1. Introduction
This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Terms of Service (or applicable Order Form or written agreement) (the “Agreement”) between Hazen Technologies Inc, operator of the AnswerWeave service (“Processor” or “we”), and the customer identified in the Agreement (“Controller” or “you”). It reflects the parties' obligations under Applicable Data Protection Laws when we process Personal Data on your behalf in connection with the Service.
This DPA takes effect automatically for customers to whom Applicable Data Protection Laws apply. No signature is required for it to be binding; customers requiring a countersigned copy may request one at support@answerweave.ai. In the event of a conflict between this DPA and the Agreement or the Privacy Policy with respect to the processing of Personal Data, this DPA controls.
2. Definitions
Capitalised terms not defined below have the meanings given in the Agreement.
- Applicable Data Protection Laws means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including (a) the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”); (b) the UK GDPR and Data Protection Act 2018 (“UK GDPR”); (c) the Swiss Federal Act on Data Protection; (d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”); (e) other U.S. state comprehensive privacy laws (including the VCDPA, CPA, CTDPA, UCPA, TDPSA, and the Florida Digital Bill of Rights where applicable); (f) Canada's Personal Information Protection and Electronic Documents Act (PIPEDA); and (g) Brazil's Lei Geral de Proteção de Dados (LGPD).
- Personal Data means information relating to an identified or identifiable natural person (including “personal information” as defined under the CCPA) that we process on your behalf under the Agreement.
- Data Subject means the identified or identifiable natural person to whom Personal Data relates.
- Sub-processor means any third party engaged by us to process Personal Data on your behalf as part of the Service.
- Processing, Controller, Processor, Data Subject Rights, Personal Data Breach, Service Provider, and Sale have the meanings given in the applicable Applicable Data Protection Law.
- Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021, as updated from time to time, available at eur-lex.europa.eu/eli/dec_impl/2021/914.
- UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under section 119A of the Data Protection Act 2018 (Version B1.0, in force 21 March 2022).
3. Scope and roles
This DPA applies where we process Personal Data on your behalf in connection with the Service. You are the Controller of Personal Data submitted to the Service by you or your End Users, and we are the Processor. Under the CCPA and equivalent U.S. state laws, you are the “Business” and we are the “Service Provider.” Each party will comply with its obligations under Applicable Data Protection Laws.
4. Details of processing
A description of the processing (subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects) is set out in Annex 1 to this DPA. Technical and organisational security measures are set out in Annex 2. Our current sub-processors are listed at answerweave.ai/subprocessors and further described in Annex 3.
5. Processor obligations
We will:
- Documented instructions. Process Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by Applicable Law (in which case we will inform you of that legal requirement before processing, unless that law prohibits such notice).
- Purpose limitation. Not process Personal Data for our own purposes, and not “sell” or “share” Personal Data (as those terms are defined under the CCPA), and not process Personal Data outside our direct business relationship with you or as necessary to provide the Service.
- Confidentiality. Ensure that personnel authorised to process Personal Data are bound by written confidentiality obligations of a nature and scope not less protective than those required by Applicable Data Protection Laws.
- Security. Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2. Security measures may be updated to reflect evolving standards, provided that the overall level of security is not diminished.
- Data-subject requests. Assist you, by appropriate technical and organisational measures and taking into account the nature of the processing, in responding to Data Subject Rights requests. Where a request is made directly to us, we will (unless legally prohibited) promptly forward it to you and will not respond except on your instructions or as required by law.
- Data protection impact assessments. Reasonably assist you with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to us.
- Breach notification. Notify you without undue delay after becoming aware of a Personal Data Breach affecting your Personal Data, and provide the information reasonably necessary for you to meet your own notification obligations. Where required by Applicable Law, we will cooperate with your investigation and comply with statutory timelines (including the Florida Information Protection Act, Fla. Stat. § 501.171, and Article 33/34 of the GDPR/UK GDPR).
- Return or deletion. At your choice, delete or return Personal Data to you at the end of the Agreement, and delete existing copies unless Applicable Law requires storage. Our default is to retain Personal Data for thirty (30) days after termination to permit export, then delete active copies within a further sixty (60) days, with backups purged within a further ninety (90) days.
- Records. Maintain records of processing activities to the extent required by Applicable Data Protection Laws.
