Skip to content
AnswerWeave

Data Processing Addendum

Effective date:

1. Introduction

This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Terms of Service (or applicable Order Form or written agreement) (the “Agreement”) between Hazen Technologies Inc, operator of the AnswerWeave service (“Processor” or “we”), and the customer identified in the Agreement (“Controller” or “you”). It reflects the parties' obligations under Applicable Data Protection Laws when we process Personal Data on your behalf in connection with the Service.

This DPA takes effect automatically for customers to whom Applicable Data Protection Laws apply. No signature is required for it to be binding; customers requiring a countersigned copy may request one at support@answerweave.ai. In the event of a conflict between this DPA and the Agreement or the Privacy Policy with respect to the processing of Personal Data, this DPA controls.

2. Definitions

Capitalised terms not defined below have the meanings given in the Agreement.

  • Applicable Data Protection Laws means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including (a) the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”); (b) the UK GDPR and Data Protection Act 2018 (“UK GDPR”); (c) the Swiss Federal Act on Data Protection; (d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”); (e) other U.S. state comprehensive privacy laws (including the VCDPA, CPA, CTDPA, UCPA, TDPSA, and the Florida Digital Bill of Rights where applicable); (f) Canada's Personal Information Protection and Electronic Documents Act (PIPEDA); and (g) Brazil's Lei Geral de Proteção de Dados (LGPD).
  • Personal Data means information relating to an identified or identifiable natural person (including “personal information” as defined under the CCPA) that we process on your behalf under the Agreement.
  • Data Subject means the identified or identifiable natural person to whom Personal Data relates.
  • Sub-processor means any third party engaged by us to process Personal Data on your behalf as part of the Service.
  • Processing, Controller, Processor, Data Subject Rights, Personal Data Breach, Service Provider, and Sale have the meanings given in the applicable Applicable Data Protection Law.
  • Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021, as updated from time to time, available at eur-lex.europa.eu/eli/dec_impl/2021/914.
  • UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under section 119A of the Data Protection Act 2018 (Version B1.0, in force 21 March 2022).

3. Scope and roles

This DPA applies where we process Personal Data on your behalf in connection with the Service. You are the Controller of Personal Data submitted to the Service by you or your End Users, and we are the Processor. Under the CCPA and equivalent U.S. state laws, you are the “Business” and we are the “Service Provider.” Each party will comply with its obligations under Applicable Data Protection Laws.

4. Details of processing

A description of the processing (subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects) is set out in Annex 1 to this DPA. Technical and organisational security measures are set out in Annex 2. Our current sub-processors are listed at answerweave.ai/subprocessors and further described in Annex 3.

5. Processor obligations

We will:

  • Documented instructions. Process Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by Applicable Law (in which case we will inform you of that legal requirement before processing, unless that law prohibits such notice).
  • Purpose limitation. Not process Personal Data for our own purposes, and not “sell” or “share” Personal Data (as those terms are defined under the CCPA), and not process Personal Data outside our direct business relationship with you or as necessary to provide the Service.
  • Confidentiality. Ensure that personnel authorised to process Personal Data are bound by written confidentiality obligations of a nature and scope not less protective than those required by Applicable Data Protection Laws.
  • Security. Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2. Security measures may be updated to reflect evolving standards, provided that the overall level of security is not diminished.
  • Data-subject requests. Assist you, by appropriate technical and organisational measures and taking into account the nature of the processing, in responding to Data Subject Rights requests. Where a request is made directly to us, we will (unless legally prohibited) promptly forward it to you and will not respond except on your instructions or as required by law.
  • Data protection impact assessments. Reasonably assist you with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to us.
  • Breach notification. Notify you without undue delay after becoming aware of a Personal Data Breach affecting your Personal Data, and provide the information reasonably necessary for you to meet your own notification obligations. Where required by Applicable Law, we will cooperate with your investigation and comply with statutory timelines (including the Florida Information Protection Act, Fla. Stat. § 501.171, and Article 33/34 of the GDPR/UK GDPR).
  • Return or deletion. At your choice, delete or return Personal Data to you at the end of the Agreement, and delete existing copies unless Applicable Law requires storage. Our default is to retain Personal Data for thirty (30) days after termination to permit export, and to delete active copies within a further sixty (60) days on your written request. Deletion is carried out manually rather than by an automated job, so please ask if you need confirmation that it has completed. Residual copies persist in backups for up to a further thirty (30) days, after which they expire automatically.
  • Records. Maintain records of processing activities to the extent required by Applicable Data Protection Laws.

6. Sub-processors

You grant us general written authorisation to engage Sub-processors to process Personal Data as necessary to provide the Service. A current list of Sub-processors, with their identity, service, and processing location, is maintained at answerweave.ai/subprocessors and in Annex 3.

