AI Support Copilot

Data Processing Agreement

Last updated: 10 October 2026

This agreement is between AI Support Copilot, operated by Thomas Volz, sole proprietor, No. 8, Unit No. J1-B06-09, Moo 6, Surasak Sub-district, Sriracha District, Chonburi 20110, Thailand (“Provider”), and the business that signs up for the service (“Customer”).

1. Purpose and scope

This agreement applies whenever the Provider processes personal data on behalf of the Customer while providing AI Support Copilot, including during the free trial. It forms part of the Terms of Service. It does not cover personal data the Provider handles for its own purposes (website, billing, outreach); the Privacy Policy covers that.

2. Roles

The Customer is the controller of the personal data in its support emails. The Provider is the processor.

3. What is processed

4. Provider’s duties

The Provider will:

  1. process the data only on the Customer’s documented instructions (the Terms, this agreement and the Customer’s configured policies), and tell the Customer if it believes an instruction breaks data protection law;
  2. keep the data confidential and limit access to the person running the service;
  3. apply appropriate security measures: a separate access key per Customer that can be switched off at any time, access limited to the Provider and the sub-processors below, no storage of email content in the drafting service, and no reading of attachments;
  4. help the Customer answer requests from the people concerned (access, correction, deletion) and meet its own data protection duties, as far as the Provider’s role allows;
  5. taking into account the nature of the processing and the information available to it, reasonably assist the Customer with its obligations under Articles 32 to 36 GDPR;
  6. tell the Customer without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting the Customer’s data, with the information it has;
  7. at the end of the service, switch off the access key and delete the Customer’s data as described in section 3, unless the law requires keeping it;
  8. give the Customer the information needed to show compliance with this agreement, and allow reasonable audits by written request, at the Customer’s cost, no more than once a year, during business hours and with 30 days’ notice, except where an additional audit is required by law or a supervisory authority, or is reasonably necessary after a security incident. The Provider may meet this by sending documentation first.

5. Customer’s duties

The Customer is responsible for having a legal basis for processing its support emails, for informing the people concerned as required, and for the content of its policies and instructions.

6. Sub-processors

The Customer agrees to these sub-processors for support-email data:

Sub-processorPurposeLocation
OpenAIAI model that sorts each email and writes the draft. Requests are sent with response storage turned off; per OpenAI’s API policies, data is not used for training and may be kept up to 30 days for abuse monitoring.United States and other countries
CloudflareHosts the drafting serviceGlobal network

The Customer’s own Make and Google accounts are the Customer’s services under its own agreements with those providers, not the Provider’s sub-processors. Paddle processes payments for the Provider and does not receive support-email data.

The Provider will tell the Customer by email at least 14 days before adding or replacing a sub-processor. The Customer may object in writing within that period; if the parties cannot agree, the Customer may cancel the subscription at the end of the paid month. The Provider binds each sub-processor to data protection duties no less protective than this agreement and remains responsible for them.

7. International transfers

The Provider is based in Thailand and its sub-processors work in the United States and other countries. Where the EU or UK GDPR applies and personal data is transferred to the Provider or onward to a country without an adequacy decision, the parties agree to the EU Standard Contractual Clauses (Module Two, controller to processor), which are incorporated by reference, with these choices: Clause 7 (docking clause) included; Clause 9(a) option 2 (general written authorisation, 14 days’ notice); Clause 11 optional redress language not included; Clause 17 option 1 and Clause 18(b): the law and courts of Ireland. For UK personal data the UK International Data Transfer Addendum applies in the same way. Annexes I to III are completed by sections 1 to 6 of this agreement. If a transfer mechanism stops being valid, the parties will agree a replacement in good faith.

8. Liability and law

Liability under this agreement is subject to the limits in the Terms of Service, to the extent the law allows. Apart from section 7, this agreement is governed by the same law as the Terms (Thailand).

9. Acceptance

The Customer accepts this agreement when it signs up and confirms the box “I agree to the Terms of Service, Refund Policy and Data Processing Agreement”, and in any case before the Provider processes real support emails. It stays in force as long as the Provider processes data for the Customer.