Data Processing Addendum
Last updated: October 2, 2026
This Data Processing Addendum (DPA) forms part of the agreement between TidyChats (the processor) and the customer (the controller) for business use of TidyChats, including Teams.
Scope of processing
TidyChats processes personal data only to provide the service. Processed data is limited to account details (email, name), team membership and roles, license status, and synced items: folders, prompts, chains, tags, bookmarks, shared team prompts and settings. Conversation content is stored in the user's browser and is not processed on TidyChats servers, except text a user explicitly submits to the @@ summarize feature.
Processor obligations
- Process personal data only on documented instructions from the controller.
- Ensure staff with access are bound by confidentiality.
- Apply appropriate technical and organizational security measures.
- Assist the controller in responding to data subject requests.
- Notify the controller without undue delay after becoming aware of a breach.
- Delete or return personal data at the end of the service.
Security measures
- Synced data encrypted at rest with AES-256-GCM
- Encryption in transit with TLS
- Authentication with signed, expiring tokens
- Access to production systems restricted to authorized staff
Sub-processors
- Stripe: payment processing and billing
- Resend: transactional email
- OpenAI: on-demand summarization, only when triggered by a user
- Hetzner Online (Germany): hosting and database
- Cloudflare: DNS and network protection
We will notify customers before adding a new sub-processor.
International transfers
Where personal data is transferred outside the customer's region, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
Requesting a signed copy
To request a countersigned DPA, email [email protected].