6. Sub-processors
You grant us general written authorisation to engage Sub-processors to process Personal Data as necessary to provide the Service. A current list of Sub-processors, with their identity, service, and processing location, is maintained at answerweave.ai/subprocessors and in Annex 3.
We will notify you of any intended addition or replacement of a Sub-processor at least fifteen (15) days before the change takes effect, by email to the administrator address on file and by updating the Sub-processor list. If you reasonably object to a new Sub-processor on data-protection grounds, you may notify us within that fifteen-day period; we will use reasonable efforts to accommodate your objection, and if we cannot, you may terminate the affected subscription for a pro-rated refund of prepaid, unused Fees.
We remain liable for the acts and omissions of Sub-processors to the same extent as for our own acts and omissions under this DPA. We impose data-protection obligations on Sub-processors that are, at a minimum, no less protective than the obligations we owe to you under this DPA.
7. International data transfers
To the extent our processing of Personal Data involves a transfer subject to Chapter V of the GDPR or the UK GDPR to a country not subject to an adequacy decision, the transfer is governed by the SCCs, which are incorporated into this DPA by reference and take effect as follows:
- Module. Module Two (Controller to Processor) applies where you are the Controller and we are the Processor. Module Three (Processor to Processor) applies where you are acting as a processor for a third-party controller.
- Clause 7 (Docking clause). Not applicable.
- Clause 9 (Sub-processors). Option 2 (general written authorisation) applies, with a notification period of fifteen (15) days, consistent with §6 above.
- Clause 11 (Redress). The optional independent-dispute- resolution language does not apply.
- Clause 17 (Governing law). The SCCs are governed by the laws of Ireland.
- Clause 18 (Forum and jurisdiction). The courts of Ireland are the forum for disputes arising under the SCCs.
- Annexes. Annex 1 of this DPA populates Annex I.A, I.B, and I.C of the SCCs. Annex 2 populates Annex II. Annex 3 populates Annex III.
- UK transfers. The UK Addendum is incorporated by reference and completes the SCCs for transfers subject to the UK GDPR. Tables 1, 2, 3, and 4 of the UK Addendum are treated as populated by the corresponding provisions of this DPA. Section 19 (Table 4: neither Party) applies.
- Swiss transfers. For transfers subject to the Swiss Federal Act on Data Protection, references in the SCCs to the GDPR are deemed to include references to the FADP, the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority, and Swiss law applies to the extent required.
8. CCPA and U.S. state privacy laws
With respect to Personal Data subject to the CCPA or an equivalent U.S. state law:
- We act as a “Service Provider” (or the analogous role) and not as a “third party.”
- We will not (a) sell or share the Personal Data; (b) retain, use, or disclose the Personal Data outside the direct business relationship with you or for any purpose other than the specific purpose of performing the Service; (c) combine the Personal Data with personal information we receive from or on behalf of another person, except to the limited extent permitted by the CCPA; or (d) engage in any conduct that would cause a transfer of Personal Data from you to us to constitute a “sale” or “sharing” under the CCPA.
- We will notify you if we determine that we can no longer meet our obligations under the CCPA.
- You may take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Data.
- We will honour opt-out and Global Privacy Control signals as required by Applicable Data Protection Laws.
9. Audits
We will make available on your written request the information reasonably necessary to demonstrate our compliance with this DPA, including summaries of independent third-party audits (such as SOC 2 or ISO 27001 reports) where we hold them. In the event you require an on-site audit under Applicable Data Protection Laws, we will cooperate on reasonable notice (not less than thirty (30) days), during normal business hours, no more than once per year (except where required by a supervisory authority or following a material Personal Data Breach), and subject to reasonable confidentiality restrictions. You will bear the costs of any on-site audit conducted at your request.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in the Agreement limits either party's liability to a Data Subject, or to a supervisory authority, under Applicable Data Protection Laws.
11. Term and effect
This DPA takes effect on the effective date of the Agreement or on the date the Agreement first becomes subject to Applicable Data Protection Laws, whichever is later, and continues until we cease processing Personal Data on your behalf. Sections that by their nature should survive termination (including §§ 7 (transfers, for as long as we retain data), 8 (CCPA obligations), 9 (audit rights for one year post-termination), and 10 (liability)) survive termination.
