced by others that provide at least the same level of protection.

7. Subprocessors

The controller gives general authorisation for the subprocessors in Annex 1. Hazelchat will notify the controller by email at least 30 days before adding or replacing a subprocessor. If the controller objects on reasonable data-protection grounds and no solution is found, the controller may close the account before the change takes effect. Hazelchat imposes data-protection obligations on each subprocessor by contract that are equivalent to those in this agreement and remains liable to the controller for its subprocessors' performance.

8. Assistance with data subject rights

The product lets the controller search saved enquiries and linked conversations by email address, export them, and delete individual records or the whole workspace. Hazelchat will forward without delay any visitor request that reaches it directly and will assist the controller with requests it cannot fulfil through the product, taking into account the nature of the processing. Hazelchat cannot identify anonymous conversations that have no associated enquiry.

9. Personal data breaches

Hazelchat notifies the controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting visitor data. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact for further information, as far as known at that time; further information follows as it becomes available. Hazelchat does not send notices to data subjects or authorities on the controller's behalf unless instructed.

10. Impact assessments and audits

Hazelchat assists the controller with data protection impact assessments and prior consultations insofar as they concern the processing under this agreement. Hazelchat provides the information needed to demonstrate compliance with Art. 28 GDPR, including this agreement, the privacy notice and Annexes 1 and 2. The controller may audit compliance with 30 days' notice, at most once a year unless a breach or a supervisory authority requires more, during business hours and without disrupting the service or exposing other customers' data. Reasonable costs of on-site audits are borne by the controller.

11. Deletion and return

Conversations and enquiries are deleted automatically after the retention period configured by the controller (default 90 days). The controller can delete individual records at any time and can export the workspace as JSON and CSV before closing the account. Closing the account deletes the workspace and cancels queued work immediately. Encrypted backups expire within 30 days; a separate deletion record ensures that deleted data is deleted again if an older backup is ever restored. Emails already delivered to the controller cannot be recalled. No visitor data is retained afterwards unless Union or member-state law requires it.

12. International transfers

Visitor data is stored in the European Union. Two subprocessors are located outside the EEA: Backblaze, Inc. receives only encrypted backup archives that it cannot decrypt, and OpenRouter, Inc. receives question text and retrieved passages only if the controller enables AI evidence selection, on routes without data retention. The safeguards are named in Annex 1. Enabling the AI feature in Settings is the controller's instruction to use that transfer.

13. Final provisions

In the event of a conflict, this agreement takes precedence over the terms of service for the processing of visitor data. Liability follows the terms of service. Governing law and jurisdiction follow section 12 of the terms of service. Amendments require text form; Hazelchat may update Annex 2 as security measures improve.

Annex 1 — Subprocessors

Subprocessor and locationPurpose and visitor data receivedTransfer safeguard
netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, GermanyServer hosting. All stored visitor data.Not required (EU)
Backblaze, Inc., 201 Baldwin Avenue, San Mateo, CA 94401, USA. Data stored in an EU data center (EU Central region, Amsterdam, Netherlands).Encrypted backup storage. Encrypted archives only; the key is held by Hazelchat.Standard contractual clauses in Backblaze's data processing addendum; archives are encrypted before upload with a key Backblaze does not hold.
OpenRouter, Inc., 169 Madison Avenue, New York, NY 10016, USA, and the model provider selected by the controller from the list offered in the product — currently models from OpenAI, DeepSeek, Mistral, Google, MiniMax, Alibaba, Moonshot AI, Z.ai, xAI and Anthropic, each reached through an OpenRouter route without data retention; for open-weight models that route is operated by a hosting provider on OpenRouter's platform.AI evidence selection, only when the controller enables it. Question text and up to eight retrieved passages; no contact details or identifiers.Standard contractual clauses approved by the European Commission (Art. 46 GDPR) in OpenRouter's data processing agreement.

Brevo (Sendinblue SAS, France) sends the controller's enquiry notifications; these contain no visitor data. Better Stack monitors public availability and receives no visitor data. Both are therefore not subprocessors of visitor data and are listed in the privacy notice for transparency.

Annex 2 — Technical and organisational measures