Legal
masterweb.ai Data Processing Addendum
Version 1.0, effective October 2, 2026
This Data Processing Addendum ("DPA") is part of the masterweb.ai Terms of Service ("Terms") between TECNOLOGIA MASTERWEB SAS (NIT 900.947.569-8), operating the Masterweb AI brand, located at Carrera 64 No. 24-47, Bogota 111321, Colombia ("we", "us", "Processor"), and the business that buys our services ("Customer", "you", "Controller"). It applies automatically when you accept the Terms.
1. Definitions
- Visitors: people who visit or interact with the Customer's website, including people who use the chatbot or submit forms.
- Visitor Data: personal information about Visitors that we process on the Customer's behalf through the service.
- Processing: any operation on Visitor Data, such as collecting, storing, using, transmitting or deleting it.
- Subprocessor: a third party we engage to process Visitor Data for us.
- Security Incident: a confirmed breach of security that leads to unauthorized access to, or accidental or unlawful loss, destruction, alteration or disclosure of, Visitor Data.
- Data Protection Laws: the privacy and data security laws of the United States and its states that apply to the processing, including Fla. Stat. 501.171 and, when they apply, comprehensive state privacy laws such as the California Consumer Privacy Act.
Other capitalized terms have the meaning given in the Terms.
2. Roles
2.1 The Customer is the controller (or "business") of Visitor Data. It decides why and how Visitor Data is processed.
2.2 We are the processor (or "service provider") of Visitor Data. We process it only on the Customer's behalf to provide the service.
2.3 For information about the Customer itself and its staff (for example account and billing contacts), we act as an independent controller under our Privacy Policy, and this DPA does not apply to that information.
3. Details of the processing
The subject matter, nature, purpose, duration, types of data and categories of people involved are described in Annex 1.
4. Customer responsibilities
The Customer:
- 4.1 is responsible for having a lawful basis, and any consents required, for the Visitor Data it asks us to process;
- 4.2 publishes its own privacy notice on its website, describing the chatbot, the recording of conversations, the use of AI providers, forms and analytics;
- 4.3 keeps the AI assistant and recording disclosures that our chatbot shows, and adds any other notice or consent that the law requires on its website;
- 4.4 obtains prior express written consent before asking us to send text or WhatsApp messages to Visitors, if that feature becomes available, and honors opt-outs;
- 4.5 does not use the service to collect sensitive information (such as health information, payment card numbers, government ID numbers or precise geolocation) or information from children under 13, unless we agree in writing to specific safeguards;
- 4.6 gives us instructions that comply with Data Protection Laws.
5. Our obligations
We:
- 5.1 Follow instructions. Process Visitor Data only to provide the service, under the Terms, this DPA and the Customer's documented instructions (including settings the Customer chooses in the service). If we believe an instruction breaks the law, we tell the Customer. If the law requires us to process Visitor Data in another way, we tell the Customer first unless the law forbids it.
- 5.2 Keep it confidential. Make sure people who access Visitor Data are bound by confidentiality obligations and access it only as needed.
- 5.3 Protect it. Maintain the security measures in Annex 2.
- 5.4 Do not sell it. We do not sell or share Visitor Data for cross-context behavioral advertising, do not use it for our own purposes outside the business relationship with the Customer, and do not combine it with personal information from other sources except as allowed by Data Protection Laws to provide the service.
- 5.5 Do not train AI models with it. We do not use Visitor Data to train AI models, and we do not allow our Subprocessors to do so.
- 5.6 Comply with state laws when they apply. When a comprehensive state privacy law applies to the processing, we comply with the service provider or processor obligations of that law, and we notify the Customer if we can no longer meet them.
6. Subprocessors
6.1 Authorization. The Customer gives us general authorization to use Subprocessors in these categories: AI (LLM) providers, hosting and infrastructure providers, email delivery providers, security and anti-bot services and, if the feature is enabled, text messaging providers. The current list is available on request at [email protected].
6.2 Our responsibility. We bind each Subprocessor by a written agreement with data protection obligations that are at least as protective as this DPA for the service it provides, including no training of AI models on Visitor Data. We remain responsible for our Subprocessors' performance.
6.3 Changes. We notify the Customer at least 30 days before adding or replacing a Subprocessor, unless an urgent change is needed for security or continuity of the service, in which case we notify as soon as possible. The Customer may object on reasonable data protection grounds. If we cannot address the objection, the Customer may cancel the affected service without a reactivation fee or other penalty and receive a refund of prepaid fees for the unused period.