12. Order of precedence
In the event of a conflict, the following order of precedence applies with respect to the processing of Personal Data: (1) the SCCs (as amended by the UK Addendum where applicable); (2) this DPA; (3) the Agreement; (4) the Privacy Policy.
Annex 1 — Description of processing
A. List of Parties
Data exporter (Controller): the customer identified in the Agreement. Role: sender and controller of Personal Data. Contact: administrator email on file.
Data importer (Processor): Hazen Technologies Inc, a Florida corporation (registered office on file with the Florida Division of Corporations). Correspondence address: 7957 N University Dr #1004, Parkland, FL 33067, USA. Contact: support@answerweave.ai. Role: processor providing the Service.
B. Description of the transfer
- Categories of Data Subjects: (i) Controller's personnel who administer the Service (customer users); (ii) End Users who interact with a Controller-deployed assistant, including visitors to Controller's websites.
- Categories of Personal Data: (i) account information (name, work email address, hashed credentials, workspace configuration); (ii) chat and conversation content (messages, transcripts, feedback, optional voice input transcribed to text); (iii) lead information voluntarily submitted by End Users (name, email, phone, message); (iv) session and technical data (session identifier, IP address, user-agent, referring page, timestamps); (v) any Personal Data included in content submitted by Controller for indexing.
- Sensitive data. The Service is not intended for the processing of special categories of Personal Data under Article 9 GDPR or sensitive personal information under the CCPA. Controller should not submit such data, and is responsible for any risks arising from doing so.
- Frequency of transfer: continuous, on-demand, and for the duration of the Agreement.
- Nature of processing: hosting; storage; retrieval; indexing; embedding generation; language-model inference; transcription; delivery of AI-generated responses to End Users; lead notification; analytics; support; and security operations.
- Purpose of processing: to provide, secure, maintain, and improve the Service and to comply with Applicable Law.
- Retention period: for the duration of the Agreement, followed by the retention periods described in the Privacy Policy and in §5 above.
- Sub-processors: as listed at answerweave.ai/subprocessors and in Annex 3.
C. Competent supervisory authority
For EEA transfers under Module Two of the SCCs, the competent supervisory authority is the Data Protection Commission of Ireland, unless another supervisory authority is designated in accordance with Clause 13 of the SCCs.
Annex 2 — Technical and organisational security measures
Taking into account the state of the art, costs of implementation, nature, scope, context, and purposes of processing, and the risks to Data Subjects, we implement measures in the following categories:
- Encryption in transit. TLS 1.2 or higher for all data in transit between clients, our infrastructure, and Sub-processors.
- Encryption at rest. Encryption at rest of credentials, database contents where feasible, and object storage.
- Access controls. Role-based access control, principle of least privilege, mandatory multi-factor authentication for personnel with access to production systems, unique credentials, and periodic access review.
- Network security. Network segmentation, firewall rules, bot- and abuse-detection, and rate-limiting.
- Application security. Secure development practices, code review, dependency scanning, and regular vulnerability assessment.
- Logging and monitoring. Centralised logging, security monitoring, and anomaly detection with defined retention.
- Backup and recovery. Regular backups with tested restore procedures and a documented incident-response plan.
- Personnel measures. Confidentiality obligations, security training, and background checks where legally permitted.
- Vendor management. Diligence on Sub-processors and contractual data-protection obligations at least as protective as this DPA.
- Data minimisation and deletion. Configurable retention, deletion controls in the dashboard, and defined default retention periods.
- Physical security. Provided by our data-centre Sub-processors, subject to their own attestations (e.g., SOC 2, ISO 27001).
- Business continuity. Documented business-continuity and disaster-recovery procedures, tested periodically.
Security measures are reviewed periodically and updated to reflect evolving risks and standards. Any change will be made in a way that does not diminish the overall level of protection.
Annex 3 — Sub-processors
A current list of Sub-processors, with name, service, and processing location, is maintained at answerweave.ai/subprocessors, which is incorporated into this DPA by reference. That page is updated in accordance with §6 above, and prior versions are retained on request.
Contact
Questions about this DPA can be sent to support@answerweave.ai (subject line: “DPA”), or by mail to Hazen Technologies Inc, Attn: Privacy, 7957 N University Dr #1004, Parkland, FL 33067, USA.