Version 1.0, effective 2026-09-05. This agreement governs Chirply’s processing of personal data on your behalf, and incorporates the Standard Contractual Clauses for transfers out of the EEA, the UK, and Switzerland.
To put this in force for your workspace, sign in and go to Settings → Your data → Data Processing Agreement. Accepting there records who signed, when, and which version, and gives you a countersigned copy to download. No email, no redlines, no waiting on us.
1. Roles and scope
This Agreement applies where Vaughn Labs (“Chirply”, “we”) processes personal data on behalf of a customer (“you”) in providing the service, and forms part of our Terms of Service.
You are the controller of the personal data you put into your workspace — your contacts, your conversations, your form submissions, the visitors to sites you track. You decide why that data is held and on what legal basis. We process it only to provide the service to you.
We are the controller of your own account data — who signed up, billing details, and how the product is used to run and improve it. That processing is described in our Privacy Policy, not here.
If you are an agency and your own clients are the controllers of data in workspaces you manage, you act as their processor and we act as your sub-processor. This Agreement is written so you can hold it out to them, and Module Three of the Standard Contractual Clauses applies to those transfers.
2. Our obligations as processor
We will:
- Process only on your instructions. Your use of the service, and this Agreement, are your documented instructions. We will not process your data for any other purpose, and specifically will not sell it, use it for advertising, or use it to train general-purpose AI models. If we are required by law to process beyond your instructions, we will tell you first unless the law forbids it.
- Keep it confidential. Everyone we authorise to access personal data is bound by confidentiality obligations that survive the end of their engagement.
- Secure it. We maintain the technical and organisational measures set out in Annex II, appropriate to the risk under Article 32.
- Help you answer data subjects. The product gives you self-service tools to export, correct, and erase an individual person’s data across every dataset, so most requests need nothing from us. Where a request cannot be satisfied with those tools, we will assist you, taking into account the nature of the processing.
- Help you with Articles 32 to 36. We will provide the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority.
- Tell you about a breach. We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification duties.
- Delete or return it. On the end of the service we delete or anonymise your data within the window published in the Privacy Policy. You can export everything yourself, at any time, before or after you ask us to delete it.
- Let you verify this. We will make available the information needed to demonstrate compliance with this Agreement, and will contribute to audits you or your auditor conduct, no more than once a year unless a supervisory authority or a breach requires otherwise.
3. Your obligations as controller
- You are responsible for having a lawful basis for the personal data you put into the service, for the notices you give the people it belongs to, and for obtaining consent where consent is the basis you rely on — including for marketing, for cookies and tracking on sites you publish, and for recording calls or sessions.
- You are responsible for the accuracy of the data and for the instructions you give us, including any instruction you issue through the API, the MCP server, or the in-app assistant.
- You must not use the service to process the categories of data excluded in Annex I.
4. Sub-processors
You give us general authorisation to engage the sub-processors listed in Annex III. We impose data protection obligations on each of them no less protective than those in this Agreement, and we remain fully liable to you for their performance.
Before we add or replace a sub-processor we will update Annex III and give at least 30 days’ notice. You can subscribe to those notices on the sub-processor page. If you reasonably object on data protection grounds, tell us within the notice period and we will work with you on an alternative; if none exists, you may terminate the affected part of the service and receive a pro-rata refund for the unused term.
Where you supply your own credentials for a provider — your own Twilio, Mailgun, or Stripe account — that provider is your contractual counterparty, not our sub-processor, and your agreement with them governs their processing in addition to this Agreement. Annex III marks which providers those are.
5. International transfers
Chirply processes personal data in the United States. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two where the customer is a controller and Module Three where the customer is itself a processor, incorporated into this Agreement by reference and completed by the Annexes below. The UK International Data Transfer Addendum applies to transfers from the United Kingdom. Chirply has carried out a transfer impact assessment covering the sub-processors listed in Annex III and makes it available on request.
For the purposes of the Standard Contractual Clauses: you are the data exporter and Vaughn Labs is the data importer; the optional docking clause applies; the governing law and forum are those of Ireland where Module Two or Three applies; Annex I, II, and III of this page complete Annexes I, II, and III of the Clauses.
6. Liability and term
This Agreement takes effect when you accept it in-app or when you begin using the service, whichever is earlier, and continues for as long as we process personal data on your behalf. The limitations of liability in the Terms of Service apply to this Agreement, except where they may not lawfully be applied to obligations under the Standard Contractual Clauses.
If any term of this Agreement conflicts with the Terms of Service, this Agreement prevails on data protection matters. If any term conflicts with the Standard Contractual Clauses, the Clauses prevail.
Annex I — Particulars of processing
A. Categories of data subject
- The controller's customers, clients, and prospective customers
- People who submit a form, book an appointment, or make a purchase on a page the controller publishes
- People who visit a website on which the controller has installed tracking
- People who call, message, or email the controller
- The controller's own staff and collaborators who hold a workspace login
- Where the controller is a white-label agency, the end customers of that agency's own clients
B. Categories of personal data
- Identity and contact details — name, email address, postal address, phone number, social profile identifiers
- Communications content — the body of emails, SMS, social messages, call recordings and their transcripts, and notes
- Commercial data — orders, invoices, payments, subscriptions, and deal history
- Online identifiers and device data — IP address, browser and device information, cookie and visitor identifiers, pages viewed, and session recordings where enabled
- Submitted content — anything a data subject types into a form, booking, or checkout the controller publishes
- Any additional field the controller chooses to create, whose contents are determined solely by the controller
C. Special categories
Chirply is not designed for, and must not be used to process, special categories of personal data as defined in Article 9 GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation), nor data relating to criminal convictions and offences. Custom fields make it technically possible for a controller to enter such data; doing so is outside the permitted scope of processing, and the controller alone bears responsibility for it.
