This Data Processing Addendum ("DPA") forms part of and supplements the Terms and Conditions, subscription agreement, order form, or other written agreement between LtsTalk and the customer using the Service (the "Agreement").
This DPA applies when LtsTalk processes Personal Data on behalf of Customer in connection with the Service.
By using the Service, installing the widget, creating a workspace, or otherwise submitting Personal Data to LtsTalk, Customer agrees to this DPA.
This DPA is a general template and should be reviewed by a qualified legal professional before public launch.
1. Parties
This DPA is entered into by and between:
Customer: the individual, company, organization, or legal entity using the LtsTalk Service.
LtsTalk: the provider of the LtsTalk platform.
Customer and LtsTalk may each be referred to as a "Party" and collectively as the "Parties."
2. Definitions
For the purposes of this DPA:
"Agreement" means the Terms and Conditions, subscription agreement, order form, or other agreement governing Customer's use of the Service.
"Applicable Data Protection Laws" means all privacy, data protection, cybersecurity, electronic communications, and related laws applicable to the processing of Personal Data under the Agreement, which may include, depending on the circumstances, laws of Mexico, the European Union, the United Kingdom, the United States, Canada, or other jurisdictions.
"Controller" means the party that determines the purposes and means of processing Personal Data.
"Processor" means the party that processes Personal Data on behalf of a Controller.
"Customer Personal Data" means Personal Data processed by LtsTalk on behalf of Customer through the Service.
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Laws.
"Processing" means any operation performed on Personal Data, including collection, recording, storage, organization, structuring, use, transmission, disclosure, retrieval, deletion, alteration, or destruction.
"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
"Service" means the LtsTalk website, dashboard, widget, inbox, APIs, documentation, hosting, automations, notifications, AI-related features, analytics, and related software services.
"Subprocessor" means any third party engaged by LtsTalk to process Customer Personal Data on behalf of Customer.
3. Relationship of the Parties
For Customer Personal Data processed through the Service:
- Customer is the Controller or Processor, as applicable.
- LtsTalk is the Processor or Subprocessor, as applicable.
- Customer determines the purposes and lawful basis for collecting and processing Customer Personal Data.
- LtsTalk processes Customer Personal Data only to provide, secure, maintain, support, and improve the Service, and in accordance with this DPA and the Agreement.
Customer is solely responsible for determining whether its use of the Service complies with Applicable Data Protection Laws.
4. Scope and Subject Matter of Processing
LtsTalk processes Customer Personal Data to provide a live chat, visitor engagement, support inbox, website widget, automation, analytics, notification, attachment, transcript, and related customer communication platform.
The subject matter, nature, purpose, duration, categories of Data Subjects, and types of Personal Data are described in Schedule 1 of this DPA.
5. Customer Instructions
Customer instructs LtsTalk to process Customer Personal Data as necessary to:
- provide the Service;
- operate the chat widget;
- store and display conversations;
- route messages to authorized users;
- support team inbox functionality;
- manage brands, websites, agents, flows, and settings;
- process attachments and transcripts;
- maintain usage limits and subscription status;
- provide technical support;
- secure, monitor, debug, and improve the Service;
- comply with applicable legal obligations;
- perform any other processing described in the Agreement or configured by Customer through the Service.
LtsTalk will not process Customer Personal Data for purposes materially different from those described in this DPA unless required by law or authorized by Customer.
If LtsTalk believes an instruction violates Applicable Data Protection Laws, LtsTalk may notify Customer and suspend the affected processing until the issue is resolved.
6. Customer Responsibilities
Customer is responsible for:
- providing all legally required privacy notices to Visitors and users;
- obtaining any required consents;
- establishing a lawful basis for processing Personal Data;
- determining what information to collect through the widget;
- ensuring that agents and users handle Personal Data lawfully;
- configuring permissions, brand access, and user roles correctly;
- avoiding unnecessary collection of sensitive Personal Data;
- responding to Data Subject requests;
- ensuring that Customer's websites comply with cookie, tracking, privacy, and consumer protection requirements;
- ensuring that Customer Content does not violate law or third-party rights.
Customer must not submit Personal Data to the Service unless Customer has all rights, notices, consents, and lawful bases required to do so.
