This section describes our data protection roles and responsibilities under the UK GDPR and EU GDPR.
9.1 Respondable as Data Controller
Respondable AI acts as the data controller for personal data relating to:
- Your client account information (name, email, authentication credentials)
- Billing and subscription data
- Administrative activity and account usage logs
- Communications between you and Respondable
For this data, we determine the purposes and means of processing. Our lawful bases for processing are set out in our Privacy Policy.
9.2 Respondable as Data Processor
Respondable AI acts as a data processor on your behalf for:
- Website content you authorise us to crawl and index
- Chat conversations between your visitors and the AI chatbot
- Lead capture data collected from your visitors
- Knowledge base entries you create
For this data, you are the data controller. We process it only on your documented instructions (as set out in these Terms) and solely to provide the Service.
9.3 Your Responsibilities as Data Controller
Where you are the data controller (for your visitors' and end users' data), you are responsible for:
- Ensuring you have the right to provide website content for processing
- Complying with applicable data protection laws (including UK GDPR, EU GDPR, or equivalent laws in your jurisdiction)
- Informing your website visitors about the chatbot and any data collection via your own privacy policy
- Obtaining appropriate consent for lead capture where required
- Responding to data subject requests from your end users
- Notifying us if you become aware of any data protection issues
9.4 Processing Scope and Instructions
Our processing of your data is limited to what is necessary to provide the Service, specifically:
- Crawling and indexing designated website domains
- Creating and storing vector embeddings
- Generating AI responses to visitor queries
- Storing and displaying conversation logs
- Providing analytics and usage metrics
These Terms, together with your configuration choices in the dashboard, constitute your documented instructions to us. We will not process your data for any other purpose without your consent.
9.5 Sub-Processors
We use third-party sub-processors to provide the Service. Current categories include:
- AI and machine learning: Providers of large language models and embedding generation (e.g., OpenAI)
- Infrastructure: Cloud hosting, databases, and compute services (e.g., Supabase, Qdrant, Render)
- Payments: Payment processing providers (e.g., Stripe)
- Email: Transactional email services (e.g., Resend)
By agreeing to these Terms, you authorise our use of these sub-processors. We maintain appropriate contracts with sub-processors that impose data protection obligations consistent with this agreement.
9.6 International Data Transfers
Your data may be processed in countries outside the United Kingdom or European Economic Area (EEA), particularly the United States, where our infrastructure providers and AI services operate.
Where data is transferred outside the UK or EEA, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreement (IDTA) where applicable
- Adequacy decisions where available
9.7 Data Processing Addendum
For clients who require a formal Data Processing Agreement (DPA) to meet their compliance requirements, please contact us at hello@respondableai.com. We can provide a DPA that sets out additional processing terms in line with Article 28 of the UK GDPR / EU GDPR.