1. Parties
This Data Processing Agreement ("DPA") is entered into between:
- Data Processor:Corebee Chat LTD ("Corebee," "Processor," "we," or "us"), the provider of the Corebee customer support platform.
- Data Controller:The customer ("Controller," "you," or "your") who has entered into a service agreement with Corebee and determines the purposes and means of the processing of personal data.
This DPA forms an integral part of the Terms of Service between the parties and is governed by the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and other applicable data protection legislation.
2. Definitions
- "Controller" means the customer who determines the purposes and means of the processing of personal data.
- "Processor" means Corebee, which processes personal data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on personal data, including collection, storage, alteration, retrieval, use, disclosure, or deletion.
- "Sub-processor" means any third party engaged by the Processor to process personal data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
3. Subject Matter and Duration
Subject Matter
This DPA governs the processing of personal data by the Processor on behalf of the Controller through the Corebee customer support platform. The Processor shall process personal data solely for the purpose of fulfilling its obligations under the service agreement.
Duration
This DPA shall remain in effect for the duration of the service agreement between the Controller and the Processor, and shall automatically terminate upon the expiration or termination of the service agreement, subject to the data deletion obligations set out in Section 14.
4. Nature and Purpose of Processing
The Processor processes personal data on behalf of the Controller for the following purposes:
- Providing AI-powered customer support services, including automated responses and conversation routing
- Storing and managing support conversations across channels (live chat, email, WhatsApp, social media)
- Managing customer contact records and conversation history
- Maintaining and serving knowledge base content for AI training and self-service
- Providing analytics, reporting, and performance metrics on support operations
- Delivering website actions and in-app engagement features
5. Types of Personal Data
The following categories of personal data may be processed under this DPA:
- Customer names and display names
- Email addresses
- Phone numbers
- Conversation content (messages, attachments, and support ticket details)
- IP addresses
- Device information (browser type, user agent strings, operating system)
- Usage data (pages visited, click events, session information)
- Cookie identifiers and tracking pixels
- Custom data fields defined by the Controller (e.g., account IDs, plan information, custom attributes)
6. Categories of Data Subjects
The personal data processed under this DPA relates to the following categories of data subjects:
- End-users and customersof the Controller's business who interact with the support widget, submit support requests, or communicate through channels managed by Corebee
- Controller's team members (agents, administrators) who use the Corebee platform to provide support
7. Sub-processors
The Controller provides general authorization for the Processor to engage sub-processors. Each sub-processor has entered into a data processing agreement with Corebee that includes obligations no less protective than those set out in this DPA.
| Sub-processor | Purpose | Location | Transfer Mechanism | DPA |
|---|
| Supabase, Inc. | Database hosting, authentication, realtime subscriptions, file storage | India (AWS ap-south-1, Mumbai) | SCCs | Link |
| Vercel, Inc. | Application hosting, serverless functions (deployed to a single region; static assets served via Vercel's global CDN edge) | India (Mumbai, bom1) + global CDN edge | SCCs | Link |
| Resend, Inc. | Transactional email delivery (notifications, system emails) | United States | DPF + SCCs | Link |
| OpenAI, LLC | AI model inference for generating support responses | United States | DPF + SCCs | Link |
| Anthropic, PBC | AI model inference for generating support responses | United States | DPF + SCCs | Link |
| Stripe, Inc. | Payment processing, subscription billing | United States | DPF + SCCs | Link |
| Polar.sh (Polar Software Inc.) | Billing and subscription management | United States | SCCs | On request |
| Cloudflare, Inc. | CDN, DDoS protection, DNS, security services, browser rendering | Global | DPF + SCCs | Link |
| Google LLC | Website analytics (Google Analytics 4), advertising conversion measurement (Google Ads) | United States | DPF + SCCs | Link |
| PostHog Inc. | Product analytics and session replay (PostHog) | Germany (EU Cloud, Frankfurt) | SCCs | Link |
| Functional Software, Inc. (Sentry) | Application error monitoring and performance tracing | United States | DPF + SCCs | Link |
| Meta Platforms, Inc. | Advertising conversion tracking (Meta Pixel, Conversions API) | United States | DPF + SCCs | Link |
Transfer Mechanisms: "SCCs" refers to the Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914) — these are our primary transfer mechanism for personal data leaving the EEA, including transfers to our Indian hosting providers and any US-located sub-processor. "DPF" refers to the EU-U.S. Data Privacy Framework, under which the sub-processor has additionally self-certified; the DPF only covers transfers to the United States and is not the mechanism relied on for transfers to India.
