Data processing agreement
This agreement governs our processing of personal data in the conversations your customers have with your agent. It forms part of the terms of service. Last updated 15 September 2026.
These are drafted documents, not legal advice. They have not been reviewed by a lawyer. If you are signing the data-processing agreement on behalf of a company, have your own counsel read it first.
Roles
For conversation data you are the controller and Media Yard LLC is the processor. We process it only on your documented instructions - which, in the ordinary course, are the configuration you set in the service. If we ever believe an instruction breaks the law, we will tell you rather than carry it out quietly.
For account data - the details of your people who sign in, your billing and your usage - Media Yard LLC is an independent controller, and the privacy notice governs it, not this agreement.
Everyone at Media Yard LLC who can access conversation data is bound by a duty of confidentiality.
What we process
Subject matter: operating an AI support agent on your behalf.
Duration: for as long as your account is open.
Nature and purpose: receiving customer messages, retrieving
passages from your knowledge base, generating replies, routing to your
people, and recording what happened; only when you ask, reading pages
of your own website to draft help articles for you to review; only if you
turn it on, receiving the support emails you forward to us and replying to
them; only if you
turn it on, taking a customer's email address in the chat so you can reply,
and sending that address one confirmation email in your name; only if you
turn it on and the customer ticks a box agreeing to it, sending them the
follow-up emails you write, each with an unsubscribe link and your postal
address; and, only if
you turn it on, counting how visitors use the pages of your website, as
daily totals.
Categories of data subject: your customers and your staff; and,
if you turn on visit counting, visitors to your website.
Categories of personal data: whatever your customers type or say,
which you control; contact details they provide; identifiers you pass
to the agent; the address of the page each conversation was started
on, without its query string or fragment; and, if you turn on visit
counting, the page-view measurements described in the
privacy notice. Those arrive with the
visitor's IP address, as every connection does, and are added into daily
totals without storing the address, the browser's details or the
individual page view.
Visit counting reads information from your visitors' browsers. Before you turn it on, you are responsible for telling your visitors about it and for any consent the law that applies to them requires. The widget honours Do Not Track and Global Privacy Control, but that is not a substitute for consent where consent is required.
The service is not built for special-category data, payment card numbers or government identifiers, and the terms prohibit sending them.
Sub-processors
You give general authorisation for the sub-processors below. We impose data protection terms on each that are at least as protective as this agreement, and we remain responsible for their performance.
We will tell the owners of your account by email at least 30 days before a new or replacement sub-processor starts processing your data, and update the list on this page at the same time. You may object on reasonable data-protection grounds within those 30 days. If we cannot resolve the objection, you may terminate the affected part of the service without penalty.
| Who | Why | What reaches them | Where |
|---|---|---|---|
| xAI |
Generates the agent's replies from a tenant's knowledge base. | Message text from a conversation, and the passages retrieved to answer it. | United States |
| OpenAI |
Turns knowledge-base documents and messages into embeddings, so the agent can find the passage that answers a question. | Knowledge-base document text, and message text at query time. | United States |
| Supabase |
Hosts the database. Everything the service stores is stored here. | Conversations, knowledge-base documents, account and user records, usage counts, the figures behind a published trust page, and the email addresses of people who joined the beta list. | United States (AWS us-east-1) |
| Cloudflare |
Runs the application, in a container on its network, and is the registrar and DNS for supportproof.com. Every request a customer or their end user makes passes through it and is served by it. | Everything in transit: message text, account records, and the IP addresses requests arrive from. Also the application's own logs, which it keeps for seven days, and the nightly database backups, which are encrypted before they reach it with a key it does not hold. | Requests are received and decrypted at the Cloudflare data centre nearest the visitor, which may be outside the United States. The application itself runs, and the backups are stored, in eastern North America. |
| GitHub |
Runs the nightly database backup. The job copies the database, checks the copy restores, encrypts it, and uploads it to Cloudflare. | A complete copy of the database, unencrypted, on a temporary machine for the few minutes the job runs. It is deleted when the job ends and is never stored at GitHub. | Temporary machines that GitHub runs in Microsoft Azure data centres, in a region GitHub chooses. |
| Resend |
Delivers sign-in links and account email. | Email addresses, and the contents of the messages we send to them. | United States |
| Stripe |
Takes payment for a paid plan, runs the subscription, and hosts the billing portal where an owner changes plan or cancels. |
The subscribing owner's email address, the account and plan being bought, and the payment details the owner enters on Stripe's own pages. Card numbers go to Stripe directly and are never stored here. | United States |
| Deepgram |
Speech to text, and text to speech, for voice conversations. |
Audio of a voice conversation, and the transcript produced from it. | United States |
Where a sub-processor uses its own infrastructure provider, it is named above. Those are onward sub-processors and the same objection right applies.