7. Security Incidents
7.1 We notify the Customer without undue delay, and in any case within 72 hours after we confirm a Security Incident affecting its Visitor Data.
7.2 The notice describes, as far as known: what happened, the types of data and approximate number of people affected, the likely consequences, and the measures taken or proposed. We update the information as we learn more.
7.3 We take reasonable steps to contain the incident and reduce its effects, and we give the Customer reasonable help so it can meet its own notice obligations, including the 30-day notice required by Fla. Stat. 501.171.
7.4 Unless the law requires otherwise, the Customer decides whether and how to notify Visitors and authorities, and we do not notify Visitors directly without the Customer's agreement.
8. Assistance
8.1 Visitor requests. If a Visitor contacts us directly with a request about Visitor Data (for example, access or deletion), we send it to the Customer and do not answer it ourselves, unless the Customer asks us to. We give the Customer the tools or help reasonably needed to find, export, correct or delete Visitor Data so it can answer the request.
8.2 Other assistance. We give the Customer reasonable information and help for risk assessments and for questions from authorities about the processing.
9. Return and deletion
9.1 During the service, the Customer can export chatbot conversations and lead data through the service or on request.
9.2 After the service ends, we keep Visitor Data for 60 days so the Customer can request an export or reactivate. After those 60 days we delete Visitor Data, and backups that contain it are removed as they expire on their normal cycle.
9.3 We may keep Visitor Data longer only where the law requires it, and then we keep protecting it under this DPA.
10. Information and audits
On written request, no more than once a year (or after a Security Incident), we give the Customer information reasonably needed to show compliance with this DPA, such as a written description of our security measures and answers to a reasonable security questionnaire. Any on-site audit requires mutual agreement on scope, timing and costs, and must protect the confidentiality of our other customers.
11. Location of processing
11.1 Visitor Data is processed in the United States and Colombia. We protect it as this DPA requires wherever it is processed.
11.2 Colombian law. Because we are a Colombian company, we also act as an Encargado del Tratamiento under Colombian Law 1581 of 2012 and Decree 1377 of 2013 when we process Visitor Data. This DPA serves as the transmission contract required by that law for the processing we do on the Customer's behalf, and our Subprocessors in the United States receive Visitor Data only under it. Section 13 of our Privacy Policy describes our obligations and the data subject rights under Colombian law.
11.3 Possible change of contracting entity. A United States company of our group may take over the service in the future. If that happens, this DPA will be assigned to it together with the Terms, with prior notice to the Customer (Terms, Section 21.3).
12. Liability and order of precedence
12.1 Each party's liability under this DPA is subject to the limitations of liability in the Terms.
12.2 If this DPA conflicts with the Terms on the processing of Visitor Data, this DPA controls.
12.3 This DPA stays in effect as long as we process Visitor Data for the Customer, including during the 60-day period after the service ends.
13. Contact
TECNOLOGIA MASTERWEB SAS (NIT 900.947.569-8), operating the Masterweb AI brand Carrera 64 No. 24-47, Bogota 111321, Colombia Email: [email protected]
Annex 1: Details of the processing
| Item | Description |
|---|---|
| Subject matter | Hosting the Customer's website and operating the AI sales chatbot and related tools on the Customer's website. |
| Nature of processing | Collection, recording, storage, organization, analysis with AI providers, transmission to the Customer, backup and deletion. |
| Purpose | Answering Visitors, capturing leads and requests, helping the Customer follow up, hosting the website and its forms, and keeping the service secure. |
| Duration | The term of the service, plus 60 days after it ends, and until backups expire. |
| Categories of people | Visitors of the Customer's website, including prospects, leads and customers of the Customer who use the chatbot or forms. |
| Types of personal data | Name, email address, phone number, messages and chat transcripts, form submissions, information Visitors choose to share about their needs, appointment details, technical data (IP address, browser, device, pages visited, approximate location derived from IP). |
| Sensitive data | Not intended. The Customer must not configure the service to collect sensitive data (Section 4.5). |
Annex 2: Security measures
We maintain measures appropriate to the risk, including:
- encryption of data in transit (HTTPS/TLS);
- separation of each Customer's data in the platform;
- access to production systems limited to authorized personnel who need it, with individual accounts;
- verification codes and session protections for account access;
- regular backups and documented restore procedures, provided on a commercially reasonable efforts basis;
- automated security updates for the platform and hosted websites;
- anti-bot protection, rate limits and abuse monitoring on forms and chat;
- logging of administrative and security-relevant events;
- confidentiality obligations for staff and contractors;
- an incident response process consistent with Section 7.