7. LtsTalk Responsibilities
LtsTalk will:
- process Customer Personal Data only as instructed by Customer and as necessary to provide the Service;
- implement reasonable technical and organizational measures designed to protect Customer Personal Data;
- ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations;
- use Subprocessors in accordance with this DPA;
- assist Customer with Data Subject requests where technically feasible and legally required;
- notify Customer of confirmed Security Incidents as described in this DPA;
- delete or return Customer Personal Data as described in this DPA;
- provide reasonable information to demonstrate compliance with this DPA, subject to confidentiality, security, and operational limitations.
8. Confidentiality
LtsTalk will ensure that personnel who process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
Customer must ensure that its users, agents, employees, contractors, and representatives who access the Service are authorized and trained to handle Personal Data appropriately.
9. Security Measures
LtsTalk will maintain reasonable technical and organizational measures designed to protect Customer Personal Data from unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include, as appropriate:
- access controls;
- authentication controls;
- role-based permissions;
- encryption in transit;
- password hashing;
- secure file storage practices;
- backup procedures;
- logging and monitoring;
- vulnerability management;
- restricted access to production systems;
- secure development practices;
- incident response procedures;
- reasonable personnel confidentiality controls.
A summary of security measures is included in Schedule 2.
Customer acknowledges that no system is completely secure and that security depends in part on Customer's configuration, users, passwords, websites, devices, and integrations.
10. Security Incidents
If LtsTalk becomes aware of a confirmed Security Incident affecting Customer Personal Data, LtsTalk will notify Customer without undue delay.
The notice may include, to the extent reasonably available:
- nature of the Security Incident;
- categories of data affected;
- approximate number of affected records, if known;
- likely consequences, if known;
- measures taken or proposed to address the incident;
- recommended steps for Customer, if applicable.
LtsTalk's notification of a Security Incident is not an admission of fault or liability.
Customer is responsible for determining whether notification to Data Subjects, regulators, authorities, or other parties is required.
11. Data Subject Requests
If LtsTalk receives a request from a Data Subject relating to Customer Personal Data, LtsTalk may:
- direct the requester to Customer;
- notify Customer where legally permitted;
- assist Customer in responding where technically feasible;
- decline to respond directly unless required by law.
Customer is responsible for responding to Data Subject requests, including requests for access, correction, deletion, restriction, objection, withdrawal of consent, portability, or similar rights.
LtsTalk may provide reasonable assistance through the Service or support channels, subject to technical feasibility, authentication, confidentiality, and reasonable limitations.
12. Subprocessors
Customer authorizes LtsTalk to engage Subprocessors to provide the Service.
Subprocessors may include providers for:
- cloud hosting;
- database hosting;
- file storage;
- email delivery;
- payment processing;
- AI processing;
- messaging services;
- analytics;
- error monitoring;
- security;
- customer support;
- infrastructure and operations.
LtsTalk will impose data protection obligations on Subprocessors that are materially similar to those in this DPA, to the extent applicable to the services provided.
LtsTalk remains responsible for its Subprocessors' processing of Customer Personal Data to the extent required by Applicable Data Protection Laws.
13. Subprocessor Changes
LtsTalk may add, replace, or remove Subprocessors from time to time.
Where required by Applicable Data Protection Laws or by a separate written agreement, LtsTalk will provide notice of material Subprocessor changes.
Customer may object to a new Subprocessor on reasonable data protection grounds. If Customer objects, the Parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may stop using the affected Service or terminate the affected subscription as its sole remedy, unless otherwise required by law.
14. International Data Transfers
Customer Personal Data may be processed in countries other than the country where Customer or Data Subjects are located.
Where international transfers require a transfer mechanism under Applicable Data Protection Laws, the Parties will cooperate to implement an appropriate mechanism, which may include:
- Standard Contractual Clauses;
- a data transfer agreement;
- adequacy decisions;
- other lawful transfer mechanisms.
Where EU, UK, or Swiss data transfer rules apply and no other lawful transfer mechanism is available, the applicable Standard Contractual Clauses may apply as incorporated by reference or by separate agreement.
Customer is responsible for determining whether its use of the Service involves international data transfers and whether additional notices, assessments, or agreements are required.
15. Sensitive Personal Data
Customer must not use the Service to collect or process sensitive Personal Data unless:
- Customer has a lawful basis;
- Customer has provided all required notices;
- Customer has obtained all required consents;
- Customer has implemented appropriate safeguards;
- such processing is permitted under the Agreement.
