Legal

Data Processing Addendum

Last updated · October 2, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Chair (“Chair”, “Processor”) and the business that uses the Service (“Customer”, “Controller”). It applies when Chair processes Personal Data on the Customer’s behalf. If this DPA conflicts with the Terms, this DPA prevails for the processing of Personal Data.

The Customer accepts this DPA by accepting the Terms. A countersigned copy is available on request at privacy@usechair.app.

01

Definitions

  • Data Protection Laws — all laws that apply to the processing of Personal Data under the Terms, including U.S. state privacy laws (such as the California Consumer Privacy Act as amended by the CPRA), the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and Brazil’s Lei Geral de Proteção de Dados, Law 13,709/2018 (“LGPD”).
  • Personal Data — any information relating to an identified or identifiable person that Chair processes on the Customer’s behalf through the Service, including Customer Data as defined in the Terms.
  • Data Subject — the person the Personal Data relates to, mainly the Customer’s clients and team members.
  • Sub-processor — a third party Chair engages to process Personal Data.
  • Security Incident — a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
  • “Controller”, “processor”, “processing”, “business”, “service provider”, “controlador” and “operador” have the meanings given in the Data Protection Laws.
02

Roles

  • The Customer is the controller (controlador under the LGPD; business under U.S. state laws) and Chair is the processor (operador; service provider).
  • For account, billing, security and usage information about the Customer and its team members, Chair acts as an independent controller, as described in the Privacy Policy.
03

Customer obligations

The Customer:

  • is responsible for the lawfulness of the Personal Data it provides and for having a valid legal basis, including any consent needed to call, text, message and record Data Subjects;
  • gives Data Subjects the notices required by law, including that it uses Chair to answer and manage communications;
  • configures the Service (recording, reminders, retention, permissions) in line with its obligations;
  • does not instruct Chair to process Personal Data in violation of Data Protection Laws.
04

Chair’s obligations

Chair:

  • processes Personal Data only on the Customer’s documented instructions. The Terms, this DPA and the Customer’s settings and actions in the Service are the Customer’s complete instructions. Chair will tell the Customer if it believes an instruction violates Data Protection Laws;
  • does not sell or share Personal Data, does not use it for targeted advertising, and does not retain, use or disclose it outside the direct business relationship with the Customer, except as permitted by Data Protection Laws;
  • does not combine Personal Data with personal data it receives from other sources, except as needed to provide the Service;
  • does not use Personal Data to train general-purpose AI models, and requires its AI model providers not to do so;
  • ensures people authorized to process Personal Data are bound by confidentiality;
  • implements the security measures in Annex 2;
  • notifies the Customer if it can no longer meet its obligations under U.S. state privacy laws.
05

Details of processing

06

Sub-processors

  • The Customer gives general authorization for Chair to engage Sub-processors. The current list is in Annex 3.
  • Chair will notify the Customer by email at least 30 days before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a refund of prepaid fees for the remaining period.
  • Chair imposes data protection obligations on each Sub-processor that are no less protective than this DPA and remains responsible for their performance.
07

Data location and international transfers

  • Chair stores Personal Data, including recordings and backups, in the United States (Northern Virginia).
  • Some Sub-processors may process Personal Data in other countries to deliver their part of the Service, as listed in Annex 3.
  • For transfers of Personal Data subject to the GDPR, UK GDPR, Swiss law or the LGPD to countries without an adequacy decision, the parties agree that the following are incorporated by reference:
    • EU: the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), with Clause 7 included, Option 2 of Clause 9 (general authorization, 30 days’ notice), the optional language in Clause 11 omitted, Clauses 17 and 18 governed by the law and courts of Ireland, and Annexes completed by Annexes 1–3 of this DPA;
    • UK: the International Data Transfer Addendum issued by the UK Information Commissioner, completed with the information in this DPA;
    • Switzerland: the EU clauses above, with the Swiss FDPIC as competent authority and references to the GDPR read as references to the Swiss FADP;
    • Brazil: the standard contractual clauses approved by ANPD Resolution CD/ANPD No. 19/2024, completed with the information in this DPA.
  • If an approved transfer mechanism is invalidated, the parties will cooperate to put an alternative in place.
08

Data Subject requests

Chair will promptly forward to the Customer any request it receives from a Data Subject about Personal Data and will not respond directly except to confirm the request was forwarded. Taking into account the nature of the processing, Chair will help the Customer respond — including through the Service’s features to view, correct, export and delete records — within the time limits of the applicable Data Protection Laws.

