1. Scope and parties
This Data Processing Agreement (“DPA”) is an integral part of theTerms of Service between PT Rigo Inovasi Digital (“Processor”, “Chatrigo”) and Customer (“Controller”). The DPA applies when Chatrigo processes personal data on Customer’s behalf in providing the service.
“Customer Data” means personal data that Customer uploads, streams, or instructs to be processed through Chatrigo, including channel conversations, contacts, knowledge, and attachments. This DPA does not govern Chatrigo account data that we process as controller; that is described in thePrivacy Policy.
2. Controller and Processor
Customer determines the purposes and essential means of processing Customer Data. Chatrigo processes Customer Data as processor on Customer’s instructions, in accordance with Law Number 27 of 2022 on Personal Data Protection.
Example: a course provider uses Chatrigo to process WhatsApp chats with its students. That course provider is the controller; Chatrigo processes those conversations on its instructions so the inbox and AI can function.
3. Processing instructions
Chatrigo processes Customer Data only according to Customer’s written instructions. Those instructions include the Terms of Service, this DPA, dashboard configuration (including knowledge, handoff rules, and connected channels), and support requests Customer provides.
Chatrigo will notify Customer if an instruction, in our reasonable judgment, violates the PDP Law, unless law prohibits that notice. Chatrigo does not use Customer Data for its own purposes beyond providing, securing, and improving the service.
4. Confidentiality
Chatrigo keeps Customer Data confidential and limits access to personnel or subprocessors who need to know it to provide the service. Those personnel are bound by confidentiality obligations. Customer Data is not used to train general artificial-intelligence models.
5. Security measures
Chatrigo applies reasonable technical and organizational measures, including:
- encryption of channel credentials and HTTPS transmission;
- role-based access restriction;
- logging of relevant security events; and
- webhook verification and session controls.
Customer is responsible for securing its account side, including team access rights and devices used to sign in to the dashboard.
6. Data-subject requests
Because Customer is the controller, data-subject rights requests relating to Customer Data must be directed to Customer. Chatrigo will reasonably assist Customer, with information available in the service, so Customer can meet its PDP Law obligations.
If a data subject contacts Chatrigo directly about Customer Data, we will direct that request to Customer unless law requires a direct response.
7. Data incidents
If Chatrigo becomes aware of a personal-data protection failure involving Customer Data, we will notify Customer without undue delay, with information reasonably available at the time of notice, so Customer can meet applicable reporting obligations.
Chatrigo will reasonably cooperate in investigation and mitigation. Incident notice is not an admission of fault.
8. Deletion and return
After the service ends or upon Customer’s written instruction, Chatrigo will delete or return Customer Data under our control, except where retention is required by law or needed to resolve disputes, invoices, or limited technical backups.
Customer may export data available in the dashboard while the account is active, according to the features we provide.
9. International transfers
Customer Data may be processed outside Indonesia because infrastructure, AI, email, or channel providers are in other jurisdictions. Those transfers are made to perform the service Customer requested, with reasonable safeguards, in accordance with Article 56 of the PDP Law.
Processing locations per provider are listed on theSubprocessor List.
10. Subprocessors
Chatrigo may engage other processors to process Customer Data. Under the PDP Law, that engagement requires the controller’s written consent. By agreeing to this DPA and using the service, Customer gives written consent to the subprocessors listed athttps://www.chatrigo.id/subprocessors.
If we add or replace a subprocessor in a material way, we will update that list and try to notify Customer via the site or email. Customer may raise a reasonable objection within 14 days. If the objection cannot be accommodated, Customer may stop the affected service under the Terms of Service.
11. Audit and cooperation
Upon a reasonable written request, Chatrigo will provide information needed to demonstrate compliance with this DPA, including a general explanation of security measures. On-site audits are conducted only if written information is insufficient, with notice, confidentiality, and without disrupting operations or other customers’ security.
12. Term
This DPA applies while Chatrigo processes Customer Data and remains binding for provisions that by their nature should survive, including confidentiality, deletion, and liability, in accordance with the Terms of Service.
Questions about this document can be sent to support@chatrigo.id. Address: Jl. Poris Paradise Eksklusif No.A4 No. 23 Ruko Lantai 2, RT.004/RW.003, Poris Gaga, Kec. Batuceper, Kota Tangerang, Banten 15148, Indonesia