We will notify you of any intended addition or replacement of a Sub-processor at least fifteen (15) days before the change takes effect, by email to the administrator address on file and by updating the Sub-processor list. If you reasonably object to a new Sub-processor on data-protection grounds, you may notify us within that fifteen-day period; we will use reasonable efforts to accommodate your objection, and if we cannot, you may terminate the affected subscription for a pro-rated refund of prepaid, unused Fees.

We remain liable for the acts and omissions of Sub-processors to the same extent as for our own acts and omissions under this DPA. We impose data-protection obligations on Sub-processors that are, at a minimum, no less protective than the obligations we owe to you under this DPA.

7. International data transfers

To the extent our processing of Personal Data involves a transfer subject to Chapter V of the GDPR or the UK GDPR to a country not subject to an adequacy decision, the transfer is governed by the SCCs, which are incorporated into this DPA by reference and take effect as follows:

  • Module. Module Two (Controller to Processor) applies where you are the Controller and we are the Processor. Module Three (Processor to Processor) applies where you are acting as a processor for a third-party controller.
  • Clause 7 (Docking clause). Not applicable.
  • Clause 9 (Sub-processors). Option 2 (general written authorisation) applies, with a notification period of fifteen (15) days, consistent with §6 above.
  • Clause 11 (Redress). The optional independent-dispute- resolution language does not apply.
  • Clause 17 (Governing law). The SCCs are governed by the laws of Ireland.
  • Clause 18 (Forum and jurisdiction). The courts of Ireland are the forum for disputes arising under the SCCs.
  • Annexes. Annex 1 of this DPA populates Annex I.A, I.B, and I.C of the SCCs. Annex 2 populates Annex II. Annex 3 populates Annex III.
  • UK transfers. The UK Addendum is incorporated by reference and completes the SCCs for transfers subject to the UK GDPR. Tables 1, 2, 3, and 4 of the UK Addendum are treated as populated by the corresponding provisions of this DPA. Section 19 (Table 4: neither Party) applies.
  • Swiss transfers. For transfers subject to the Swiss Federal Act on Data Protection, references in the SCCs to the GDPR are deemed to include references to the FADP, the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority, and Swiss law applies to the extent required.

8. CCPA and U.S. state privacy laws

With respect to Personal Data subject to the CCPA or an equivalent U.S. state law:

  • We act as a “Service Provider” (or the analogous role) and not as a “third party.”
  • We will not (a) sell or share the Personal Data; (b) retain, use, or disclose the Personal Data outside the direct business relationship with you or for any purpose other than the specific purpose of performing the Service; (c) combine the Personal Data with personal information we receive from or on behalf of another person, except to the limited extent permitted by the CCPA; or (d) engage in any conduct that would cause a transfer of Personal Data from you to us to constitute a “sale” or “sharing” under the CCPA.
  • We will notify you if we determine that we can no longer meet our obligations under the CCPA.
  • You may take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Data.
  • We will honour opt-out and Global Privacy Control signals as required by Applicable Data Protection Laws.

9. Audits

We will make available on your written request the information reasonably necessary to demonstrate our compliance with this DPA, including summaries of independent third-party audits (such as SOC 2 or ISO 27001 reports) where we hold them. In the event you require an on-site audit under Applicable Data Protection Laws, we will cooperate on reasonable notice (not less than thirty (30) days), during normal business hours, no more than once per year (except where required by a supervisory authority or following a material Personal Data Breach), and subject to reasonable confidentiality restrictions. You will bear the costs of any on-site audit conducted at your request.

10. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in the Agreement limits either party's liability to a Data Subject, or to a supervisory authority, under Applicable Data Protection Laws.

11. Term and effect

This DPA takes effect on the effective date of the Agreement or on the date the Agreement first becomes subject to Applicable Data Protection Laws, whichever is later, and continues until we cease processing Personal Data on your behalf. Sections that by their nature should survive termination (including §§ 7 (transfers, for as long as we retain data), 8 (CCPA obligations), 9 (audit rights for one year post-termination), and 10 (liability)) survive termination.

12. Order of precedence

In the event of a conflict, the following order of precedence applies with respect to the processing of Personal Data: (1) the SCCs (as amended by the UK Addendum where applicable); (2) this DPA; (3) the Agreement; (4) the Privacy Policy.

Annex 1 — Description of processing

A. List of Parties

Data exporter (Controller): the customer identified in the Agreement. Role: sender and controller of Personal Data. Contact: administrator email on file.

Data importer (Processor): Hazen Technologies Inc, a Florida corporation (registered office on file with the Florida Division of Corporations). Correspondence address: 7957 N University Dr #1004, Parkland, FL 33067, USA. Contact: support@answerweave.ai. Role: processor providing the Service.