Security
Data is encrypted in transit. Access to production data is limited to people who need it. Tenant data is separated by account and every query is parameterised. Alert destinations must be HTTPS, because a URL you supply that we POST to is a request-forgery primitive if it is not.
We do not currently hold SOC 2 or ISO 27001 certification, and we say so rather than implying otherwise.
Breach notification
If we become aware of a personal data breach affecting your data, we will tell the owners of your account by email without undue delay, and in any event within 48 hours of becoming aware of it.
The notice will describe, as far as we know at the time: the nature of the breach, including the categories and approximate number of people and records affected; its likely consequences; the measures we have taken or propose to take; and who to contact for more. Where we cannot give everything at once, we will send it in phases as we learn it. Telling you is not an admission of fault.
Helping you answer your customers
If one of your customers exercises a right - access, deletion, correction - the service gives you the tools to answer it yourself. Where it does not, we will help, and we will not charge you for reasonable assistance.
International transfers
The application and its database run in the United States, and our other sub-processors process in the United States. The exception is Cloudflare: a request is received and decrypted at the data centre nearest the person making it, which may be outside the United States, before it is passed to the application. The sub-processor table above states each location.
From the EEA. Where you transfer conversation data to us from the EEA, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated into this agreement, with you as data exporter and Media Yard LLC as data importer:
- Module Two (controller to processor) applies where you are the controller, and Module Three (processor to processor) where you process the data for someone else.
- Clause 7 (the docking clause) is included.
- Clause 9: Option 2, general written authorisation, with the 30-day notice period set out above.
- Clause 11: the optional independent dispute resolution wording is not used.
- Clause 13: the competent supervisory authority is the one that supervises you as exporter, or as the clause otherwise provides.
- Clause 17: Option 1, the law of Ireland. Clause 18: the courts of Ireland.
- Annex I is completed by the parties and the "What we process" section of this agreement; Annex II by the "Annex II" section below; Annex III by the sub-processor table above.
From the UK. The International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner applies, completed with the same parties, modules and annexes as above. Either party may end the Addendum as it allows.
From Switzerland. The same clauses apply with the Swiss adjustments: the Federal Data Protection and Information Commissioner is the competent authority for transfers governed by the Swiss Federal Act on Data Protection, references to the GDPR include that Act, and people in Switzerland may bring claims there.
United States privacy laws
Where you are a business under the California Consumer Privacy Act or a similar state law, we act as your service provider or processor for conversation data. We will not sell or share it; will not retain, use or disclose it for any purpose other than the business purpose of providing the service described in this agreement, including outside our direct business relationship with you; and will not combine it with personal data we receive from anyone else, except as those laws allow. We will tell you if we can no longer meet these obligations, and you may take reasonable steps to stop and remedy any unauthorised use. We certify that we understand these restrictions and will comply with them.
Return and deletion
You can export your conversation data in a machine-readable format, and delete a conversation or everything before a date, at any time while your account is open, through the admin API described in the documentation. A deletion removes every copy of the conversation's words that the service holds. When your account closes, we delete the rest within 30 days, except where the law requires us to keep something, and backups are overwritten in the ordinary cycle.
Audit
On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer a reasonable security questionnaire and provide the information you need to demonstrate compliance.
If documents conflict
On personal data, this agreement prevails over the terms of service. If this agreement conflicts with the Standard Contractual Clauses or the UK Addendum, the clauses prevail.
Annex II: security measures
- Traffic between browsers and the service is encrypted with TLS, and the application reaches its database over TLS.
- Admin API keys, sign-in links and session secrets are stored only as SHA-256 hashes, so a copy of the database does not contain usable credentials. A sign-in link expires after 15 minutes.
- The session cookie is HttpOnly, Secure and SameSite=Lax.
- Each account's data is separated by account, and every database query is parameterised.
- An embed key only works from the origins the account has allowed.
- Alert destinations must be HTTPS.
- Consequential actions are recorded in an audit log.
- Access to production data is limited to people who need it, who are bound by confidentiality.
- The database is hosted by Supabase on Amazon Web Services, which encrypts stored data at rest.
We do not currently hold SOC 2 or ISO 27001 certification.