Data Processing Agreement

Version 1.0 — Last Updated: July 26, 2026

Scope: the embeddable PLAI.chat widget only. This agreement is for website operators who embed our chat widget on their own website with a <script> tag. In that arrangement you are the controller of the personal data of your website's visitors and we act as your processor.

It does not govern your own use of the Slack app, the Microsoft Teams app, or plai.chat as an end user — for those, our Privacy Policy and Terms of Service apply and we are the controller of your account data.

1. Parties and Acceptance

This Data Processing Agreement ("DPA") is entered into between the legal entity operating the website on which the widget is embedded ("Customer", the controller) and Plug and AI ("Processor", "we", "us"). It forms part of, and is subject to, our Terms of Service.

The DPA takes effect when the Customer creates an embed key and deploys the widget on a website they operate. A countersigned copy naming the Customer's legal entity can be requested at any time via our Support page; where a Customer's own DPA or supplementary terms are required, send them with that request.

2. Subject Matter and Details of Processing

Required by Article 28(3) GDPR:

3. Our Obligations as Processor

4. Customer Obligations

The Customer is responsible for having a lawful basis for the processing, for informing its website visitors that the widget is provided by a third party (the widget itself carries a visible "Powered by plai.chat" label to support this), for the accuracy of the instructions and prompts it configures, and for keeping its embed key and allowed-origin list accurate.

5. Sub-processors

The Customer grants a general authorisation for us to engage the sub-processors listed in Annex I. We impose data protection obligations on each sub-processor no less protective than those in this DPA and remain fully liable for their performance.

We will announce any intended addition or replacement of a sub-processor on this page at least 30 days before it starts processing. The Customer may object on reasonable data protection grounds via our Support page within that period; if the objection cannot be resolved, the Customer may terminate the affected service without penalty.

Annex I — Sub-processors

Sub-processor Purpose Location
OpenRouter, Inc. Gateway to AI model providers — message content is transmitted here and routed onward to the selected model provider USA
AI model providers reached through OpenRouter (OpenAI, Anthropic, Google and others, depending on the model configured for the key) Generating the response to a visitor's message Varies by provider
Salesforce, Inc. (Heroku) Application hosting USA
Cloudflare, Inc. CDN, bot protection (Turnstile), and the D1 database holding embed configuration and usage records Global edge; database primary in the EU
Stripe, Inc. Payment processing for the account paying for the widget (billing data only — never visitor conversation content) USA / EU
Mailgun (Sinch) Transactional email (sign-in links, service notifications) — used only if a visitor chooses to sign in with an email address EU / USA

The specific AI model provider used depends on the model chain configured for the embed key. Current model list: OpenRouter Models. Where a model supports Zero Data Retention and it is enabled, OpenRouter and the downstream provider are instructed not to store the data or use it for training; see our Privacy Policy for the limits of that guarantee.

6. International Transfers

Some sub-processors are located outside the EEA. Transfers to them are made on the basis of the European Commission's Standard Contractual Clauses (Decision 2021/914) or another valid transfer mechanism available to that sub-processor, together with the technical measures in Annex II (transport encryption and data minimisation). The Customer authorises us to enter into Standard Contractual Clauses with sub-processors on its behalf for this purpose.

7. Personal Data Breaches

We notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer's data, including the information available to us under Article 33(3) and the measures taken or proposed. Notification is sent to the email address on the Customer's account.

8. Retention and Deletion

9. Audits

On reasonable written request, and no more than once per year unless required by a supervisory authority or following a breach, we provide the information necessary to demonstrate compliance with this DPA and respond to a reasonable security questionnaire. On-site audits may be conducted where legally required, subject to reasonable notice, confidentiality, and the Customer bearing its own costs.

10. Annex II — Technical and Organisational Measures

11. Order of Precedence and Changes

In case of conflict between this DPA and the Terms of Service, this DPA prevails for matters of personal data processing. We may update this DPA where required by law or by a change to the service; material changes and sub-processor changes are announced on this page with the notice period in Section 5.

12. Contact

For data protection matters, a countersigned copy of this DPA, or a sub-processor objection, please use our Support page.