← Back to stirel.com

Data processing addendum

How we process personal data on behalf of the businesses that use Stirel. Last updated 15 September 2026.

This addendum forms part of the terms of service between Prime Frame LLC ("we", the processor) and each business that uses Stirel (the "business", the controller). It applies whenever we process personal data on the business's behalf and meets the requirements of Article 28 of the GDPR. Where Malaysian, Singaporean or Mexican law applies, it sets out our obligations as a data processor, data intermediary or encargado under that law. On data protection it prevails over the terms. A business that needs a signed copy can ask for one at [email protected].

1. What is processed

PurposeAnswering visitors and customers on the business's behalf on its website, shop and WhatsApp number; showing those conversations in its dashboard; passing conversations to a person; reporting which conversations ended in a sale.
DurationWhile the business uses Stirel, plus the deletion periods in section 9.
People concernedVisitors to the business's website or shop, people who write to its WhatsApp number, and the business's staff who use the dashboard.
DataMessages and replies; contact details a person chooses to leave; text transcribed from voice notes; WhatsApp phone number and profile name; a random visitor identifier; pages and products viewed and questions asked, stored in the business's own website; order number, amount, currency and status; dashboard users' names and emails.
Sensitive dataNot intended. The business does not use the service to request it.

2. Instructions

We process personal data only on the business's documented instructions, which are these terms, the settings it chooses and its use of the service, unless the law requires otherwise, in which case we tell the business first where the law allows. If we believe an instruction breaks data protection law, we tell the business. We do not use the data for our own purposes, sell it, or use message content to train models.

3. Confidentiality

Everyone we authorise to access personal data is bound by a duty of confidentiality.

4. Security

We apply measures appropriate to the risk, including encryption of stored conversations, encrypted connections, separate storage for each business, access limited to authorised people who need it, backups kept no longer than 14 days, and monitoring of the service. We review these measures as the service changes and do not reduce the overall level of protection.

5. Sub-processors

The business gives general authorisation for us to use sub-processors in these categories: hosting and network, language models, speech services, messaging platforms, and email for service notices. We bind each one to data protection obligations that are in substance the same as these, and we remain responsible for their work. A current list, with the countries where they process data, is available on request.

We give at least 14 days' notice before adding or replacing a sub-processor. The business can object on reasonable data protection grounds; if we cannot resolve the objection, it can end the affected service without penalty.

6. International transfers

Personal data may be processed in Singapore, China, the United States and the European Union. Where a transfer from the European Economic Area requires it, the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, module two, are incorporated into this addendum, with the business as data exporter and us as data importer; the sections of this addendum provide the information their annexes require, and for the United Kingdom the UK addendum to those clauses applies. For onward transfers to sub-processors we use the safeguards available for each destination. A business can require, before it goes live, that its account uses only providers that do not process data in China.

7. Help with requests and obligations

Taking into account the nature of the processing and the information available to us, we help the business answer requests from people exercising their rights, and meet its obligations on security, breach notification, impact assessments and consultation with authorities. The dashboard lets the business see and delete conversations itself. If a request reaches us directly, we pass it to the business and do not answer on its behalf unless it asks us to.

8. Personal data breaches

We notify the business without undue delay, and no later than 48 hours after becoming aware of a breach affecting its personal data. The notice includes what we know at that point: what happened, the categories and approximate number of people and records affected, the likely consequences, and the measures taken or proposed. We add information as we learn more. Notifying a breach is not an admission of fault.

9. Deletion at the end

While it uses Stirel, the business can delete conversations from its dashboard. When it stops, it can ask within 30 days for a copy of its conversations in a common format. We then delete its live data within 7 days, and backups within a further 14 days, unless the law requires us to keep something. Visitor history stored in the business's own website remains under its control and is removed from there.

10. Audits

We make available the information needed to show that we meet this addendum and answer a reasonable security questionnaire once a year. Where the law requires more, we allow an audit by the business or an independent auditor it appoints, with 30 days' notice, during business hours, under confidentiality, at the business's cost, and without access to other businesses' data.

11. The business's responsibilities

The business is responsible for having a legal basis for the processing, for informing its visitors and customers, for obtaining any consent its law requires, including for cookies, for giving lawful instructions, and for keeping on the notice that tells visitors they are talking to an automated assistant.

12. Liability and duration

Each side's liability under this addendum is subject to the limitations in the terms of service, except where the law or the standard contractual clauses do not allow it. This addendum lasts for as long as we process personal data on the business's behalf.