This public DPA is provided by Aiginno Technologies Pvt Ltd, registered address Science City, Ahmedabad, for customer review.
1. Purpose and Scope
This Data Processing Addendum (DPA) supplements the Ginnobot Terms and Conditions or other written agreement between the customer and Ginnobot. It applies when Ginnobot processes Customer Personal Data on behalf of a customer through the Ginnobot website, dashboard, APIs, embeddable chatbot widget, WordPress plugin, customer cookie banner tools, lead capture, integrations, and related support services.
2. Parties and Roles
For Customer Personal Data, the customer is the controller, business, or data fiduciary that determines the purposes and means of processing. Ginnobot acts as processor, service provider, or data processor when it processes that data only to provide the Services. Ginnobot may act as an independent controller for its own account, billing, security, website analytics, marketing, support, and legal compliance data as described in the Privacy Policy.
3. Customer Instructions
Ginnobot will process Customer Personal Data only on documented customer instructions, including through product settings, chatbot configuration, source uploads, API requests, support tickets, and the governing agreement, unless law requires otherwise. The customer is responsible for ensuring that its instructions, chatbot content, visitor notices, consent choices, and use of the Services comply with applicable law.
4. Categories of Data
Customer Personal Data may include account user details, chatbot configuration, uploaded or crawled knowledge sources, website page content, chat conversation content, visitor messages, lead form details, phone numbers, email addresses, WhatsApp conversation data where enabled, consent records, support content, billing metadata, technical identifiers, page URLs, timestamps, IP-derived country signals where available, and other data submitted to or generated through the Services.
5. Processing Activities
Ginnobot may collect, receive, host, store, retrieve, structure, index, embed, transmit, disclose to approved subprocessors, analyze, generate AI responses from, display, secure, delete, and otherwise process Customer Personal Data as needed to provide chatbot training, chat responses, conversation management, lead capture, dashboard analytics, billing, support, security, integrations, and service administration.
6. Confidentiality and Access
Ginnobot will limit access to Customer Personal Data to authorized personnel, contractors, and subprocessors who need access to provide or secure the Services and who are subject to confidentiality obligations. Ginnobot will maintain internal controls designed to prevent unauthorized access, use, alteration, or disclosure.
7. Security Measures
Ginnobot uses reasonable technical and organizational safeguards appropriate to the nature of the Services, including HTTPS in transit for public service traffic, authentication controls, access controls, secret management practices, operational monitoring, role-based administrative access where available, backups where configured, and separation of customer chatbot data by account and chatbot identifiers. No online service can guarantee absolute security.
8. Subprocessors
Ginnobot may use subprocessors to provide hosting, database, object storage, AI response generation, embeddings, email delivery, payment processing, authentication, WhatsApp messaging, analytics, logging, monitoring, and support functions. Ginnobot remains responsible for subprocessors it appoints to process Customer Personal Data on its behalf and will require them to protect personal data under written obligations appropriate to their role.
9. Current Subprocessor Categories
Current or configurable subprocessor categories may include hosting and infrastructure providers, PostgreSQL database providers, AWS S3 or compatible object storage where configured, AI providers such as Google Gemini and Groq where enabled, email delivery providers such as Resend where configured, Razorpay for billing and subscriptions, Google authentication services, Meta WhatsApp Cloud API where configured, analytics and advertising providers such as Google Analytics and Google AdSense where consented, ipapi.co for browser-side country or currency signals where consented, and logging, monitoring, security, or customer-support tools used to operate the Services.
10. Subprocessor Changes
Ginnobot may update its subprocessors as the Services evolve. Where required by applicable law or a signed agreement, Ginnobot will provide notice of material subprocessor changes and give customers a reasonable opportunity to object on data protection grounds before the new subprocessor processes Customer Personal Data.
11. Assistance With Rights Requests
Taking into account the nature of the processing and the information available to Ginnobot, Ginnobot will reasonably assist customers in responding to data subject, data principal, or consumer rights requests relating to Customer Personal Data. If Ginnobot receives a request directly from a visitor or end user about Customer Personal Data, Ginnobot may direct that person to the relevant customer unless law requires a different response.
12. Breach Notification
Ginnobot will notify affected customers without undue delay after becoming aware of a confirmed personal data breach involving Customer Personal Data processed by Ginnobot. The notice will include information reasonably available to Ginnobot to help the customer meet applicable breach notification obligations.
13. Deletion and Return
Upon termination of the Services or written customer request, Ginnobot will delete or return Customer Personal Data in accordance with product functionality, support processes, backup cycles, and applicable legal retention requirements. Ginnobot may retain limited records where required for security, dispute resolution, legal compliance, accounting, or legitimate business records.
14. International Transfers
Customer Personal Data may be processed in countries other than the country where the customer, its users, or visitors are located. Where GDPR, UK GDPR, or similar transfer rules apply, the parties will use appropriate transfer safeguards such as standard contractual clauses, adequacy mechanisms, or other lawful transfer tools as applicable.
15. Audits and Information
Upon reasonable written request and subject to confidentiality, security, and availability limitations, Ginnobot will provide information reasonably necessary to demonstrate compliance with this DPA. Any audit or review must avoid disruption to the Services, protect other customers' data, and comply with reasonable security requirements.
16. Customer Responsibilities
The customer is responsible for having a lawful basis for processing, providing accurate privacy and cookie notices, obtaining required consents, configuring chatbot and cookie banner settings correctly, keeping source content lawful and up to date, securing its own accounts and websites, and responding to its visitors, leads, users, or customers.
17. Conflict and Duration
If this DPA conflicts with the Terms and Conditions regarding processing of Customer Personal Data, this DPA controls only for that processing. This DPA remains in effect while Ginnobot processes Customer Personal Data on behalf of the customer.
18. Governing Law
This DPA is governed by the law stated in the Terms and Conditions or other governing agreement between the parties, unless mandatory data protection law requires otherwise.
19. Contact
Data processing and privacy requests should be sent to sales@ginnobot.ai. Support requests should be sent to sales@ginnobot.ai. Include enough detail to identify the relevant customer account, chatbot, visitor request, or processing activity.
