Data Processing Agreement

Last updated: September 9, 2026

This Data Processing Agreement (“DPA”) summarizes the terms that apply whenever Bubagent processes personal data of a Customer’s End Visitors on the Customer’s behalf, as required by Article 28 of the EU/UK GDPR and similar laws. It supplements our Terms of Service. Customers who need a counter-signed version for their own compliance records can request one — see below.

Purpose & scope

This DPA applies whenever personal data that originates from a Customer’s End Visitors (chat messages, lead-capture details, uploaded files) is processed through the Service. It does not cover a Customer’s own account data, for which Bubagent acts as an independent controller under our Privacy Policy.

Roles of the parties

For End Visitor personal data, the Customer is the data controller(or “business” under the CCPA) — it’s the Customer’s website, the Customer’s relationship with its visitors, and the Customer who decides what the agent is trained on and how it’s configured. Bubagent is the data processor(or “service provider”) — we process that data only to provide the Service, and only on the Customer’s documented instructions as expressed through their account configuration and our Terms of Service.

Subject matter, nature & duration

  • Subject matter: provision of an AI chat widget, knowledge base, and related dashboard features.
  • Nature & purpose: receiving, storing, and routing End Visitor chat content and lead-capture details to generate and deliver agent replies, and to provide conversation history back to the Customer.
  • Categories of data subjects: the Customer’s website visitors who interact with the embedded agent.
  • Categories of personal data: chat message content, optionally a name and email address, optionally uploaded files/images, and a device-generated visitor/session identifier.
  • Duration: for as long as the Customer’s account is active and retains the data, per our retention terms.

Sub-processors

The Customer generally authorizes Bubagent’s use of sub-processors to provide the Service, listed in full in our Privacy Policy (currently: Anthropic, OpenAI, Neon, Vercel, Cloudflare, Stripe, Resend, Upstash, and Sentry). We'll update that list if it changes and, on request, notify a Customer who has asked to be informed of new sub-processors.

Security measures

Bubagent maintains technical and organizational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest for particularly sensitive stored credentials, access controls restricting production data access to personnel who need it, and rate-limiting against abusive traffic. See our Privacy Policy for more detail.

International transfers

Where End Visitor personal data originating in the EEA, UK, or Switzerland is transferred to the United States (where Bubagent and most of its sub-processors operate), that transfer is made subject to Standard Contractual Clauses and/or a relevant Data Privacy Framework certification, as described in our Privacy Policy.

Breach notification & assistance

Bubagent will notify affected Customers without undue delay after becoming aware of a confirmed security incident affecting their End Visitors’ personal data, and will provide reasonably requested information and cooperation to help the Customer meet its own notification obligations to regulators or data subjects.

Requesting a signed copy

This page is a summary of our standard DPA terms. If your organization requires a formally executed copy, a specific SCC module annex, or has questions about a particular sub-processor, email legal@bubagent.comand we’ll follow up.