How this agreement applies
This Data Processing Agreement (DPA) is part of our Terms of service. It applies automatically when you use SiteBrain to process personal data of your website's visitors. You do not need to sign anything. If you want a signed PDF copy, write to [email protected].
The parties are you, the customer, as controller, and Sebastian Czajkowski, sole trader, Rathgar, Dublin 6, D06 X294, Ireland, as processor. If this DPA and the Terms conflict on personal data, this DPA wins.
What we process
- Subject matter and duration: running your chatbot, for as long as your account exists, plus the deletion periods in our privacy policy.
- Nature and purpose: running the chatbot, answering your visitors, storing conversations and contact-form messages for your dashboard, emailing you contact-form messages, and forwarding a conversation to your own Telegram when you connect it.
- Data subjects: visitors who use your chatbot or its contact form.
- Categories of data: messages and anything a visitor types, a random visitor ID, the page address, the name, email, optional phone number and message from the contact form, a one-way hash of the IP address, and timestamps.
SiteBrain is not meant for special-category data (health, religion and the like). Do not set your bot up to ask for it.
Our commitments
- Only your instructions. We process the data only on your documented instructions: the Terms, this DPA and the settings you choose in the dashboard. If an instruction breaks the law, we will tell you.
- Confidentiality. Anyone with access to the data is bound to confidentiality. Today only the operator has access.
- Security. We apply the measures in section 5.
- Sub-processors. We use them on the terms in section 4.
- Requests from data subjects. We help you handle them. In the dashboard you can view and export conversations, and delete a conversation, a contact-form message or a bot. Requests that reach us, we forward to you.
- Breaches and impact assessments. If we become aware of a personal data breach, we tell you without undue delay. We also help with data protection impact assessments and prior consultation with a regulator, using the information available to us.
- At the end. We delete the data when you delete the bot or the account (export it first if you want to keep it). The database's restore history is gone within 30 days.
- Proof and audits. We give you the information you need to show compliance. We answer written questions. On-site or remote audits are possible by agreement, with reasonable notice, at your cost and no more than once a year, unless a regulator requires more or after a breach.
Sub-processors
You give general authorisation for the providers listed in our privacy policy. We email the address on your account at least 14 days before we add or replace one. You can object, and if we cannot resolve it, you can close the account with no further charge.
We pass the same data-protection obligations on to each sub-processor and stay responsible for them towards you.
Security measures
- all traffic runs over HTTPS,
- passwords are stored hashed,
- every dashboard request checks that the logged-in account owns the bot,
- rate limits and one-way hashing of visitors' IP addresses,
- data minimisation: no web server request logs, and automatic deletion periods,
- infrastructure on Cloudflare (DPF-certified, SCCs in its data processing addendum). Cloudflare encrypts the database and stored files at rest.
Transfers outside the EEA
Since 10 October 2026 the database (Cloudflare D1) and uploaded files (Cloudflare R2) are kept in Cloudflare's EU jurisdiction, with no read replication. The copy made before the move stays in the eastern United States as a fallback until 17 October 2026, then we delete it. Data still leaves the EEA for processing: the nearest Cloudflare data centre handles each request, and Workers AI can run outside the EU. Cloudflare is certified under the EU-U.S. Data Privacy Framework, and its customer data processing addendum includes the EU Standard Contractual Clauses. Google, Stripe and Resend are DPF-certified. OpenRouter is not; its data processing agreement includes the Standard Contractual Clauses. Firecrawl only receives public pages of a website we crawl with it. Telegram receives messages only if you connect your own Telegram. Details are in the privacy policy.
Liability and law
The liability limit and governing law in the Terms apply to this DPA. Questions: [email protected].
Write to [email protected] — we reply quickly, like humans.