Legal
Data Processing Agreement
Last updated: 13 September 2026
When the people who message your bots send you their name, their questions and their photos, that data is yours, not ours — we only handle it to run the service for you. This agreement is the promise that comes with that: what we may do with it, who else touches it, how we protect it, how we help you answer those people, and when we delete it. It applies to every Chatonaut account automatically, and you do not have to sign anything to get it.
1. Who is who
You are the controller of the personal data of the people who message your bots: you decide what to collect from them and why. We are your processor: we handle that data on your instructions, to deliver Chatonaut to you. In the language of the GDPR and the UK GDPR those are Articles 4(7) and 4(8); Brazil's LGPD calls the same two roles controlador and operador.
This agreement covers only that data. Your own account data — your name, your email address, your plan — is data we control ourselves, and our Privacy Policy explains what we do with it.
The processor is Individual Entrepreneur Dmitrii Yuryevich Kiselev, a sole proprietor registered in Russia. Full details are in section 12.
2. What we process, and for whom
- Whose data. The people who contact you through a channel you connected — your customers, not ours.
- What data. Their identifier on the platform, their username and display name, their profile photo if the platform provides one, the content of the messages, comments and story mentions they send you, the media attached to them, and the metadata that comes with each one — time, delivery state, which automation replied.
- Why. To receive and route messages, show them in your inbox, store the history, send your replies back, run the automations and AI agents you built, and keep the service secure and working.
- How long. For as long as the channel exists. Deleting the channel deletes the data collected under it; section 8 sets out the detail.
- Special categories. We do not ask for data under Article 9 of the GDPR, and you must not use Chatonaut to collect it deliberately. If someone sends it to you in a message anyway, it reaches us the same way the rest of that message does.
3. We process only on your instructions
We process that data only to do what this agreement, our Terms of Service and your use of the product tell us to do — and for nothing else. We do not sell it, we do not use it for advertising or to build advertising profiles, and we do not use it to train any model of our own.
If the law obliges us to process it some other way, we will tell you before we do, unless that same law forbids us from telling you. And if we think an instruction of yours breaks data protection law, we will say so rather than quietly carry it out.
4. Confidentiality
Everyone on our side who can reach this data is bound to keep it confidential, and that duty does not end when they stop working with us. Access is given by role and only where the work requires it.
5. Security
We encrypt data in transit, store passwords only as hashes, keep the servers and the database behind a firewall that only our own machines can pass, and limit access so that our own team sees only what the work requires. We keep these measures under review as the service grows, and we will not weaken them below what this section describes.
If personal data we hold for you is exposed in a security incident, we will tell you without undue delay and in any case within 48 hours of confirming it — what we know at the time, which data and roughly how many people are affected, what we are doing about it and who to contact — and we will keep you updated until it is closed. That is what lets you meet your own 72-hour duty to your supervisory authority. We will help you make that report and, where it is needed, tell the people affected.
6. The companies that help us (sub-processors)
You give us general permission to use the companies below, and we stay responsible to you for what they do with your data as if we had done it ourselves. Each of them is bound to obligations no weaker than the ones in this agreement.
| Company | What it does for us | Where |
|---|---|---|
| Iron Hosting Centre LTD | Runs the servers that hold the service and its backups | Netherlands |
| Cloudflare, Inc. | Protects the site and carries traffic to it; handles requests in transit and does not store your conversations | Nearest edge location to the visitor |
| Meta Platforms, Inc. | Instagram itself — the platform your messages necessarily pass through | Meta's own infrastructure |
| OpenAI | Generates replies, when you switch on an AI feature and pick one of its models | United States |
| Anthropic | Generates replies, when you switch on an AI feature and pick one of its models | United States |
| Replicate | Generates images and audio, when an automation of yours asks for them | United States |
| Our email provider | Delivers account and notification emails | European Union |
| CloudPayments | Will process card payments once paid plans start — it receives no end-customer data, only your billing details | Not in use today |
Before we add a new sub-processor or replace one, we will tell you by email at least 30 days in advance. If you object on reasonable data protection grounds within those 30 days, write to us and we will look for another way to give you the feature; if there is none, you may stop using the feature or close your account, and we will not charge you for the part you did not use.
7. Helping you with the people whose data it is
If one of your customers asks to see, correct, export or delete what you hold about them, that request is yours to answer — but we will help you answer it. Much of it you can do yourself in the app: open the conversation, the contact card or the channel. For anything the interface does not reach, write to us and we will do it.
If such a request arrives at us directly, we will not answer it ourselves. We will pass it to you and tell the person we have done so.
We will also give you what you reasonably need for a data protection impact assessment or a prior consultation with your supervisory authority, and answer questions about how the service handles data.
8. Deletion and return
You can delete a channel at any time, and that deletes the data collected under it. Database records go at once. The files behind them — attachments, media an operator sent, cached profile photos — sit on disk separately and are removed within 30 days; write to us if you want them gone sooner and we will do it by hand.
When your account closes, we delete the data we hold for you within 30 days, apart from the few records named in the Privacy Policy and anything the law requires us to keep. If you want a copy before that, ask us while the account is still open and we will export it. Backups taken before a deletion live out their own term on the storage side; we do not restore them to satisfy a deletion request, and deleted data does not come back into the service from them.
The Data Deletion page walks through each route step by step.
9. Showing you that we do this
Ask us and we will describe, in writing, how we meet this agreement — the security measures in place, who our sub-processors are, and how a particular kind of data is handled. If your own auditor or regulator needs more than that, write to us and we will agree a reasonable way to give it to them, at reasonable notice and without exposing another customer's data. We will not hide behind this paragraph: if you need something to satisfy your regulator, the starting point is that you get it.
10. Where the data is, and where it goes
The data lives on servers in the Netherlands, inside the European Union. Two things leave it, and we would rather you read them here than find them yourself.
- AI providers. If you switch on an AI feature, the text needed to answer that message goes to OpenAI or Anthropic in the United States, and a prompt for a generated image or sound goes to Replicate. Nothing goes to them if you use no AI feature.
- Running the service from Russia. The person who operates Chatonaut lives and is registered in Russia and supports the service from there, so the data on the Dutch servers is reached from a Russian connection. The data is not copied to Russia and is not stored there.
Where a transfer out of the European Economic Area or the United Kingdom needs a legal basis, we use the European Commission's Standard Contractual Clauses (and the UK Addendum), and we will sign them with you on request.
11. What you are responsible for
- Having a lawful basis for collecting your customers' data through Chatonaut, and telling them about it in your own privacy notice.
- Following the rules of the platform you connected — the Meta Platform Terms and the Meta Developer Policies, including when a message may be sent.
- Not using the service for unlawful collection, for spam, or for anything our Terms of Service forbid.
- Keeping your account secure and your team's access current, and telling us promptly if a request from one of your customers needs us to act.
12. Term, precedence and who to write to
This agreement applies for as long as you have a Chatonaut account, and it is part of the Terms of Service. Where it conflicts with any other document of ours about data we process on your behalf, this one comes first. If any part of it is unenforceable, the rest still stands.
If you need a signed copy on your own paper, write to us and we will sign it.
For anything in this agreement, email [email protected] with DPA in the subject line.
- Operator
- Individual Entrepreneur Dmitrii Yuryevich Kiselev
- Legal form
- Individual entrepreneur (sole proprietor)
- Tax ID (INN)
- 165720128759
- State registration (OGRNIP)
- 323169000141965
- Registered address
- 25 Chetaeva St., Kazan 420126, Russia
- Contact
- [email protected]