Data Processing Agreement
Last updated September 24, 2026. This agreement forms part of our terms of service.
This Data Processing Agreement (“DPA”) applies when you (the “Customer”) use Which AI Sent, operated by Tamitechs (“we”, “us”), and we process personal information on your behalf. If a separate signed DPA exists between us, that one takes priority.
1. Roles
For personal information collected from your website visitors and customers, you are the business / controller and we act as your service provider (CCPA) / processor (GDPR and similar laws). We process that information only to provide the service to you and on your documented instructions, which are these terms, this DPA and your use of the service’s settings.
2. What we process
| Item | Details |
|---|---|
| Subject matter | Measuring which marketing channels, including AI assistants, bring you leads, bookings and revenue |
| People involved | Visitors to your website; people who submit your forms, buy, book or contact you; your staff who use the dashboard |
| Types of data | Random visitor and visit IDs; referring page, landing page, pages viewed (address and title), campaign tags and device type; name, email address, phone number and “how did you hear about us” answers submitted through your forms or connected tools; lead status, bookings, amounts, notes and call logs you record; dashboard user account details |
| Not intended | Sensitive data (health, financial account, government ID, precise location). Please don’t configure forms or integrations to send it to us |
| Duration | For as long as you use the service, then deleted as described in section 8 |
3. What we won’t do
We will not:
- sell or share your personal information (as the CCPA defines those terms);
- retain, use or disclose it for any purpose other than providing the service to you, including for our own marketing or advertising;
- combine it with personal information we receive from other customers or other sources, except to provide the service to you;
- use it outside the direct business relationship between you and us.
We may use aggregated, de-identified statistics that can’t identify you or any person, such as how common AI referrals are overall, to improve the service. We will not attempt to re-identify them. We’ll tell you if we believe we can no longer meet these obligations, and you may then take reasonable steps to stop and remediate unauthorised use.
4. Confidentiality
Only people who need access to operate or support the service can access your data. They are bound by confidentiality obligations.
5. Security
We maintain appropriate technical and organisational measures, including:
- encryption in transit (TLS) and at rest (AES-256, provided by our database host);
- separate accounts for every staff member, with mandatory two-factor authentication, role-based permissions and an audit log of changes;
- salted, peppered password hashing and short-lived, revocable sessions for customer and staff accounts;
- strict separation between customers’ data, verified by automated tests;
- rate limiting, cross-site request protection and security headers;
- collecting only what’s needed, with no IP address storage in attribution data;
- automatic deletion under documented retention periods, and point-in-time backups.
6. Subprocessors
You authorise us to use these subprocessors. We’ll give you at least 14 days’ notice by email before adding or replacing one, and you may object on reasonable grounds.
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, content delivery | Global network |
| Resend (Plus Five Five, Inc.) | Account and alert emails | United States |
| OpenAI, L.L.C. / Anthropic, PBC | Help-chat replies (only what users type into the chat); AI visibility checks (only your business name, service and area, no personal data) | United States |
Destinations you connect yourself (for example your CRM, Zapier, Make or GoHighLevel) are chosen and controlled by you. We send data there on your instruction; they aren’t our subprocessors.
We impose data-protection obligations on subprocessors that are at least as protective as this DPA, and we remain responsible for their performance.
7. Helping you with requests and incidents
Individual requests. If someone asks to access, correct, delete or copy their information, we’ll help you respond. Most of it you can do yourself, since you can view and export your data from the dashboard. If a request comes to us directly, we’ll pass it to you rather than answer it ourselves, unless the law requires otherwise.
Security incidents. If we become aware of a breach affecting your personal information, we’ll notify you without undue delay, and within 72 hours where feasible. We’ll include what we know, what we’re doing about it, and how you can reduce the impact.
Assessments. We’ll give you reasonable information you need for data-protection assessments or to show compliance, such as answers to security questionnaires.
8. Deletion and return
When your account ends, you have 30 days to export your data. We then delete it from our live systems within 90 days of the account ending, and backups roll off within a further 30 days, unless the law requires us to keep something. You can also ask us to delete everything sooner.
9. International transfers
Data may be processed in the United States and other countries where our subprocessors operate. Where the law requires it, transfers are covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
10. Your responsibilities
You’re responsible for having a lawful basis to collect the data, for telling your visitors about analytics in your own privacy policy (see our suggested wording), and for getting any consent your local law requires.
11. Contact
Privacy and security questions: info@whichaisent.com (subject line “DPA”).