Data Processing Addendum

The terms under which MapleChat processes personal data on your behalf.

Effective 2026-09-08

This addendum forms part of the Terms of Service and applies whenever MapleChat processes personal data on your behalf. Where it conflicts with the Terms, this addendum wins on data-protection matters.

Roles

You are the controller of the personal data in your workspace — your contacts, their messages, and the attributes you record about them. MapleChat is the processor of that data.

For your own account, billing and support records, MapleChat is a controller in its own right; those are covered by the Privacy Policy, not this addendum.

Scope of processing

Subject matter: provision of the MapleChat platform. Duration: for as long as your account is active, plus the deletion window in Data Deletion. Nature and purpose: storing, transmitting, routing and displaying conversation data so that you can communicate with your customers and automate replies. Types of data: phone numbers, names, contact attributes you define, message content, media, and message metadata. Categories of data subject: your customers and prospects, and your own team members.

You must not use MapleChat to process special categories of personal data — health, biometric, religious or similar — unless we have agreed to it in writing in advance.

Our obligations

We will:

  • process personal data only on your documented instructions, including for transfers, unless the law requires otherwise — in which case we will tell you before processing, where we may;
  • ensure the people who access personal data are bound by confidentiality;
  • implement appropriate technical and organisational measures, described on the Security page;
  • assist you, so far as is reasonable, with data-subject requests, impact assessments and regulator consultations;
  • notify you without undue delay after becoming aware of a personal data breach affecting your data, with the detail you need to meet your own notification duties;
  • delete or return personal data at the end of the service, per Data Deletion;
  • make available the information needed to demonstrate compliance, and allow audits as described below.

Subprocessors

You give us general authorisation to engage subprocessors. The current list is at Subprocessors. We impose data-protection obligations on each of them no less protective than these, and we remain liable to you for their performance. We will give notice before adding a new one, and you may object on reasonable data-protection grounds.

International transfers

Where personal data is transferred out of a jurisdiction that restricts transfers, we rely on a lawful transfer mechanism — standard contractual clauses or an adequacy decision — and on the safeguards our subprocessors provide.

Audits

On reasonable written notice, no more than once a year unless a regulator requires otherwise, we will provide the information reasonably needed to verify our compliance. Where documentation does not suffice, we will cooperate with an audit conducted at your cost, at a time that does not disrupt the service, and subject to confidentiality.

Deletion and return

On termination we delete personal data per Data Deletion, except where law requires retention. Ask us if you need a copy returned before deletion completes.

Liability

Liability under this addendum is subject to the limits in the Terms of Service.

Contact

privacy@maplechat.app