Data Processing Agreement
Last updated: 9/28/2026
This data processing agreement (the "DPA") governs the processing of personal data that Feedbax carries out on behalf of the Customer when operating the LeadWin agent on the Customer's website. It sets out the parties' obligations under Art. 28 GDPR and is based on the European Commission's standard contractual clauses under Art. 28(7) GDPR (Implementing Decision (EU) 2021/915).
This agreement is concluded when the Customer accepts it upon signing up for LeadWin; users registered with Feedbax (service providers and clients) whose LeadWin access comes from their Feedbax account accept it in the LeadWin dashboard. It thereby becomes part of the LeadWin usage agreement. Before this acceptance, Feedbax does not provide any code for embedding the LeadWin agent. No separate signature is required.
Parties
Controller is the Customer: the holder of the LeadWin account and operator of the website on which the LeadWin agent is embedded (the "Customer").
Processor is Feedbax, owner: Armin Bossag, Holsteinstr. 10, 41564 Kaarst, Germany, e-mail [email protected] ("Feedbax" or "we").
"Usage agreement" means the agreement on the use of LeadWin governed by the Terms of Use and, for paid plans, additionally by the Terms and Conditions.
1. Subject matter and duration
1.1 The subject matter of this DPA is the operation of the LeadWin agent on the Customer's website, including the dashboard and the inbox in which the Customer and their team members view and handle conversations, contacts and appointment bookings.
1.2 The duration of this DPA corresponds to the term of the usage agreement. The usage agreement exists for as long as the Customer maintains a LeadWin account, including on the free plan; the expiry or cancellation of a paid plan does not end it. It ends when the account is deleted or when Feedbax terminates the user relationship. This DPA ends together with the usage agreement without separate notice. The obligations under Section 10 survive the end of the agreement until the data has been deleted or returned.
2. Nature, purpose, types of data and data subjects
The nature and purpose of the processing, the categories of personal data and the categories of data subjects are described in Annex 1.
3. Instructions
3.1 Feedbax processes the personal data only on documented instructions from the Customer, unless Feedbax is required to process by Union or Member State law. In that case Feedbax informs the Customer of that legal requirement before processing, unless the law in question prohibits such information.
3.2 This DPA, the usage agreement and the configuration the Customer makes in the dashboard (in particular instructions, knowledge sources, enabled features, connected systems and the consent declaration for visitor analytics) count as documented instructions. Further instructions are given by the Customer in text form to [email protected].
3.3 If Feedbax considers that an instruction infringes the GDPR or other Union or Member State data protection provisions, Feedbax informs the Customer without delay. Feedbax may suspend the execution of the instruction concerned until the Customer confirms or changes it.
4. Confidentiality
Feedbax ensures that the persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to the data is limited to the persons who need it to perform this DPA.
5. Security of processing
5.1 Feedbax implements the technical and organizational measures described in Annex 3 to ensure a level of security appropriate to the risk pursuant to Art. 32 GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing and the risks for data subjects.
5.2 Feedbax may adapt the measures to technical developments provided the agreed level of protection is not reduced. Material changes are documented in Annex 3.
6. Sub-processors
6.1 The Customer grants Feedbax general authorization to engage the sub-processors listed in Annex 2.
6.2 Feedbax informs the Customer of any intended addition or replacement of a sub-processor at least seven days in advance by e-mail to the Customer's account address. Within this period the Customer may object to the change in text form on important data protection grounds. If the parties cannot reach agreement, the Customer may terminate the usage agreement with effect from the date of the change.
6.3 Feedbax imposes on every sub-processor, by way of a contract, the same data protection obligations as set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organizational measures. Feedbax remains liable to the Customer for the performance of the sub-processor's obligations.
6.4 On request Feedbax provides the Customer with a copy of the essential data protection provisions of its contract with a sub-processor; business secrets may be redacted.
7. Transfers to third countries
7.1 Personal data is transferred to a country outside the European Economic Area only where the requirements of Chapter V GDPR are met: on the basis of an adequacy decision of the European Commission (for example for the United Kingdom), the recipient's certification under the EU-U.S. Data Privacy Framework or the European Commission's standard contractual clauses, in each case supplemented by the additional measures required.
7.2 The transfer mechanism applicable to each sub-processor is stated in Annex 2.
8. Assistance to the controller
8.1 Taking into account the nature of the processing, Feedbax assists the Customer by appropriate technical and organizational measures in fulfilling the Customer's obligation to respond to requests for exercising the data subjects' rights (Art. 12 to 22 GDPR). Feedbax provides access to visitor data and deletes it at the Customer's request where the Customer cannot do so themselves via the dashboard.
8.2 Requests from data subjects that reach Feedbax directly and concern processing on behalf of the Customer are forwarded to the Customer without delay. Feedbax does not answer such requests itself, only on the Customer's instruction.
