Data processing agreement
Last updated 30 September 2026
We’re finishing registering our business details. Our business address and our ICO registration number will appear here shortly.
The short version
- This agreement applies automatically when you use Chatterbell. There’s nothing to sign.
- Your visitors’ data is yours. We process it only to run your chat, only on your instructions, and we never sell it.
- We tell you about new sub-processors in advance, help you answer data requests, and report any breach quickly.
- You tell your visitors that you use Chatterbell. Here’s wording you can copy.
Who this is between
This data processing agreement (“DPA”) is between the business using Chatterbell (“you”, the controller) and Matthew Cooke, a sole trader trading as Chatterbell, United Kingdom (“we”, the processor). It forms part of our terms of service and meets the requirements of Article 28 of the UK GDPR (and the EU GDPR where that applies to you). If this DPA and the terms disagree about personal data, this DPA wins.
What we process
| Purpose | Providing Chatterbell to you: showing your chat, storing and delivering messages and files, AI answers, alerts, reports, exports and support. |
|---|---|
| People | Your website visitors and customers who use your chat, and the people on your team. |
| Personal data | Names, email addresses and phone numbers people give; messages, photos and files; pages viewed during a chat; browser, device, language, time zone and approximate country; conversation IDs; team members’ names, photos and job titles. |
| Special category data | None intended. Don’t ask for it in chat. If a visitor volunteers it, we handle it with the same protections. |
| How long | For as long as you use Chatterbell, within your plan’s history limit, until you delete it, or until we delete it at the end of the agreement. |
What we promise
- Your instructions only. We process your personal data only to provide Chatterbell, as set by your settings and use of the service, unless the law requires otherwise (and then we’ll tell you, unless the law forbids it).
- Confidentiality. Anyone who can access your data is bound by confidentiality.
- Security. We keep the measures in the security annex in place, and improve them over time.
- Sub-processors. You authorise the sub-processors listed below. Before adding or replacing one, we’ll give at least 30 days’ notice (by email and on this page). If you object on reasonable data protection grounds and we can’t resolve it, you can cancel and get a pro-rata refund. Each sub-processor is bound by written terms that protect your data at least as well as this DPA.
- Helping with requests. Chatterbell lets you find, export and delete any visitor’s data yourself. If you need more help to respond to a request or a regulator, we’ll give it.
- Breaches. If we become aware of a personal data breach affecting your data, we’ll tell you without undue delay, and within 48 hours, with what we know and what we’re doing about it.
- Assessments. We’ll give you the information you reasonably need for a data protection impact assessment or prior consultation.
- Deletion at the end. When your account is closed, you can export your data first. We delete it within 30 days, and it leaves our encrypted backups within 12 months.
- Evidence. We’ll give you the information you reasonably need to show we meet this DPA, and answer reasonable questions. Where that isn’t enough, you can arrange an audit on reasonable notice, at your cost, and no more than once a year.
International transfers
We store your data in the UK, with encrypted backups in the EU. Where a sub-processor outside the UK and EU is involved (see below), transfers rely on the UK-US data bridge where the provider is certified, or on the UK International Data Transfer Addendum to the EU standard contractual clauses (and those clauses themselves for EU data), with extra measures where needed.
Sub-processors
| Provider | What for | Where |
|---|---|---|
| Hostinger International Ltd | Server hosting: the app, database and files | United Kingdom |
| Hetzner Online GmbH | Encrypted off-site backups | European Union |
| Anthropic PBC | AI answers (only if you turn them on): recent chat messages and relevant passages from your website and notes | United States |
| Resend Inc. | Sending emails: alerts, replies to visitors who left, transcripts | United States |
| Cloudflare Inc. | Domain name service (DNS) for chatterbell.com | Global |
When card payments launch we’ll add our payment provider here, with the usual notice. It will handle only your account’s billing details, not your visitors’ data.
What you promise
- You have a lawful basis for the chats on your website and give your visitors the information the law requires, including that you use Chatterbell.
- Your instructions to us (through your settings and use of Chatterbell) are lawful.
- You don’t use the chat to collect payment card details, passwords, or special category data without proper safeguards.
Wording for your own privacy policy
You can copy this into your privacy policy and change it to suit your business:
Live chat. Our website has a live chat provided by Chatterbell. If you use it, we receive your messages and any details you choose to give (such as your name, email address, photos or files), along with the page you’re on and basic information about your browser and device. We use this to answer your questions and to follow up if you ask us to. Some common questions may be answered by an AI assistant, which is clearly labelled, and you can ask to speak to a person at any time. The chat stores a random conversation ID in your browser only after you send a message, so the conversation continues as you move around our site. Chatterbell processes this information on our behalf and stores it in the UK. We keep chats for [how long] and you can ask us for a copy, or for them to be deleted, at any time.
Security annex
- All connections to Chatterbell are encrypted with HTTPS/TLS. Real-time chat connections are encrypted too.
- Passwords are stored only as salted scrypt hashes. Login sessions use random tokens stored as hashes, and sign-out ends them.
- Each workspace’s data is separated and every request checks you belong to that workspace. Cross-site requests are blocked.
- Uploaded files are checked by their actual contents, limited in type and size, served from unguessable addresses, and sandboxed so they can’t run as web pages.
- The app runs as an unprivileged, sandboxed service with no access to the rest of the server. Access to our servers is restricted to the people who run Chatterbell.
- Every night we back up the database and files. The off-site copy is encrypted (AES-256) before it leaves the server, and we test that backups can be read.
- Rate limits protect against abuse. The AI’s website reader can’t be pointed at private networks.
- We keep software up to date, record important admin actions, and only give access to people who need it.