B. Description of the transfer

  • Categories of Data Subjects: (i) Controller's personnel who administer the Service (customer users); (ii) End Users who interact with a Controller-deployed assistant, including visitors to Controller's websites.
  • Categories of Personal Data: (i) account information (name, work email address, hashed credentials, workspace configuration); (ii) chat and conversation content (messages, transcripts, feedback, optional voice input transcribed to text); (iii) lead information voluntarily submitted by End Users (name, email, phone, message); (iv) session and technical data (session identifier, IP address, user-agent, referring page, timestamps); (v) any Personal Data included in content submitted by Controller for indexing.
  • Sensitive data. The Service is not intended for the processing of special categories of Personal Data under Article 9 GDPR or sensitive personal information under the CCPA. Controller should not submit such data, and is responsible for any risks arising from doing so.
  • Frequency of transfer: continuous, on-demand, and for the duration of the Agreement.
  • Nature of processing: hosting; storage; retrieval; indexing; embedding generation; language-model inference; transcription; delivery of AI-generated responses to End Users; lead notification; analytics; support; and security operations.
  • Purpose of processing: to provide, secure, maintain, and improve the Service and to comply with Applicable Law.
  • Retention period: for the duration of the Agreement, followed by the retention periods described in the Privacy Policy and in §5 above.
  • Sub-processors: as listed at answerweave.ai/subprocessors and in Annex 3.

C. Competent supervisory authority

For EEA transfers under Module Two of the SCCs, the competent supervisory authority is the Data Protection Commission of Ireland, unless another supervisory authority is designated in accordance with Clause 13 of the SCCs.

Annex 2 — Technical and organisational security measures

Taking into account the state of the art, costs of implementation, nature, scope, context, and purposes of processing, and the risks to Data Subjects, the measures below are the ones we actually have in place today. We have deliberately listed only these, rather than a longer catalogue of controls we have not yet implemented.

  • Encryption in transit. HTTPS with TLS 1.2 or higher, with certificates issued and renewed automatically, for traffic between clients, our infrastructure, and Sub-processors.
  • Credential handling. Account passwords are stored only as salted one-way hashes and are never recoverable. Payment card details never reach our servers; they are collected and stored by Stripe. Service credentials are held as deployment secrets rather than in source control.
  • Storage encryption. Database and object storage sit on cloud infrastructure whose disk-level encryption is provided by our hosting Sub-processor. We do not currently apply application-layer or field-level encryption to database contents beyond the credential hashing described above.
  • Access controls. Role-based access control within the Service (owner, admin, and member roles, with platform-administrator functions gated separately), unique per-user credentials, and email verification on account creation.
  • Network controls. A single reverse proxy terminates TLS and is the only public entry point; application, database, and object-storage services are not directly exposed to the internet. Rate-limiting is applied to authentication and other sensitive endpoints, and widget keys can be restricted to customer-nominated domains.
  • Application security. Changes reach production only through peer-reviewed pull requests with an automated typecheck and test suite that must pass before merge.
  • Administrative audit trail. Platform-administrator actions are recorded to an audit log with a defined retention window.
  • Database backups. Two layers, both retained for thirty (30) days. Our managed database service takes automated backups continuously, providing a thirty (30) day point-in-time restore window. Separately, a verified dump is taken and integrity-checked immediately before any migration runs, and the deployment is blocked if that dump fails. A documented restore procedure exists and has been exercised by hand; it is not on a scheduled drill.
  • Customer-controlled deletion. Customers can delete indexed sources and whole assistants from the dashboard; deleting an assistant also removes its conversations and captured leads.
  • Voice data minimisation. Audio submitted for transcription is never written to persistent storage; only the resulting text is retained.
  • Confidentiality. Personnel with access to Personal Data are bound by written confidentiality obligations.
  • Vendor management. Sub-processors are engaged under written data-protection terms no less protective than this DPA, and are listed at answerweave.ai/subprocessors.
  • Physical security. Provided entirely by our hosting Sub-processor, under its own attestations (which may include SOC 2 and ISO 27001). We operate no data centres and hold no such certification ourselves.

Controls we do not yet have

Stated plainly, because a security schedule that implies more than exists is worse than a short one. As of the effective date above we do not have: a scheduled restore drill (the restore procedure is documented and has been exercised by hand, but not on a fixed cadence); centralised security logging, monitoring, or anomaly detection; automated dependency or vulnerability scanning; third-party penetration testing; a formal written incident-response plan; a formal business-continuity or disaster-recovery plan with periodic testing; enforced multi-factor authentication or periodic access reviews for personnel; formal security training or background checks; and no SOC 2, ISO 27001, or comparable certification of our own.

Customers with requirements beyond the measures listed above should raise them before relying on the Service for the relevant processing. We expect to strengthen these controls over time; any change will be made in a way that does not diminish the overall level of protection, and this Annex will be updated to match what is actually in place.

Annex 3 — Sub-processors

A current list of Sub-processors, with name, service, and processing location, is maintained at answerweave.ai/subprocessors, which is incorporated into this DPA by reference. That page is updated in accordance with §6 above, and prior versions are retained on request.

Contact

Questions about this DPA can be sent to support@answerweave.ai (subject line: “DPA”), or by mail to Hazen Technologies Inc, Attn: Privacy, 7957 N University Dr #1004, Parkland, FL 33067, USA.