Impact AI Inc

    Business terms

    Data Processing Addendum

    Version 2026.10 — last updated September 24, 2026

    The controller-and-processor terms that apply to the visitor conversations and contact details we handle on your behalf. Accepted automatically as part of the Terms of Service.

    1. Roles of the parties

    For the personal information contained in your visitors' conversations and the contact details your bot collects ("Customer Personal Data"), you are the controller (or "business") and Impact AI Inc is the processor (or "service provider"). For your own account details — your name, email, billing record — we are the controller and our Privacy Policy applies.

    2. Subject matter, purpose and duration

    • Subject matter: hosting and operating your chatbots and the analysis you see about them.
    • Nature of processing: storing approved answers, matching incoming questions, recording conversations, generating bounded fallback replies, producing your reports.
    • Categories of data: visitor messages, and any name, email or phone number a visitor provides; technical data such as session identifiers and timestamps.
    • Categories of people: your website visitors and customers.
    • Duration: for as long as your account is active, plus the retention period described in our Privacy Policy.

    You must not send us special-category data (health, biometric, precise financial or government-identifier data) through chat, and you must configure your bot accordingly.

    3. Our obligations

    • We process Customer Personal Data only to provide the service and only on your documented instructions, including your settings in the product.
    • We do not sell it, share it for cross-context behavioural advertising, or use it for our own purposes.
    • We do not use it to train AI models.
    • Our staff access it only where needed to operate or support the service, under confidentiality obligations.
    • We will tell you if we believe an instruction would breach applicable data-protection law.

    4. Security measures

    • Encryption in transit (TLS) and at rest for stored data.
    • Row-level access rules in the database so each account can only reach its own records.
    • Authenticated access with per-request verification for every server operation.
    • Secrets, including any AI key you connect, stored separately with restricted access.
    • Least-privilege access for staff, logging of administrative access, and periodic review.
    • Managed infrastructure with automated backups and recovery procedures.

    5. Sub-processors

    You authorise us to use the sub-processors listed on our Sub-processor List. We impose data protection terms on each of them no less protective than this addendum, and we remain responsible for their performance. We will update that list before adding a new sub-processor and, if you object on reasonable data-protection grounds, you may end your subscription for the affected service.

    6. Helping with individual rights

    The product lets you find, export and delete visitor conversations and collected contact details yourself, which covers most access, correction and deletion requests. If you need help with a request you cannot fulfil in the product, contact legal@impactaiinc.com and we will assist within a reasonable time at no extra charge.

    7. Incident notification

    If we become aware of a personal-data breach affecting Customer Personal Data, we will notify you without undue delay and in any event within 72 hours of confirming it, describe what we know, and keep you updated as we investigate and remediate.

    8. Audits and records

    On reasonable written request, and no more than once a year unless required by a regulator, we will provide the information reasonably needed to demonstrate compliance with this addendum, including a description of our security measures and relevant records.

    9. International transfers

    Our infrastructure and sub-processors may process data in the United States and other countries. Where data protected by EU or UK law is transferred, the parties rely on the European Commission's Standard Contractual Clauses and the UK Addendum, which are incorporated here by reference, with Impact AI Inc as data importer and you as data exporter.

    9a. Retention, access and deletion requests

    • Conversations and contact details are kept while your account is active unless you set a shorter retention period for a bot, after which contact details are deleted automatically each day.
    • You can delete a visitor's collected details at any time from your bot's contact records.
    • When a visitor asks you to see, export or delete their information, you can do it from your dashboard, or ask us at the address below and we will help within 30 days.
    • If a visitor contacts us directly, we will pass the request to you as the controller.

    10. Return and deletion

    You can export your data at any time while your account is active. When your account ends, we delete or de-identify Customer Personal Data within a reasonable period, except where law requires us to keep it, in which case we keep only what is required and continue to protect it.

    11. General

    This addendum forms part of the Terms of Service. Where it conflicts with them on the handling of Customer Personal Data, this addendum prevails. It is governed by the laws of the State of Tennessee, United States, except where mandatory data-protection law requires otherwise.

    Questions about this document: legal@impactaiinc.com

    All agreements