Data Processing Agreement

You own your customers’ data. This explains what we do with it on your behalf, and the promises we make about it.

Last updated: September 16, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Customer”) and KA Digital Labs LLC, a North Carolina limited liability company doing business as SiteMind. It applies whenever we handle personal data on your behalf. If this DPA and the Terms disagree about personal data, this DPA wins.

1. Who Is Responsible For What

You are the controller. You decide whose data is collected and why, because it is your website, your visitors, and your business.

We are the processor. We handle that data only to run the service for you, and only as this agreement and your instructions allow. Where United States state privacy laws use the words “business” and “service provider” instead, you are the business and we are the service provider.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use your visitors’ data to build products for anyone else.

2. What We Process, And Why

Using the service tells us to do the following, and nothing beyond it:

  • Read the pages of the website you connect, so the assistant can answer from your content.
  • Receive and answer questions your visitors type into the chat widget.
  • Capture contact details a visitor chooses to give you, and pass them to you as leads.
  • Book appointments when a visitor asks to, and notify you.
  • Keep records so you can see conversations, leads and analytics in your dashboard.
  • Keep the service secure, available, and working correctly.

If you ask us in writing to stop processing in a particular way, we will, unless the law requires otherwise. If an instruction from you would break the law, we will tell you instead of following it.

3. Whose Data, And What Kind

  • Your visitors. The questions they type and the answers they receive, a random session identifier, the page they were on, the site that referred them, and any advertising parameters in the link they followed.
  • People who contact you. Name, email address, phone number, and whatever they write in a message or appointment note, when they choose to give it.
  • You and your team. Name, email address, role, and sign-in records.

We never store a visitor’s IP address. Addresses are held in memory to limit abuse and are never written to our database. We do not store the full browser identification string either. We keep one coarse label per website, such as “Chrome on macOS”, to confirm your widget is installed and working.

The service is not built for special categories of data such as health, biometric or financial account records, and it is not built to collect data from children. Please do not use it to gather that kind of information.

4. How Long We Keep It

These are deleted automatically, by a job that runs every day:

  • Chat conversations: 180 days.
  • Analytics and marketing records: 365 days.
  • Notifications: 90 days.

These are kept for as long as you keep them, because they are yours to manage:

  • Leads and appointments, including the contact details a visitor gave you and the part of their message that produced the lead. We do not delete these on a timer. They stay until you delete them, or until your account closes.
  • The page content and facts we read from your website, for as long as that site is connected. Remove a site and it stops answering immediately; we hold its content for 90 days so you can bring it back, then remove it from our live systems.
  • Records of a visitor accepting the AI notice, for as long as your account is open. They are the evidence that the notice was shown, so deleting them would destroy the proof.

You can export all of this yourself at any time, and delete all of it from your account settings.

5. When You Leave

When you close or delete your account we keep your data for 30 days in case you change your mind, then remove it from our live systems. You can export everything before you go. If you ask us to delete it from our live systems sooner, we will.

Encrypted disaster-recovery backups are separate from live systems. Backups are scheduled to expire 30 days after creation, with daily cleanup; deletion is not instant and may be delayed by a storage outage. A backup made during your account recovery window may therefore remain after that window ends. We restrict access to backups and do not use deleted data for normal service operations. Before a restored backup can return to service, we must reapply deletions; if we cannot verify that, the restored service stays unavailable.

We may keep records required by law, such as billing records. We also keep limited deletion records in our separate backup-recovery journal to prevent deleted data from returning through a restore. These contain account or record identifiers and deletion times, not messages or contact details. Records in this journal are scheduled for removal 60 days after the recorded deletion, with daily cleanup; storage outages may delay cleanup.

6. Helping You Answer Your Visitors

If one of your visitors asks you to show them their data, correct it, or delete it, that request is yours to answer, because you are the controller. We will help you do it.

Your dashboard lets you search and export the records we hold for you, and lets you delete everything at once from your account settings. There is no button for deleting one single lead or conversation yet, so for an individual record, email support@sitemind.bot and we will action it within 10 business days. If a visitor contacts us directly, we will not answer for you. We will tell them to contact you, and let you know it happened.

7. Security

  • Data is encrypted in transit. Our infrastructure provider encrypts it at rest.
  • Dashboard access requires a password or a Google sign-in, and sessions expire.
  • Each account’s data is separated, so one customer cannot read another’s.
  • Only people who need access to run the service have it, and they are bound to keep it confidential.
  • We keep our software patched, and scan our dependencies for known vulnerabilities before every release to production and once a week.