Sub-processor Change Notification
Corebee will notify the Controller at least 30 days in advance of any intended changes to the list of sub-processors, including additions or replacements, by email to the Controller's registered account address.
If the Controller objects to a new sub-processor on reasonable grounds related to data protection, the Controller may notify Corebee in writing within 14 days of receiving the notification. In such case, Corebee will use reasonable efforts to make available a change in the service that avoids processing by the objected-to sub-processor. If no such alternative is reasonably available, either party may terminate the affected service by providing written notice.
8. Security Measures
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, in accordance with Article 32 of the GDPR. These measures include:
Encryption
- At rest: AES-256-GCM encryption for all personal data stored in databases and file storage
- In transit: TLS 1.3 encryption for all data transmitted between clients, servers, and sub-processors
Access Controls
- Row-Level Security (RLS) for strict tenant isolation between customer organizations, ensuring no cross-tenant data access
- Role-based access controls (RBAC) with principle of least privilege for all personnel
- Multi-factor authentication required for administrative access
Monitoring and Protection
- Comprehensive audit logging of all data access and administrative operations
- Server-Side Request Forgery (SSRF) protection on all server-side HTTP requests
- Regular security assessments and vulnerability monitoring
- Automated threat detection and DDoS protection via Cloudflare
For more details on our security practices, please visit our Security page.
9. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under Chapter III of the GDPR, including:
- Right of access (Article 15) -- the right to obtain confirmation of processing and a copy of personal data
- Right to rectification (Article 16) -- the right to correct inaccurate personal data
- Right to erasure(Article 17) -- the right to have personal data deleted ("right to be forgotten")
- Right to data portability (Article 20) -- the right to receive personal data in a structured, commonly used, machine-readable format
- Right to restriction of processing (Article 18) -- the right to restrict processing under certain circumstances
- Right to object (Article 21) -- the right to object to processing based on legitimate interests
The Processor commits to responding to data subject right requests forwarded by the Controller within 72 hoursof receipt, and to completing the requested action without undue delay. If the Processor receives a data subject request directly, it shall promptly inform the Controller and shall not respond to the request without the Controller's prior authorization, unless required by applicable law.
10. Breach Notification
In the event of a personal data breach, the Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
The notification shall include:
- A description of the nature of the personal data breach, including the categories and approximate number of data subjects and records concerned
- The name and contact details of the Processor's data protection point of contact
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects
The Processor shall cooperate with and assist the Controller in relation to any investigation, mitigation, or remediation of the breach, and shall take all reasonable steps to contain and remedy the breach.
11. Data Retention
The Processor retains personal data only for as long as necessary to fulfill the purposes described in this DPA or as required by applicable law.
- Configurable retention: Data retention periods are configurable per organization through the Corebee platform settings, allowing the Controller to define retention policies that align with their own data governance requirements.
- Default retention: In the absence of a custom configuration, the default data retention period is 2 years from the date of last activity.
- Auto-deletion: The Controller may enable automatic deletion of personal data after the configured retention period expires. When enabled, data is permanently and irreversibly deleted from all primary and backup storage.
- Manual deletion: The Controller may request deletion of specific data at any time through the platform interface or by contacting Corebee support.
