Data processing agreement (DPA)
Last updated: 25 August 2026
This data processing agreement (DPA) is entered into between the customer, as controller, and 404 AFK, as processor, under Article 28 GDPR. It forms an integral part of the contract, is accepted at account creation together with the terms of sale and the terms of use, and covers the eight stipulations required by Article 28(3).
Subject matter and roles
The customer entrusts content to Raggli (documents, web pages, pinned answers) and embeds the chat widget on their site; in doing so, they entrust 404 AFK with the processing of personal data that may appear in that content and in their visitors' conversations.
For that data, the customer alone determines the purposes and means: they are the controller. 404 AFK processes it only to provide the service: it is the processor.
The customer's own account data (credentials, billing, audit log) falls outside this agreement: 404 AFK is its controller, under the conditions of the privacy policy.
Duration
This agreement applies for the whole duration of the contract, and until the data has actually been deleted under the conditions of the “End of contract” section.
Nature and purposes of the processing
The processing has one purpose only: providing the service described in the terms of sale — letting the widget answer the visitors of the customer's site from the content provided. It comprises the following operations:
- storing the uploaded documents and the text extracted from them (including through optical character recognition for scanned documents);
- computing vector representations of that text, for search;
- automatically generating answers with an artificial-intelligence model, from the relevant excerpts of the customer's content alone (documents, web pages, pinned answers) — without using that data to train any model;
- retaining conversations and making them available to the customer in their dashboard.
Categories of data and of data subjects
Data subjects: the visitors of the customer's site who use the chat, and the people mentioned in the content the customer provides.
Data processed: the content provided by the customer (uploaded documents, added web pages, pinned answers); the messages exchanged with the widget (questions and answers), the detected language, a technical session identifier, the origin domain and technical counters. The service collects neither the visitors' IP address nor their browser fingerprint, and never asks for their identity — what personal data is actually processed therefore depends on what the customer uploads and what their visitors write.
The customer shall not upload special-category data within the meaning of Article 9 GDPR without an appropriate legal basis, as the terms of use provide.
Documented instructions
404 AFK processes the data only for the purposes described above, on the customer's documented instructions — the terms of use, this agreement and the service configuration in the customer dashboard together constituting those instructions. Any additional instruction is to be sent in writing to [email protected].
If 404 AFK considers that an instruction infringes the GDPR or another applicable provision, it shall immediately inform the customer. This instruction requirement also covers transfers of data outside the European Union.
Confidentiality
404 AFK ensures that the persons authorised to process the data — its officers and, where applicable, its staff — are bound by a contractual or statutory duty of confidentiality, and access the data only to the extent needed to operate and support the service.
Security
404 AFK implements the appropriate technical and organisational measures within the meaning of Article 32 GDPR, including in particular:
- strict isolation of organizations at the database level, enforced through forced row-level security rules that the application role cannot bypass;
- encryption of data in transit (TLS) and at rest, across the whole hosting infrastructure;
- separation of technical roles (application, background jobs, migrations), each limited to its own privileges;
- an audit log of sensitive actions, and automatic purges enforcing the stated retention periods.
Sub-processors
The customer gives general authorisation for the sub-processors listed, with their role, location and transfer safeguards, on this site's Sub-processors page — dated at every change.
404 AFK informs the customer, by email and at least 30 days in advance, of any addition or replacement of a sub-processor affecting the data covered by this agreement. The customer may raise a reasoned objection within that period; if no reasonable solution is found, they may terminate the contract free of charge before the change takes effect.
404 AFK imposes on every sub-processor, by contract, data-protection obligations equivalent to those of this agreement, and remains fully liable to the customer for their performance.
Assistance: data subject rights
404 AFK assists the customer, through appropriate technical and organisational measures, in answering requests to exercise data subjects' rights (access, rectification, erasure, restriction, objection, portability).
Most of that assistance is directly tooled in the customer dashboard: browsing conversations, exporting the history in a structured format, deleting the conversation history, deleting documents, and deleting the account. For any request those tools do not cover, 404 AFK answers within a reasonable time of the customer's written request.
Assistance: security and data breaches
404 AFK notifies the customer of any personal data breach affecting the data covered by this agreement, without undue delay after becoming aware of it, providing the elements at its disposal to document the breach and, where relevant, to notify the supervisory authority and inform the data subjects (nature of the breach, approximate categories and volumes concerned, measures taken or proposed).
404 AFK further assists the customer, taking into account the nature of the processing and the information available to it, in complying with its obligations under Articles 32 to 36 GDPR, including, where applicable, a data protection impact assessment.
Retention periods
The following periods, enforced by daily automatic purges, apply to the data covered by this agreement:
- uploaded documents: kept until the customer deletes them; deletion is immediate, search index included;
- conversations and messages: 365 days after the conversation's last activity;
- vectors of asked questions: 120 days.
End of contract
When the account is closed, all documents, conversations and derived data are deleted. Before closing, the customer can use the export tools in their dashboard to retrieve their data in a structured format.
Account deletion is actual deletion, not deactivation: the data is not kept “just in case”. Two exceptions, and two only, both time-bounded: accounting records, which Article L123-22 of the French Commercial Code requires to be kept for ten years, and the record of acceptance of the contractual documents, kept five years after the account is closed — the commercial limitation period — then deleted in turn by an automatic purge.
Audit
404 AFK makes available to the customer all information necessary to demonstrate compliance with this agreement — this page, the privacy policy, the Sub-processors page and the service documentation forming its basis.
The customer may additionally have compliance with this agreement audited, at their own expense, at most once a year, with 30 days' written notice, during business hours and without access to other customers' data — tenant isolation ruling out any cross access.