Data Processing Agreement
Last updated: 10 October 2026
This agreement is between AI Support Copilot, operated by Thomas Volz, sole proprietor, No. 8, Unit No. J1-B06-09, Moo 6, Surasak Sub-district, Sriracha District, Chonburi 20110, Thailand (“Provider”), and the business that signs up for the service (“Customer”).
1. Purpose and scope
This agreement applies whenever the Provider processes personal data on behalf of the Customer while providing AI Support Copilot, including during the free trial. It forms part of the Terms of Service. It does not cover personal data the Provider handles for its own purposes (website, billing, outreach); the Privacy Policy covers that.
2. Roles
The Customer is the controller of the personal data in its support emails. The Provider is the processor.
3. What is processed
- Subject: writing reply drafts for the Customer’s support inbox.
- People: the Customer’s customers and other people who email the Customer’s support inbox.
- Data: name and email address, subject and text of the email, order number if written, assigned topic, priority and language, and the draft. Attachments are not opened or read.
- Duration: while the service runs. Email content is not stored by the drafting service after the draft is returned. Usage counts and store policies are deleted within 30 days after the service ends.
4. Provider’s duties
The Provider will:
- process the data only on the Customer’s documented instructions (the Terms, this agreement and the Customer’s configured policies), and tell the Customer if it believes an instruction breaks data protection law;
- keep the data confidential and limit access to the person running the service;
- apply appropriate security measures: a separate access key per Customer that can be switched off at any time, access limited to the Provider and the sub-processors below, no storage of email content in the drafting service, and no reading of attachments;
- help the Customer answer requests from the people concerned (access, correction, deletion) and meet its own data protection duties, as far as the Provider’s role allows;
- taking into account the nature of the processing and the information available to it, reasonably assist the Customer with its obligations under Articles 32 to 36 GDPR;
- tell the Customer without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting the Customer’s data, with the information it has;
- at the end of the service, switch off the access key and delete the Customer’s data as described in section 3, unless the law requires keeping it;
- give the Customer the information needed to show compliance with this agreement, and allow reasonable audits by written request, at the Customer’s cost, no more than once a year, during business hours and with 30 days’ notice, except where an additional audit is required by law or a supervisory authority, or is reasonably necessary after a security incident. The Provider may meet this by sending documentation first.
5. Customer’s duties
The Customer is responsible for having a legal basis for processing its support emails, for informing the people concerned as required, and for the content of its policies and instructions.
6. Sub-processors
The Customer agrees to these sub-processors for support-email data:
| Sub-processor | Purpose | Location |
|---|---|---|
| OpenAI | AI model that sorts each email and writes the draft. Requests are sent with response storage turned off; per OpenAI’s API policies, data is not used for training and may be kept up to 30 days for abuse monitoring. | United States and other countries |
| Cloudflare | Hosts the drafting service | Global network |
The Customer’s own Make and Google accounts are the Customer’s services under its own agreements with those providers, not the Provider’s sub-processors. Paddle processes payments for the Provider and does not receive support-email data.
The Provider will tell the Customer by email at least 14 days before adding or replacing a sub-processor. The Customer may object in writing within that period; if the parties cannot agree, the Customer may cancel the subscription at the end of the paid month. The Provider binds each sub-processor to data protection duties no less protective than this agreement and remains responsible for them.
7. International transfers
The Provider is based in Thailand and its sub-processors work in the United States and other countries. Where the EU or UK GDPR applies and personal data is transferred to the Provider or onward to a country without an adequacy decision, the parties agree to the EU Standard Contractual Clauses (Module Two, controller to processor), which are incorporated by reference, with these choices: Clause 7 (docking clause) included; Clause 9(a) option 2 (general written authorisation, 14 days’ notice); Clause 11 optional redress language not included; Clause 17 option 1 and Clause 18(b): the law and courts of Ireland. For UK personal data the UK International Data Transfer Addendum applies in the same way. Annexes I to III are completed by sections 1 to 6 of this agreement. If a transfer mechanism stops being valid, the parties will agree a replacement in good faith.
8. Liability and law
Liability under this agreement is subject to the limits in the Terms of Service, to the extent the law allows. Apart from section 7, this agreement is governed by the same law as the Terms (Thailand).
9. Acceptance
The Customer accepts this agreement when it signs up and confirms the box “I agree to the Terms of Service, Refund Policy and Data Processing Agreement”, and in any case before the Provider processes real support emails. It stays in force as long as the Provider processes data for the Customer.