Chatpont, built by Autom Mate, is committed to protecting personal data and supporting our customers in meeting their obligations under the EU General Data Protection Regulation (“GDPR”). This page summarises how we process personal data and the rights available to individuals.
Roles: controller and processor
For personal data you submit to Chatpont in order to operate your AI agents (for example, end-customer conversations), you act as the data controller and Chatpont acts as the processor, processing that data only on your documented instructions. For account and billing data, Chatpont acts as a controller.
Lawful basis for processing
We process personal data where we have a lawful basis to do so — typically the performance of a contract, your consent, our legitimate interests in operating and improving the service, or compliance with a legal obligation.
Data subject rights
Subject to applicable law, individuals have the right to:
- Access the personal data we hold about them;
- Request rectification of inaccurate data;
- Request erasure (“right to be forgotten”);
- Restrict or object to certain processing;
- Request data portability; and
- Withdraw consent at any time, without affecting prior processing.
If you are an end customer interacting with an agent built on Chatpont, please direct requests to the business operating that agent (the controller). Customers can exercise and fulfil these requests using Chatpont's tooling and by contacting us.
Data Processing Addendum
Our Data Processing Addendum (DPA) forms part of our agreement with customers and sets out the contractual terms governing our processing of personal data on your behalf, including international transfer mechanisms such as the EU Standard Contractual Clauses where applicable.
Sub-processors
We use a limited set of vetted sub-processors to deliver the service (for example, cloud hosting and model providers). Each is bound by data protection obligations consistent with the GDPR. A current list is available on request.
Security
Chatpont runs on Autom Mate infrastructure, which is ISO 27001 certified. We apply technical and organisational measures — including encryption in transit, access controls and audit logging — designed to protect personal data. See our Privacy Policy for more detail.
International transfers
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.
Contact
For privacy or GDPR enquiries, including to exercise your rights or to request our sub-processor list or DPA, please contact us via the contact form.