Legal

Data Processing Agreement

Last updated July 16, 2026

Draft — pending legal review

This DPA supplements the Terms of Service and governs how AskThis processes personal data on behalf of publishers acting as controllers. It applies automatically to every publisher — nothing to sign — and includes our full sub-processor list rather than making you request it.

Scope and roles

This Data Processing Agreement supplements our Terms of Service and applies automatically to every publisher who installs the widget. You do not need to sign a separate copy; if your organisation requires a countersigned version, write to legal@askthis.io.

For personal data collected through your installation of the widget, you are the controller (or, under India's DPDP Act, the data fiduciary) and Agochar Tech LLP is the processor (data processor). We process that data only on your documented instructions — which your configuration in the dashboard forms part of — and as needed to provide the service.

One honest carve-out: where we derive aggregated, non-identifying signals for our own commercial datasets, we act as a controller in our own right, not as your processor. That processing is governed by our Privacy Policy, is subject to a k-anonymity floor of 50, and only ever covers data carrying a positive consent signal.

Nature of the processing

Subject matterProvision of the AskThis sharing widget, analytics, prompt generation and related services.
DurationFor as long as your account is open, plus the retention periods below.
Nature and purposeCollecting pseudonymous interaction events, aggregating them into analytics, and generating prompts and metadata from your page content.
Categories of data subjectVisitors to your website, and the users you invite into your organisation.
Types of personal dataPseudonymous event data: event type, platform, hashed page address, page type, random session identifier, country code, device class, timestamp, referring hostname. No names, emails, phone numbers or IP addresses. Typed-question text only if you enable capture, in which case it is redacted at ingestion and retained no more than 90 days.
Special category dataNone. The widget is not designed to collect it and you must not configure it to.

Our obligations

  • We process personal data only on your instructions, unless the law requires otherwise — in which case we will tell you first, unless the law forbids it.
  • We ensure that everyone authorised to process the data is bound by confidentiality.
  • We implement the technical and organisational measures described below.
  • We assist you with data-subject requests, security, breach notification and impact assessments, taking into account the nature of the processing and the information available to us.
  • We make available the information needed to demonstrate compliance and allow audits, as described under “Audit” below.
  • We tell you without undue delay if we become aware of a personal data breach affecting your data.

Your obligations

As controller you are responsible for having a lawful basis for the processing, for obtaining any consent your law requires before the widget runs — including prior consent under the ePrivacy rules if you have EEA or UK visitors — and for giving your visitors the information their law entitles them to.

You confirm your instructions to us will be lawful, and that you will not use the widget to collect special category data or data from children in circumstances your law does not permit.

Sub-processors

You give us general authorisation to engage the sub-processors below. We impose data-protection obligations on each of them no less protective than this DPA, and we remain liable to you for their performance.

We publish this list rather than making you ask for it. We will give at least 30 days' notice before adding a new sub-processor, by updating this page and notifying account owners. If you reasonably object on data-protection grounds within that period, we will work with you in good faith to find a solution; if we cannot, you may terminate the affected service and receive a pro-rata refund of prepaid fees.

Sub-processorPurposeData it can touchLocationStatus
Cloudflare, Inc.Edge delivery, DNS, widget CDN, event ingestion WorkersEvent payloads in transit; derives country code from IP at the edge. Raw IP is never stored.Global edge networkActive
Anthropic PBCPrompt and summary generation at scan timePublisher page text only (max 6,000 characters). No visitor data is ever sent.United StatesActive
OpenRouter, Inc.Alternative LLM routing when configuredPublisher page text only. Same boundary as Anthropic.United StatesActive when enabled
Stripe, Inc.Subscription and credit-pack paymentsBilling contact, payment card brand and last four digits. We never receive or store a full card number.United StatesActive when enabled
Razorpay Software Private LimitedSubscription and credit-pack paymentsBilling contact, payment card brand and last four digits. We never receive or store a full card number.IndiaActive when enabled
PayPal Holdings, Inc.Subscription and credit-pack paymentsBilling contact and a PayPal account reference (payer id / email). We never receive or store your full card, bank or PayPal login details.United StatesActive when enabled
Google LLC (Analytics 4)Marketing-site analytics onlySite usage with IP anonymisation. Loads only after you accept cookies. Never used for widget events.United StatesActive when enabled
Microsoft Corporation (Clarity)Marketing-site usage analytics onlySite interaction data. Loads only after you accept cookies. Never used for widget events.United StatesActive when enabled

"Active when enabled" means the sub-processor is integrated but only receives data once that payment gateway, AI provider or analytics tool is switched on for your account or on our marketing site. We also self-host our own database, cache and analytics infrastructure; those are not third parties.

Security measures

We apply, and keep under review, the following measures:

  • TLS for data in transit and encryption at rest.
  • Least-privilege access control, with two-factor authentication available on all accounts and enforced for staff with production access.
  • Row-level authorisation: every query is scoped to the authenticated organisation, so one publisher can never read another's data.
  • Strict origin checks and rate limiting at the network edge.
  • A widget that uses no eval and is friendly to a strict content security policy.
  • Data-minimisation by design: no cookies, no IP addresses at rest from widget traffic, typed-question text only when a site enables capture (redacted at ingestion, deleted within 90 days), and identifier patterns dropped at ingestion.
  • Segregation of the event pipeline from the application database, so visitor events never enter the system that holds account data.
  • Automated dependency scanning and a published vulnerability-disclosure route.

Two things we would rather you hear from us directly: the visitor identifier is a salted HMAC in production (strong pseudonymisation, though key rotation is not yet automated, so treat it as pseudonymous rather than fully anonymous); and we hold no third-party security certification — SOC 2 Type II is our target, not our current state. Our Trust page tracks both.

Data-subject rights and deletion

We assist you in responding to access, correction, deletion, objection and do-not-sell requests through dashboard controls, our deletion endpoints and our suppression list. A consent audit log is available to support your accountability obligations.

Where you supply an identifier, adding it to the suppression list removes the associated data from every commercial dataset, including ones already built. Because widget data is pseudonymous and carries no name or email, we often cannot connect a request to specific records — the practical limits are set out in our Privacy Policy.

If a data subject contacts us directly about your site, we will refer them to you rather than act on your behalf.

International transfers

Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (Module Three, processor-to-processor, or Module Two where you are a controller outside the EEA) together with the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and take precedence over it in the event of conflict.

We carry out transfer impact assessments and apply the technical measures described above as supplementary safeguards. The locations of our sub-processors are listed in the table above.

Return and deletion

Raw event data is deleted automatically 13 months after collection, enforced by the database itself. Aggregated statistics contain no identifiers and are retained while we operate the service.

On termination we delete or return the personal data we process on your behalf within 30 days, except where the law requires us to keep it, and except for the suppression list — deleting that would undo the exclusions people have asked for. You can export your analytics from the dashboard before you close your account.

Audit

On reasonable written notice, and no more than once a year unless a regulator requires otherwise or we have had a breach affecting your data, we will provide the information reasonably needed to demonstrate compliance with this DPA. Where a documentary response is insufficient, we will agree the scope of an audit with you in good faith, at your cost, conducted so as not to disrupt the service or compromise other customers' confidentiality.

Liability and contact

Liability under this DPA is subject to the limitations in our Terms of Service, except where the applicable data-protection law does not permit it.

Data-protection questions go to privacy@askthis.io. Our Grievance Officer under India's IT Rules is Rajesh Dalsaniya, at grievance@askthis.io.

Questions about this document? Email legal@askthis.io. This document is not legal advice.