D. Nature and purpose of the processing
- Storing and organising the controller's customer records, companies, deals, and related business data.
- Sending and receiving communications the controller initiates or configures — email, SMS, voice calls, and social messaging — and storing the resulting history.
- Recording calls and, where the controller enables it, recording website sessions, on the controller's instruction and subject to the controller's own legal basis.
- Running the controller's automations, campaigns, and scheduled workflows against their own records.
- Hosting the controller's public pages, forms, funnels, stores, and booking pages, and receiving submissions made to them.
- Measuring website and campaign activity for the controller, where the controller has enabled tracking.
- Generating content, summaries, and suggestions with AI models at the controller's request, using only the material submitted for that request.
- Providing support to the controller, including access to their workspace by named staff where the controller asks for help.
- Maintaining backups and ensuring availability, security, and integrity of the service.
E. Frequency and duration
Frequency: Continuous, for as long as the controller's workspace is active.
Duration: For the term of the controller's subscription, and thereafter for no longer than the retention window published in the Privacy Policy, after which the data is deleted or anonymised except where retention is required by law.
F. Competent supervisory authority
Determined by the data exporter’s place of establishment under Clause 13 of the Standard Contractual Clauses.
Annex II — Technical and organisational measures
The measures below are in force today. The full detail, including what we do not yet claim, is on the security page.
- Encryption. All traffic to Chirply is served over TLS 1.2 or higher. Data at rest in the primary database and in object storage is encrypted by the storage layer.
- Encryption. Third-party provider credentials and OAuth access tokens carry a second layer of application-level AES-256-GCM encryption, so a database disclosure alone does not yield working credentials for a customer's Twilio, Mailgun, Stripe, or Meta account.
- Access control — tenant isolation. Separation between customer workspaces is enforced in the database with PostgreSQL row-level security, not in application code. Policies resolve access through audited SECURITY DEFINER helpers, and an automated suite asserts that every table carries RLS and that no privileged function is callable anonymously.
- Access control — roles. Access within a workspace is role-based (owner, admin, member). The public API, the MCP server, and the in-app assistant enforce the same role requirements as the user interface, verified by an automated conformance test, so an integration can never do more than the person who authorised it.
- Access control — staff. Administrative access to production is limited to named platform administrators. Staff access to a customer workspace for support is explicit, role-gated, and recorded in the workspace's own activity log.
- Secret management. Runtime secrets are held in the hosting platform's secret store, are scoped per service, and are never present in the source repository or in build artefacts. Service-role database credentials are server-only and cannot be reached from browser code.
- Pseudonymisation and minimisation. Session recordings mask every value a visitor types — including email addresses, phone numbers, and free text — in the browser before anything is transmitted; the masking is not a setting a site can switch off. Password, hidden, and file inputs are excluded outright, and canvas content is never captured.
- Pseudonymisation and minimisation. Visitor tracking honours the browser's Do Not Track and Global Privacy Control signals, and, where a workspace has enabled consent management, collects nothing at all before the visitor has consented.
- Resilience and availability. The application runs on a globally distributed edge platform with automatic failover between locations. The database is managed, replicated, and monitored by the provider.
- Backup and restoration. The primary database is backed up continuously with point-in-time recovery. The recovery window is seven days. Customers who need a longer retrievable history should use the self-service workspace export or configure scheduled backups to their own storage.
- Monitoring and incident detection. Every uncaught server and browser error in production is captured, grouped by cause, and triaged from an internal queue daily. Regressions reopen automatically when a previously resolved fault recurs after a deployment.
- Secure development. Changes reach production only through an automated pipeline from the main branch. A full type check and unit suite gate every deployment, and a failing suite stops the release before anything is built. Direct manual deployment from a developer machine is prohibited by policy.
- Vulnerability management. Dependencies are updated on a rolling basis and security advisories affecting them are actioned on discovery. Chirply does not currently hold a SOC 2 or ISO 27001 certification and does not claim one. Independent penetration testing has not yet been commissioned.
- Deletion and retention. Closing a workspace starts a documented retention window after which its contents are deleted or anonymised. Workspaces can additionally set their own retention windows for tracking data, session recordings, call recordings, and message history, and can erase an individual person's records across every dataset on request.
- Personnel. Everyone with access to customer data is bound by confidentiality obligations that survive the end of their engagement.
Annex III — Sub-processors
The current list, always in sync with the sub-processor page:
- Supabase (United States) — Primary database, authentication, and file storage.
- Cloudflare (United States, with a global edge network) — Application hosting, DNS, CDN, and object storage (R2).
- Stripe (United States, Ireland) — Payment processing and subscription billing.
- Twilio (United States, with regional edge options) — Telephony, SMS, and call recording transport. Engaged under your own account where you supply credentials.
- Mailgun (Sinch) (United States, with an EU region available) — Outbound and inbound email delivery. Engaged under your own account where you supply credentials.
- Meta Platforms (United States, Ireland) — Facebook and Instagram messaging, lead forms, and ad reporting.
- OpenRouter (United States) — Routing prompts to AI models for assistive and generative features.
- Resend (United States) — Transactional email for platform notices and authentication.
Contact
Vaughn Labs — privacy@chirply.io
See also our Privacy Policy, Security, Sub-processors, and Data Deletion.