Sensitive Personal Data may include, depending on Applicable Data Protection Laws:
- health information;
- biometric data;
- government identification numbers;
- financial account data;
- precise location data;
- information about minors;
- racial or ethnic origin;
- religious beliefs;
- political opinions;
- union membership;
- sexual orientation;
- criminal records;
- payment card data;
- passwords or credentials.
LtsTalk is not designed to store or process highly sensitive information unless expressly agreed in writing.
16. AI and Automated Processing
If Customer enables AI-assisted features, Customer instructs LtsTalk to process applicable text or metadata through AI providers as necessary to provide those features.
AI features may include:
- text improvement;
- translation;
- summaries;
- suggested replies;
- classification;
- automation support;
- related assistance.
Customer remains responsible for reviewing AI output before using it or sending it to Visitors.
Customer should not submit sensitive Personal Data to AI features unless Customer has a lawful basis and appropriate safeguards.
LtsTalk may record technical metadata about AI usage, such as model, provider, status, token usage, feature type, and timestamps, but should avoid storing draft text or prompts unless necessary for the feature and disclosed appropriately.
17. Deletion and Return of Data
Upon termination of the Agreement or upon Customer's written request, LtsTalk will delete or return Customer Personal Data in accordance with the Agreement, product functionality, technical feasibility, and Applicable Data Protection Laws.
Deletion may be subject to:
- backup retention;
- legal obligations;
- fraud prevention;
- security requirements;
- accounting and billing records;
- dispute resolution;
- abuse prevention;
- technical limitations.
Data may remain in backups or logs for a limited period before being deleted or overwritten according to LtsTalk's retention practices.
Customer is responsible for exporting any data it needs before termination or deletion, where export functionality is available.
18. Audits and Compliance Information
Upon reasonable request, LtsTalk may provide information necessary to demonstrate compliance with this DPA.
Audits must be:
- reasonable in scope;
- subject to confidentiality;
- limited to information relevant to Customer Personal Data;
- scheduled in advance;
- conducted in a manner that does not disrupt LtsTalk operations or compromise security of other customers.
LtsTalk may satisfy audit requests by providing:
- security documentation;
- written responses;
- compliance summaries;
- third-party reports, if available;
- descriptions of controls;
- certifications, if available.
Customer may not access systems, code, infrastructure, data, or environments that could compromise security, confidentiality, or other customers.
19. Assistance With Compliance
Taking into account the nature of processing and information available to LtsTalk, LtsTalk will provide reasonable assistance to Customer where required by Applicable Data Protection Laws, including assistance related to:
- Data Subject requests;
- security obligations;
- breach notifications;
- data protection impact assessments;
- consultations with supervisory authorities;
- deletion or export of data.
LtsTalk may charge reasonable fees for assistance that is not included in the standard Service or that requires substantial manual effort.
20. Legal Requests
If LtsTalk receives a subpoena, court order, government request, law enforcement request, or other legal demand for Customer Personal Data, LtsTalk may disclose information if required by law.
Where legally permitted, LtsTalk may notify Customer before disclosure.
LtsTalk is not required to challenge legal requests unless required by law or agreed in writing.
21. Customer Affiliates and Users
Customer is responsible for all users, affiliates, agents, contractors, employees, and representatives who access the Service under Customer's Workspace.
Customer must ensure that such users comply with this DPA and the Agreement.
Any act or omission by Customer's users will be deemed an act or omission of Customer.
22. Order of Precedence
If there is a conflict between this DPA and the Agreement regarding processing of Customer Personal Data, this DPA will control to the extent of the conflict.
If Standard Contractual Clauses or other mandatory transfer terms apply and conflict with this DPA, those mandatory terms will control to the extent required by law.
23. Liability
Each Party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by Applicable Data Protection Laws.
Nothing in this DPA limits liability where such limitation is not permitted by law.
24. Term
This DPA remains in effect for as long as LtsTalk processes Customer Personal Data on behalf of Customer.
Obligations that by their nature should survive termination will survive, including confidentiality, deletion, security, liability, and audit-related provisions.
Schedule 1: Details of Processing
Subject Matter
Processing of Personal Data through the LtsTalk Service for live chat, visitor engagement, customer support, website widget operation, team inbox management, automations, transcripts, analytics, notifications, file attachments, and related SaaS functionality.