12. International Data Transfers
Primary hosting location. Personal data processed under this DPA is hosted in India (Mumbai): the application and serverless functions run on Vercel's bom1 region, and the primary database runs on Supabase / AWS ap-south-1. Additional sub-processors listed in Section 7 operate in the United States, the European Union, or globally, as indicated in the "Location" column.
India has not received an adequacy decision from the European Commission. Transfers to India and any onward transfer to the United States are therefore third-country transfers under Chapter V of the GDPR. Where personal data is transferred from the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs): The Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914) are the primary transfer mechanism for personal data leaving the EEA, including transfers to our Indian hosting providers (Vercel Mumbai, Supabase Mumbai). The Controller may request a copy of the applicable SCCs by contacting us.
- EU-U.S. Data Privacy Framework (DPF): Where a US sub-processor listed in Section 7 has self-certified under the EU-U.S. Data Privacy Framework as administered by the U.S. Department of Commerce, we additionally rely on that certification. The DPF does not cover transfers to India and is therefore not the mechanism we rely on for the Vercel Mumbai or Supabase Mumbai hosting tier.
- UK International Data Transfer Agreement:For transfers from the United Kingdom, we rely on the UK Addendum to the EU SCCs, as approved by the UK Information Commissioner's Office (ICO).
- Transfer Impact Assessment (TIA):For each third-country transfer the Processor performs a Transfer Impact Assessment covering the destination country's surveillance laws, the practical likelihood of access by public authorities, and the supplementary technical and organisational measures in place (encryption in transit, encryption at rest, row-level tenant isolation, role-based access controls). A summary is available alongside other security disclosures at /security.
The Processor shall ensure that any onward transfer of personal data to a third country or international organization is subject to appropriate safeguards in accordance with Chapter V of the GDPR.
13. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 of the GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller.
- The Controller shall provide the Processor with reasonable prior written notice (at least 30 days) of any audit request, unless a shorter period is required by a supervisory authority.
- Audits shall be conducted during normal business hours, shall not unreasonably interfere with the Processor's business operations, and shall be subject to reasonable confidentiality obligations.
- The Controller shall bear the cost of any audit, except where the audit reveals material non-compliance by the Processor.
- The Processor may satisfy audit requests by providing relevant certifications, reports from independent third-party auditors (such as SOC 2 reports), or by making available written responses to reasonable audit questionnaires.
14. Termination and Data Deletion
Upon termination or expiration of the service agreement, the Processor shall, at the Controller's election:
- Return all personal data to the Controller in a structured, commonly used, and machine-readable format (e.g., JSON or CSV export); or
- Delete all personal data, including all existing copies, from all systems and storage, unless retention is required by applicable law.
The Controller shall communicate its choice within 30 days of termination. In the absence of instructions, the Processor shall delete all personal data within 30 days of the termination date. The Processor shall provide written confirmation of deletion upon request.
15. Processor Obligations
Corebee, as the Processor, shall:
- Process personal data only on documented instructions from the Controller, unless required by applicable law, in which case the Processor shall inform the Controller of that legal requirement before processing (unless prohibited from doing so)
- Ensure that all personnel authorized to process personal data are bound by appropriate obligations of confidentiality
- Implement and maintain the technical and organizational security measures described in Section 8
- Not engage any sub-processor without the general or specific prior written authorization of the Controller, subject to the notification requirements in Section 7
- Assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor
- Immediately inform the Controller if, in its opinion, an instruction from the Controller infringes the GDPR or other applicable data protection provisions
16. Governing Law
This DPA shall be governed by and construed in accordance with the laws that govern the service agreement between the parties. To the extent that a conflict arises between this DPA and the service agreement, the provisions of this DPA shall prevail with respect to matters relating to the processing of personal data.
17. Contact
For questions about this Data Processing Agreement, to submit a DPA-related request, or to exercise audit rights, please contact us at jonathan@corebee.ai.