09

Security Incidents

  • Chair will notify the Customer without undue delay, and in any case within 48 hours, after confirming a Security Incident affecting the Customer’s Personal Data.
  • The notice will describe, as far as known, the nature of the incident, the categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed. Chair will update the Customer as more information becomes available.
  • Chair will take reasonable steps to contain and remedy the incident and help the Customer meet its notification obligations to authorities and Data Subjects.
  • Notification is not an admission of fault.
10

Assistance, records and audits

  • Chair will provide reasonable assistance with data protection impact assessments and prior consultations with authorities, to the extent related to the Service.
  • On written request, no more than once a year, Chair will provide information reasonably necessary to demonstrate compliance with this DPA, such as a completed security questionnaire and a summary of its Sub-processors’ certifications (for example SOC 2 and ISO 27001 reports).
  • If that information is insufficient, or if required by a supervisory authority, the Customer may conduct an audit with 30 days’ notice, during business hours, at its own cost, by an independent auditor bound by confidentiality, in a way that does not disrupt the Service or compromise other customers’ data.
11

Return and deletion

  • During the term, the Customer can view, export and delete Personal Data in the Service.
  • When the Customer deletes its account or the Terms end, Chair deletes Personal Data from active systems within 30 days and from backups within 90 days, unless law requires retention. Call recordings are kept for 12 months unless the Customer deletes them sooner.
  • On request made before deletion, Chair will provide an export of the Customer’s Personal Data in a commonly used format.
12

Liability and general

  • Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws do not permit limitation.
  • This DPA is governed by the law that governs the Terms (Delaware), except where the transfer mechanisms in Section 7 require otherwise.
  • Chair may update this DPA to reflect changes in law or the Service. Changes will not reduce the overall protection for Personal Data, and Chair will notify the Customer at least 30 days before material changes take effect.
Annex 1

Parties

Controller / data exporter: the Customer identified in its Chair account. Contact: the Account Owner’s email. Role: controller.

Processor / data importer: Chair, usechair.app. Contact: privacy@usechair.app. Role: processor.

Description of the processing and transfer: see Section 5. Competent supervisory authority: the authority of the EU Member State where the Customer is established, or as determined under Clause 13 of the EU clauses.

Annex 2

Security measures

  • Encryption: TLS 1.2+ in transit; AES-256 at rest for databases, recordings and backups.
  • Hosting: United States (Northern Virginia), in data centers with independently audited physical and environmental controls.
  • Access control: least-privilege access for Chair personnel, multi-factor authentication for Chair’s own administrative access to production systems, access logging and periodic review.
  • Customer-side controls: role-based permissions, optional two-factor authentication (which the Customer can require for its whole team), session management, login history and alerts for suspicious sign-ins.
  • Separation: logical separation of each customer’s data.
  • Availability: automated backups, tested restores, monitoring and alerting.
  • Application security: secure development practices, dependency updates, vulnerability scanning and prompt patching.
  • AI safeguards: only the data needed for a conversation is sent to AI model providers, under terms that prohibit training on it and limit their retention to 30 days for abuse monitoring; escalation rules route refunds, complaints and health-related messages to people.
  • Messaging compliance: automatic processing of STOP opt-outs; call recording notices when recording is enabled; quiet hours.
  • Incident response: documented process for detection, containment, investigation and notification.
  • Personnel: confidentiality obligations and data protection training.
Annex 3

Sub-processors

Integrations the Customer chooses to connect (for example Google Calendar, Microsoft Outlook Calendar, Square) are not Chair’s Sub-processors. Data exchanged with them is governed by the Customer’s own agreement with that provider.