Legal

Data Processing Agreement

Widgo, Inc.

Effective date: 25 August 2026 · Last updated: 25 August 2026

This Data Processing Agreement ("DPA") forms part of the Widgo Terms of Service between Widgo, Inc. ("Widgo", "Processor") and the customer that accepts those Terms ("Customer", "Controller").

No signature is required. This DPA applies automatically to every customer whose use of the Service involves personal data subject to Data Protection Law. Accepting the Terms of Service accepts this DPA. If your procurement process requires a counter-signed copy, or you need it on your own paper, email support@widgo.ai and we will execute it.

Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA controls.

1. Definitions

Data Protection Law means all laws applicable to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, PIPEDA, and the CCPA as amended by the CPRA.

Customer Personal Data means personal data contained in Customer Data that Widgo processes on Customer's behalf under the Terms.

Data Subject, processing, controller, processor, personal data and personal data breach have the meanings given in the GDPR. Business, service provider, sell and share have the meanings given in the CCPA.

SCCs means the Standard Contractual Clauses in European Commission Implementing Decision (EU) 2021/914.

UK Addendum means the UK Information Commissioner's International Data Transfer Addendum to the SCCs, version B1.0.

Subprocessor means a third party engaged by Widgo to process Customer Personal Data.

2. Roles

Customer is the controller. Widgo is the processor. Customer determines the purposes and means of processing Customer Personal Data and is responsible for the lawfulness of the instructions it gives.

Where Customer is itself a processor for a third party, Customer warrants that it has the authority of that controller to appoint Widgo as a subprocessor on these terms, and references to Customer's instructions include that controller's instructions.

Widgo is a controller for its own account, billing, security and product analytics data, as described in the Privacy Policy. That processing is outside this DPA.

3. Scope of processing

Subject matter. Provision of the Widgo Service.

Duration. For as long as Customer's account is open, plus the deletion periods in section 10.

Nature and purpose. Hosting, storing, retrieving, analysing, generating responses to, transmitting and deleting Customer Personal Data in order to run an AI agent on Customer's website, identify visiting organisations, capture and score leads, book meetings, and sync data to Customer's chosen integrations.

Types of personal data. Contact details volunteered by visitors (name, email, phone, company, role); conversation content, including anything a visitor chooses to type or say; IP address and approximate location derived from it; device, browser and referrer data; pages viewed on Customer's site; company-level firmographic data; lead scores; booking details; and, where Customer enables them, session replay recordings and voice audio with transcripts.

Categories of Data Subject. Visitors to Customer's websites; Customer's own personnel with workspace access; and any individual whose details a visitor enters.

Special category data. Customer must not submit special category data under GDPR Article 9, criminal offence data, government identifiers, payment card numbers, biometric data, precise geolocation, or data about children under 16.

HIPAA. Protected health information may be processed only where Widgo and Customer have executed a Business Associate Agreement. Widgo makes a BAA available on request at support@widgo.ai. Until it is executed, Widgo is not a Business Associate and PHI must not be submitted to the Service.

4. Widgo's obligations

Widgo will:

1. Process Customer Personal Data only on Customer's documented instructions, which comprise the Terms, this DPA, and Customer's use of and configuration of the Service, unless required otherwise by law, in which case Widgo will inform Customer first unless the law prohibits it.

2. Immediately inform Customer if, in Widgo's opinion, an instruction infringes Data Protection Law.

3. Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality and are trained appropriately.

4. Implement and maintain the technical and organisational measures in Annex A.

5. Assist Customer, taking into account the nature of processing and the information available, with data subject requests, data protection impact assessments, prior consultations with supervisory authorities, and security and breach obligations under Articles 32 to 36 GDPR.

6. Make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in section 8.

7. Not sell or share Customer Personal Data, retain, use or disclose it for any purpose other than performing the Service, or combine it with personal data from other sources except as necessary to provide the Service. Widgo certifies it understands and will comply with these CCPA restrictions.

8. Not use Customer Personal Data or conversation content to train foundation models, and require the same of the AI providers it uses to deliver the Service.

5. Customer's obligations

Customer will:

1. Comply with Data Protection Law as controller, including providing all required notices and establishing and documenting a lawful basis for the processing carried out through the Service.

2. Maintain an accurate privacy notice on its website describing the processing performed through Widgo, including conversation collection, IP-based company identification, and any session replay or voice recording it enables.

3. Obtain and maintain any consent required, including under ePrivacy and cookie rules and under session recording, call recording and wiretap laws, and configure the Service behind its consent management tooling where required.

4. Not enable session replay or voice recording without the notices and consents that recording requires in the jurisdictions where its visitors are located.

5. Not submit prohibited data as described in section 3.

6. Respond to data subject requests it receives as controller, using the Service's own export, correction and deletion controls in the first instance.

7. Configure retention, access and integrations appropriately for its own compliance posture.

6. Data subject requests

The Service gives Customer the ability to access, correct, export and delete Customer Personal Data itself. Where Customer cannot fulfil a request through the Service, Widgo will provide reasonable assistance at Customer's request.

