Data processing addendum
Effective 7 September 2026. This is the standard DPA for hosted FluxyChat. Print or save this page. A signed PDF with custom clauses is only with a written MSA. Hosted is open beta. Self-host if you need the Worker in your Cloudflare account with no Clerk or Stripe.
- Roles. You (the customer) are the controller of end-user chat, presence, and room documents. FluxyChat is the processor for hosted cloud. If you self-host, you are both controller and operator; this DPA does not apply to your Cloudflare account.
- Subject matter. We process message bodies, room ids, user ids you send, presence and Yjs updates, files you upload to R2, and billing/account data needed to run the service.
- Instructions. We process that data to provide the Worker APIs, dashboard, and related support. We do not sell it. We do not use it to train public models.
- Subprocessors. Listed at /subprocessors. LLM providers only run if you configure in-room agents.
- Security. TLS in transit. Access to hosted production is limited to operators who need it. Report issues via security.txt. This is not a SOC 2 report.
- Assistance. GDPR export and erasure: console Privacy tools, or Worker
GET /gdpr/exportand related delete routes, with a member or admin JWT. - Retention. Defaults are on the privacy policy. You can shorten retention in project settings where the Worker supports it.
- International transfers. Cloudflare and Vercel may process outside the EEA. Their terms apply to those transfers.
- Term. This DPA lasts while you use hosted FluxyChat. After deletion or account close, we delete or anonymize remaining copies on the schedule in the privacy policy, except where law requires a longer hold.
- Liability. Hosted is open beta. Liability is as in the terms. Written SLA only in a signed MSA.
Questions: fluxychat@outlook.com. Privacy policy: /privacy-policy.