Data Processing Agreement
Data Processing Agreement for n8nchatui.com services, incorporated into our Terms of Service.
Effective date: 9 September 2026 Version: 2.0 Previous versions: available on request at [email protected]
1. Parties and scope
This Data Processing Agreement ("DPA") is entered into between:
DigitalME FZE, Premises No. DSO-THUB-G-D-FLEX-G125C, THUB, Dubai Silicon Oasis, Dubai, United Arab Emirates, licence no. 30919 (Dubai Integrated Economic Zones Authority), operating the service at n8nchatui.com ("we", "us", "the Processor"); and
the customer identified in the Account ("you", "the Customer").
This DPA forms part of and is incorporated into the Terms of Service. It applies where and to the extent that we process personal data on your behalf in connection with the Service.
1.1 When this DPA applies
This DPA applies to managed widgets, where chat messages are routed in real time through our message proxy.
It does not apply where you self-host or otherwise operate the widget such that no message traffic passes through our infrastructure. In that case we process no personal data on your behalf and act only as a controller of your own account data, which is governed by our Privacy Policy rather than this DPA.
1.2 Roles
You may act as a controller in your own right, or as a processor for a third-party controller. We act as your processor in the first case and as your sub-processor in the second. Where you act as a processor, you confirm that you have the controller's authorisation to engage us and that your instructions to us reflect the controller's instructions.
Our processing of your own account data — your name, contact details, billing information and usage — is carried out as a controller and is governed by our Privacy Policy.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, read with the Data Protection Act 2018. "Data Protection Law" means the GDPR, the UK GDPR and any other data protection law applicable to the processing.
"Personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
"SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
"End User Data" means personal data relating to visitors to your website who interact with a widget, processed by us on your behalf.
3. Description of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
4. Our obligations as processor
We shall:
(a) Process only on documented instructions. We process End User Data only on your documented instructions, including in relation to transfers to a third country, unless required otherwise by law to which we are subject. Where such a legal requirement applies, we will inform you before processing unless the law prohibits it. Your instructions are constituted by this DPA, the Terms of Service, and the configuration you set in the Service. We will inform you if, in our opinion, an instruction infringes Data Protection Law.
(b) Ensure confidentiality. We ensure that persons authorised to process End User Data, whether personnel or contractors, are bound by written confidentiality undertakings.
(c) Implement security measures. We implement the technical and organisational measures set out in Annex 2, appropriate to the risk under Article 32.
(d) Engage sub-processors on the terms in clause 5.
(e) Assist with data subject rights. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights. Because we do not store message content, our assistance concerns configuration data and metadata. If a data subject contacts us directly, we will refer them to you and will not respond substantively except to confirm the referral.
(f) Assist with your wider obligations. We assist you in ensuring compliance with Articles 32 to 36, taking into account the nature of the processing and the information available to us. This includes providing information reasonably necessary for a data protection impact assessment.
(g) Delete or return data. On termination, and at your choice, we delete or return End User Data and delete existing copies, unless retention is required by law. Deletion of configuration data and metadata is completed within 30 days of account closure. Backup copies are deleted in accordance with our backup cycle, described in Annex 2.
(h) Make information available and permit audits. We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, on the terms in clause 8.
5. Sub-processors
5.1 General authorisation. You give general written authorisation for us to engage sub-processors. The current list is published at https://n8nchatui.com/sub-processors and forms part of this DPA.
5.2 Changes. We will give at least 30 days' notice of any intended addition or replacement of a sub-processor, by email to your account contact and by updating the published list. To subscribe to notifications, email [email protected].
5.3 Objection. You may object to a change on reasonable data protection grounds within the notice period. We will work with you in good faith to find an alternative. If none is available, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid unused fees.
5.4 Flow-down. We impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA. We remain fully liable to you for each sub-processor's performance.
6. International transfers
6.1 We are established in the United Arab Emirates, a third country in respect of which no adequacy decision has been adopted under Article 45 GDPR or the UK GDPR.
6.2 Where End User Data protected by the GDPR is transferred to us, the SCCs apply and are incorporated into this DPA by reference, with Module Two applying where you act as a controller and Module Three where you act as a processor. Where End User Data protected by the UK GDPR is transferred to us, the UK Addendum applies to those SCCs.
6.3 Selections. For the purposes of the SCCs: Clause 7 (docking clause) does not apply; Clause 9(a) Option 2 (general written authorisation) applies with a 30-day notice period; Clause 11(a) optional independent dispute resolution does not apply; Clause 17 Option 1 applies, governed by the law of the EU member state in which you are established or, where you are not established in the European Union, the law of Ireland; Clause 18(b) designates the courts of that member state. Annexes I, II and III of the SCCs are populated by Annexes 1, 2 and 3 of this DPA together with the published sub-processor list.
6.4 Execution. Where you require the SCCs executed as a separate signed instrument, we will provide and sign our standard SCC cover agreement on request at no charge.
6.5 Data location. Notwithstanding our place of establishment, End User Data is hosted in the European Union as described in Annex 2. Our connection to the United Arab Emirates in respect of End User Data is administrative access, not storage.
6.6 Government access. We have no record of receiving any request from a public authority for End User Data. If we receive one we will, unless legally prohibited, notify you promptly, challenge requests that appear unlawful or excessive, and disclose only the minimum required.
7. Personal data breach
We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting End User Data. The notification will describe the nature of the breach, the categories and approximate volume of data concerned, the likely consequences and the measures taken, to the extent known at the time. We will provide further information as it becomes available. Notification is not an acknowledgement of fault.