8.3 Feedbax assists the Customer in complying with the obligations under Art. 32 to 36 GDPR, in particular regarding the security of processing, the notification of personal data breaches, data protection impact assessments and prior consultation of the supervisory authority, and provides the information available to Feedbax for this purpose.
9. Notification of personal data breaches
9.1 Feedbax notifies the Customer of any personal data breach affecting data processed on the Customer's behalf without undue delay after becoming aware of it, by e-mail to the Customer's account address.
9.2 As far as known, the notification contains the information listed in Art. 33(3) GDPR: the nature of the breach including the categories and approximate number of data subjects and records concerned, the name and contact details of a contact point, the likely consequences of the breach and the measures taken or proposed to address the breach and mitigate its effects. Where the information cannot be provided at the same time, it is provided without undue further delay.
9.3 Feedbax assists the Customer with the notification to the supervisory authority and the communication to data subjects under Art. 33 and 34 GDPR.
10. Deletion and return
10.1 The Customer determines how long the data processed on its behalf is stored. During the term of the usage agreement Feedbax does not delete it on its own initiative; the exception is visitor analytics data, which is deleted after the periods set out in Annex 1. The Customer can at any time delete individual agents with all associated data, or its entire account, in the dashboard, or request deletion by e-mail to [email protected]. Feedbax deletes individual conversations, contacts and appointment bookings at the Customer's request.
10.2 If the Customer deletes an agent or its account, or requests deletion, Feedbax deletes the personal data concerned without undue delay. If the Customer wishes to have the data returned instead, it informs Feedbax in text form before the deletion; Feedbax then provides the data in a common machine-readable format. If Feedbax terminates the user relationship, the Customer can request the return of the data until the end of the agreement; Feedbax deletes the data after the end of the agreement. Copies in backups are overwritten in the regular rotation cycle of the backups. Data is stored for longer only where Union or Member State law requires it.
10.3 On request Feedbax confirms the deletion in text form.
11. Evidence and audits
11.1 Feedbax makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, in particular the description of the technical and organizational measures in Annex 3, information on the sub-processors and, where available, reports and certificates.
11.2 The Customer may verify compliance with this DPA through audits, including inspections, conducted by the Customer or by an auditor mandated by the Customer and bound to confidentiality. Audits are announced at least 14 days in advance, take place during normal business hours and are conducted so that Feedbax's business operations are not unreasonably disrupted. Without a specific reason, at most one audit takes place per calendar year; where there is a specific reason, such as a personal data breach or an order of the supervisory authority, at any time.
11.3 The Customer bears the costs of an audit unless it reveals breaches of this DPA.
12. Obligations of the controller
12.1 The Customer is responsible for the lawfulness of the processing, in particular for the legal bases, for safeguarding the rights of data subjects and for fulfilling the information obligations under Art. 13 and 14 GDPR.
12.2 The Customer informs the visitors of their website about the use of the LeadWin agent in their own privacy notice. For this purpose Feedbax provides a text block in the dashboard under "Privacy" which the Customer adapts to their circumstances.
12.3 If the Customer enables the optional visitor analytics, the Customer obtains the required consent of the visitors through their own consent management and ensures that the agent runs visitor analytics only after consent has been given. Without consent only the data designated as consent-free in Annex 1 is processed.
12.4 The Customer advises their visitors not to enter special categories of personal data (Art. 9 GDPR) in the chat unless this is necessary for the Customer's offering.
13. Liability and final provisions
13.1 The liability of the parties is governed by Art. 82 GDPR and otherwise by the liability provisions of the usage agreement.
13.2 The law of the Federal Republic of Germany applies.
13.3 In the event of conflicts between this DPA and the usage agreement, this DPA prevails in matters of data protection.
13.4 Feedbax may amend this DPA with effect for the future where this is necessary due to a change in the law, in the agent's features or in the sub-processors. Amendments are announced to the Customer in good time before they take effect by e-mail to the account address. Section 6.2 applies to changes of sub-processors.
13.5 The contract language is German. Translations of this DPA are for information only; in the event of discrepancies the German version prevails.
13.6 Should individual provisions of this DPA be invalid, the validity of the remaining provisions remains unaffected. The statutory provision takes the place of the invalid provision.
Annex 1: Description of the processing
Purpose of the processing
- answering visitor enquiries in the chat on the Customer's website,
- capturing and qualifying contact requests (leads),
- appointment booking,
- handing conversations over to the Customer's team,
- evaluating usage (statistics) for the Customer.
Categories of data subjects
- visitors of the Customer's website,
- team members of the Customer.
Categories of personal data
- chat messages and attached files;
- origin context: path of the page visited, referring host, country of origin (derived from the truncated IP address);
- contact details left by the visitor: name, e-mail address, phone number, company, request;
- appointment data: chosen time, event type, participants;
- with visitor analytics enabled and consent given: pseudonymous visitor identifier, page history, dwell times, device type, browser, language, UTM parameters;
- a keyed one-way hash of the IP address, solely for block lists;
- data of team members: name, e-mail address, role, actions in the inbox.
