Ուժի մեջ է՝ 15 հուլիսի 2026
Տվյալների մշակման հավելված
AskHelper AI-ի կողմից հաճախորդի անունից widget-ի եւ knowledge base-ի անձնական տվյալների մշակման պայմանները։
1. Կողմեր, շրջանակ եւ ժամկետ
DPA-ն Terms of Service-ի մաս է եւ գործում է, երբ IE FEDOSEENKO N.A.-ն (AskHelper AI, processor) հաճախորդի (controller) անունից մշակում է անձնական տվյալներ՝ սկզբից մինչեւ վերադարձ կամ deletion, հաշվի առնելով backups եւ mandatory retention։
2. Առարկա, operations, subjects եւ data
Մշակումը սպասարկում է AI widget-ը, knowledge base-ը, history-ն եւ հարակից functions-ը՝ collection, storage, retrieval, transformation, embeddings, AI provider transmission, generation, display, support, export եւ deletion operations-ով։ Subjects-ը կարող են լինել customer personnel/users, website visitors, customers/prospects եւ lawful content-ում գտնվող անձինք։ Data-ն կարող է ներառել identifiers, name/email/metadata, messages/history/ratings, files/pages/chunks/embeddings, instructions եւ technical events։ Sensitive data չպետք է ուղարկվի առանց necessity, lawful basis եւ risk assessment։
3. Հրահանգներ, confidentiality եւ security
Մենք մշակում ենք միայն agreement/settings/lawful support requests-ի documented instructions-ով, բացի legal duty-ից։ Ենթադրաբար unlawful instruction-ի մասին հայտնում եւ կարող ենք pause անել։ Need-to-know personnel-ը կապված է confidentiality-ով։ Measures-ը ներառում է tenant scoping/access controls, hashed widget keys, server-side BYOK encryption, HttpOnly cookies, domain allowlist, secret management, audit եւ abuse controls եւ կարող է զարգանալ առանց overall protection-ի էական նվազման. absolute security չի երաշխավորվում։
4. Subprocessors եւ Paddle
General authorization-ը ներառում է Supabase, Vercel, Jina AI, OpenRouter եւ selected models, Resend, Forward Email եւ Google support-ի համար, Telegram միայն enabled alerts-ի համար։ Applicable duties են դրվում, եւ օրենքով պահանջվող պատասխանատվությունը մնում է մեզ վրա։ Material new subprocessor-ի մասին available notice է տրվում, իսկ timely reasoned privacy objection-ի դեպքում որոնվում է լուծում կամ դադարեցվում affected function-ը։ Paddle-ը checkout/payment/tax/billing-ի independent controller եւ Merchant of Record է, ոչ մեր subprocessor այդ անկախ նպատակների համար։
5. Transfers, breach եւ assistance
Մշակումը կարող է միջազգային լինել։ Պահանջվելու դեպքում կողմերը կիրառում են available lawful transfer mechanism եւ reasonable supplementary measures. EU-only կամ already-executed SCC չենք խոստանում։ Customer data breach-ի մասին հայտնում ենք without undue delay եւ տրամադրում available information։ Reasonably օգնում ենք data-subject requests, DPIA, regulator consultation/inquiries հարցերում, իսկ customer-ը պատասխանատու է decisions, deadlines եւ notices-ի համար։
6. Return, deletion, audit եւ պարտականություններ
Service end-ին data-ն վերադարձվում կամ ջնջվում է available choice-ով, բացի legal retention-ից։ Միայն owner-ը ջնջում է ամբողջ workspace-ը. limited backups/logs մնում են մինչեւ provider cycle expiry, եւ export-ը չի ներառում secrets/raw payment events։ Մենք տալիս ենք reasonable compliance information. եթե այն բավարար չէ, հնարավոր է confidential remote audit առավելագույնը տարեկան մեկ անգամ կամ material confirmed incident-ից հետո՝ customer expense-ով, advance notice-ով եւ առանց այլ customers data/security secrets access-ի։ Customer-ը երաշխավորում է lawful bases/notices/consents/instructions/minimization/rights եւ պատասխանատու է website/config/users/content-ի համար։ DPA-ն processing conflict-ի դեպքում գերակա է Terms-ից։ Կապ՝ support@askhelper-ai.com, +374 77 828 236։