Legal

Data Processing Addendum

Last updated 11 September 2026. This DPA is between the customer (Controller) and AnswerTide (Processor).

Scope

The Processor hosts the AnswerTide service and processes visitor conversations, citations, handoff transcripts, and account data on the Controller's behalf to provide the service described in the Terms.

Instructions

The Processor processes personal data only on documented instructions from the Controller: providing the widget, answering from the Controller's index, handoff, billing, and security. The Processor will not sell that data or use it to train a general model.

Security

Tenant isolation is enforced with Postgres row-level security. The widget request path does not use a service-role key. Crawled content is treated as untrusted input. Action endpoints are guarded against SSRF. Conversations are retained 12 months, then anonymized, unless the Controller deletes sooner.

Subprocessors

The current list is published at /subprocessors. The Processor will post updates there before a new subprocessor processes customer personal data.

Assistance, deletion, and audit

The Processor will assist with data-subject requests that the Controller cannot fulfill from the dashboard, delete or return personal data on request at the end of the service (demos are already hard-deleted at 7 days or on request), and make available information reasonably necessary to demonstrate this DPA.

International transfers

Infrastructure is hosted in the United States. If the Controller is subject to GDPR or similar law, the parties will execute standard contractual clauses on request. AnswerTide outbound email is US-only; this DPA does not change that.

Contact

privacy@answertide.com

Data Processing Addendum — AnswerTide