Duration
For the term of the Agreement and any period required for deletion, backup retention, legal compliance, security, dispute resolution, or continued processing authorized by Customer.
Nature of Processing
Collection, recording, storage, organization, structuring, transmission, retrieval, display, hosting, analysis, modification, deletion, backup, support, and other processing necessary to provide the Service.
Purpose of Processing
To provide and operate the Service, including:
- enabling website visitors to contact Customer;
- displaying chat messages to authorized agents;
- managing conversations;
- managing visitor details;
- enabling automations and proactive flows;
- processing attachments;
- sending transcripts;
- supporting notifications;
- managing user access;
- calculating usage and subscription limits;
- improving security and reliability;
- providing support.
Categories of Data Subjects
Customer may submit or cause the Service to process Personal Data relating to:
- Customer account owners;
- admins;
- supervisors;
- agents;
- employees;
- contractors;
- website visitors;
- prospects;
- customers of Customer;
- support contacts;
- billing contacts.
Categories of Personal Data
Customer Personal Data may include:
- name;
- email address;
- phone number;
- chat messages;
- attachments;
- profile information;
- assigned agent information;
- conversation metadata;
- timestamps;
- website activity;
- visited page information;
- browser or device context;
- IP-derived technical information;
- account and authentication metadata;
- billing identifiers;
- support communications;
- usage data;
- preferences and settings.
Sensitive Data
The Service is not intended for unnecessary sensitive data. Customer must avoid submitting sensitive data unless lawful, necessary, and appropriately protected.
Possible sensitive data may be included only if Customer, its users, or Visitors voluntarily submit it in chat messages, files, or fields.
Customer is solely responsible for determining whether sensitive data is submitted and whether such processing is lawful.
Schedule 2: Technical and Organizational Measures
LtsTalk will maintain reasonable safeguards appropriate to the nature of the Service, which may include:
Access Control
- user authentication;
- password hashing;
- role-based access controls;
- workspace permissions;
- brand or conversation access controls where available;
- restricted administrative access;
- removal of inactive users where configured by Customer.
Data Protection
- encryption in transit using HTTPS/TLS;
- secure handling of session data;
- protected access to attachments;
- logical separation of customer data;
- database access restrictions;
- backup procedures;
- avoidance of exposing internal storage paths publicly.
Application Security
- CSRF protection where applicable;
- signed or protected download routes where applicable;
- input validation;
- output escaping;
- rate limits for sensitive endpoints;
- secure framework practices;
- logging of operational errors.
Operational Security
- limited production access;
- use of service credentials through environment variables;
- restricted handling of API keys;
- monitoring and debugging procedures;
- incident response process;
- updates and maintenance.
Confidentiality
- access limited to personnel or service providers with a need to know;
- confidentiality obligations for personnel and contractors;
- reasonable controls over support access.
Availability and Resilience
- hosting infrastructure;
- backups;
- queue workers where applicable;
- scheduled tasks where applicable;
- error handling;
- service monitoring where configured.
Customer acknowledges that specific measures may evolve over time as the Service changes.
Schedule 3: Subprocessors
LtsTalk may use Subprocessors to provide the Service.
The current Subprocessor list should be maintained separately before publication.
Potential categories of Subprocessors may include:
- cloud hosting provider;
- database provider;
- storage provider;
- email provider;
- payment processor;
- AI provider;
- messaging provider;
- analytics or monitoring provider;
- customer support tools;
- domain, DNS, or infrastructure provider.
Before publishing this DPA, LtsTalk should complete this Schedule with Subprocessor name, service provided, location or processing region, and links to privacy or security terms when available.
Schedule 4: International Transfers
Where required by Applicable Data Protection Laws, the Parties will use appropriate transfer mechanisms for international transfers of Personal Data.
If the EU Standard Contractual Clauses apply, the Parties should complete the appropriate modules and annexes separately or incorporate them by reference.
This DPA does not itself replace any mandatory transfer document required by law unless expressly stated and completed by the Parties.
Schedule 5: Contact Information
Customer Privacy Contact
Customer privacy contact information should be provided by Customer where applicable.
LtsTalk Privacy Contact
For privacy-related questions, contact LtsTalk through the support or contact channels provided by the Service.
Website: https://ltstalk.io