No service can promise perfect security. We will keep these measures at least as strong as described here for as long as you are a customer.

8. If There Is A Breach

If personal data we hold for you is lost, exposed, or accessed by someone who should not have it, we will tell you without undue delay and within 72 hours of becoming aware.

We will tell you what happened, which data and roughly how many people are affected, what we have done about it, and what we suggest you do. We will keep you updated as we learn more. You decide whether your visitors or a regulator need to be told, and we will give you what you need to do that.

9. Companies That Help Us

Running the service means trusting a small number of other companies. You agree to our using them. Each is bound by terms at least as protective as this agreement, and we remain responsible to you for what they do.

  • Railway — hosting and databases (United States).
  • Cloudflare — three jobs. It shields the service from attack and stores uploaded files. It runs the “are you human?” check on our sign-up and chat forms, which sees the visitor’s IP address and loads a small script into the page. And it holds our off-site backups: an encrypted copy of the whole database, uploaded on a schedule, so we can restore the service after a disaster.
  • OpenRouter — routes every request we make to an AI model. It receives your page content, images from your site, your visitors’ questions, and our draft answers. OpenRouter passes each request on to the model provider we picked for that job.
  • Mistral, reached through OpenRouter — writes the answers your visitors see.
  • Anthropic, reached through OpenRouter — reads your website during setup, reads images on your pages, checks that a live answer is actually supported by your content, and drafts suggestions for you inside your dashboard.
  • Stripe — payments. Receives your billing details, not your visitors’ data.
  • Google — sign-in and calendar booking, if you connect it.
  • Resend — sends email such as lead notifications.
  • Twilio — sends text messages, using your own Twilio account if you connect one.
  • PostHog — product analytics. No PostHog code runs inside the chat widget and it stores nothing in your visitors’ browsers. Our own server does send PostHog counts of widget activity, recorded against your account, never against an individual visitor.
  • Sentry — error reporting and performance monitoring. When the dashboard hits an error it sends Sentry a recording of the screen with all text masked out, so we can see what broke without seeing your data.

Separately, you can tell us to send your leads somewhere: an email address, a webhook of your choosing, or a chat channel such as Slack or Microsoft Teams. Where you send your own leads is your decision and your transfer, not ours. The same applies if you connect your own text-message provider. We pass on the lead you asked us to pass on, and nothing else.

We keep this list current. Before we add or replace one, we will post the change here and email the address on your account at least 30 days beforehand. If you object on reasonable data-protection grounds, tell us within those 30 days and we will work with you; if we cannot resolve it, you may cancel without penalty and we will refund any unused prepaid fees.

10. Where Your Data Is

Our application and database are hosted in the United States. We currently offer a US-first pilot for ordinary business questions and lead capture, not a service approved for every country or every type of data.

This agreement does not include completed European Commission Standard Contractual Clauses or a United Kingdom Addendum. We do not currently support deployments that require EU or UK international-transfer safeguards. Do not connect a site or send us data that requires those safeguards until the required arrangements have been completed and separately approved by both parties in writing. Contact support@sitemind.bot before using the service if you are unsure.

A US business or billing address alone does not resolve this: your visitors and the laws that apply to their data also matter. We do not automatically block visitors by country. This launch scope does not waive anyone’s rights under applicable privacy law.

11. Showing You We Are Doing This

If you need to check we are meeting this agreement, ask us and we will answer your questions in writing and share what documentation we have. If that genuinely is not enough for your own legal obligations, you may audit us, or appoint an independent auditor to, no more than once a year and after 30 days’ notice, at your cost, at a time that does not disrupt the service. If a regulator requires an audit sooner, we will cooperate.

12. Our Own Records

We keep a record of the processing we carry out for customers, and we will give you a copy on request so you can meet your own record-keeping duties.

13. Liability

The limits and exclusions in section 13 of the Terms of Service apply to this agreement too, and the total for both together is capped once, not twice.

14. Changes

If we change this agreement we will update this page and the date at the top. For a change that materially reduces your protection, we will email the address on your account at least 30 days before it takes effect.

15. Contact

Privacy questions go to support@sitemind.bot.

KA Digital Labs LLC
4030 Wake Forest Road, Ste 349, Raleigh, NC 27609, USA

The short version

It is your data. We only touch it to run the service for you.

We tell you within 72 hours if anything goes wrong, and 30 days before we change who helps us.

Leave whenever you like. Export your data before closing your account. Live-system deletion and backup expiry follow the separate timelines in section 5.