Last updated: June 2026
This Data Processing Agreement ('DPA') is entered into between the Customer (data controller) and Alapchat (data processor).
This DPA applies to all processing of personal data by Alapchat on behalf of the Customer in connection with the Alapchat service. It remains in effect for the duration of the service agreement.
Alapchat processes personal data to provide the AI chatbot service, including:
We implement TLS 1.3 encryption in transit, AES-256 encryption at rest, row-level security for tenant isolation, and regular security assessments.
Alapchat uses the following sub-processors:
All data is processed within the European Union. No Standard Contractual Clauses are required.
Alapchat will notify the Customer of any personal data breach within 72 hours of becoming aware of it, in accordance with GDPR Art. 33.
The Customer has the right to audit Alapchat's data processing practices, subject to reasonable notice and confidentiality obligations.
Upon termination, Alapchat will return or delete all personal data within 30 days, unless retention is required by law.
Liability under this DPA is subject to the limitations set forth in the main service agreement.
For DPA-related inquiries, contact alapchat.com/contact.