AskHelper AI

Effective: July 15, 2026

Data Processing Addendum

Terms governing AskHelper AI processing personal data for a customer through the widget and knowledge base.

1. Incorporation, parties, and term

This DPA forms part of the Terms of Service and applies when IE FEDOSEENKO N.A. (AskHelper AI, processor) processes personal data for the customer (controller) in providing the service. It runs from the start of that processing until data is returned or deleted under the agreement, subject to backups and mandatory retention.

2. Subject matter, operations, and purpose

Processing supports the AI widget, knowledge base, conversation history, and related functions. Operations may include collection, recording, organization, storage, retrieval, transformation, embedding, transmission to AI providers, response generation, display, support, export, restriction, and deletion. The purpose is to follow documented customer settings and requests, provide and secure the service, and perform the agreement.

3. People and data

Data subjects may include customer personnel and users, website visitors, customers, prospects, and people lawfully represented in submitted knowledge-base content or conversations. Data may include identifiers, name, email, online identifiers, metadata, messages and history, ratings, file and page content, extracted chunks and embeddings, project instructions, and technical events. The customer must not submit special-category or other sensitive data without necessity, a lawful basis, and an appropriate risk assessment.

4. Instructions and confidentiality

We process only on documented instructions in the agreement, service settings, and lawful support requests, unless law requires otherwise; where permitted, we will notify the customer. If we reasonably believe an instruction violates applicable data-protection law, we will inform the customer and may pause the affected operation. Personnel with access are bound by confidentiality and access data only as needed.

5. Security

We maintain risk-appropriate measures including tenant scoping and access controls, database hashing of widget keys, server-side BYOK encryption, HttpOnly auth cookies, domain allowlists, secret management, audit records, and abuse controls, together with infrastructure-provider safeguards. Measures may evolve without materially reducing overall protection. Absolute security is not guaranteed.

6. Subprocessors

The customer generally authorizes Supabase (DB/Auth/Storage), Vercel (hosting/runtime/logs), Jina AI (embeddings), OpenRouter and selected models (generation), Resend (transactional email), and Forward Email and Google for support communications; Telegram is used only for enabled operational alerts. We impose applicable data-protection duties and remain responsible as required by law. We will give available notice of a material new subprocessor. A customer may timely object on reasonable data-protection grounds; the parties will seek a practical solution, failing which the affected function may be terminated.

7. Paddle carve-out

Paddle acts as Merchant of Record and an independent controller for checkout, payment, tax, and billing purposes, not as our subprocessor for those independent activities. Order or subscription events received by us are handled under the Privacy Policy and, where they form customer-processor data, this DPA.

8. Transfers

Processing may occur internationally. Where applicable law requires a transfer mechanism, the parties will cooperate in using an available lawful mechanism and reasonable supplementary measures. This DPA does not promise EU-only processing or state that a particular set of standard contractual clauses has already been executed.

9. Breach and assistance

After becoming aware of a breach affecting customer personal data, we will notify the customer without undue delay and provide available information reasonably needed for assessment and notices. Considering the nature of processing and available information, we reasonably assist with data-subject requests, impact assessments, prior consultations, and regulator inquiries. The customer remains responsible for its decisions, deadlines, and notices; non-standard assistance may be charged by prior agreement where law permits.

10. Return and deletion

At service end, and at the customer's choice where available through service controls or a written request, we delete or return personal data unless law requires retention. Only the owner can delete an entire workspace. Limited copies may remain in backups and logs until ordinary provider cycles expire and are not restored to active use except for recovery. Export needed data before deletion; exports exclude secrets and raw internal payment events.

11. Information and audits

We provide information reasonably necessary to demonstrate compliance. If insufficient, the customer may request a reasonable remote audit no more than annually, or after a material confirmed incident, at its expense and with advance notice, confidentiality, and no access to other customers' data, secrets, or security-sensitive systems. The parties first use documents and reports to avoid unnecessary disruption.

12. Customer warranties, priority, and contact

The customer warrants lawful bases, required notices and consents, lawful instructions, data minimization, and fulfillment of data-subject rights. It is responsible for its widget configuration, website, users, and content. This DPA prevails over the Terms for conflicting processing provisions; the remaining Terms continue. DPA requests: support@askhelper-ai.com or +374 77 828 236.