Scope, roles, and instructions
This addendum forms part of the Website Chat Terms between Automation Room Control, LLC and the business customer. It applies when ARC processes personal information in hosted Website Chat on the customer’s behalf (“Chat Data”). The customer determines the purposes and lawful basis for collecting Chat Data. ARC acts as its service provider or processor, as applicable. Account, billing, and ARC security records handled for ARC’s own purposes are described separately in the Privacy Policy. If this addendum conflicts with a general use license or product-improvement clause, this addendum controls Chat Data processing.
The customer instructs ARC to receive, store, route, display, and delete conversations; authenticate authorized staff and visitors; provide optional AI using the configured account; and perform related security, support, and verified privacy-request work. Chat Data may include visitor and staff names, contact details and other message content, identifiers, timestamps, conversation status, website page context, and personal information supplied in business knowledge or settings. Processing continues while the service is enabled and during the documented retention and deletion process.
Purpose limits and confidentiality
ARC will process Chat Data only for the specific service purposes above, on the customer’s documented instructions, or as required by applicable law. ARC will not sell or share Chat Data for cross-context behavioral advertising, retain or use it for unrelated commercial purposes, use it to train ARC models, or combine it with other customers’ or independently collected personal information except as permitted to provide the contracted services or by applicable law. General feedback or improvement rights do not override these restrictions. ARC will limit access to authorized people who need it for those purposes and are bound by confidentiality obligations.
The customer is responsible for lawful instructions, appropriate notices and consents, staff authorization, data minimization, and its connected-provider account settings. The customer must not direct optional provider model training or data sharing with Chat Data. ARC will notify the customer if it determines it cannot meet these obligations or an instruction violates applicable data-protection law, and the parties will address, suspend, or end the affected processing as appropriate.
Security and incidents
ARC will maintain reasonable administrative, technical, and organizational safeguards appropriate to the service and the information involved, including access controls, encrypted network transport, protected API credentials, and measures to prevent unauthorized access. Hosted conversations are not end-to-end encrypted. Cloud Backup encryption statements do not describe Website Chat. The customer must protect its local ARC system, staff accounts, API account, and downloaded exports.
ARC will notify the customer without undue delay after becoming aware of a personal-information breach affecting Chat Data, subject to applicable law. ARC will provide information then available to support the customer’s investigation and legally required notifications, provide material updates as information develops, and take reasonable remedial steps. This does not promise a fixed notification deadline beyond applicable law.
Providers and third-party instructions
The customer authorizes ARC to use the infrastructure providers identified in the Website Chat provider notice for the contracted processing. ARC will require providers it appoints to protect Chat Data under written obligations appropriate to their role and will remain responsible for the processing it entrusts to them under this addendum. ARC will update the provider notice and give additional notice when law or contract requires. A customer with a reasonable data-protection concern may contact support so the parties can address it or end the affected service.
The selected provider (OpenAI or Anthropic) is enabled using the customer’s provider account and key. The customer authorizes ARC to transmit the selected content needed for that service and is responsible for its agreement and settings with that provider. ARC remains responsible for its own handling; the provider’s separate account terms govern its processing. This addendum does not create a promise of exclusive United States storage or supply every arrangement that may be needed for international visitors.
Requests and verification
Taking account of the service and information available, ARC will reasonably assist the customer with applicable access, export, correction, deletion, security, and assessment obligations concerning Chat Data. Requests received directly from visitors will ordinarily be referred to the business, unless law requires another response. Verified administrators can contact support to request available exports or deletion. ARC will provide reasonably available information to demonstrate compliance with these obligations and cooperate with reasonable verification requests while protecting other customers’ information, security, and confidentiality.
Where applicable service-provider law requires it, the customer may take reasonable steps to verify that ARC uses Chat Data consistently with its obligations and to stop and remediate unauthorized use. The parties will coordinate an appropriate, proportionate method; this does not authorize unrestricted access to production systems or other customers’ data.
Retention and end of processing
Conversations expire under the service retention setting: 30 days from creation by default, bounded from 1 to 90 days at deployment level. The customer can request an earlier export or deletion through verified support procedures. Closing or disabling chat is not deletion. Settings, knowledge, and credentials remain until deleted. On a verified request to end the service and remove its data, ARC will delete the requested Chat Data and configuration, subject to applicable legal requirements and identified operational backup limitations. Any retained exception remains protected and limited to its required purpose. The customer remains responsible for downloaded copies and independently retained provider records.
Questions, instructions, and privacy requests should be sent to [email protected]. This addendum supplements the existing agreement; it does not certify compliance with every privacy law or remove either party’s obligations under applicable law.