Third Party Index

Snapshot 24991

Document
Subprocessor list
URL
https://plugand.ai/dpa.html#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
23692 bytes
SHA-256 (raw)
0d9abc9c4c923d9f3fccb9298a69c6e72cab56c630ca4e1361693a53fe9ba6e7
SHA-256 (normalized text)
dc6c5381d64da0925f2f2af7e7f3d9d2ada77b2ada691c9cc0ca6cdab34598a6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Processing Agreement
Version 1.1 — Last Updated: September 19, 2026
Scope: the embeddable PLAI.chat widget only. This agreement is for website operators who embed our chat widget on their own website with a <script> tag. In that arrangement you are the controller of the personal data of your website's visitors and we act as your processor.
It does not govern your own use of the Slack app, the Microsoft Teams app, or plai.chat as an end user — for those, our Privacy Policy and Terms of Service apply and we are the controller of your account data.
1. Parties and Acceptance
This Data Processing Agreement ("DPA") is entered into between the legal entity operating the website on which the widget is embedded ("Customer", the controller) and Plug and AI ("Processor", "we", "us"). It forms part of, and is subject to, our Terms of Service.
The DPA takes effect when the Customer creates an embed key and deploys the widget on a website they operate. A countersigned copy naming the Customer's legal entity can be requested at any time via our Support page; where a Customer's own DPA or supplementary terms are required, send them with that request.
2. Subject Matter and Details of Processing
Required by Article 28(3) GDPR:
Subject matter: provision of an AI chat assistant embedded in the Customer's website.
Duration: for as long as the Customer's embed key is active, plus the short retention periods in Section 8.
Nature and purpose: receiving a visitor's message and page context, transmitting it to an AI model provider, returning the generated response, and operating abuse prevention, rate limiting and billing for the service.
Types of personal data: the content of messages a visitor chooses to send (which may contain personal data if the visitor includes it); the URL and title of the page the widget is embedded on; the origin of the embedding website; the visitor's IP address; a randomly-generated, short-lived visitor session identifier; and any files a visitor attaches. We do not ask visitors for names, email addresses or account credentials in the widget's anonymous mode.
Categories of data subjects: visitors to the Customer's website who interact with the widget.
Special categories of data: not requested and not required by the service. A visitor may nevertheless type such data into a message; the Customer is responsible for the instructions and prompts it configures, and should not configure the widget to solicit special category data.
3. Our Obligations as Processor
Documented instructions. We process personal data only on the Customer's documented instructions, which consist of this DPA, the Terms of Service, and the configuration the Customer sets for its embed key (allowed origins, system prompt, enabled features, page-context settings). We will inform the Customer if, in our opinion, an instruction infringes applicable data protection law.
Confidentiality. Personnel authorised to process the data are bound by confidentiality obligations.
Security. We implement the technical and organisational measures described in Annex II (Article 32 GDPR).
Assistance. Taking into account the nature of the processing, we assist the Customer with responding to data subject requests (Articles 12–23) and with its obligations under Articles 32–36, including breach notification and data protection impact assessments.
Deletion and return. On termination we delete personal data as set out in Section 8.
Audit information. We make available the information necessary to demonstrate compliance with Article 28 and allow for audits as described in Section 9.
4. Customer Obligations
The Customer is responsible for having a lawful basis for the processing, for informing its website visitors that the widget is provided by a third party (the widget itself carries a visible "Powered by plai.chat" label to support this), for the accuracy of the instructions and prompts it configures, and for keeping its embed key and allowed-origin list accurate.
5. Sub-processors
The Customer grants a general authorisation for us to engage the sub-processors listed in Annex I. We impose data protection obligations on each sub-processor no less protective than those in this DPA and remain fully liable for their performance.
We announce any addition or replacement of a sub-processor on this page on the day it starts processing. The Customer may object on reasonable data protection grounds at any time thereafter via our Support page; if the objection cannot be resolved, the Customer may terminate the affected service without penalty and we will delete the personal data processed by the sub-processor objected to, in line with Section 8.