Without consent only the chat messages, the origin context, the contact and appointment data the visitor leaves voluntarily and the hash for block lists are processed.
Special categories of personal data
The processing of special categories of personal data (Art. 9 GDPR) is not intended. The Customer advises visitors not to enter such data.
Processing operations
Storage, transmission to the AI language model to generate the answers, transmission of the message text to the language detection service, display in the inbox, evaluation in aggregated form, deletion.
Duration of the processing
Term of the usage agreement (Section 1.2), unless the Customer deletes the data earlier (Section 10). Raw visitor analytics data is deleted after 90 days, daily aggregates after two years.
Annex 2: Sub-processors
| Company | Registered office | Purpose | Transfer mechanism |
|---|---|---|---|
| UmbHost Limited | United Kingdom; servers in the data center of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen) in Nuremberg, encrypted backups at Hetzner in Falkenstein, Germany | Hosting and database (all data) | Storage in Germany, no transfer; the adequacy decision of the European Commission covers administrative access from the United Kingdom |
| Cloudflare, Inc. | 101 Townsend St., San Francisco, CA 94107, USA | Content delivery network, DNS, protection against attacks (IP address and connection data) | EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses |
| OpenAI, L.L.C. | 1455 3rd Street, San Francisco, CA 94158, USA | AI language model generating the answers (chat messages, origin context, the Customer's knowledge sources). Requests are made with the parameter "store=false", so OpenAI does not store inputs and outputs beyond abuse monitoring (at most 30 days) and does not use them for training. | EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses |
| Web Cats UAB (detectlanguage.com) | Baltupio st. 57-2, LT-08322 Vilnius, Lithuania | Detecting the language of a chat message (message text, at most 1,000 characters, not stored there) | EU, no transfer to a third country |
| Operator of ip-api.com | The provider does not publish a registered office | Deriving the country of origin from the IP address truncated to its network (IPv4 /24, IPv6 /48); according to its own statements, the provider does not log requests | Only the truncated address without personal reference is transmitted; no transfer of personal data |
| Microsoft Ireland Operations Limited | One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland | Sending e-mails (appointment confirmations to visitors, notifications to the Customer) | EU |
| Twilio Inc. | 101 Spear Street, San Francisco, CA 94105, USA | SMS verification codes (phone number), only if the Customer has enabled verification of contact details | Standard contractual clauses |
Systems the Customer connects themselves (Google Calendar, Microsoft 365, Calendly, Intercom, their own webhooks and CRM systems) are not sub-processors of Feedbax. The Customer uses them under their own responsibility.
For the knowledge base and the live search, Feedbax retrieves, via ScraperAPI LLC (USA), exclusively public pages of the Customer's website. ScraperAPI receives only the addresses of these pages; no visitor data (messages, identifiers, IP addresses) is transmitted. ScraperAPI is therefore not a sub-processor for visitor data.
Reviews from Google, Trustpilot and Trusted Shops are read, at the Customer's instruction, through the Wextractor service (operated by Lucas Moauro; its terms name Argentine law and no postal address). Only the Customer business's public identifier on the platform in question is transmitted; no visitor data and no contact details of the Customer are sent. What comes back are publicly posted reviews together with the name the reviewer is shown under. Wextractor is therefore not a sub-processor for visitor data.
Posts from the Customer's social media profiles (LinkedIn, Instagram, TikTok, X) are read by Feedbax at the Customer's instigation via Apify Technologies s.r.o. (Prague, Czech Republic). Only the address of the respective Customer profile is transmitted; no visitor data is transmitted. What comes back are the posts publicly published there. Apify is therefore not a sub-processor for visitor data.
Annex 3: Technical and organizational measures (Art. 32 GDPR)
Confidentiality
- Transport encryption: all connections between visitors, dashboard, agent and sub-processors are encrypted end to end with TLS.
- Access control: roles and team seats in the dashboard; access to conversations only for the Customer and their team members. Administrative access at Feedbax is limited to a few persons.
- Pseudonymization: the IP address is truncated before geolocation and not stored; for block lists only a keyed one-way hash is kept. Visitor identifiers for visitor analytics are assigned only with consent and pseudonymously.
- Separation control: tenant-separated storage per widget; access token per conversation.
Integrity
- Input control: actions of the agent (bookings, handovers) are traceable in the inbox.
- Hardening against prompt injection: values supplied by the browser are sanitized before they reach the language model.
Availability and resilience
- daily backups by the hosting provider,
- content delivery network and DDoS protection.
Procedures for regular review
- Deletion concept: raw visitor analytics data after 90 days, daily aggregates after 730 days; conversations, contacts and appointment bookings as soon as the Customer deletes the agent or its account or requests deletion; copies in backups in the regular rotation cycle.
- Processor control: data processing agreements with all sub-processors; authorized persons committed to confidentiality.
- Organization: data protection management process with regular review and adaptation of the measures.