Data processing agreement
Effective 1 September 2026, version 1. This agreement is part of the FAQ Plus terms of service and applies to every customer. FAQ Plus is operated by Solid Software B.V., Rümkelaan 32, Utrecht, Netherlands, KvK 94194432 ("we", the processor). The customer is the business holding the FAQ Plus account ("you", the controller).
1. Roles and scope
- For personal data of your visitors processed through your chat page and your uploaded documents, you are the controller and we are your processor within the meaning of art. 28 GDPR. This agreement governs that processing. Annex 1 specifies it.
- For your own account data (business name, login email, password hash, billing status) we are an independent controller; the privacy statement covers it. Payment data is processed by Stripe as an independent controller and is outside this agreement.
- This agreement applies for as long as you hold an account, and until the deletion described in section 8 is complete.
2. Instructions
- We process the data in Annex 1 only on your documented instructions. Your instructions are: this agreement, the service as described in the terms and the privacy statement, and the settings you choose in your dashboard (conversation storage, unanswered-question logging, escalation mode and address).
- We process outside your instructions only where EU or member state law requires it; in that case we inform you of the legal requirement before processing, unless that law prohibits it.
- We inform you without delay if, in our opinion, an instruction infringes the GDPR or other EU or member state data protection law.
3. Confidentiality
Persons authorised by us to process the data are bound by confidentiality. We do not sell the data and do not use it to train AI models.
4. Security
We implement and maintain the technical and organisational measures in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, so that they provide a level of security appropriate to the risk (art. 32 GDPR). We may update Annex 2, but not in a way that lowers the level of protection.
5. Sub-processors
- You authorise the sub-processors in Annex 3 (art. 28(2) GDPR).
- We impose on every sub-processor, by contract, data protection obligations equivalent to those in this agreement, and we remain fully liable to you for the sub-processor's performance (art. 28(4) GDPR).
- We announce the addition or replacement of a sub-processor by email to your account address at least 14 days before it takes effect. If you object on reasonable data protection grounds and we cannot offer a solution, you may terminate by deleting your account; fees for the remaining paid period after termination are refunded pro rata.
6. Assistance
- Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures, as far as reasonably possible, in answering data subject requests under chapter III GDPR. Requests reaching us directly are forwarded to you without undue delay; we do not answer them on your behalf.
- We assist you, taking into account the nature of the processing and the information available to us, with your obligations under arts. 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation).
7. Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting the data in Annex 1, at your account email address. The notification describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We document breaches and keep you informed as the investigation develops.
8. Deletion and return
- During the term you can retrieve the data yourself: document text, escalated questions, logged unanswered questions and stored conversations are readable and individually deletable in your dashboard.
- Deleting a document, an escalation, a logged question or a stored conversation removes it immediately. Deleting your account removes all data in Annex 1, unless EU or member state law requires storage.
- Backups kept for disaster recovery expire within 30 days of deletion.
9. Audits
We make available to you the information necessary to demonstrate compliance with art. 28 GDPR, in the first place through this agreement, the privacy statement and Annex 2. Where the GDPR gives you an audit right that this information does not satisfy, we allow an audit by you or an auditor mandated by you, at most once per twelve months, on 30 days written notice, during business hours, without access to other customers' data, at your cost.
10. International transfers
We process and store the data in Annex 1 in the European Union. Where a sub-processor processes data outside the EU or EEA, the transfer is covered by the mechanism named in Annex 3 (an adequacy decision, the EU-US Data Privacy Framework, or the European Commission's Standard Contractual Clauses).
11. Final provisions
- This agreement is part of the terms of service; the terms' liability provisions apply to it. Where this agreement and the terms conflict on the processing of personal data, this agreement prevails.
- Dutch law applies. Changes to this agreement follow the terms' change procedure (30 days notice by email; termination right on material disadvantage).
- Questions: support@faqplus.app.
Annex 1: processing details
- Subject matter: operating a chat page that answers your visitors' questions from your documents, with escalation of unanswered questions to you.
- Duration: the lifetime of your account, plus the deletion periods below.
- Nature and purpose: storing document text; generating AI answers from it; transmitting chat messages to the AI model provider for answer generation; emailing escalated questions to you; optional storage of conversations and unanswered questions for you to read; abuse prevention.
- Categories of data subjects: visitors of your chat page; the persons whose personal data your documents contain, where they contain any.
- Categories of personal data: chat messages, which may contain whatever a visitor writes; the email address and optional note a visitor submits when escalating a question; a hashed, non-reversible form of the visitor's IP address; personal data contained in your documents. The terms prohibit uploading special categories of personal data and data of children; the service is not designed for them.
- Retention: document text, escalations and logged unanswered questions until you delete them or your account; stored conversations at most 30 days; hashed IP addresses at most one month; conversations not stored at your choice are not retained at all. Chat messages sent to Anthropic for answer generation are deleted by Anthropic within 30 days; messages flagged for abuse can be kept by Anthropic up to two years under its API terms.
Annex 2: technical and organisational measures
- All traffic encrypted in transit (TLS); stored data encrypted at rest by our hosting provider.
- Data stored in the European Union (Cloudflare EU region).
- Passwords stored as salted PBKDF2 hashes; session cookies and verification links HMAC-signed and time-limited.
- Visitor IP addresses stored only as non-reversible HMAC hashes, for abuse limits.
- The operator dashboard sits behind Cloudflare Access with additional token verification; there are no shared accounts.
- Bot protection (Cloudflare Turnstile) and rate limiting on chat and authentication endpoints.
- Data minimisation by design: uploaded files are discarded after text extraction; conversations are not stored unless you enable storage; the visitor's escalation email address never passes through the AI model.
- Backups for disaster recovery, retained at most 30 days.
- Software changes are version-controlled.
Annex 3: sub-processors
- Cloudflare, Inc. (US) — hosting, database, storage, bot protection. Data stored in the EU region. Transfer mechanism: EU-US Data Privacy Framework.
- Anthropic, PBC (US) — AI answer generation. Processing in the United States. Transfer mechanism: Standard Contractual Clauses, in its data processing agreement.
- Plus Five Five, Inc. (Resend) (US) — email delivery. EU region. Transfer mechanism: Standard Contractual Clauses, in its data processing agreement.
Stripe processes billing data as an independent controller and is therefore not a sub-processor under this agreement.