8. Audit
8.1 On written request, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach affecting your data, we will provide the information necessary to demonstrate compliance with this DPA. This ordinarily takes the form of our security documentation and a completed security questionnaire, provided within 30 days.
8.2 Where that information is not sufficient to demonstrate compliance, you or an independent auditor mandated by you may conduct an audit. Audits are conducted on at least 30 days' notice, during business hours, subject to confidentiality undertakings, and in a manner that does not disrupt the Service or compromise the data of other customers. You bear the cost of the audit unless it identifies a material breach of this DPA by us.
8.3 Where a sub-processor's environment is in scope, we will use reasonable endeavours to obtain the relevant information or audit rights from that sub-processor.
9. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, save that nothing in this DPA or the Terms of Service limits liability that cannot be limited under applicable law, and save that where the SCCs apply, the liability provisions of the SCCs prevail as between the parties in accordance with Clause 5 of the SCCs.
10. Term, precedence and changes
10.1 This DPA takes effect when you accept the Terms of Service and continues while we process End User Data on your behalf.
10.2 In the event of conflict, the order of precedence is: the SCCs, then this DPA, then the Terms of Service.
10.3 We may update this DPA to reflect changes in law, our sub-processors or our technical measures. Material changes will be notified by email at least 30 days in advance. Previous versions are available on request at [email protected].
11. Contact
Data protection enquiries: [email protected]
We have not appointed a representative under Article 27 GDPR or UK GDPR. Our assessment is that Article 27 is not engaged in respect of our processing as a technical sub-processor with no direct relationship to data subjects. We keep this under review.
Annex 1 — Description of the processing
Subject matter: provision of the n8nChatUI managed chat widget service.
Duration: the term of the Customer's account, plus the retention and deletion periods in Annex 2.
Nature and purpose: real-time routing of chat messages between the widget in the end user's browser and the Customer's workflow endpoint; provision, configuration and styling of the widget; metering of message volume for billing. No language model inference or other analysis of message content is performed on our infrastructure.
Categories of data subjects: visitors to the Customer's website, or to the website of the Customer's own client, who interact with a widget.
Types of personal data:
| Category | Detail | Stored? |
|---|---|---|
| Message content | Free text entered by the end user and returned by the Customer's workflow | No — transient, in memory only |
| Session and widget identifiers | Session ID, widget identifier, account identifier, message direction | Yes |
| Technical metadata | Timestamp, client-reported local date and time, client-reported timezone, user agent string | Yes |
| Coarse location | Country and city, derived from Cloudflare edge headers | Yes |
| Response status | HTTP status code and message | Yes |
No precise geolocation is collected. No special category data is intentionally processed; free-text input may incidentally contain it, and the safeguard is that message content is never stored, cached or logged.
Retention: message content — not stored. Session and technical metadata — 24 months from creation, then automatic deletion. Configuration data — duration of the account, deleted within 30 days of closure.
Annex 2 — Technical and organisational measures
Encryption. TLS 1.3 on all transmission paths, from widget to proxy and from proxy to the Customer's endpoint. Data at rest encrypted by our hosting and database providers as standard.
Transient processing of message content. Message content is routed in real time and exists in memory only for the duration of the request. It is not persisted in the application database, application logs or error logs.
Processing location. Widget proxy infrastructure in Amsterdam, Netherlands. Configuration and metadata storage in MongoDB Atlas on AWS eu-central-1, Frankfurt, Germany. No End User Data is stored in the United Arab Emirates.
Access control. Access to production systems is granted on a least-privilege, need-to-know basis and reviewed on personnel change. Read access to stored metadata and configuration is restricted to the company's directors; development personnel hold repository and deployment access only, enforced by scoped database user permissions. Multi-factor authentication is enforced on all hosting, database, DNS and edge provider accounts.
Authentication and separation. Per-widget webhook authentication; customer workflow endpoints are not exposed publicly. Customer configurations are logically separated per widget instance. Rate limiting is applied at the edge.
Data minimisation and retention. Only the fields enumerated in Annex 1 are collected. Metadata is deleted automatically 24 months after creation by scheduled deletion.
Backups. MongoDB Atlas snapshot backups with an 8-day retention window, stored in AWS eu-central-1, the same region as the primary cluster.
Personnel. All personnel and contractors with access to production systems are bound by written confidentiality undertakings.
Incident response. Breach notification to the Customer without undue delay and in any event within 48 hours of becoming aware.
Sub-processor management. Written data processing agreements in place with each sub-processor listed in Annex 3.
Deletion. Configuration data and remaining metadata deleted within 30 days of account closure, subject to the backup cycle above.
Annex 3 — Sub-processors
Sub-processors engaged in the processing of End User Data:
| Provider | Legal entity | Purpose | Location |
|---|---|---|---|
| Railway | Railway Corporation, 548 Market St PMB 68956, San Francisco, California 94104, USA | Hosting of widget proxy infrastructure | Amsterdam, Netherlands (EU) |
| Cloudflare | Cloudflare, Inc. | CDN, DNS, edge security, geo-headers | Global edge network |
| MongoDB | MongoDB, Inc. (MongoDB Atlas) | Storage of configuration data and metadata | AWS eu-central-1, Frankfurt, Germany (EU) |
Providers processing our own customer data, but not End User Data, are listed separately in our Privacy Policy and are not sub-processors for the purposes of this DPA. These currently include Stripe (payments) and Loops (transactional email).
The current list is maintained at https://n8nchatui.com/sub-processors.