Annex I — Sub-processors
Sub-processor	Purpose	Location
OpenRouter, Inc.	Gateway to AI model providers — message content is transmitted here and routed onward to the selected model provider	USA
AI model providers reached through OpenRouter (OpenAI, Anthropic, Google and others, depending on the model configured for the key)	Generating the response to a visitor's message	Varies by provider
TypeSafe (Jev model)	Classifying what a message is asking for, so the service can offer the right tools and models. Receives the text of up to the three most recent user messages in the conversation and one boolean flag; never the assistant's replies, attachments, email addresses or account identifiers. Not used where Zero Data Retention is enabled. plai.chat only — not the Slack or Microsoft Teams apps	USA
Salesforce, Inc. (Heroku)	Application hosting	USA
Cloudflare, Inc.	CDN, bot protection (Turnstile), and the D1 database holding embed configuration and usage records	Global edge; database primary in the EU
Stripe, Inc.	Payment processing for the account paying for the widget (billing data only — never visitor conversation content)	USA / EU
Mailgun (Sinch)	Transactional email (sign-in links, service notifications) — used only if a visitor chooses to sign in with an email address	EU / USA
The specific AI model provider used depends on the model chain configured for the embed key. Current model list: OpenRouter Models. Where a model supports Zero Data Retention and it is enabled, OpenRouter and the downstream provider are instructed not to store the data or use it for training; see our Privacy Policy for the limits of that guarantee.
6. International Transfers
Some sub-processors are located outside the EEA. Transfers to them are made on the basis of the European Commission's Standard Contractual Clauses (Decision 2021/914) or another valid transfer mechanism available to that sub-processor, together with the technical measures in Annex II (transport encryption and data minimisation). The Customer authorises us to enter into Standard Contractual Clauses with sub-processors on its behalf for this purpose.
7. Personal Data Breaches
We notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer's data, including the information available to us under Article 33(3) and the measures taken or proposed. Notification is sent to the email address on the Customer's account.
8. Retention and Deletion
Conversation content is not stored on our servers. Messages are processed in memory to generate a response and to provide conversational context, then discarded. Within the widget, a visitor's conversation is stored in that visitor's own browser storage, which we cannot read.
Visitor sessions exist in server memory for up to 2 hours and are destroyed on expiry or on restart.
Usage and abuse-prevention records (timestamp, embed key, model, cost, a truncated hash of the session identifier — no message content) are retained while the Customer's account is active, for billing, abuse investigation and accounting purposes, and are deleted on request except where statutory accounting retention applies.
Application logs containing IP addresses are retained for up to 7 days.
On termination or on the Customer's written request, we delete the embed configuration and remaining personal data within 30 days, except where retention is required by law (for example accounting records).
9. Audits
On reasonable written request, and no more than once per year unless required by a supervisory authority or following a breach, we provide the information necessary to demonstrate compliance with this DPA and respond to a reasonable security questionnaire. On-site audits may be conducted where legally required, subject to reasonable notice, confidentiality, and the Customer bearing its own costs.
10. Annex II — Technical and Organisational Measures
Encryption in transit: HTTPS/TLS for all connections between the visitor's browser, our servers and every sub-processor.
Data minimisation: no persistent server-side storage of conversation content; the page context sent to the model is limited to the page URL, title and what the Customer explicitly supplies; the visitor session identifier is random and unlinked to any account.
Isolation: the widget runs in a cross-origin iframe with a restrictive Content-Security-Policy: frame-ancestors allowlist, so the host page cannot read the conversation and the widget cannot read the host page.
Access control: administrative access to production systems is limited to authorised personnel using individual accounts and multi-factor authentication where supported by the platform.
Abuse prevention: Cloudflare Turnstile bot verification, per-key and per-network rate limiting, server-side origin verification, and configurable spending caps.
Segregation: each embed key has its own configuration, origin allowlist and usage records.
Resilience: managed hosting and a managed database with provider-side backups.
11. Order of Precedence and Changes
In case of conflict between this DPA and the Terms of Service, this DPA prevails for matters of personal data processing. We may update this DPA where required by law or by a change to the service; material changes and sub-processor changes are announced on this page as set out in Section 5.
12. Contact
For data protection matters, a countersigned copy of this DPA, or a sub-processor objection, please use our Support page.