DATA PROCESSING AGREEMENT
DPA.
Data processing agreement per Art. 28 GDPR · Effective: June 1, 2026
(1) The subject of this agreement is the data processing of personal data per Art. 28 GDPR in the context of the use of the SilentChat platform by the customer ("Controller") through Forge12 Interactive GmbH ("Processor").
(2) Processing takes place exclusively to provide the contractually agreed services.
Nature: collection, storage, modification, retrieval, transmission, deletion, destruction of personal data in the context of platform use (live chat, AI chatbot, knowledge base, workflows, inbox).
Purpose: providing the customer support services of the Controller to its end users.
Duration: for the term of the main contract between Controller and Processor.
The following data categories are processed in particular:
· Master data (name, email, phone, address, company — if provided)
· Communication data (conversation content, timestamps, channels)
· Technical data (user agent, language, anonymized IP)
· Usage data (click paths within the conversation)
· Survey responses (CSAT, NPS, custom feedback)
· File uploads (if attached by the end user)
· Visitor attributes transmitted by the Controller through the widget JavaScript API (freely chosen key-value pairs, e.g. plan or customer number)
· Event data from the Controller’s website (event name, timestamp, transmitted properties)
· End customers of the Controller using the widget
· Employees of the Controller working as agents
· Other natural persons whose data the Controller uploads to the platform
(1) The Processor processes personal data only on documented instructions from the Controller, unless required by Union or member state law.
(2) The Processor ensures that all persons involved in processing are committed to confidentiality or are subject to an appropriate statutory obligation of confidentiality.
(3) The Processor takes all measures required by Art. 32 GDPR for the security of processing — see Annex 2 (TOM).
(4) The Processor supports the Controller, considering the nature of processing and as far as possible, with appropriate technical and organizational measures in fulfilling its obligations to respond to data subject requests.
(5) The Processor supports the Controller in complying with obligations under Art. 32 to 36 GDPR.
(1) Upon conclusion of the contract, the Controller approves the subprocessors named in the current subprocessor list.
(2) The Processor informs the Controller at least 30 days before adding or replacing a subprocessor by email.
(3) The Controller may object to the change within 14 days. With justified objection the Controller has the right to extraordinary termination.
(1) After termination of the contract, the Processor makes all personal data of the Controller available — as signed JSON export, retrievable in the self-service portal for 30 days.
(2) After the 30-day period expires, all data is deleted. Backup data is deleted with the next rotation cycle (max. 30 days later). The Processor confirms deletion in writing.
(1) The Controller has the right to audit compliance with the obligations from this agreement on-site and with reasonable advance notice — or to have it audited by commissioned third parties.
(2) Instead of an on-site audit, the Processor may provide current certificates, pen test reports, or an ISAE 3000 report, insofar as these cover the essential content.
Part of this contract are:
· Annex 1: Technical and organizational measures (TOM) — see silentchat.de/security
· Annex 2: Subprocessor list
· Annex 3: Data categories & processing purposes (see §3, §4)