If Widgo receives a request directly from a Data Subject relating to Customer Personal Data, Widgo will not respond to it substantively, will refer the Data Subject to Customer, and will inform Customer promptly.

7. Subprocessors

Customer gives general written authorisation for Widgo to engage subprocessors. The current list, with each subprocessor's purpose and processing location, is published at the Subprocessors page and is incorporated here.

Widgo will impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to Customer for each subprocessor's performance.

Change notice. Widgo will give at least 30 days' notice before adding or replacing a subprocessor, by updating the Subprocessors page and notifying customers who subscribe to change notices at the address on that page. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid unused fees. That is Customer's sole remedy for an objection.

8. Audit

On written request, no more than once in any 12-month period unless a personal data breach or a supervisory authority requires otherwise, Widgo will provide its then-current security documentation, completed security questionnaire, and any third-party audit report or certification it holds, subject to confidentiality.

If that is genuinely insufficient to demonstrate compliance, Customer may conduct an audit on 30 days' written notice, during business hours, without disrupting the Service, limited in scope to processing under this DPA, conducted by an independent auditor who is not a Widgo competitor and who signs a confidentiality agreement, at Customer's expense. Widgo may charge reasonable fees for time spent beyond eight hours.

9. Personal data breach

Widgo will notify Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of records and Data Subjects affected so far as known, the likely consequences, the measures taken or proposed, and a contact point.

Widgo will take reasonable steps to contain and remediate, and will assist Customer with its own notification duties. Notification is not an acknowledgement of fault or liability.

10. Deletion and return

On termination or expiry, and on Customer's written request at any time, Widgo will delete or return Customer Personal Data. Deletion from live systems takes place within 30 days. Backups are overwritten on a rolling cycle no longer than 90 days.

Widgo may retain Customer Personal Data where required by law, and in that case will continue to protect it under this DPA and process it only for the purpose that requires retention.

Customer is responsible for exporting its data before deleting a workspace.

11. International transfers

Where Widgo processes Customer Personal Data subject to GDPR outside the EEA without an adequacy decision, the SCCs apply and are incorporated into this DPA by reference:

  • Module Two (controller to processor) applies where Customer is a controller.

  • Module Three (processor to processor) applies where Customer is a processor.

  • Clause 7 (docking) applies. Clause 9, option 2 (general written authorisation) applies with a 30-day notice period. Clause 11 does not include the optional independent dispute resolution body. Clause 17, option 1 applies, governed by the law of Ireland. Clause 18(b) selects the courts of Ireland.

  • Annex I is populated by section 3 of this DPA and the Subprocessors page. Annex II is Annex A below.

For UK transfers, the UK Addendum applies to the SCCs, with tables completed by reference to this DPA, and the ending date determined by clause 19 of the Addendum. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP, the supervisory authority is the FDPIC, and "member state" includes Switzerland.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the maximum extent permitted by Data Protection Law. Nothing in this DPA limits any liability to a Data Subject that cannot be limited by law.

13. Term

This DPA takes effect when Customer accepts the Terms and continues until Widgo has deleted or returned all Customer Personal Data.

Annex A · Technical and organisational measures

Access control. Role-based access inside the product (Owner, Admin, Member, Billing). Tenant isolation enforced at the database layer so a workspace can only read its own records. Internal access on a least-privilege, need-to-know basis, reviewed periodically and revoked on role change or departure.

Authentication. Federated sign-in with Google and Microsoft, password sign-in with strength requirements, two-factor authentication, active session listing and revocation.

Encryption. TLS on all connections in transit. Encryption at rest for stored data with keys managed by the underlying platform providers.

Network and edge security. Web application firewall, DDoS mitigation, bot management, per-IP rate limiting, and human verification challenges on sign-up and widget endpoints.

Logging and monitoring. Centralised application, infrastructure and security logging with alerting on anomalies and errors. Retention of security logs for up to 24 months.

Resilience. Managed platform providers with redundancy and automated backup. Restore procedures tested periodically.

Secure development. Version control with peer review before merge, automated checks in the pipeline, secrets held in managed secret stores and never in source control, separate environments.

Personnel. Confidentiality obligations in every employment and contractor agreement, intellectual property and confidentiality assignment on entry, security awareness expectations, and access revocation on exit.

Vendor management. Written data protection terms with every subprocessor, documented review before engagement, and a published subprocessor list with change notice.

Data minimisation. Company-level identification only. No person-level identification from traffic. No cross-site visitor profiling. No use of customer conversation content for foundation model training.

Incident response. Documented process for detection, triage, containment, notification and post-incident review, with the notification timeframe in section 9.

Widgo, Inc. · Delaware, USA · support@widgo.ai

Your next customer is already on your site.

Widgo talks to every visitor, answers what they ask, and hands your team the ones who are ready.

Live in 5 minutes, free forever.

Your next customer is already on your site.

Widgo talks to every visitor, answers what they ask, and hands your team the ones who are ready.

Live in 5 minutes, free forever.

Your next customer is already on your site.

Widgo talks to every visitor, answers what they ask, and hands your team the ones who are ready.

Live in 5 minutes, free forever.